Automated report

This commit is contained in:
github-bot 2022-02-16 09:14:28 +00:00
parent 5cee2f03a6
commit 4dfee2f6c1
6 changed files with 123 additions and 123 deletions

View File

@ -1,7 +1,7 @@
<?xml version="1.0" encoding="utf-8"?>
<bom xmlns="http://cyclonedx.org/schema/bom/1.4" serialNumber="urn:uuid:1842114f-d6f2-434f-81f7-d1e4e404476d" version="1">
<bom xmlns="http://cyclonedx.org/schema/bom/1.4" serialNumber="urn:uuid:6a1b3be6-c3d2-468f-b391-6826d9565cf4" version="1">
<metadata>
<timestamp>2022-02-16T02:10:34.172Z</timestamp>
<timestamp>2022-02-16T09:14:26.048Z</timestamp>
<tools>
<tool>
<vendor>AppThreat</vendor>

View File

@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.2
DataLicense: CC0-1.0
SPDXID: SPDXRef-DOCUMENT
DocumentName: Tern report for boxyhq/jackson
DocumentNamespace: https://spdx.org/spdxdocs/tern-report-2.3.0-boxyhq/jackson-e8781e6f-fce6-454a-a755-c4ee36bde62d
DocumentNamespace: https://spdx.org/spdxdocs/tern-report-2.3.0-boxyhq/jackson-f39546e7-5f7b-4734-9078-748a6469fc5d
LicenseListVersion: 3.8
Creator: Tool: tern-2.3.0
Created: 2022-02-16T02:09:57Z
Created: 2022-02-16T09:13:39Z
DocumentComment: <text>This document was generated by the Tern Project: https://github.com/tern-tools/tern</text>
PackageName: boxyhq/jackson
@ -21,14 +21,14 @@ Relationship: SPDXRef-boxyhq/jac-boxyhq/jackson-latest CONTAINS SPDXRef-1a058d53
Relationship: SPDXRef-boxyhq/jac-boxyhq/jackson-latest CONTAINS SPDXRef-be2ae69cd5
Relationship: SPDXRef-boxyhq/jac-boxyhq/jackson-latest CONTAINS SPDXRef-fbaccaf771
Relationship: SPDXRef-boxyhq/jac-boxyhq/jackson-latest CONTAINS SPDXRef-37fd5d56f1
Relationship: SPDXRef-boxyhq/jac-boxyhq/jackson-latest CONTAINS SPDXRef-654f3a0d4a
Relationship: SPDXRef-boxyhq/jac-boxyhq/jackson-latest CONTAINS SPDXRef-1367cdcb13
Relationship: SPDXRef-boxyhq/jac-boxyhq/jackson-latest CONTAINS SPDXRef-b10c35f886
Relationship: SPDXRef-boxyhq/jac-boxyhq/jackson-latest CONTAINS SPDXRef-2b610b74fd
Relationship: SPDXRef-boxyhq/jac-boxyhq/jackson-latest CONTAINS SPDXRef-3b6ea39844
Relationship: SPDXRef-boxyhq/jac-boxyhq/jackson-latest CONTAINS SPDXRef-bcada5d55a
Relationship: SPDXRef-boxyhq/jac-boxyhq/jackson-latest CONTAINS SPDXRef-6e09477446
Relationship: SPDXRef-boxyhq/jac-boxyhq/jackson-latest CONTAINS SPDXRef-573aacfebf
Relationship: SPDXRef-boxyhq/jac-boxyhq/jackson-latest CONTAINS SPDXRef-aec9583af5
Relationship: SPDXRef-boxyhq/jac-boxyhq/jackson-latest CONTAINS SPDXRef-81f47eb772
Relationship: SPDXRef-boxyhq/jac-boxyhq/jackson-latest CONTAINS SPDXRef-7aefe3f152
Relationship: SPDXRef-boxyhq/jac-boxyhq/jackson-latest CONTAINS SPDXRef-3598ccf87e
Relationship: SPDXRef-boxyhq/jac-boxyhq/jackson-latest CONTAINS SPDXRef-b913aa86c5
Relationship: SPDXRef-boxyhq/jac-boxyhq/jackson-latest CONTAINS SPDXRef-1a7c794c48
Relationship: SPDXRef-boxyhq/jac-boxyhq/jackson-latest CONTAINS SPDXRef-eaf05d5537
Relationship: SPDXRef-boxyhq/jac-boxyhq/jackson-latest CONTAINS SPDXRef-f53c16e9a0
PackageName: layer.tar
@ -44,34 +44,34 @@ PackageComment: <text>
Layer 1:
info: Found 'Alpine Linux v3.14' in /etc/os-release.
info: Retrieved by invoking listing in command_lib/base.yml
files:
licenses:
in container:
pkgs=`apk info 2>/dev/null`
for p in $pkgs; do files=`apk -L info $p 2>/dev/null`; for file in $files; do if [ -f $file ]; then echo $file; fi; done; echo LICF; done
names:
in container:
apk info 2>/dev/null
for p in $pkgs; do apk -a info $p 2>/dev/null | tail -2 | head -1; done
proj_urls:
in container:
pkgs=`apk info 2>/dev/null`
for p in $pkgs; do apk info $p 2>/dev/null | head -5 | tail -1; done
names:
in container:
apk info 2>/dev/null
files:
in container:
pkgs=`apk info 2>/dev/null`
for p in $pkgs; do files=`apk -L info $p 2>/dev/null`; for file in $files; do if [ -f $file ]; then echo $file; fi; done; echo LICF; done
versions:
in container:
pkgs=`apk info 2>/dev/null`
for p in $pkgs; do lic=`apk info $p 2>/dev/null | head -1 | awk '{print $1}'`; echo $lic | awk -F "${p}-" '{print $2}'; done
licenses:
in container:
pkgs=`apk info 2>/dev/null`
for p in $pkgs; do apk -a info $p 2>/dev/null | tail -2 | head -1; done
warning: No listing method for 'srcs'. Additional analysis may be required.
No listing method for 'copyrights'. Additional analysis may be required.
warning: No listing method for 'copyrights'. Additional analysis may be required.
No listing method for 'srcs'. Additional analysis may be required.
</text>
@ -144,34 +144,34 @@ fi
info: Retrieved by invoking listing in command_lib/base.yml
files:
licenses:
in container:
pkgs=`apk info 2>/dev/null`
for p in $pkgs; do files=`apk -L info $p 2>/dev/null`; for file in $files; do if [ -f $file ]; then echo $file; fi; done; echo LICF; done
names:
in container:
apk info 2>/dev/null
for p in $pkgs; do apk -a info $p 2>/dev/null | tail -2 | head -1; done
proj_urls:
in container:
pkgs=`apk info 2>/dev/null`
for p in $pkgs; do apk info $p 2>/dev/null | head -5 | tail -1; done
names:
in container:
apk info 2>/dev/null
files:
in container:
pkgs=`apk info 2>/dev/null`
for p in $pkgs; do files=`apk -L info $p 2>/dev/null`; for file in $files; do if [ -f $file ]; then echo $file; fi; done; echo LICF; done
versions:
in container:
pkgs=`apk info 2>/dev/null`
for p in $pkgs; do lic=`apk info $p 2>/dev/null | head -1 | awk '{print $1}'`; echo $lic | awk -F "${p}-" '{print $2}'; done
licenses:
in container:
pkgs=`apk info 2>/dev/null`
for p in $pkgs; do apk -a info $p 2>/dev/null | tail -2 | head -1; done
warning: No listing method for 'srcs'. Additional analysis may be required.
No listing method for 'copyrights'. Additional analysis may be required.
warning: No listing method for 'copyrights'. Additional analysis may be required.
No listing method for 'srcs'. Additional analysis may be required.
</text>
@ -219,7 +219,7 @@ rm yarn-v$YARN_VERSION.tar.gz.asc yarn-v$YARN_VERSION.tar.gz
yarn --version
info: Retrieved by invoking listing in command_lib/base.yml
files:
licenses:
in container:
export NEXT_TELEMETRY_DISABLED=1
export NODE_ENV=production
@ -228,17 +228,7 @@ files:
export NODE_VERSION=16.13.1
export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
pkgs=`apk info 2>/dev/null`
for p in $pkgs; do files=`apk -L info $p 2>/dev/null`; for file in $files; do if [ -f $file ]; then echo $file; fi; done; echo LICF; done
names:
in container:
export NEXT_TELEMETRY_DISABLED=1
export NODE_ENV=production
export NODE_OPTIONS=--max-http-header-size
export YARN_VERSION=1.22.15
export NODE_VERSION=16.13.1
export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
apk info 2>/dev/null
for p in $pkgs; do apk -a info $p 2>/dev/null | tail -2 | head -1; done
proj_urls:
in container:
@ -251,6 +241,27 @@ proj_urls:
pkgs=`apk info 2>/dev/null`
for p in $pkgs; do apk info $p 2>/dev/null | head -5 | tail -1; done
names:
in container:
export NEXT_TELEMETRY_DISABLED=1
export NODE_ENV=production
export NODE_OPTIONS=--max-http-header-size
export YARN_VERSION=1.22.15
export NODE_VERSION=16.13.1
export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
apk info 2>/dev/null
files:
in container:
export NEXT_TELEMETRY_DISABLED=1
export NODE_ENV=production
export NODE_OPTIONS=--max-http-header-size
export YARN_VERSION=1.22.15
export NODE_VERSION=16.13.1
export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
pkgs=`apk info 2>/dev/null`
for p in $pkgs; do files=`apk -L info $p 2>/dev/null`; for file in $files; do if [ -f $file ]; then echo $file; fi; done; echo LICF; done
versions:
in container:
export NEXT_TELEMETRY_DISABLED=1
@ -262,21 +273,10 @@ versions:
pkgs=`apk info 2>/dev/null`
for p in $pkgs; do lic=`apk info $p 2>/dev/null | head -1 | awk '{print $1}'`; echo $lic | awk -F "${p}-" '{print $2}'; done
licenses:
in container:
export NEXT_TELEMETRY_DISABLED=1
export NODE_ENV=production
export NODE_OPTIONS=--max-http-header-size
export YARN_VERSION=1.22.15
export NODE_VERSION=16.13.1
export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
pkgs=`apk info 2>/dev/null`
for p in $pkgs; do apk -a info $p 2>/dev/null | tail -2 | head -1; done
warning: No listing method for 'srcs'. Additional analysis may be required.
No listing method for 'copyrights'. Additional analysis may be required.
warning: No listing method for 'copyrights'. Additional analysis may be required.
No listing method for 'srcs'. Additional analysis may be required.
</text>
@ -301,11 +301,11 @@ Unrecognized Commands:#(nop) COPY file:4d192565a7220e135cab6c77fbc1c73211b69f3d9
Relationship: SPDXRef-37fd5d56f1 HAS_PREREQUISITE SPDXRef-fbaccaf771
PackageName: layer.tar
SPDXID: SPDXRef-654f3a0d4a
PackageFileName: f6dffbda1d5d5285adf463b5e9f46b3748618b09dfc66622476f1c7cd645e2ca/layer.tar
PackageDownloadLocation: f6dffbda1d5d5285adf463b5e9f46b3748618b09dfc66622476f1c7cd645e2ca/layer.tar
SPDXID: SPDXRef-aec9583af5
PackageFileName: e11c21989a428917ab08c0d28fec04f5b40053d0fd81e5d5a126301817cb4409/layer.tar
PackageDownloadLocation: e11c21989a428917ab08c0d28fec04f5b40053d0fd81e5d5a126301817cb4409/layer.tar
FilesAnalyzed: false
PackageChecksum: SHA256: 654f3a0d4aa1c0ad3d272190cded41fed51aa36aa04c1535ffac54fa23deb347
PackageChecksum: SHA256: aec9583af512ad346bb32300c8091f0ebe55236f8cc088b73ea4f19b39450ff2
PackageLicenseConcluded: NOASSERTION
PackageLicenseDeclared: NOASSERTION
PackageCopyrightText: NOASSERTION
@ -316,13 +316,13 @@ Layer 5:
</text>
Relationship: SPDXRef-654f3a0d4a HAS_PREREQUISITE SPDXRef-37fd5d56f1
Relationship: SPDXRef-aec9583af5 HAS_PREREQUISITE SPDXRef-37fd5d56f1
PackageName: layer.tar
SPDXID: SPDXRef-1367cdcb13
PackageFileName: 46e72f1a41cf9fd44759ac1c8e56c6c5c0fef7534646b4fd985aae78b8efe860/layer.tar
PackageDownloadLocation: 46e72f1a41cf9fd44759ac1c8e56c6c5c0fef7534646b4fd985aae78b8efe860/layer.tar
SPDXID: SPDXRef-81f47eb772
PackageFileName: db38d91fcbe46b4bbdf2a813598c29f5a3087fbc93e00490d1c4e06e459c6d4c/layer.tar
PackageDownloadLocation: db38d91fcbe46b4bbdf2a813598c29f5a3087fbc93e00490d1c4e06e459c6d4c/layer.tar
FilesAnalyzed: false
PackageChecksum: SHA256: 1367cdcb13e5f91c51ae686c888df48f4da3d224e4577405e58ec2fcec7f93e5
PackageChecksum: SHA256: 81f47eb7727254fe8b6db8fca411a74ff90a9e8b6b9e1f35af65ba56a5293541
PackageLicenseConcluded: NOASSERTION
PackageLicenseDeclared: NOASSERTION
PackageCopyrightText: NOASSERTION
@ -334,13 +334,13 @@ Unrecognized Commands:RUN addgroup -g 1001 -S nodejs # buildkit
</text>
Relationship: SPDXRef-1367cdcb13 HAS_PREREQUISITE SPDXRef-654f3a0d4a
Relationship: SPDXRef-81f47eb772 HAS_PREREQUISITE SPDXRef-aec9583af5
PackageName: layer.tar
SPDXID: SPDXRef-b10c35f886
PackageFileName: 70037c360529d842d565c0976191d1f056430becc443a9dc717dfbbdff2cddd6/layer.tar
PackageDownloadLocation: 70037c360529d842d565c0976191d1f056430becc443a9dc717dfbbdff2cddd6/layer.tar
SPDXID: SPDXRef-7aefe3f152
PackageFileName: b42fef188f100d0c148d69e1a6a0578e37330e243b2bd95f9600d70fe48fc64d/layer.tar
PackageDownloadLocation: b42fef188f100d0c148d69e1a6a0578e37330e243b2bd95f9600d70fe48fc64d/layer.tar
FilesAnalyzed: false
PackageChecksum: SHA256: b10c35f886bcc78f2e3b6a722b3e107c10d418c9193b86bb7e0e6a1860c5e5aa
PackageChecksum: SHA256: 7aefe3f152f07bc1d097f78785b6461405e7be9afc53cb57deb78cec9700bbae
PackageLicenseConcluded: NOASSERTION
PackageLicenseDeclared: NOASSERTION
PackageCopyrightText: NOASSERTION
@ -352,13 +352,13 @@ Unrecognized Commands:RUN adduser -S nextjs -u 1001 # buildkit
</text>
Relationship: SPDXRef-b10c35f886 HAS_PREREQUISITE SPDXRef-1367cdcb13
Relationship: SPDXRef-7aefe3f152 HAS_PREREQUISITE SPDXRef-81f47eb772
PackageName: layer.tar
SPDXID: SPDXRef-2b610b74fd
PackageFileName: b7558f53ac3b7989234fe7f2814f4a30c825bb5c616245e9a051ad7a404bc361/layer.tar
PackageDownloadLocation: b7558f53ac3b7989234fe7f2814f4a30c825bb5c616245e9a051ad7a404bc361/layer.tar
SPDXID: SPDXRef-3598ccf87e
PackageFileName: 6be7b4f90dd66472ec98fe0e86c7d55941da3a64a78e21b839641fa84774d9da/layer.tar
PackageDownloadLocation: 6be7b4f90dd66472ec98fe0e86c7d55941da3a64a78e21b839641fa84774d9da/layer.tar
FilesAnalyzed: false
PackageChecksum: SHA256: 2b610b74fdb3281bf1afccf0e425f107a3ec72328522b978f5c850c74f5370e0
PackageChecksum: SHA256: 3598ccf87e8b0b5915855c8123755873640532e213135b5f6c1c01b86a7f5575
PackageLicenseConcluded: NOASSERTION
PackageLicenseDeclared: NOASSERTION
PackageCopyrightText: NOASSERTION
@ -369,13 +369,13 @@ Layer 8:
</text>
Relationship: SPDXRef-2b610b74fd HAS_PREREQUISITE SPDXRef-b10c35f886
Relationship: SPDXRef-3598ccf87e HAS_PREREQUISITE SPDXRef-7aefe3f152
PackageName: layer.tar
SPDXID: SPDXRef-3b6ea39844
PackageFileName: c705e72c771715617f2ed5a74b97e5beae1f7ef2f55381d81d83e72b356584aa/layer.tar
PackageDownloadLocation: c705e72c771715617f2ed5a74b97e5beae1f7ef2f55381d81d83e72b356584aa/layer.tar
SPDXID: SPDXRef-b913aa86c5
PackageFileName: 1c458e17fc9c18b3e436394d53a9f821713a908c0ca792bbc6b7c85b18540f4c/layer.tar
PackageDownloadLocation: 1c458e17fc9c18b3e436394d53a9f821713a908c0ca792bbc6b7c85b18540f4c/layer.tar
FilesAnalyzed: false
PackageChecksum: SHA256: 3b6ea39844075f4fd24d869478d46ebc5dee9d1c22855b8b93bc6ef7280437f4
PackageChecksum: SHA256: b913aa86c5862e9f3fd98689f72c51f130c8201fe1739946815fa83e45f77cc1
PackageLicenseConcluded: NOASSERTION
PackageLicenseDeclared: NOASSERTION
PackageCopyrightText: NOASSERTION
@ -386,13 +386,13 @@ Layer 9:
</text>
Relationship: SPDXRef-3b6ea39844 HAS_PREREQUISITE SPDXRef-2b610b74fd
Relationship: SPDXRef-b913aa86c5 HAS_PREREQUISITE SPDXRef-3598ccf87e
PackageName: layer.tar
SPDXID: SPDXRef-bcada5d55a
PackageFileName: 765f485cafa3670c41a1778e7c6202c3fab57d464dd9e7c44be52f6a0ff9b2af/layer.tar
PackageDownloadLocation: 765f485cafa3670c41a1778e7c6202c3fab57d464dd9e7c44be52f6a0ff9b2af/layer.tar
SPDXID: SPDXRef-1a7c794c48
PackageFileName: f2ae6674294177b5876499e87791c677b1b1951dbf4d962d9c3349988ab37b2d/layer.tar
PackageDownloadLocation: f2ae6674294177b5876499e87791c677b1b1951dbf4d962d9c3349988ab37b2d/layer.tar
FilesAnalyzed: false
PackageChecksum: SHA256: bcada5d55acbd6af2d44ad9c8cb6102feca0c47b332f21742f5f37c44024652f
PackageChecksum: SHA256: 1a7c794c48169216b28c4ae028277611f61648bb548c29d884f3351601f6bac8
PackageLicenseConcluded: NOASSERTION
PackageLicenseDeclared: NOASSERTION
PackageCopyrightText: NOASSERTION
@ -403,13 +403,13 @@ Layer 10:
</text>
Relationship: SPDXRef-bcada5d55a HAS_PREREQUISITE SPDXRef-3b6ea39844
Relationship: SPDXRef-1a7c794c48 HAS_PREREQUISITE SPDXRef-b913aa86c5
PackageName: layer.tar
SPDXID: SPDXRef-6e09477446
PackageFileName: 5573d0a3ddb973af973882bfaa05365c631505e45708239fe20ba62ab18ec664/layer.tar
PackageDownloadLocation: 5573d0a3ddb973af973882bfaa05365c631505e45708239fe20ba62ab18ec664/layer.tar
SPDXID: SPDXRef-eaf05d5537
PackageFileName: 78f740758f55de4b0d4ae7174fb6fecb0f43fb1458b64f85749bea1b666da107/layer.tar
PackageDownloadLocation: 78f740758f55de4b0d4ae7174fb6fecb0f43fb1458b64f85749bea1b666da107/layer.tar
FilesAnalyzed: false
PackageChecksum: SHA256: 6e094774463402d15b876a761311cf45fc7d29104ba18a96a09ba89bc00cdc3a
PackageChecksum: SHA256: eaf05d553754646fff7fc6e93018918b3023e1a46280e2708a6b182313c749c5
PackageLicenseConcluded: NOASSERTION
PackageLicenseDeclared: NOASSERTION
PackageCopyrightText: NOASSERTION
@ -420,13 +420,13 @@ Layer 11:
</text>
Relationship: SPDXRef-6e09477446 HAS_PREREQUISITE SPDXRef-bcada5d55a
Relationship: SPDXRef-eaf05d5537 HAS_PREREQUISITE SPDXRef-1a7c794c48
PackageName: layer.tar
SPDXID: SPDXRef-573aacfebf
PackageFileName: c204855865e77cbbab4b42fd26698569ba46aa79df3a697dcd2e018e99d268a0/layer.tar
PackageDownloadLocation: c204855865e77cbbab4b42fd26698569ba46aa79df3a697dcd2e018e99d268a0/layer.tar
SPDXID: SPDXRef-f53c16e9a0
PackageFileName: 79bb3dc192252898f8b9614689732849a66b28ae39f420a36f645663c26984f6/layer.tar
PackageDownloadLocation: 79bb3dc192252898f8b9614689732849a66b28ae39f420a36f645663c26984f6/layer.tar
FilesAnalyzed: false
PackageChecksum: SHA256: 573aacfebf777d9079fd9627a18de212c19b1b60ee7e03c29adbb17dc6003da2
PackageChecksum: SHA256: f53c16e9a0f52353423deff19146a107dfee6db0697e6278235568f1167ef8e9
PackageLicenseConcluded: NOASSERTION
PackageLicenseDeclared: NOASSERTION
PackageCopyrightText: NOASSERTION
@ -437,7 +437,7 @@ Layer 12:
</text>
Relationship: SPDXRef-573aacfebf HAS_PREREQUISITE SPDXRef-6e09477446
Relationship: SPDXRef-f53c16e9a0 HAS_PREREQUISITE SPDXRef-eaf05d5537
PackageName: musl
SPDXID: SPDXRef-musl-1.2.2-r3
PackageVersion: 1.2.2-r3
@ -919,23 +919,23 @@ libstdc++:
</text>
LicenseID: LicenseRef-5a8406a
ExtractedText: <text>Original license: BSD-2-Clause AND BSD-3-Clause</text>
LicenseID: LicenseRef-c66410f
ExtractedText: <text>Original license: GPL-2.0-only</text>
LicenseID: LicenseRef-6aefaec
ExtractedText: <text>Original license: ISC AND (BSD-3-Clause OR MIT)</text>
LicenseID: LicenseRef-de5acdd
ExtractedText: <text>Original license: OpenSSL</text>
LicenseID: LicenseRef-f262406
ExtractedText: <text>Original license: Zlib</text>
LicenseID: LicenseRef-c66410f
ExtractedText: <text>Original license: GPL-2.0-only</text>
LicenseID: LicenseRef-5a8406a
ExtractedText: <text>Original license: BSD-2-Clause AND BSD-3-Clause</text>
LicenseID: LicenseRef-d312664
ExtractedText: <text>Original license: MIT BSD GPL2+</text>
LicenseID: LicenseRef-9661d80
ExtractedText: <text>Original license: GPL-2.0-or-later LGPL-2.1-or-later</text>
LicenseID: LicenseRef-c7ea3b7
ExtractedText: <text>Original license: MIT</text>
LicenseID: LicenseRef-86d0cc1
ExtractedText: <text>Original license: MPL-2.0 AND MIT</text>
LicenseID: LicenseRef-9661d80
ExtractedText: <text>Original license: GPL-2.0-or-later LGPL-2.1-or-later</text>
LicenseID: LicenseRef-f262406
ExtractedText: <text>Original license: Zlib</text>
LicenseID: LicenseRef-d312664
ExtractedText: <text>Original license: MIT BSD GPL2+</text>
LicenseID: LicenseRef-c7ea3b7
ExtractedText: <text>Original license: MIT</text>

View File

@ -1,7 +1,7 @@
<?xml version="1.0" encoding="UTF-8"?>
<bom xmlns="http://cyclonedx.org/schema/bom/1.3" serialNumber="urn:uuid:14dd12a3-b2bd-40da-8ecf-3873b8f25fb4" version="1">
<bom xmlns="http://cyclonedx.org/schema/bom/1.3" serialNumber="urn:uuid:ff54be2a-62a5-462c-9436-e48afeca06c5" version="1">
<metadata>
<timestamp>2022-02-16T02:08:14Z</timestamp>
<timestamp>2022-02-16T09:11:51Z</timestamp>
<tools>
<tool>
<vendor>anchore</vendor>

View File

@ -2,11 +2,11 @@ SPDXVersion: SPDX-2.2
DataLicense: CC0-1.0
SPDXID: SPDXRef-DOCUMENT
DocumentName: .
DocumentNamespace: https://anchore.com/syft/dir/7e8daf8d-f091-478c-b6a9-afdbedbfde40
DocumentNamespace: https://anchore.com/syft/dir/d75df552-f7e7-4df4-a903-fa9216b22aa7
LicenseListVersion: 3.15
Creator: Organization: Anchore, Inc
Creator: Tool: syft-0.33.0
Created: 2022-02-16T02:08:06Z
Created: 2022-02-16T09:11:50Z
##### Package: @ampproject/remapping

View File

@ -1,7 +1,7 @@
<?xml version="1.0" encoding="UTF-8"?>
<bom xmlns="http://cyclonedx.org/schema/bom/1.3" serialNumber="urn:uuid:643deefd-27b4-4d24-8d22-3f706936900d" version="1">
<bom xmlns="http://cyclonedx.org/schema/bom/1.3" serialNumber="urn:uuid:85fb3101-9ab8-4740-8b16-9453802b7f70" version="1">
<metadata>
<timestamp>2022-02-16T02:08:18Z</timestamp>
<timestamp>2022-02-16T09:11:54Z</timestamp>
<tools>
<tool>
<vendor>anchore</vendor>

View File

@ -2,11 +2,11 @@ SPDXVersion: SPDX-2.2
DataLicense: CC0-1.0
SPDXID: SPDXRef-DOCUMENT
DocumentName: .
DocumentNamespace: https://anchore.com/syft/dir/bdd97536-01ef-4ff1-a697-4d35ef1b702b
DocumentNamespace: https://anchore.com/syft/dir/6f00a0fb-80ae-4663-962f-32efa29ededf
LicenseListVersion: 3.15
Creator: Organization: Anchore, Inc
Creator: Tool: syft-0.33.0
Created: 2022-02-16T02:08:17Z
Created: 2022-02-16T09:11:53Z
##### Package: @ampproject/remapping