{
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:01feaacd-0cc3-4421-8bea-400147c6cf33",
  "version": 1,
  "metadata": {
    "timestamp": "2026-10-10T21:14:38.275524+00:00",
    "component": {
      "type": "application",
      "name": "SBOM App 1.2.26",
      "bom-ref": "release-icqhNxeRitYj"
    }
  },
  "components": [
    {
      "bom-ref": "pkg:apk/alpine/busybox-binsh@1.37.0-r31",
      "type": "library",
      "name": "alpine/busybox-binsh",
      "purl": "pkg:apk/alpine/busybox-binsh@1.37.0-r31",
      "version": "1.37.0-r31"
    },
    {
      "bom-ref": "pkg:maven/io.netty/netty-codec-http@4.2.15.final",
      "type": "library",
      "name": "io.netty/netty-codec-http",
      "purl": "pkg:maven/io.netty/netty-codec-http@4.2.15.final",
      "version": "4.2.15.final"
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-60876",
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "detail": "[openvex justification: vulnerable_code_not_in_execute_path]"
      },
      "affects": [
        {
          "ref": "pkg:apk/alpine/busybox-binsh@1.37.0-r31"
        }
      ]
    },
    {
      "id": "GHSA-6JQX-86GH-F27W",
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "detail": "[openvex justification: vulnerable_code_not_in_execute_path]"
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.2.15.final"
        }
      ]
    },
    {
      "id": "GHSA-JPPX-W49H-X2QQ",
      "analysis": {
        "state": "not_affected",
        "justification": "protected_by_mitigating_control",
        "detail": "[openvex justification: inline_mitigations_already_exist]"
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.2.15.final"
        }
      ]
    }
  ]
}