{
  "bomFormat": "CycloneDX",
  "specVersion": "1.7",
  "serialNumber": "urn:uuid:f1aa8221-4f01-454a-9d1e-8e1fd1ec2356",
  "version": 1,
  "metadata": {
    "timestamp": "2026-09-09T18:26:21Z",
    "tools": {
      "components": [
        {
          "group": "@cyclonedx",
          "name": "cdxgen",
          "version": "12.8.4",
          "purl": "pkg:npm/%40cyclonedx/cdxgen@12.8.4",
          "type": "application",
          "bom-ref": "pkg:npm/@cyclonedx/cdxgen@12.8.4",
          "publisher": "OWASP Foundation",
          "authors": [
            {
              "name": "OWASP Foundation"
            }
          ]
        }
      ]
    },
    "authors": [
      {
        "name": "OWASP Foundation"
      }
    ],
    "lifecycles": [
      {
        "phase": "pre-build"
      }
    ],
    "component": {
      "name": "npm-path",
      "group": "",
      "version": "1.1.0",
      "description": "Get a PATH with all executables available to npm scripts.",
      "purl": "pkg:npm/npm-path@1.1.0",
      "bom-ref": "pkg:npm/npm-path@1.1.0",
      "author": "Tim Oxley",
      "properties": [
        {
          "name": "cdx:npm:bin",
          "value": "npm-path"
        },
        {
          "name": "cdx:npm:has_binary",
          "value": "true"
        },
        {
          "name": "cdx:npm:scripts",
          "value": "test"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "type": "application",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/timoxley/npm-path"
        },
        {
          "type": "vcs",
          "url": "https://github.com/timoxley/npm-path.git"
        }
      ]
    },
    "properties": [
      {
        "name": "cdx:bom:componentTypes",
        "value": "npm"
      },
      {
        "name": "cdx:bom:componentSrcFiles",
        "value": "node_modules/balanced-match/package.json\\nnode_modules/brace-expansion/package.json\\nnode_modules/concat-map/package.json\\nnode_modules/core-util-is/package.json\\nnode_modules/deep-equal/package.json\\nnode_modules/define-properties/package.json\\nnode_modules/defined/package.json\\nnode_modules/duplexer/package.json\\nnode_modules/es-abstract/package.json\\nnode_modules/es-to-primitive/package.json\\nnode_modules/faucet/node_modules/deep-equal/package.json\\nnode_modules/faucet/node_modules/tape/package.json\\nnode_modules/faucet/package.json\\nnode_modules/foreach/package.json\\nnode_modules/function-bind/package.json\\nnode_modules/glob/package.json\\nnode_modules/has/package.json\\nnode_modules/inflight/package.json\\nnode_modules/inherits/package.json\\nnode_modules/is-absolute/package.json\\nnode_modules/is-callable/package.json\\nnode_modules/is-date-object/package.json\\nnode_modules/is-regex/package.json\\nnode_modules/is-relative/package.json\\nnode_modules/is-symbol/package.json\\nnode_modules/isarray/package.json\\nnode_modules/isexe/package.json\\nnode_modules/jsonify/package.json\\nnode_modules/minimatch/package.json\\nnode_modules/minimist/package.json\\nnode_modules/npm/node_modules/abbrev/package.json\\nnode_modules/npm/node_modules/ansi-regex/package.json\\nnode_modules/npm/node_modules/ansicolors/package.json\\nnode_modules/npm/node_modules/ansistyles/package.json\\nnode_modules/npm/node_modules/aproba/package.json\\nnode_modules/npm/node_modules/archy/package.json\\nnode_modules/npm/node_modules/async-some/package.json\\nnode_modules/npm/node_modules/chownr/package.json\\nnode_modules/npm/node_modules/cmd-shim/package.json\\nnode_modules/npm/node_modules/columnify/node_modules/wcwidth/node_modules/defaults/node_modules/clone/package.json\\nnode_modules/npm/node_modules/columnify/node_modules/wcwidth/node_modules/defaults/package.json\\nnode_modules/npm/node_modules/columnify/node_modules/wcwidth/package.json\\nnode_modules/npm/node_modules/columnify/package.json\\nnode_modules/npm/node_modules/config-chain/node_modules/proto-list/package.json\\nnode_modules/npm/node_modules/config-chain/package.json\\nnode_modules/npm/node_modules/debuglog/package.json\\nnode_modules/npm/node_modules/dezalgo/node_modules/asap/package.json\\nnode_modules/npm/node_modules/dezalgo/package.json\\nnode_modules/npm/node_modules/editor/package.json\\nnode_modules/npm/node_modules/fs-vacuum/package.json\\nnode_modules/npm/node_modules/fs-write-stream-atomic/package.json\\nnode_modules/npm/node_modules/fstream-npm/node_modules/fstream-ignore/node_modules/minimatch/node_modules/brace-expansion/node_modules/balanced-match/package.json\\nnode_modules/npm/node_modules/fstream-npm/node_modules/fstream-ignore/node_modules/minimatch/node_modules/brace-expansion/node_modules/concat-map/package.json\\nnode_modules/npm/node_modules/fstream-npm/node_modules/fstream-ignore/node_modules/minimatch/node_modules/brace-expansion/package.json\\nnode_modules/npm/node_modules/fstream-npm/node_modules/fstream-ignore/node_modules/minimatch/package.json\\nnode_modules/npm/node_modules/fstream-npm/node_modules/fstream-ignore/package.json\\nnode_modules/npm/node_modules/fstream-npm/package.json\\nnode_modules/npm/node_modules/fstream/package.json\\nnode_modules/npm/node_modules/glob/node_modules/minimatch/node_modules/brace-expansion/node_modules/balanced-match/package.json\\nnode_modules/npm/node_modules/glob/node_modules/minimatch/node_modules/brace-expansion/node_modules/concat-map/package.json\\nnode_modules/npm/node_modules/glob/node_modules/minimatch/node_modules/brace-expansion/package.json\\nnode_modules/npm/node_modules/glob/node_modules/minimatch/package.json\\nnode_modules/npm/node_modules/glob/node_modules/path-is-absolute/package.json\\nnode_modules/npm/node_modules/glob/package.json\\nnode_modules/npm/node_modules/graceful-fs/package.json\\nnode_modules/npm/node_modules/has-unicode/package.json\\nnode_modules/npm/node_modules/hosted-git-info/package.json\\nnode_modules/npm/node_modules/iferr/package.json\\nnode_modules/npm/node_modules/imurmurhash/package.json\\nnode_modules/npm/node_modules/inflight/package.json\\nnode_modules/npm/node_modules/inherits/package.json\\nnode_modules/npm/node_modules/ini/package.json\\nnode_modules/npm/node_modules/init-package-json/node_modules/promzard/example/npm-init/package.json\\nnode_modules/npm/node_modules/init-package-json/node_modules/promzard/package.json\\nnode_modules/npm/node_modules/init-package-json/package.json\\nnode_modules/npm/node_modules/lockfile/package.json\\nnode_modules/npm/node_modules/lodash._baseindexof/package.json\\nnode_modules/npm/node_modules/lodash._baseuniq/package.json\\nnode_modules/npm/node_modules/lodash._bindcallback/package.json\\nnode_modules/npm/node_modules/lodash._cacheindexof/package.json\\nnode_modules/npm/node_modules/lodash._createcache/package.json\\nnode_modules/npm/node_modules/lodash._getnative/package.json\\nnode_modules/npm/node_modules/lodash.clonedeep/node_modules/lodash._arrayeach/package.json\\nnode_modules/npm/node_modules/lodash.clonedeep/node_modules/lodash._basefor/package.json\\nnode_modules/npm/node_modules/lodash.clonedeep/node_modules/lodash._root/package.json\\nnode_modules/npm/node_modules/lodash.clonedeep/node_modules/lodash._stack/node_modules/lodash._mapcache/package.json\\nnode_modules/npm/node_modules/lodash.clonedeep/node_modules/lodash._stack/package.json\\nnode_modules/npm/node_modules/lodash.clonedeep/package.json\\nnode_modules/npm/node_modules/lodash.isarguments/package.json\\nnode_modules/npm/node_modules/lodash.isarray/package.json\\nnode_modules/npm/node_modules/lodash.keys/package.json\\nnode_modules/npm/node_modules/lodash.restparam/package.json\\nnode_modules/npm/node_modules/lodash.union/node_modules/lodash._arrayincludes/package.json\\nnode_modules/npm/node_modules/lodash.union/node_modules/lodash._arrayincludeswith/package.json\\nnode_modules/npm/node_modules/lodash.union/node_modules/lodash._baseflatten/package.json\\nnode_modules/npm/node_modules/lodash.union/node_modules/lodash._cachehas/package.json\\nnode_modules/npm/node_modules/lodash.union/node_modules/lodash._root/package.json\\nnode_modules/npm/node_modules/lodash.union/node_modules/lodash._setcache/node_modules/lodash._mapcache/package.json\\nnode_modules/npm/node_modules/lodash.union/node_modules/lodash._setcache/package.json\\nnode_modules/npm/node_modules/lodash.union/node_modules/lodash.rest/package.json\\nnode_modules/npm/node_modules/lodash.union/package.json\\nnode_modules/npm/node_modules/lodash.uniq/node_modules/lodash._arrayincludes/package.json\\nnode_modules/npm/node_modules/lodash.uniq/node_modules/lodash._arrayincludeswith/package.json\\nnode_modules/npm/node_modules/lodash.uniq/node_modules/lodash._cachehas/package.json\\nnode_modules/npm/node_modules/lodash.uniq/node_modules/lodash._root/package.json\\nnode_modules/npm/node_modules/lodash.uniq/node_modules/lodash._setcache/node_modules/lodash._mapcache/package.json\\nnode_modules/npm/node_modules/lodash.uniq/node_modules/lodash._setcache/package.json\\nnode_modules/npm/node_modules/lodash.uniq/package.json\\nnode_modules/npm/node_modules/lodash.without/node_modules/lodash._arrayincludes/package.json\\nnode_modules/npm/node_modules/lodash.without/node_modules/lodash._arrayincludeswith/package.json\\nnode_modules/npm/node_modules/lodash.without/node_modules/lodash._arraymap/package.json\\nnode_modules/npm/node_modules/lodash.without/node_modules/lodash._cachehas/package.json\\nnode_modules/npm/node_modules/lodash.without/node_modules/lodash._setcache/node_modules/lodash._mapcache/package.json\\nnode_modules/npm/node_modules/lodash.without/node_modules/lodash._setcache/package.json\\nnode_modules/npm/node_modules/lodash.without/node_modules/lodash.rest/package.json\\nnode_modules/npm/node_modules/lodash.without/package.json\\nnode_modules/npm/node_modules/mkdirp/node_modules/minimist/package.json\\nnode_modules/npm/node_modules/mkdirp/package.json\\nnode_modules/npm/node_modules/node-gyp/node_modules/glob/node_modules/minimatch/node_modules/brace-expansion/node_modules/balanced-match/package.json\\nnode_modules/npm/node_modules/node-gyp/node_modules/glob/node_modules/minimatch/node_modules/brace-expansion/node_modules/concat-map/package.json\\nnode_modules/npm/node_modules/node-gyp/node_modules/glob/node_modules/minimatch/node_modules/brace-expansion/package.json\\nnode_modules/npm/node_modules/node-gyp/node_modules/glob/node_modules/minimatch/package.json\\nnode_modules/npm/node_modules/node-gyp/node_modules/glob/package.json\\nnode_modules/npm/node_modules/node-gyp/node_modules/minimatch/node_modules/lru-cache/package.json\\nnode_modules/npm/node_modules/node-gyp/node_modules/minimatch/node_modules/sigmund/package.json\\nnode_modules/npm/node_modules/node-gyp/node_modules/minimatch/package.json\\nnode_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/ansi/package.json\\nnode_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/are-we-there-yet/node_modules/delegates/package.json\\nnode_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/are-we-there-yet/package.json\\nnode_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/gauge/node_modules/lodash.pad/node_modules/lodash.repeat/package.json\\nnode_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/gauge/node_modules/lodash.pad/package.json\\nnode_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padleft/node_modules/lodash._basetostring/package.json\\nnode_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padleft/node_modules/lodash._createpadding/node_modules/lodash.repeat/package.json\\nnode_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padleft/node_modules/lodash._createpadding/package.json\\nnode_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padleft/package.json\\nnode_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padright/node_modules/lodash._basetostring/package.json\\nnode_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padright/node_modules/lodash._createpadding/node_modules/lodash.repeat/package.json\\nnode_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padright/node_modules/lodash._createpadding/package.json\\nnode_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padright/package.json\\nnode_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/gauge/package.json\\nnode_modules/npm/node_modules/node-gyp/node_modules/npmlog/package.json\\nnode_modules/npm/node_modules/node-gyp/node_modules/path-array/node_modules/array-index/node_modules/debug/node_modules/ms/package.json\\nnode_modules/npm/node_modules/node-gyp/node_modules/path-array/node_modules/array-index/node_modules/debug/package.json\\nnode_modules/npm/node_modules/node-gyp/node_modules/path-array/node_modules/array-index/node_modules/es6-symbol/node_modules/d/package.json\\nnode_modules/npm/node_modules/node-gyp/node_modules/path-array/node_modules/array-index/node_modules/es6-symbol/node_modules/es5-ext/node_modules/es6-iterator/package.json\\nnode_modules/npm/node_modules/node-gyp/node_modules/path-array/node_modules/array-index/node_modules/es6-symbol/node_modules/es5-ext/package.json\\nnode_modules/npm/node_modules/node-gyp/node_modules/path-array/node_modules/array-index/node_modules/es6-symbol/package.json\\nnode_modules/npm/node_modules/node-gyp/node_modules/path-array/node_modules/array-index/package.json\\nnode_modules/npm/node_modules/node-gyp/node_modules/path-array/package.json\\nnode_modules/npm/node_modules/node-gyp/package.json\\nnode_modules/npm/node_modules/nopt/package.json\\nnode_modules/npm/node_modules/normalize-git-url/package.json\\nnode_modules/npm/node_modules/normalize-package-data/node_modules/is-builtin-module/node_modules/builtin-modules/package.json\\nnode_modules/npm/node_modules/normalize-package-data/node_modules/is-builtin-module/package.json\\nnode_modules/npm/node_modules/normalize-package-data/package.json\\nnode_modules/npm/node_modules/npm-cache-filename/package.json\\nnode_modules/npm/node_modules/npm-install-checks/package.json\\nnode_modules/npm/node_modules/npm-package-arg/package.json\\nnode_modules/npm/node_modules/npm-registry-client/node_modules/concat-stream/node_modules/typedarray/package.json\\nnode_modules/npm/node_modules/npm-registry-client/node_modules/concat-stream/package.json\\nnode_modules/npm/node_modules/npm-registry-client/node_modules/retry/package.json\\nnode_modules/npm/node_modules/npm-registry-client/package.json\\nnode_modules/npm/node_modules/npm-user-validate/package.json\\nnode_modules/npm/node_modules/npmlog/node_modules/ansi/package.json\\nnode_modules/npm/node_modules/npmlog/node_modules/are-we-there-yet/node_modules/delegates/package.json\\nnode_modules/npm/node_modules/npmlog/node_modules/are-we-there-yet/package.json\\nnode_modules/npm/node_modules/npmlog/node_modules/gauge/node_modules/lodash.pad/node_modules/lodash.repeat/package.json\\nnode_modules/npm/node_modules/npmlog/node_modules/gauge/node_modules/lodash.pad/package.json\\nnode_modules/npm/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padleft/node_modules/lodash._basetostring/package.json\\nnode_modules/npm/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padleft/node_modules/lodash._createpadding/node_modules/lodash.repeat/package.json\\nnode_modules/npm/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padleft/node_modules/lodash._createpadding/package.json\\nnode_modules/npm/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padleft/package.json\\nnode_modules/npm/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padright/node_modules/lodash._basetostring/package.json\\nnode_modules/npm/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padright/node_modules/lodash._createpadding/node_modules/lodash.repeat/package.json\\nnode_modules/npm/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padright/node_modules/lodash._createpadding/package.json\\nnode_modules/npm/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padright/package.json\\nnode_modules/npm/node_modules/npmlog/node_modules/gauge/package.json\\nnode_modules/npm/node_modules/npmlog/package.json\\nnode_modules/npm/node_modules/once/package.json\\nnode_modules/npm/node_modules/opener/package.json\\nnode_modules/npm/node_modules/osenv/node_modules/os-homedir/package.json\\nnode_modules/npm/node_modules/osenv/node_modules/os-tmpdir/package.json\\nnode_modules/npm/node_modules/osenv/package.json\\nnode_modules/npm/node_modules/path-is-inside/package.json\\nnode_modules/npm/node_modules/read-cmd-shim/package.json\\nnode_modules/npm/node_modules/read-installed/node_modules/util-extend/package.json\\nnode_modules/npm/node_modules/read-installed/package.json\\nnode_modules/npm/node_modules/read-installed/test/fixtures/extraneous-detected/package.json\\nnode_modules/npm/node_modules/read-installed/test/fixtures/extraneous-dev-dep/package.json\\nnode_modules/npm/node_modules/read-installed/test/fixtures/grandparent-peer-dev/package.json\\nnode_modules/npm/node_modules/read-installed/test/fixtures/grandparent-peer/package.json\\nnode_modules/npm/node_modules/read-installed/test/fixtures/package.json\\nnode_modules/npm/node_modules/read-package-json/node_modules/json-parse-helpfulerror/node_modules/jju/package.json\\nnode_modules/npm/node_modules/read-package-json/node_modules/json-parse-helpfulerror/package.json\\nnode_modules/npm/node_modules/read-package-json/package.json\\nnode_modules/npm/node_modules/read-package-json/test/fixtures/readmes/package.json\\nnode_modules/npm/node_modules/read-package-tree/package.json\\nnode_modules/npm/node_modules/read-package-tree/test/fixtures/root/package.json\\nnode_modules/npm/node_modules/read-package-tree/test/fixtures/selflink/package.json\\nnode_modules/npm/node_modules/read/node_modules/mute-stream/package.json\\nnode_modules/npm/node_modules/read/package.json\\nnode_modules/npm/node_modules/readable-stream/node_modules/core-util-is/package.json\\nnode_modules/npm/node_modules/readable-stream/node_modules/isarray/package.json\\nnode_modules/npm/node_modules/readable-stream/node_modules/process-nextick-args/package.json\\nnode_modules/npm/node_modules/readable-stream/node_modules/string_decoder/package.json\\nnode_modules/npm/node_modules/readable-stream/node_modules/util-deprecate/package.json\\nnode_modules/npm/node_modules/readable-stream/package.json\\nnode_modules/npm/node_modules/readdir-scoped-modules/package.json\\nnode_modules/npm/node_modules/realize-package-specifier/package.json\\nnode_modules/npm/node_modules/request/node_modules/aws-sign2/package.json\\nnode_modules/npm/node_modules/request/node_modules/aws4/node_modules/lru-cache/package.json\\nnode_modules/npm/node_modules/request/node_modules/aws4/package.json\\nnode_modules/npm/node_modules/request/node_modules/bl/package.json\\nnode_modules/npm/node_modules/request/node_modules/caseless/package.json\\nnode_modules/npm/node_modules/request/node_modules/combined-stream/node_modules/delayed-stream/package.json\\nnode_modules/npm/node_modules/request/node_modules/combined-stream/package.json\\nnode_modules/npm/node_modules/request/node_modules/extend/package.json\\nnode_modules/npm/node_modules/request/node_modules/forever-agent/package.json\\nnode_modules/npm/node_modules/request/node_modules/form-data/node_modules/async/package.json\\nnode_modules/npm/node_modules/request/node_modules/form-data/package.json\\nnode_modules/npm/node_modules/request/node_modules/har-validator/node_modules/chalk/node_modules/ansi-styles/package.json\\nnode_modules/npm/node_modules/request/node_modules/har-validator/node_modules/chalk/node_modules/escape-string-regexp/package.json\\nnode_modules/npm/node_modules/request/node_modules/har-validator/node_modules/chalk/node_modules/has-ansi/package.json\\nnode_modules/npm/node_modules/request/node_modules/har-validator/node_modules/chalk/node_modules/supports-color/package.json\\nnode_modules/npm/node_modules/request/node_modules/har-validator/node_modules/chalk/package.json\\nnode_modules/npm/node_modules/request/node_modules/har-validator/node_modules/commander/node_modules/graceful-readlink/package.json\\nnode_modules/npm/node_modules/request/node_modules/har-validator/node_modules/commander/package.json\\nnode_modules/npm/node_modules/request/node_modules/har-validator/node_modules/is-my-json-valid/node_modules/generate-function/package.json\\nnode_modules/npm/node_modules/request/node_modules/har-validator/node_modules/is-my-json-valid/node_modules/generate-object-property/node_modules/is-property/package.json\\nnode_modules/npm/node_modules/request/node_modules/har-validator/node_modules/is-my-json-valid/node_modules/generate-object-property/package.json\\nnode_modules/npm/node_modules/request/node_modules/har-validator/node_modules/is-my-json-valid/node_modules/jsonpointer/package.json\\nnode_modules/npm/node_modules/request/node_modules/har-validator/node_modules/is-my-json-valid/node_modules/xtend/package.json\\nnode_modules/npm/node_modules/request/node_modules/har-validator/node_modules/is-my-json-valid/package.json\\nnode_modules/npm/node_modules/request/node_modules/har-validator/node_modules/pinkie-promise/node_modules/pinkie/package.json\\nnode_modules/npm/node_modules/request/node_modules/har-validator/node_modules/pinkie-promise/package.json\\nnode_modules/npm/node_modules/request/node_modules/har-validator/package.json\\nnode_modules/npm/node_modules/request/node_modules/hawk/node_modules/boom/package.json\\nnode_modules/npm/node_modules/request/node_modules/hawk/node_modules/cryptiles/package.json\\nnode_modules/npm/node_modules/request/node_modules/hawk/node_modules/hoek/package.json\\nnode_modules/npm/node_modules/request/node_modules/hawk/node_modules/sntp/package.json\\nnode_modules/npm/node_modules/request/node_modules/hawk/package.json\\nnode_modules/npm/node_modules/request/node_modules/http-signature/node_modules/assert-plus/package.json\\nnode_modules/npm/node_modules/request/node_modules/http-signature/node_modules/jsprim/node_modules/extsprintf/package.json\\nnode_modules/npm/node_modules/request/node_modules/http-signature/node_modules/jsprim/node_modules/json-schema/package.json\\nnode_modules/npm/node_modules/request/node_modules/http-signature/node_modules/jsprim/node_modules/verror/package.json\\nnode_modules/npm/node_modules/request/node_modules/http-signature/node_modules/jsprim/package.json\\nnode_modules/npm/node_modules/request/node_modules/http-signature/node_modules/sshpk/node_modules/asn1/package.json\\nnode_modules/npm/node_modules/request/node_modules/http-signature/node_modules/sshpk/node_modules/dashdash/package.json\\nnode_modules/npm/node_modules/request/node_modules/http-signature/node_modules/sshpk/node_modules/ecc-jsbn/package.json\\nnode_modules/npm/node_modules/request/node_modules/http-signature/node_modules/sshpk/node_modules/jodid25519/package.json\\nnode_modules/npm/node_modules/request/node_modules/http-signature/node_modules/sshpk/node_modules/jsbn/package.json\\nnode_modules/npm/node_modules/request/node_modules/http-signature/node_modules/sshpk/node_modules/tweetnacl/package.json\\nnode_modules/npm/node_modules/request/node_modules/http-signature/node_modules/sshpk/package.json\\nnode_modules/npm/node_modules/request/node_modules/http-signature/package.json\\nnode_modules/npm/node_modules/request/node_modules/is-typedarray/package.json\\nnode_modules/npm/node_modules/request/node_modules/isstream/package.json\\nnode_modules/npm/node_modules/request/node_modules/json-stringify-safe/package.json\\nnode_modules/npm/node_modules/request/node_modules/mime-types/node_modules/mime-db/package.json\\nnode_modules/npm/node_modules/request/node_modules/mime-types/package.json\\nnode_modules/npm/node_modules/request/node_modules/node-uuid/package.json\\nnode_modules/npm/node_modules/request/node_modules/oauth-sign/package.json\\nnode_modules/npm/node_modules/request/node_modules/qs/package.json\\nnode_modules/npm/node_modules/request/node_modules/stringstream/package.json\\nnode_modules/npm/node_modules/request/node_modules/tough-cookie/package.json\\nnode_modules/npm/node_modules/request/node_modules/tunnel-agent/package.json\\nnode_modules/npm/node_modules/request/package.json\\nnode_modules/npm/node_modules/retry/package.json\\nnode_modules/npm/node_modules/rimraf/package.json\\nnode_modules/npm/node_modules/semver/package.json\\nnode_modules/npm/node_modules/sha/package.json\\nnode_modules/npm/node_modules/slide/package.json\\nnode_modules/npm/node_modules/sorted-object/package.json\\nnode_modules/npm/node_modules/strip-ansi/package.json\\nnode_modules/npm/node_modules/tar/node_modules/block-stream/package.json\\nnode_modules/npm/node_modules/tar/package.json\\nnode_modules/npm/node_modules/text-table/package.json\\nnode_modules/npm/node_modules/uid-number/package.json\\nnode_modules/npm/node_modules/umask/package.json\\nnode_modules/npm/node_modules/unique-filename/node_modules/unique-slug/package.json\\nnode_modules/npm/node_modules/unique-filename/package.json\\nnode_modules/npm/node_modules/unpipe/package.json\\nnode_modules/npm/node_modules/validate-npm-package-license/node_modules/spdx-correct/node_modules/spdx-license-ids/package.json\\nnode_modules/npm/node_modules/validate-npm-package-license/node_modules/spdx-correct/package.json\\nnode_modules/npm/node_modules/validate-npm-package-license/node_modules/spdx-expression-parse/node_modules/spdx-exceptions/package.json\\nnode_modules/npm/node_modules/validate-npm-package-license/node_modules/spdx-expression-parse/node_modules/spdx-license-ids/package.json\\nnode_modules/npm/node_modules/validate-npm-package-license/node_modules/spdx-expression-parse/package.json\\nnode_modules/npm/node_modules/validate-npm-package-license/package.json\\nnode_modules/npm/node_modules/validate-npm-package-name/node_modules/builtins/package.json\\nnode_modules/npm/node_modules/validate-npm-package-name/package.json\\nnode_modules/npm/node_modules/which/node_modules/is-absolute/node_modules/is-relative/package.json\\nnode_modules/npm/node_modules/which/node_modules/is-absolute/package.json\\nnode_modules/npm/node_modules/which/node_modules/isexe/package.json\\nnode_modules/npm/node_modules/which/package.json\\nnode_modules/npm/node_modules/wrappy/package.json\\nnode_modules/npm/node_modules/write-file-atomic/package.json\\nnode_modules/npm/package.json\\nnode_modules/npm/test/disabled/bundlerecurs/package.json\\nnode_modules/npm/test/disabled/change-bin-1/package.json\\nnode_modules/npm/test/disabled/change-bin-2/package.json\\nnode_modules/npm/test/disabled/failer/package.json\\nnode_modules/npm/test/disabled/fast/package.json\\nnode_modules/npm/test/disabled/package-bar/package.json\\nnode_modules/npm/test/disabled/package-config/package.json\\nnode_modules/npm/test/disabled/package-foo/package.json\\nnode_modules/npm/test/disabled/slow/package.json\\nnode_modules/npm/test/packages/npm-test-array-bin/package.json\\nnode_modules/npm/test/packages/npm-test-blerg/package.json\\nnode_modules/npm/test/packages/npm-test-blerg3/package.json\\nnode_modules/npm/test/packages/npm-test-bundled-git/package.json\\nnode_modules/npm/test/packages/npm-test-dir-bin/package.json\\nnode_modules/npm/test/packages/npm-test-env-reader/package.json\\nnode_modules/npm/test/packages/npm-test-files/package.json\\nnode_modules/npm/test/packages/npm-test-ignore-nested-nm/package.json\\nnode_modules/npm/test/packages/npm-test-ignore/package.json\\nnode_modules/npm/test/packages/npm-test-missing-bindir/package.json\\nnode_modules/npm/test/packages/npm-test-optional-deps/package.json\\nnode_modules/npm/test/packages/npm-test-platform-all/package.json\\nnode_modules/npm/test/packages/npm-test-platform/package.json\\nnode_modules/npm/test/packages/npm-test-private/package.json\\nnode_modules/npm/test/packages/npm-test-shrinkwrap/package.json\\nnode_modules/npm/test/packages/npm-test-test-package/package.json\\nnode_modules/npm/test/packages/npm-test-url-dep/package.json\\nnode_modules/object-inspect/package.json\\nnode_modules/object-keys/package.json\\nnode_modules/once/package.json\\nnode_modules/path-is-absolute/package.json\\nnode_modules/readable-stream/package.json\\nnode_modules/resolve/package.json\\nnode_modules/resolve/test/pathfilter/deep_ref/node_modules/deep/package.json\\nnode_modules/resumer/package.json\\nnode_modules/sprintf/package.json\\nnode_modules/string.prototype.trim/package.json\\nnode_modules/string_decoder/package.json\\nnode_modules/tap-parser/package.json\\nnode_modules/tape/node_modules/defined/package.json\\nnode_modules/tape/node_modules/minimist/package.json\\nnode_modules/tape/package.json\\nnode_modules/through/package.json\\nnode_modules/through2/package.json\\nnode_modules/which/package.json\\nnode_modules/wrappy/package.json\\nnode_modules/xtend/node_modules/object-keys/package.json\\nnode_modules/xtend/package.json"
      }
    ]
  },
  "components": [
    {
      "authors": [
        {
          "name": "Raynos <raynos2@gmail.com>"
        }
      ],
      "group": "",
      "name": "xtend",
      "version": "2.1.2",
      "description": "extend like a boss",
      "scope": "optional",
      "purl": "pkg:npm/xtend@2.1.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/Raynos/xtend"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/xtend@2.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/xtend/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/xtend/package.json"
              }
            ],
            "concludedValue": "node_modules/xtend/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jordan Harband"
        }
      ],
      "group": "",
      "name": "object-keys",
      "version": "0.4.0",
      "description": "An Object.keys replacement, in case Object.keys is not available. From https://github.com/kriskowal/es5-shim",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/object-keys@0.4.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/ljharb/object-keys.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/object-keys@0.4.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/xtend/node_modules/object-keys/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/xtend/node_modules/object-keys/package.json"
              }
            ],
            "concludedValue": "node_modules/xtend/node_modules/object-keys/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "wrappy",
      "version": "1.0.1",
      "description": "Callback wrapping utility",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/wrappy@1.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/npm/wrappy"
        },
        {
          "type": "vcs",
          "url": "https://github.com/npm/wrappy"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/wrappy@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/wrappy/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/wrappy/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/wrappy/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/wrappy/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me)"
        }
      ],
      "group": "",
      "name": "which",
      "version": "1.2.4",
      "description": "Like which(1) unix command. Find the first instance of an executable in the PATH.",
      "scope": "required",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/which@1.2.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/node-which.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/which@1.2.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/which/package.json"
        },
        {
          "name": "ImportedModules",
          "value": "which"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/which/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/which/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/which/package.json"
          }
        ],
        "occurrences": [
          {
            "location": "index.js",
            "line": 5
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Rod Vagg <r@va.gg> (https://github.com/rvagg)"
        }
      ],
      "group": "",
      "name": "through2",
      "version": "0.2.3",
      "description": "A tiny wrapper around Node streams2 Transform to avoid explicit subclassing noise",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/through2@0.2.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/rvagg/through2.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/through2@0.2.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/through2/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/through2/package.json"
              }
            ],
            "concludedValue": "node_modules/through2/package.json"
          }
        ]
      },
      "tags": [
        "transform"
      ]
    },
    {
      "authors": [
        {
          "name": "Dominic Tarr <dominic.tarr@gmail.com> (dominictarr.com)"
        }
      ],
      "group": "",
      "name": "through",
      "version": "2.3.8",
      "description": "simplified stream construction",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/through@2.3.8",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/dominictarr/through"
        },
        {
          "type": "vcs",
          "url": "https://github.com/dominictarr/through.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/through@2.3.8",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/through/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/through/package.json"
              }
            ],
            "concludedValue": "node_modules/through/package.json"
          }
        ]
      },
      "tags": [
        "stream"
      ]
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "tape",
      "version": "4.4.0",
      "description": "tap-producing test harness for node and browsers",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/tape@4.4.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/tape"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/tape.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/tape@4.4.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tape/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tape/package.json"
              }
            ],
            "concludedValue": "node_modules/tape/package.json"
          }
        ]
      },
      "tags": [
        "test"
      ]
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "minimist",
      "version": "1.2.0",
      "description": "parse argument options",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/minimist@1.2.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/minimist"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/minimist.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/minimist@1.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tape/node_modules/minimist/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tape/node_modules/minimist/package.json"
              }
            ],
            "concludedValue": "node_modules/tape/node_modules/minimist/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "defined",
      "version": "1.0.0",
      "description": "return the first argument that is `!== undefined`",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/defined@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/defined"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/defined.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/defined@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tape/node_modules/defined/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tape/node_modules/defined/package.json"
              }
            ],
            "concludedValue": "node_modules/tape/node_modules/defined/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "tap-parser",
      "version": "0.4.3",
      "description": "parse the test anything protocol",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/tap-parser@0.4.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/tap-parser"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/tap-parser.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/tap-parser@0.4.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tap-parser/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tap-parser/package.json"
              }
            ],
            "concludedValue": "node_modules/tap-parser/package.json"
          }
        ]
      },
      "tags": [
        "parse",
        "test"
      ]
    },
    {
      "group": "",
      "name": "string_decoder",
      "version": "0.10.31",
      "description": "The string_decoder module from Node core",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/string_decoder@0.10.31",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/rvagg/string_decoder"
        },
        {
          "type": "vcs",
          "url": "git://github.com/rvagg/string_decoder.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/string_decoder@0.10.31",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/string_decoder/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/readable-stream/node_modules/string_decoder/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/readable-stream/node_modules/string_decoder/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/readable-stream/node_modules/string_decoder/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jordan Harband <ljharb@gmail.com> (http://ljharb.codes)"
        }
      ],
      "group": "",
      "name": "string.prototype.trim",
      "version": "1.1.2",
      "description": "ES5 spec-compliant shim for String.prototype.trim",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/string.prototype.trim@1.1.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/es-shims/String.prototype.trim.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/string.prototype.trim@1.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/string.prototype.trim/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/string.prototype.trim/package.json"
              }
            ],
            "concludedValue": "node_modules/string.prototype.trim/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Moritz Peters"
        }
      ],
      "group": "",
      "name": "sprintf",
      "version": "0.1.5",
      "description": "Sprintf() for node.js",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-3-Clause",
            "url": "https://opensource.org/licenses/BSD-3-Clause",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/sprintf@0.1.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/maritz/node-sprintf"
        },
        {
          "type": "vcs",
          "url": "https://github.com/maritz/node-sprintf.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/sprintf@0.1.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/sprintf/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/sprintf/package.json"
              }
            ],
            "concludedValue": "node_modules/sprintf/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "resumer",
      "version": "0.0.0",
      "description": "a through stream that starts paused and resumes on the next tick",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/resumer@0.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/resumer"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/resumer.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/resumer@0.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/resumer/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/resumer/package.json"
              }
            ],
            "concludedValue": "node_modules/resumer/package.json"
          }
        ]
      },
      "tags": [
        "stream"
      ]
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "resolve",
      "version": "1.1.7",
      "description": "resolve like require.resolve() on behalf of files asynchronously and synchronously",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/resolve@1.1.7",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/substack/node-resolve.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/resolve@1.1.7",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/resolve/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/resolve/package.json"
              }
            ],
            "concludedValue": "node_modules/resolve/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "deep",
      "version": "1.2.3",
      "scope": "optional",
      "purl": "pkg:npm/deep@1.2.3",
      "type": "library",
      "bom-ref": "pkg:npm/deep@1.2.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/resolve/test/pathfilter/deep_ref/node_modules/deep/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/resolve/test/pathfilter/deep_ref/node_modules/deep/package.json"
              }
            ],
            "concludedValue": "node_modules/resolve/test/pathfilter/deep_ref/node_modules/deep/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "readable-stream",
      "version": "1.1.13",
      "description": "Streams3, a user-land copy of the stream library from Node.js v0.11.x",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/readable-stream@1.1.13",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/readable-stream"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/readable-stream@1.1.13",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/readable-stream/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/readable-stream/package.json"
              }
            ],
            "concludedValue": "node_modules/readable-stream/package.json"
          }
        ]
      },
      "tags": [
        "stream"
      ]
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "path-is-absolute",
      "version": "1.0.0",
      "description": "Node.js 0.12 path.isAbsolute() ponyfill",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/path-is-absolute@1.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/path-is-absolute@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/path-is-absolute/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/glob/node_modules/path-is-absolute/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/glob/node_modules/path-is-absolute/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/glob/node_modules/path-is-absolute/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "once",
      "version": "1.3.3",
      "description": "Run a function exactly one time",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/once@1.3.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/once"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/once@1.3.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/once/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/once/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/once/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/once/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jordan Harband <ljharb@gmail.com> (http://ljharb.codes)"
        }
      ],
      "group": "",
      "name": "object-keys",
      "version": "1.0.9",
      "description": "An Object.keys replacement, in case Object.keys is not available. From https://github.com/es-shims/es5-shim",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/object-keys@1.0.9",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/ljharb/object-keys.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/object-keys@1.0.9",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/object-keys/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/object-keys/package.json"
              }
            ],
            "concludedValue": "node_modules/object-keys/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "object-inspect",
      "version": "1.0.2",
      "description": "string representations of objects in node and the browser",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/object-inspect@1.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/object-inspect"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/object-inspect.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/object-inspect@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/object-inspect/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/object-inspect/package.json"
              }
            ],
            "concludedValue": "node_modules/object-inspect/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me)"
        }
      ],
      "group": "",
      "name": "npm",
      "version": "3.7.3",
      "description": "a package manager for JavaScript",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Artistic-2.0",
            "url": "https://opensource.org/licenses/Artistic-2.0",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Copyleft Limited"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/npm@3.7.3",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://docs.npmjs.com/"
        },
        {
          "type": "vcs",
          "url": "https://github.com/npm/npm"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/npm@3.7.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Copyleft Limited"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "npm-test-url-dep",
      "version": "1.2.3",
      "scope": "optional",
      "purl": "pkg:npm/npm-test-url-dep@1.2.3",
      "type": "library",
      "bom-ref": "pkg:npm/npm-test-url-dep@1.2.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/test/packages/npm-test-url-dep/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/test/packages/npm-test-url-dep/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/test/packages/npm-test-url-dep/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Testy McMock"
        }
      ],
      "group": "",
      "name": "npm-test-test-package",
      "version": "1.2.3-99-b",
      "description": "This is a test package used for debugging. It has some random data and that's all.",
      "scope": "optional",
      "purl": "pkg:npm/npm-test-test-package@1.2.3-99-b",
      "type": "library",
      "bom-ref": "pkg:npm/npm-test-test-package@1.2.3-99-b",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/test/packages/npm-test-test-package/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/test/packages/npm-test-test-package/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/test/packages/npm-test-test-package/package.json"
          }
        ]
      },
      "tags": [
        "test"
      ]
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "npm-test-shrinkwrap",
      "version": "0.0.0",
      "scope": "optional",
      "purl": "pkg:npm/npm-test-shrinkwrap@0.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/npm-test-shrinkwrap@0.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/test/packages/npm-test-shrinkwrap/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/test/packages/npm-test-shrinkwrap/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/test/packages/npm-test-shrinkwrap/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "npm-test-private",
      "version": "9.9.9-9",
      "scope": "optional",
      "purl": "pkg:npm/npm-test-private@9.9.9-9",
      "externalReferences": [
        {
          "type": "website",
          "url": "http://www.youtube.com/watch?v=1MLry6Cn_D4"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/npm-test-private@9.9.9-9",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/test/packages/npm-test-private/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/test/packages/npm-test-private/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/test/packages/npm-test-private/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "npm-test-platform-all",
      "version": "9.9.9-9",
      "scope": "optional",
      "purl": "pkg:npm/npm-test-platform-all@9.9.9-9",
      "externalReferences": [
        {
          "type": "website",
          "url": "http://www.zombo.com/"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/npm-test-platform-all@9.9.9-9",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/test/packages/npm-test-platform-all/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/test/packages/npm-test-platform-all/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/test/packages/npm-test-platform-all/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "npm-test-platform",
      "version": "9.9.9-9",
      "scope": "optional",
      "purl": "pkg:npm/npm-test-platform@9.9.9-9",
      "externalReferences": [
        {
          "type": "website",
          "url": "http://www.youtube.com/watch?v=dQw4w9WgXcQ"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/npm-test-platform@9.9.9-9",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/test/packages/npm-test-platform/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/test/packages/npm-test-platform/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/test/packages/npm-test-platform/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "npm-test-optional-deps",
      "version": "1.2.5",
      "scope": "optional",
      "purl": "pkg:npm/npm-test-optional-deps@1.2.5",
      "type": "library",
      "bom-ref": "pkg:npm/npm-test-optional-deps@1.2.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/test/packages/npm-test-optional-deps/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/test/packages/npm-test-optional-deps/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/test/packages/npm-test-optional-deps/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "npm-test-missing-bindir",
      "version": "0.0.0",
      "scope": "optional",
      "purl": "pkg:npm/npm-test-missing-bindir@0.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/npm-test-missing-bindir@0.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/test/packages/npm-test-missing-bindir/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/test/packages/npm-test-missing-bindir/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/test/packages/npm-test-missing-bindir/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "npm-test-ignore-nested-nm",
      "version": "1.2.5",
      "scope": "optional",
      "purl": "pkg:npm/npm-test-ignore-nested-nm@1.2.5",
      "type": "library",
      "bom-ref": "pkg:npm/npm-test-ignore-nested-nm@1.2.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/test/packages/npm-test-ignore-nested-nm/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/test/packages/npm-test-ignore-nested-nm/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/test/packages/npm-test-ignore-nested-nm/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "npm-test-ignore",
      "version": "1.2.5",
      "scope": "optional",
      "purl": "pkg:npm/npm-test-ignore@1.2.5",
      "type": "library",
      "bom-ref": "pkg:npm/npm-test-ignore@1.2.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/test/packages/npm-test-ignore/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/test/packages/npm-test-ignore/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/test/packages/npm-test-ignore/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "npm-test-files",
      "version": "1.2.5",
      "scope": "optional",
      "purl": "pkg:npm/npm-test-files@1.2.5",
      "type": "library",
      "bom-ref": "pkg:npm/npm-test-files@1.2.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/test/packages/npm-test-files/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/test/packages/npm-test-files/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/test/packages/npm-test-files/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "npm-test-env-reader",
      "version": "1.2.3",
      "scope": "optional",
      "purl": "pkg:npm/npm-test-env-reader@1.2.3",
      "type": "library",
      "bom-ref": "pkg:npm/npm-test-env-reader@1.2.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/test/packages/npm-test-env-reader/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/test/packages/npm-test-env-reader/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/test/packages/npm-test-env-reader/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "npm-test-dir-bin",
      "version": "1.2.5",
      "scope": "optional",
      "purl": "pkg:npm/npm-test-dir-bin@1.2.5",
      "type": "library",
      "bom-ref": "pkg:npm/npm-test-dir-bin@1.2.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/test/packages/npm-test-dir-bin/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/test/packages/npm-test-dir-bin/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/test/packages/npm-test-dir-bin/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "npm-test-bundled-git",
      "version": "1.2.5",
      "scope": "optional",
      "purl": "pkg:npm/npm-test-bundled-git@1.2.5",
      "type": "library",
      "bom-ref": "pkg:npm/npm-test-bundled-git@1.2.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/test/packages/npm-test-bundled-git/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/test/packages/npm-test-bundled-git/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/test/packages/npm-test-bundled-git/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "npm-test-blerg3",
      "version": "0.0.0",
      "scope": "optional",
      "purl": "pkg:npm/npm-test-blerg3@0.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/npm/npm/issues/2658"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/npm-test-blerg3@0.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/test/packages/npm-test-blerg3/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/test/packages/npm-test-blerg3/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/test/packages/npm-test-blerg3/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "npm-test-blerg",
      "version": "0.0.2",
      "scope": "optional",
      "purl": "pkg:npm/npm-test-blerg@0.0.2",
      "type": "library",
      "bom-ref": "pkg:npm/npm-test-blerg@0.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/test/packages/npm-test-blerg/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/test/packages/npm-test-blerg/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/test/packages/npm-test-blerg/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "npm-test-array-bin",
      "version": "1.2.5",
      "scope": "optional",
      "purl": "pkg:npm/npm-test-array-bin@1.2.5",
      "type": "library",
      "bom-ref": "pkg:npm/npm-test-array-bin@1.2.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/test/packages/npm-test-array-bin/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/test/packages/npm-test-array-bin/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/test/packages/npm-test-array-bin/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "slow",
      "version": "1.2.3",
      "description": "just like fast, but even slower",
      "scope": "optional",
      "purl": "pkg:npm/slow@1.2.3",
      "type": "library",
      "bom-ref": "pkg:npm/slow@1.2.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/test/disabled/slow/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/test/disabled/slow/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/test/disabled/slow/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "package-foo",
      "version": "0.5.0",
      "scope": "optional",
      "purl": "pkg:npm/package-foo@0.5.0",
      "type": "library",
      "bom-ref": "pkg:npm/package-foo@0.5.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/test/disabled/package-foo/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/test/disabled/package-foo/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/test/disabled/package-foo/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "package-config",
      "version": "1.2.3",
      "scope": "optional",
      "purl": "pkg:npm/package-config@1.2.3",
      "type": "library",
      "bom-ref": "pkg:npm/package-config@1.2.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/test/disabled/package-config/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/test/disabled/package-config/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/test/disabled/package-config/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "package-bar",
      "version": "0.5.0",
      "scope": "optional",
      "purl": "pkg:npm/package-bar@0.5.0",
      "type": "library",
      "bom-ref": "pkg:npm/package-bar@0.5.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/test/disabled/package-bar/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/test/disabled/package-bar/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/test/disabled/package-bar/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "fast",
      "version": "1.2.3",
      "description": "does nothing, and not very fast",
      "scope": "optional",
      "purl": "pkg:npm/fast@1.2.3",
      "type": "library",
      "bom-ref": "pkg:npm/fast@1.2.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/test/disabled/fast/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/test/disabled/fast/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/test/disabled/fast/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "npm-test-failer",
      "version": "9999.999.99",
      "scope": "optional",
      "purl": "pkg:npm/npm-test-failer@9999.999.99",
      "type": "library",
      "bom-ref": "pkg:npm/npm-test-failer@9999.999.99",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/test/disabled/failer/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/test/disabled/failer/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/test/disabled/failer/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "npm-test-change-bin",
      "version": "2.3.4",
      "scope": "optional",
      "purl": "pkg:npm/npm-test-change-bin@2.3.4",
      "type": "library",
      "bom-ref": "pkg:npm/npm-test-change-bin@2.3.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/test/disabled/change-bin-2/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/test/disabled/change-bin-2/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/test/disabled/change-bin-2/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "npm-test-change-bin",
      "version": "1.2.3",
      "scope": "optional",
      "purl": "pkg:npm/npm-test-change-bin@1.2.3",
      "type": "library",
      "bom-ref": "pkg:npm/npm-test-change-bin@1.2.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/test/disabled/change-bin-1/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/test/disabled/change-bin-1/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/test/disabled/change-bin-1/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "bundletest",
      "version": "1.0.0",
      "scope": "optional",
      "purl": "pkg:npm/bundletest@1.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/bundletest@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/test/disabled/bundlerecurs/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/test/disabled/bundlerecurs/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/test/disabled/bundlerecurs/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Rebecca Turner <me@re-becca.org> (http://re-becca.org)"
        }
      ],
      "group": "",
      "name": "write-file-atomic",
      "version": "1.1.4",
      "description": "Write files in an atomic fashion w/configurable ownership",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/write-file-atomic@1.1.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/iarna/write-file-atomic"
        },
        {
          "type": "vcs",
          "url": "git+ssh://git@github.com/iarna/write-file-atomic.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/write-file-atomic@1.1.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/write-file-atomic/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/write-file-atomic/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/write-file-atomic/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "isexe",
      "version": "1.1.1",
      "description": "Minimal module to check if a file is executable.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/isexe@1.1.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/isexe#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/isaacs/isexe.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/isexe@1.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/which/node_modules/isexe/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/which/node_modules/isexe/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/which/node_modules/isexe/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jon Schlinkert (https://github.com/jonschlinkert)"
        }
      ],
      "group": "",
      "name": "is-absolute",
      "version": "0.1.7",
      "description": "Return true if a file path is absolute.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/is-absolute@0.1.7",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jonschlinkert/is-absolute"
        },
        {
          "type": "vcs",
          "url": "git://github.com/jonschlinkert/is-absolute.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/is-absolute@0.1.7",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/which/node_modules/is-absolute/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/is-absolute/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-absolute/package.json"
              }
            ],
            "concludedValue": "node_modules/is-absolute/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jon Schlinkert (https://github.com/jonschlinkert)"
        }
      ],
      "group": "",
      "name": "is-relative",
      "version": "0.1.3",
      "description": "Returns `true` if the path appears to be relative.",
      "scope": "optional",
      "purl": "pkg:npm/is-relative@0.1.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jonschlinkert/is-relative"
        },
        {
          "type": "vcs",
          "url": "git://github.com/jonschlinkert/is-relative.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/is-relative@0.1.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/which/node_modules/is-absolute/node_modules/is-relative/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/is-relative/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-relative/package.json"
              }
            ],
            "concludedValue": "node_modules/is-relative/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "zeke"
        }
      ],
      "group": "",
      "name": "validate-npm-package-name",
      "version": "2.2.2",
      "description": "Give me a string and I'll tell you if it's a valid npm package name",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/validate-npm-package-name@2.2.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/npm/validate-npm-package-name"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/npm/validate-npm-package-name.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/validate-npm-package-name@2.2.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/validate-npm-package-name/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/validate-npm-package-name/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/validate-npm-package-name/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "builtins",
      "version": "0.0.7",
      "description": "List of node.js builtin modules",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/builtins@0.0.7",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/juliangruber/builtins"
        },
        {
          "type": "vcs",
          "url": "git://github.com/juliangruber/builtins.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/builtins@0.0.7",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/validate-npm-package-name/node_modules/builtins/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/validate-npm-package-name/node_modules/builtins/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/validate-npm-package-name/node_modules/builtins/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Kyle E. Mitchell <kyle@kemitchell.com> (https://kemitchell.com)"
        }
      ],
      "group": "",
      "name": "validate-npm-package-license",
      "version": "3.0.1",
      "description": "Give me a string and I'll tell you if it's a valid npm package license string",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0",
            "url": "https://opensource.org/licenses/Apache-2.0",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/validate-npm-package-license@3.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/kemitchell/validate-npm-package-license.js#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/kemitchell/validate-npm-package-license.js.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/validate-npm-package-license@3.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/validate-npm-package-license/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/validate-npm-package-license/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/validate-npm-package-license/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Kyle E. Mitchell <kyle@kemitchell.com> (http://kemitchell.com)"
        }
      ],
      "group": "",
      "name": "spdx-expression-parse",
      "version": "1.0.2",
      "description": "parse SPDX license expressions",
      "scope": "optional",
      "licenses": [
        {
          "expression": "MIT AND CC-BY-3.0"
        }
      ],
      "purl": "pkg:npm/spdx-expression-parse@1.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/kemitchell/spdx-expression-parse.js#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/kemitchell/spdx-expression-parse.js.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/spdx-expression-parse@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/validate-npm-package-license/node_modules/spdx-expression-parse/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/validate-npm-package-license/node_modules/spdx-expression-parse/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/validate-npm-package-license/node_modules/spdx-expression-parse/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Shinnosuke Watanabe (https://github.com/shinnn)"
        }
      ],
      "group": "",
      "name": "spdx-license-ids",
      "version": "1.2.0",
      "description": "A list of SPDX license identifiers",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Unlicense",
            "url": "https://opensource.org/licenses/Unlicense",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Public Domain"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/spdx-license-ids@1.2.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/shinnn/spdx-license-ids#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/shinnn/spdx-license-ids.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/spdx-license-ids@1.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/validate-npm-package-license/node_modules/spdx-expression-parse/node_modules/spdx-license-ids/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/validate-npm-package-license/node_modules/spdx-correct/node_modules/spdx-license-ids/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Public Domain"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/validate-npm-package-license/node_modules/spdx-correct/node_modules/spdx-license-ids/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/validate-npm-package-license/node_modules/spdx-correct/node_modules/spdx-license-ids/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "The Linux Foundation"
        }
      ],
      "group": "",
      "name": "spdx-exceptions",
      "version": "1.0.4",
      "description": "list of SPDX standard license exceptions",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "CC-BY-3.0",
            "url": "https://opensource.org/licenses/CC-BY-3.0",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "false"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "false"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/spdx-exceptions@1.0.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/kemitchell/spdx-exceptions.json#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/kemitchell/spdx-exceptions.json.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/spdx-exceptions@1.0.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/validate-npm-package-license/node_modules/spdx-expression-parse/node_modules/spdx-exceptions/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/validate-npm-package-license/node_modules/spdx-expression-parse/node_modules/spdx-exceptions/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/validate-npm-package-license/node_modules/spdx-expression-parse/node_modules/spdx-exceptions/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Kyle E. Mitchell <kyle@kemitchell.com> (https://kemitchell.com)"
        }
      ],
      "group": "",
      "name": "spdx-correct",
      "version": "1.0.2",
      "description": "correct invalid SPDX identifiers",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0",
            "url": "https://opensource.org/licenses/Apache-2.0",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/spdx-correct@1.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/kemitchell/spdx-correct.js#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/kemitchell/spdx-correct.js.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/spdx-correct@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/validate-npm-package-license/node_modules/spdx-correct/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/validate-npm-package-license/node_modules/spdx-correct/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/validate-npm-package-license/node_modules/spdx-correct/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Douglas Christopher Wilson <doug@somethingdoug.com>"
        }
      ],
      "group": "",
      "name": "unpipe",
      "version": "1.0.0",
      "description": "Unpipe a stream from all destinations",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/unpipe@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/stream-utils/unpipe#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/stream-utils/unpipe.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/unpipe@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/unpipe/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/unpipe/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/unpipe/package.json"
          }
        ]
      },
      "tags": [
        "stream"
      ]
    },
    {
      "authors": [
        {
          "name": "Rebecca Turner <me@re-becca.org> (http://re-becca.org/)"
        }
      ],
      "group": "",
      "name": "unique-filename",
      "version": "1.1.0",
      "description": "Generate a unique filename for use in temporary directories or caches.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/unique-filename@1.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/iarna/unique-filename"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/iarna/unique-filename.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/unique-filename@1.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/unique-filename/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/unique-filename/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/unique-filename/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Rebecca Turner <me@re-becca.org> (http://re-becca.org)"
        }
      ],
      "group": "",
      "name": "unique-slug",
      "version": "2.0.0",
      "description": "Generate a unique character string suitible for use in files and URLs.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/unique-slug@2.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/iarna/unique-slug#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/iarna/unique-slug.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/unique-slug@2.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/unique-filename/node_modules/unique-slug/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/unique-filename/node_modules/unique-slug/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/unique-filename/node_modules/unique-slug/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sam Mikes <smikes@cubane.com>"
        }
      ],
      "group": "",
      "name": "umask",
      "version": "1.1.0",
      "description": "convert umask from string <-> number",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/umask@1.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/smikes/umask"
        },
        {
          "type": "vcs",
          "url": "https://github.com/smikes/umask.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/umask@1.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/umask/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/umask/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/umask/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "uid-number",
      "version": "0.0.6",
      "description": "Convert a username/group name to a uid/gid number",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/uid-number@0.0.6",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/uid-number"
        },
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/uid-number.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/uid-number@0.0.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/uid-number/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/uid-number/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/uid-number/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "text-table",
      "version": "0.2.0",
      "description": "borderless text tables with alignment",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/text-table@0.2.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/text-table"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/text-table.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/text-table@0.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/text-table/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/text-table/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/text-table/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "tar",
      "version": "2.2.1",
      "description": "tar for node",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/tar@2.2.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/node-tar#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/node-tar.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/tar@2.2.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/tar/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/tar/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/tar/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "block-stream",
      "version": "0.0.8",
      "description": "a stream of blocks",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/block-stream@0.0.8",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/block-stream#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/block-stream.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/block-stream@0.0.8",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/tar/node_modules/block-stream/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/tar/node_modules/block-stream/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/tar/node_modules/block-stream/package.json"
          }
        ]
      },
      "tags": [
        "stream"
      ]
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "strip-ansi",
      "version": "3.0.0",
      "description": "Strip ANSI escape codes",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/strip-ansi@3.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/sindresorhus/strip-ansi#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/sindresorhus/strip-ansi.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/strip-ansi@3.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/strip-ansi/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/strip-ansi/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/strip-ansi/package.json"
          }
        ]
      },
      "tags": [
        "escape"
      ]
    },
    {
      "authors": [
        {
          "name": "Domenic Denicola <domenic@domenicdenicola.com> (http://domenic.me/)"
        }
      ],
      "group": "",
      "name": "sorted-object",
      "version": "1.0.0",
      "description": "Returns a copy of an object with its keys sorted",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "WTFPL",
            "url": "https://opensource.org/licenses/WTFPL",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Public Domain"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "false"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/sorted-object@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/domenic/sorted-object"
        },
        {
          "type": "vcs",
          "url": "git://github.com/domenic/sorted-object.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/sorted-object@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/sorted-object/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Public Domain"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/sorted-object/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/sorted-object/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "slide",
      "version": "1.1.6",
      "description": "A flow control lib small enough to fit on in a slide presentation. Derived live at Oak.JS",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/slide@1.1.6",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/slide-flow-control"
        },
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/slide-flow-control.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/slide@1.1.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/slide/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/slide/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/slide/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "sha",
      "version": "2.0.1",
      "description": "Check and get file hashes",
      "scope": "optional",
      "licenses": [
        {
          "expression": "BSD-2-Clause OR MIT"
        }
      ],
      "purl": "pkg:npm/sha@2.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/ForbesLindesay/sha"
        },
        {
          "type": "vcs",
          "url": "https://github.com/ForbesLindesay/sha.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/sha@2.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/sha/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/sha/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/sha/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "semver",
      "version": "5.1.0",
      "description": "The semantic version parser used by npm.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/semver@5.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/npm/node-semver#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/npm/node-semver.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/semver@5.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/semver/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/semver/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/semver/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "rimraf",
      "version": "2.5.1",
      "description": "A deep deletion module for node (like `rm -rf`)",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/rimraf@2.5.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/rimraf#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/rimraf.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/rimraf@2.5.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/rimraf/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/rimraf/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/rimraf/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Tim Koschützki <tim@debuggable.com> (http://debuggable.com/)"
        }
      ],
      "group": "",
      "name": "retry",
      "version": "0.9.0",
      "description": "Abstraction for exponential and custom retry strategies for failed operations.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/retry@0.9.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/tim-kos/node-retry"
        },
        {
          "type": "vcs",
          "url": "git://github.com/tim-kos/node-retry.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/retry@0.9.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/retry/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/retry/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/retry/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mikeal Rogers <mikeal.rogers@gmail.com>"
        }
      ],
      "group": "",
      "name": "request",
      "version": "2.69.0",
      "description": "Simplified HTTP request client.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0",
            "url": "https://opensource.org/licenses/Apache-2.0",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/request@2.69.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/request/request#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/request/request.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/request@2.69.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mikeal Rogers <mikeal.rogers@gmail.com> (http://www.futurealoof.com)"
        }
      ],
      "group": "",
      "name": "tunnel-agent",
      "version": "0.4.2",
      "description": "HTTP proxy tunneling agent. Formerly part of mikeal/request, now a standalone module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0",
            "url": "https://opensource.org/licenses/Apache-2.0",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/tunnel-agent@0.4.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mikeal/tunnel-agent#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/mikeal/tunnel-agent.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/tunnel-agent@0.4.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/tunnel-agent/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/tunnel-agent/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/tunnel-agent/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jeremy Stashewsky <jstashewsky@salesforce.com>"
        }
      ],
      "group": "",
      "name": "tough-cookie",
      "version": "2.2.1",
      "description": "RFC6265 Cookies and Cookie Jar for node.js",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-3-Clause",
            "url": "https://opensource.org/licenses/BSD-3-Clause",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/tough-cookie@2.2.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/SalesforceEng/tough-cookie"
        },
        {
          "type": "vcs",
          "url": "git://github.com/SalesforceEng/tough-cookie.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/tough-cookie@2.2.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/tough-cookie/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/tough-cookie/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/tough-cookie/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Michael Hart <michael.hart.au@gmail.com> (http://github.com/mhart)"
        }
      ],
      "group": "",
      "name": "stringstream",
      "version": "0.0.5",
      "description": "Encode and decode streams into string streams",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/stringstream@0.0.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mhart/StringStream#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/mhart/StringStream.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/stringstream@0.0.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/stringstream/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/stringstream/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/stringstream/package.json"
          }
        ]
      },
      "tags": [
        "decode"
      ]
    },
    {
      "group": "",
      "name": "qs",
      "version": "6.0.2",
      "description": "A querystring parser that supports nesting and arrays, with a depth limit",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-3-Clause",
            "url": "https://opensource.org/licenses/BSD-3-Clause",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/qs@6.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/ljharb/qs"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/ljharb/qs.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/qs@6.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/qs/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/qs/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/qs/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mikeal Rogers <mikeal.rogers@gmail.com> (http://www.futurealoof.com)"
        }
      ],
      "group": "",
      "name": "oauth-sign",
      "version": "0.8.0",
      "description": "OAuth 1 signing. Formerly a vendor lib in mikeal/request, now a standalone module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0",
            "url": "https://opensource.org/licenses/Apache-2.0",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/oauth-sign@0.8.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mikeal/oauth-sign#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/mikeal/oauth-sign.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/oauth-sign@0.8.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/oauth-sign/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/oauth-sign/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/oauth-sign/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Robert Kieffer <robert@broofa.com>"
        }
      ],
      "group": "",
      "name": "node-uuid",
      "version": "1.4.7",
      "description": "Rigorous implementation of RFC4122 (v1 and v4) UUIDs.",
      "scope": "optional",
      "purl": "pkg:npm/node-uuid@1.4.7",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/broofa/node-uuid"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/broofa/node-uuid.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/node-uuid@1.4.7",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/node-uuid/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/node-uuid/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/node-uuid/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "mime-types",
      "version": "2.1.9",
      "description": "The ultimate javascript content-type utility.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/mime-types@2.1.9",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jshttp/mime-types"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/jshttp/mime-types.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/mime-types@2.1.9",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/mime-types/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/mime-types/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/mime-types/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "mime-db",
      "version": "1.21.0",
      "description": "Media Type Database",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/mime-db@1.21.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jshttp/mime-db"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/jshttp/mime-db.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/mime-db@1.21.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/mime-types/node_modules/mime-db/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/mime-types/node_modules/mime-db/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/mime-types/node_modules/mime-db/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me)"
        }
      ],
      "group": "",
      "name": "json-stringify-safe",
      "version": "5.0.1",
      "description": "Like JSON.stringify, but doesn't blow up on circular refs.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/json-stringify-safe@5.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/json-stringify-safe"
        },
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/json-stringify-safe.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/json-stringify-safe@5.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/json-stringify-safe/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/json-stringify-safe/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/json-stringify-safe/package.json"
          }
        ]
      },
      "tags": [
        "json"
      ]
    },
    {
      "authors": [
        {
          "name": "Rod Vagg <rod@vagg.org>"
        }
      ],
      "group": "",
      "name": "isstream",
      "version": "0.1.2",
      "description": "Determine if an object is a Stream",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/isstream@0.1.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/rvagg/isstream"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/rvagg/isstream.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/isstream@0.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/isstream/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/isstream/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/isstream/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Hugh Kennedy <hughskennedy@gmail.com> (http://hughsk.io/)"
        }
      ],
      "group": "",
      "name": "is-typedarray",
      "version": "1.0.0",
      "description": "Detect whether or not an object is a Typed Array",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/is-typedarray@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/hughsk/is-typedarray"
        },
        {
          "type": "vcs",
          "url": "git://github.com/hughsk/is-typedarray.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/is-typedarray@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/is-typedarray/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/is-typedarray/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/is-typedarray/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Joyent"
        },
        {
          "name": " Inc"
        }
      ],
      "group": "",
      "name": "http-signature",
      "version": "1.1.1",
      "description": "Reference implementation of Joyent's HTTP Signature scheme.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/http-signature@1.1.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/joyent/node-http-signature/"
        },
        {
          "type": "vcs",
          "url": "git://github.com/joyent/node-http-signature.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/http-signature@1.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/http-signature/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/http-signature/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/http-signature/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Joyent"
        },
        {
          "name": " Inc"
        }
      ],
      "group": "",
      "name": "sshpk",
      "version": "1.7.3",
      "description": "A library for finding and using SSH public keys",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/sshpk@1.7.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/arekinath/node-sshpk#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/arekinath/node-sshpk.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/sshpk@1.7.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/http-signature/node_modules/sshpk/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/http-signature/node_modules/sshpk/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/http-signature/node_modules/sshpk/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "TweetNaCl-js contributors"
        }
      ],
      "group": "",
      "name": "tweetnacl",
      "version": "0.13.3",
      "description": "Port of TweetNaCl cryptographic library to JavaScript",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "name": "Public domain",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Public Domain"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "false"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "false"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/tweetnacl@0.13.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://dchest.github.io/tweetnacl-js"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/dchest/tweetnacl-js.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/tweetnacl@0.13.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/http-signature/node_modules/sshpk/node_modules/tweetnacl/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Public Domain"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/http-signature/node_modules/sshpk/node_modules/tweetnacl/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/http-signature/node_modules/sshpk/node_modules/tweetnacl/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Tom Wu"
        }
      ],
      "group": "",
      "name": "jsbn",
      "version": "0.1.0",
      "description": "The jsbn library is a fast, portable implementation of large-number math in pure JavaScript, enabling public-key crypto and other applications on desktop and mobile browsers.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "name": "BSD",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Unstated License"
              },
              {
                "name": "cdx:license:foss",
                "value": "false"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "false"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "false"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/jsbn@0.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/andyperlitch/jsbn"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/andyperlitch/jsbn.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/jsbn@0.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/http-signature/node_modules/sshpk/node_modules/jsbn/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Unstated License"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/http-signature/node_modules/sshpk/node_modules/jsbn/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/http-signature/node_modules/sshpk/node_modules/jsbn/package.json"
          }
        ]
      },
      "tags": [
        "crypto"
      ]
    },
    {
      "authors": [
        {
          "name": "Michele Bini"
        },
        {
          "name": " Ron Garret"
        },
        {
          "name": " Guy K. Kloss"
        }
      ],
      "group": "",
      "name": "jodid25519",
      "version": "1.0.2",
      "description": "jodid25519 - Curve 25519-based cryptography",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/jodid25519@1.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/meganz/jodid25519"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/meganz/jodid25519.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/jodid25519@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/http-signature/node_modules/sshpk/node_modules/jodid25519/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/http-signature/node_modules/sshpk/node_modules/jodid25519/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/http-signature/node_modules/sshpk/node_modules/jodid25519/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jeremie Miller <jeremie@jabber.org> (http://jeremie.com/)"
        }
      ],
      "group": "",
      "name": "ecc-jsbn",
      "version": "0.1.1",
      "description": "ECC JS code based on JSBN",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/ecc-jsbn@0.1.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/quartzjer/ecc-jsbn"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/quartzjer/ecc-jsbn.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/ecc-jsbn@0.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/http-signature/node_modules/sshpk/node_modules/ecc-jsbn/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/http-signature/node_modules/sshpk/node_modules/ecc-jsbn/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/http-signature/node_modules/sshpk/node_modules/ecc-jsbn/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Trent Mick <trentm@gmail.com> (http://trentm.com)"
        }
      ],
      "group": "",
      "name": "dashdash",
      "version": "1.12.2",
      "description": "A light, featureful and explicit option parsing library.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/dashdash@1.12.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/trentm/node-dashdash"
        },
        {
          "type": "vcs",
          "url": "git://github.com/trentm/node-dashdash.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/dashdash@1.12.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/http-signature/node_modules/sshpk/node_modules/dashdash/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/http-signature/node_modules/sshpk/node_modules/dashdash/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/http-signature/node_modules/sshpk/node_modules/dashdash/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mark Cavage <mcavage@gmail.com>"
        }
      ],
      "group": "",
      "name": "asn1",
      "version": "0.2.3",
      "description": "Contains parsers and serializers for ASN.1 (currently BER only)",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/asn1@0.2.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mcavage/node-asn1"
        },
        {
          "type": "vcs",
          "url": "git://github.com/mcavage/node-asn1.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/asn1@0.2.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/http-signature/node_modules/sshpk/node_modules/asn1/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/http-signature/node_modules/sshpk/node_modules/asn1/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/http-signature/node_modules/sshpk/node_modules/asn1/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "jsprim",
      "version": "1.2.2",
      "description": "utilities for primitive JavaScript types",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/jsprim@1.2.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/davepacheco/node-jsprim"
        },
        {
          "type": "vcs",
          "url": "git://github.com/davepacheco/node-jsprim.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/jsprim@1.2.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/http-signature/node_modules/jsprim/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/http-signature/node_modules/jsprim/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/http-signature/node_modules/jsprim/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "verror",
      "version": "1.3.6",
      "description": "richer JavaScript errors",
      "scope": "optional",
      "purl": "pkg:npm/verror@1.3.6",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/davepacheco/node-verror#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/davepacheco/node-verror.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/verror@1.3.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/http-signature/node_modules/jsprim/node_modules/verror/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/http-signature/node_modules/jsprim/node_modules/verror/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/http-signature/node_modules/jsprim/node_modules/verror/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Kris Zyp"
        }
      ],
      "group": "",
      "name": "json-schema",
      "version": "0.2.2",
      "description": "JSON Schema validation and specifications",
      "scope": "optional",
      "purl": "pkg:npm/json-schema@0.2.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/kriszyp/json-schema#readme"
        },
        {
          "type": "vcs",
          "url": "git+ssh://git@github.com/kriszyp/json-schema.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/json-schema@0.2.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/http-signature/node_modules/jsprim/node_modules/json-schema/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/http-signature/node_modules/jsprim/node_modules/json-schema/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/http-signature/node_modules/jsprim/node_modules/json-schema/package.json"
          }
        ]
      },
      "tags": [
        "validation"
      ]
    },
    {
      "group": "",
      "name": "extsprintf",
      "version": "1.0.2",
      "description": "extended POSIX-style sprintf",
      "scope": "optional",
      "purl": "pkg:npm/extsprintf@1.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/davepacheco/node-extsprintf#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/davepacheco/node-extsprintf.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/extsprintf@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/http-signature/node_modules/jsprim/node_modules/extsprintf/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/http-signature/node_modules/jsprim/node_modules/extsprintf/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/http-signature/node_modules/jsprim/node_modules/extsprintf/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mark Cavage <mcavage@gmail.com>"
        }
      ],
      "group": "",
      "name": "assert-plus",
      "version": "0.2.0",
      "description": "Extra assertions on top of node's assert module",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/assert-plus@0.2.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mcavage/node-assert-plus#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/mcavage/node-assert-plus.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/assert-plus@0.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/http-signature/node_modules/assert-plus/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/http-signature/node_modules/assert-plus/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/http-signature/node_modules/assert-plus/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Eran Hammer <eran@hammer.io> (http://hueniverse.com)"
        }
      ],
      "group": "",
      "name": "hawk",
      "version": "3.1.3",
      "description": "HTTP Hawk Authentication Scheme",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-3-Clause",
            "url": "https://opensource.org/licenses/BSD-3-Clause",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/hawk@3.1.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/hueniverse/hawk#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/hueniverse/hawk.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/hawk@3.1.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/hawk/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/hawk/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/hawk/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Eran Hammer <eran@hammer.io> (http://hueniverse.com)"
        }
      ],
      "group": "",
      "name": "sntp",
      "version": "1.0.9",
      "description": "SNTP Client",
      "scope": "optional",
      "purl": "pkg:npm/sntp@1.0.9",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/hueniverse/sntp#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/hueniverse/sntp.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/sntp@1.0.9",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/hawk/node_modules/sntp/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/hawk/node_modules/sntp/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/hawk/node_modules/sntp/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "hoek",
      "version": "2.16.3",
      "description": "General purpose node utilities",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-3-Clause",
            "url": "https://opensource.org/licenses/BSD-3-Clause",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/hoek@2.16.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/hapijs/hoek#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/hapijs/hoek.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/hoek@2.16.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/hawk/node_modules/hoek/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/hawk/node_modules/hoek/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/hawk/node_modules/hoek/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "cryptiles",
      "version": "2.0.5",
      "description": "General purpose crypto utilities",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-3-Clause",
            "url": "https://opensource.org/licenses/BSD-3-Clause",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/cryptiles@2.0.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/hapijs/cryptiles#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/hapijs/cryptiles.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/cryptiles@2.0.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/hawk/node_modules/cryptiles/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/hawk/node_modules/cryptiles/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/hawk/node_modules/cryptiles/package.json"
          }
        ]
      },
      "tags": [
        "crypto"
      ]
    },
    {
      "group": "",
      "name": "boom",
      "version": "2.10.1",
      "description": "HTTP-friendly error objects",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-3-Clause",
            "url": "https://opensource.org/licenses/BSD-3-Clause",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/boom@2.10.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/hapijs/boom#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/hapijs/boom.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/boom@2.10.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/hawk/node_modules/boom/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/hawk/node_modules/boom/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/hawk/node_modules/boom/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Ahmad Nassri <ahmad@ahmadnassri.com> (https://www.ahmadnassri.com/)"
        }
      ],
      "group": "",
      "name": "har-validator",
      "version": "2.0.6",
      "description": "Extremely fast HTTP Archive (HAR) validator using JSON Schema",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/har-validator@2.0.6",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/ahmadnassri/har-validator"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/ahmadnassri/har-validator.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/har-validator@2.0.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/har-validator/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/har-validator/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/har-validator/package.json"
          }
        ]
      },
      "tags": [
        "json"
      ]
    },
    {
      "authors": [
        {
          "name": "Vsevolod Strukchinsky <floatdrop@gmail.com> (github.com/floatdrop)"
        }
      ],
      "group": "",
      "name": "pinkie-promise",
      "version": "2.0.0",
      "description": "ES2015 Promise ponyfill",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/pinkie-promise@2.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/floatdrop/pinkie-promise"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/floatdrop/pinkie-promise.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/pinkie-promise@2.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/pinkie-promise/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/pinkie-promise/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/pinkie-promise/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Vsevolod Strukchinsky <floatdrop@gmail.com> (github.com/floatdrop)"
        }
      ],
      "group": "",
      "name": "pinkie",
      "version": "2.0.1",
      "description": "Itty bitty little widdle twinkie pinkie ES2015 Promise implementation",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/pinkie@2.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/floatdrop/pinkie"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/floatdrop/pinkie.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/pinkie@2.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/pinkie-promise/node_modules/pinkie/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/pinkie-promise/node_modules/pinkie/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/pinkie-promise/node_modules/pinkie/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mathias Buus"
        }
      ],
      "group": "",
      "name": "is-my-json-valid",
      "version": "2.12.4",
      "description": "A JSONSchema validator that uses code generation to be extremely fast",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/is-my-json-valid@2.12.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mafintosh/is-my-json-valid"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/mafintosh/is-my-json-valid.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/is-my-json-valid@2.12.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/is-my-json-valid/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/is-my-json-valid/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/is-my-json-valid/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Raynos <raynos2@gmail.com>"
        }
      ],
      "group": "",
      "name": "xtend",
      "version": "4.0.1",
      "description": "extend like a boss",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/xtend@4.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/Raynos/xtend"
        },
        {
          "type": "vcs",
          "url": "git://github.com/Raynos/xtend.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/xtend@4.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/is-my-json-valid/node_modules/xtend/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/is-my-json-valid/node_modules/xtend/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/is-my-json-valid/node_modules/xtend/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jan Lehnardt <jan@apache.org>"
        }
      ],
      "group": "",
      "name": "jsonpointer",
      "version": "2.0.0",
      "description": "Simple JSON Addressing.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/jsonpointer@2.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/janl/node-jsonpointer#readme"
        },
        {
          "type": "vcs",
          "url": "git+ssh://git@github.com/janl/node-jsonpointer.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/jsonpointer@2.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/is-my-json-valid/node_modules/jsonpointer/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/is-my-json-valid/node_modules/jsonpointer/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/is-my-json-valid/node_modules/jsonpointer/package.json"
          }
        ]
      },
      "tags": [
        "json"
      ]
    },
    {
      "authors": [
        {
          "name": "Mathias Buus (@mafintosh)"
        }
      ],
      "group": "",
      "name": "generate-object-property",
      "version": "1.2.0",
      "description": "Generate safe JS code that can used to reference a object property",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/generate-object-property@1.2.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mafintosh/generate-object-property"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/mafintosh/generate-object-property.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/generate-object-property@1.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/is-my-json-valid/node_modules/generate-object-property/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/is-my-json-valid/node_modules/generate-object-property/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/is-my-json-valid/node_modules/generate-object-property/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mikola Lysenko"
        }
      ],
      "group": "",
      "name": "is-property",
      "version": "1.0.2",
      "description": "Tests if a JSON property can be accessed using . syntax",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/is-property@1.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mikolalysenko/is-property#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/mikolalysenko/is-property.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/is-property@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/is-my-json-valid/node_modules/generate-object-property/node_modules/is-property/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/is-my-json-valid/node_modules/generate-object-property/node_modules/is-property/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/is-my-json-valid/node_modules/generate-object-property/node_modules/is-property/package.json"
          }
        ]
      },
      "tags": [
        "json"
      ]
    },
    {
      "authors": [
        {
          "name": "Mathias Buus"
        }
      ],
      "group": "",
      "name": "generate-function",
      "version": "2.0.0",
      "description": "Module that helps you write generated functions in Node",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/generate-function@2.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mafintosh/generate-function"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/mafintosh/generate-function.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/generate-function@2.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/is-my-json-valid/node_modules/generate-function/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/is-my-json-valid/node_modules/generate-function/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/is-my-json-valid/node_modules/generate-function/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "TJ Holowaychuk <tj@vision-media.ca>"
        }
      ],
      "group": "",
      "name": "commander",
      "version": "2.9.0",
      "description": "the complete solution for node.js command-line programs",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/commander@2.9.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/tj/commander.js#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/tj/commander.js.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/commander@2.9.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/commander/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/commander/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/commander/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "zhiyelee"
        }
      ],
      "group": "",
      "name": "graceful-readlink",
      "version": "1.0.1",
      "description": "graceful fs.readlink",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/graceful-readlink@1.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/zhiyelee/graceful-readlink"
        },
        {
          "type": "vcs",
          "url": "git://github.com/zhiyelee/graceful-readlink.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/graceful-readlink@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/commander/node_modules/graceful-readlink/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/commander/node_modules/graceful-readlink/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/commander/node_modules/graceful-readlink/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "chalk",
      "version": "1.1.1",
      "description": "Terminal string styling done right. Much color.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/chalk@1.1.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/chalk/chalk#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/chalk/chalk.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/chalk@1.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/chalk/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/chalk/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/chalk/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "supports-color",
      "version": "2.0.0",
      "description": "Detect whether a terminal supports color",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/supports-color@2.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/chalk/supports-color#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/chalk/supports-color.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/supports-color@2.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/chalk/node_modules/supports-color/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/chalk/node_modules/supports-color/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/chalk/node_modules/supports-color/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "has-ansi",
      "version": "2.0.0",
      "description": "Check if a string has ANSI escape codes",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/has-ansi@2.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/sindresorhus/has-ansi#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/sindresorhus/has-ansi.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/has-ansi@2.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/chalk/node_modules/has-ansi/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/chalk/node_modules/has-ansi/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/chalk/node_modules/has-ansi/package.json"
          }
        ]
      },
      "tags": [
        "escape"
      ]
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "escape-string-regexp",
      "version": "1.0.4",
      "description": "Escape RegExp special characters",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/escape-string-regexp@1.0.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/sindresorhus/escape-string-regexp"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/sindresorhus/escape-string-regexp.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/escape-string-regexp@1.0.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/chalk/node_modules/escape-string-regexp/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/chalk/node_modules/escape-string-regexp/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/chalk/node_modules/escape-string-regexp/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "ansi-styles",
      "version": "2.1.0",
      "description": "ANSI escape codes for styling strings in the terminal",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/ansi-styles@2.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/chalk/ansi-styles#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/chalk/ansi-styles.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/ansi-styles@2.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/chalk/node_modules/ansi-styles/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/chalk/node_modules/ansi-styles/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/har-validator/node_modules/chalk/node_modules/ansi-styles/package.json"
          }
        ]
      },
      "tags": [
        "escape"
      ]
    },
    {
      "authors": [
        {
          "name": "Felix Geisendörfer <felix@debuggable.com> (http://debuggable.com/)"
        }
      ],
      "group": "",
      "name": "form-data",
      "version": "1.0.0-rc3",
      "description": "A library to create readable \"multipart/form-data\" streams. Can be used to submit forms and file uploads to other web applications.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/form-data@1.0.0-rc3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/form-data/form-data#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/form-data/form-data.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/form-data@1.0.0-rc3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/form-data/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/form-data/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/form-data/package.json"
          }
        ]
      },
      "tags": [
        "web"
      ]
    },
    {
      "authors": [
        {
          "name": "Caolan McMahon"
        }
      ],
      "group": "",
      "name": "async",
      "version": "1.5.2",
      "description": "Higher-order functions and common patterns for asynchronous code",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/async@1.5.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/caolan/async#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/caolan/async.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/async@1.5.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/form-data/node_modules/async/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/form-data/node_modules/async/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/form-data/node_modules/async/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mikeal Rogers <mikeal.rogers@gmail.com> (http://www.futurealoof.com)"
        }
      ],
      "group": "",
      "name": "forever-agent",
      "version": "0.6.1",
      "description": "HTTP Agent that keeps socket connections alive between keep-alive requests. Formerly part of mikeal/request, now a standalone module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0",
            "url": "https://opensource.org/licenses/Apache-2.0",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/forever-agent@0.6.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mikeal/forever-agent#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/mikeal/forever-agent.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/forever-agent@0.6.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/forever-agent/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/forever-agent/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/forever-agent/package.json"
          }
        ]
      },
      "tags": [
        "socket"
      ]
    },
    {
      "authors": [
        {
          "name": "Stefan Thomas <justmoon@members.fsf.org> (http://www.justmoon.net)"
        }
      ],
      "group": "",
      "name": "extend",
      "version": "3.0.0",
      "description": "Port of jQuery.extend for node.js and the browser",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/extend@3.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/justmoon/node-extend#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/justmoon/node-extend.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/extend@3.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/extend/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/extend/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/extend/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Felix Geisendörfer <felix@debuggable.com> (http://debuggable.com/)"
        }
      ],
      "group": "",
      "name": "combined-stream",
      "version": "1.0.5",
      "description": "A stream that emits multiple other streams one after another.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/combined-stream@1.0.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/felixge/node-combined-stream"
        },
        {
          "type": "vcs",
          "url": "git://github.com/felixge/node-combined-stream.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/combined-stream@1.0.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/combined-stream/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/combined-stream/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/combined-stream/package.json"
          }
        ]
      },
      "tags": [
        "stream"
      ]
    },
    {
      "authors": [
        {
          "name": "Felix Geisendörfer <felix@debuggable.com> (http://debuggable.com/)"
        }
      ],
      "group": "",
      "name": "delayed-stream",
      "version": "1.0.0",
      "description": "Buffers events from a stream until you are ready to handle them.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/delayed-stream@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/felixge/node-delayed-stream"
        },
        {
          "type": "vcs",
          "url": "git://github.com/felixge/node-delayed-stream.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/delayed-stream@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/combined-stream/node_modules/delayed-stream/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/combined-stream/node_modules/delayed-stream/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/combined-stream/node_modules/delayed-stream/package.json"
          }
        ]
      },
      "tags": [
        "stream"
      ]
    },
    {
      "authors": [
        {
          "name": "Mikeal Rogers <mikeal.rogers@gmail.com>"
        }
      ],
      "group": "",
      "name": "caseless",
      "version": "0.11.0",
      "description": "Caseless object set/get/has, very useful when working with HTTP headers.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0",
            "url": "https://opensource.org/licenses/Apache-2.0",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/caseless@0.11.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mikeal/caseless#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/mikeal/caseless.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/caseless@0.11.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/caseless/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/caseless/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/caseless/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "bl",
      "version": "1.0.1",
      "description": "Buffer List: collect buffers and access with a standard readable Buffer interface, streamable too!",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/bl@1.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/rvagg/bl"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/rvagg/bl.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/bl@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/bl/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/bl/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/bl/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Michael Hart <michael.hart.au@gmail.com> (http://github.com/mhart)"
        }
      ],
      "group": "",
      "name": "aws4",
      "version": "1.2.1",
      "description": "Signs and prepares requests using AWS Signature Version 4",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/aws4@1.2.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mhart/aws4#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/mhart/aws4.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/aws4@1.2.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/aws4/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/aws4/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/aws4/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me>"
        }
      ],
      "group": "",
      "name": "lru-cache",
      "version": "2.7.3",
      "description": "A cache object that deletes the least-recently-used items.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/lru-cache@2.7.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/node-lru-cache#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/node-lru-cache.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lru-cache@2.7.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/aws4/node_modules/lru-cache/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/node-gyp/node_modules/minimatch/node_modules/lru-cache/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/node-gyp/node_modules/minimatch/node_modules/lru-cache/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/node-gyp/node_modules/minimatch/node_modules/lru-cache/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mikeal Rogers <mikeal.rogers@gmail.com> (http://www.futurealoof.com)"
        }
      ],
      "group": "",
      "name": "aws-sign2",
      "version": "0.6.0",
      "description": "AWS signing. Originally pulled from LearnBoost/knox, maintained as vendor in request, now a standalone module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0",
            "url": "https://opensource.org/licenses/Apache-2.0",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/aws-sign2@0.6.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mikeal/aws-sign#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/mikeal/aws-sign.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/aws-sign2@0.6.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/request/node_modules/aws-sign2/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/request/node_modules/aws-sign2/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/request/node_modules/aws-sign2/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Rebecca Turner <me@re-becca.org> (http://re-becca.org)"
        }
      ],
      "group": "",
      "name": "realize-package-specifier",
      "version": "3.0.1",
      "description": "Like npm-package-arg, but more so, producing full file paths and differentiating local tar and directory sources.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/realize-package-specifier@3.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/npm/realize-package-specifier"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/npm/realize-package-specifier.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/realize-package-specifier@3.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/realize-package-specifier/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/realize-package-specifier/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/realize-package-specifier/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "readdir-scoped-modules",
      "version": "1.0.2",
      "description": "Like `fs.readdir` but handling `@org/module` dirs as if they were a single entry.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/readdir-scoped-modules@1.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/npm/readdir-scoped-modules"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/npm/readdir-scoped-modules.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/readdir-scoped-modules@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/readdir-scoped-modules/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/readdir-scoped-modules/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/readdir-scoped-modules/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "readable-stream",
      "version": "2.0.5",
      "description": "Streams3, a user-land copy of the stream library from iojs v2.x",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/readable-stream@2.0.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/nodejs/readable-stream#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/nodejs/readable-stream.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/readable-stream@2.0.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/readable-stream/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/readable-stream/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/readable-stream/package.json"
          }
        ]
      },
      "tags": [
        "stream"
      ]
    },
    {
      "authors": [
        {
          "name": "Nathan Rajlich <nathan@tootallnate.net> (http://n8.io/)"
        }
      ],
      "group": "",
      "name": "util-deprecate",
      "version": "1.0.2",
      "description": "The Node.js `util.deprecate()` function with browser support",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/util-deprecate@1.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/TooTallNate/util-deprecate"
        },
        {
          "type": "vcs",
          "url": "git://github.com/TooTallNate/util-deprecate.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/util-deprecate@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/readable-stream/node_modules/util-deprecate/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/readable-stream/node_modules/util-deprecate/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/readable-stream/node_modules/util-deprecate/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "process-nextick-args",
      "version": "1.0.6",
      "description": "process.nextTick but always with args",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/process-nextick-args@1.0.6",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/calvinmetcalf/process-nextick-args"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/calvinmetcalf/process-nextick-args.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/process-nextick-args@1.0.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/readable-stream/node_modules/process-nextick-args/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/readable-stream/node_modules/process-nextick-args/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/readable-stream/node_modules/process-nextick-args/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Julian Gruber <mail@juliangruber.com> (http://juliangruber.com)"
        }
      ],
      "group": "",
      "name": "isarray",
      "version": "0.0.1",
      "description": "Array#isArray for older browsers",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/isarray@0.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/juliangruber/isarray"
        },
        {
          "type": "vcs",
          "url": "git://github.com/juliangruber/isarray.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/isarray@0.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/readable-stream/node_modules/isarray/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/isarray/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/isarray/package.json"
              }
            ],
            "concludedValue": "node_modules/isarray/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "core-util-is",
      "version": "1.0.2",
      "description": "The `util.is*` functions introduced in Node v0.12.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/core-util-is@1.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/core-util-is#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/core-util-is.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/core-util-is@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/readable-stream/node_modules/core-util-is/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/core-util-is/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/core-util-is/package.json"
              }
            ],
            "concludedValue": "node_modules/core-util-is/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "read-package-tree",
      "version": "5.1.2",
      "description": "Read the contents of node_modules.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/read-package-tree@5.1.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/npm/read-package-tree"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/npm/read-package-tree.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/read-package-tree@5.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/read-package-tree/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/read-package-tree/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/read-package-tree/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "selflink",
      "version": "1.2.3",
      "scope": "optional",
      "purl": "pkg:npm/selflink@1.2.3",
      "type": "library",
      "bom-ref": "pkg:npm/selflink@1.2.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/read-package-tree/test/fixtures/selflink/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/read-package-tree/test/fixtures/selflink/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/read-package-tree/test/fixtures/selflink/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "root",
      "version": "1.2.3",
      "scope": "optional",
      "purl": "pkg:npm/root@1.2.3",
      "type": "library",
      "bom-ref": "pkg:npm/root@1.2.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/read-package-tree/test/fixtures/root/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/read-package-tree/test/fixtures/root/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/read-package-tree/test/fixtures/root/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "read-package-json",
      "version": "2.0.3",
      "description": "The thing npm uses to read package.json files with semantics and defaults and validation",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/read-package-json@2.0.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/npm/read-package-json#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/npm/read-package-json.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/read-package-json@2.0.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/read-package-json/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/read-package-json/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/read-package-json/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "readmes",
      "version": "99.999.999999999",
      "scope": "optional",
      "purl": "pkg:npm/readmes@99.999.999999999",
      "type": "library",
      "bom-ref": "pkg:npm/readmes@99.999.999999999",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/read-package-json/test/fixtures/readmes/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/read-package-json/test/fixtures/readmes/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/read-package-json/test/fixtures/readmes/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sam Mikes <smikes@cubane.com>"
        }
      ],
      "group": "",
      "name": "json-parse-helpfulerror",
      "version": "1.0.3",
      "description": "A drop-in replacement for JSON.parse that uses `jju` to give helpful errors",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/json-parse-helpfulerror@1.0.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/smikes/json-parse-helpfulerror"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/smikes/json-parse-helpfulerror.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/json-parse-helpfulerror@1.0.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/read-package-json/node_modules/json-parse-helpfulerror/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/read-package-json/node_modules/json-parse-helpfulerror/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/read-package-json/node_modules/json-parse-helpfulerror/package.json"
          }
        ]
      },
      "tags": [
        "json"
      ]
    },
    {
      "authors": [
        {
          "name": "Alex Kocharin <alex@kocharin.ru>"
        }
      ],
      "group": "",
      "name": "jju",
      "version": "1.2.1",
      "description": "a set of utilities to work with JSON / JSON5 documents",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "WTFPL",
            "url": "https://opensource.org/licenses/WTFPL",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Public Domain"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "false"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/jju@1.2.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://rlidwka.github.io/jju/"
        },
        {
          "type": "vcs",
          "url": "git://github.com/rlidwka/jju.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/jju@1.2.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/read-package-json/node_modules/json-parse-helpfulerror/node_modules/jju/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Public Domain"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/read-package-json/node_modules/json-parse-helpfulerror/node_modules/jju/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/read-package-json/node_modules/json-parse-helpfulerror/node_modules/jju/package.json"
          }
        ]
      },
      "tags": [
        "json"
      ]
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "read-installed",
      "version": "4.0.3",
      "description": "Read all the installed packages in a folder, and return a tree structure with all the data.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/read-installed@4.0.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/read-installed#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/read-installed.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/read-installed@4.0.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/read-installed/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/read-installed/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/read-installed/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "read-installed",
      "version": "1.0.0",
      "description": "Read all the installed packages in a folder, and return a tree structure with all the data.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/read-installed@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/read-installed"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/read-installed@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/read-installed/test/fixtures/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/read-installed/test/fixtures/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/read-installed/test/fixtures/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "example",
      "version": "0.0.0",
      "scope": "optional",
      "purl": "pkg:npm/example@0.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/example@0.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/read-installed/test/fixtures/grandparent-peer-dev/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/read-installed/test/fixtures/grandparent-peer/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/read-installed/test/fixtures/grandparent-peer/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/read-installed/test/fixtures/grandparent-peer/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "extraneous-dev-dep",
      "version": "0.0.0",
      "scope": "optional",
      "purl": "pkg:npm/extraneous-dev-dep@0.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/extraneous-dev-dep@0.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/read-installed/test/fixtures/extraneous-dev-dep/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/read-installed/test/fixtures/extraneous-dev-dep/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/read-installed/test/fixtures/extraneous-dev-dep/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "extraneous-detected",
      "version": "0.0.0",
      "scope": "optional",
      "purl": "pkg:npm/extraneous-detected@0.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/extraneous-detected@0.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/read-installed/test/fixtures/extraneous-detected/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/read-installed/test/fixtures/extraneous-detected/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/read-installed/test/fixtures/extraneous-detected/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "util-extend",
      "version": "1.0.3",
      "description": "Node's internal object extension function",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/util-extend@1.0.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/util-extend#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/util-extend.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/util-extend@1.0.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/read-installed/node_modules/util-extend/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/read-installed/node_modules/util-extend/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/read-installed/node_modules/util-extend/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Rebecca Turner <me@re-becca.org> (http://re-becca.org/)"
        }
      ],
      "group": "",
      "name": "read-cmd-shim",
      "version": "1.0.1",
      "description": "Figure out what a cmd-shim is pointing at. This acts as the equivalent of fs.readlink.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/read-cmd-shim@1.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/npm/read-cmd-shim#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/npm/read-cmd-shim.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/read-cmd-shim@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/read-cmd-shim/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/read-cmd-shim/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/read-cmd-shim/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "read",
      "version": "1.0.7",
      "description": "read(1) for node programs",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/read@1.0.7",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/read#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/read.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/read@1.0.7",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/read/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/read/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/read/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "mute-stream",
      "version": "0.0.5",
      "description": "Bytes go in, but they don't come out (when muted).",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/mute-stream@0.0.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/mute-stream#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/mute-stream.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/mute-stream@0.0.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/read/node_modules/mute-stream/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/read/node_modules/mute-stream/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/read/node_modules/mute-stream/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Domenic Denicola <domenic@domenicdenicola.com> (http://domenic.me)"
        }
      ],
      "group": "",
      "name": "path-is-inside",
      "version": "1.0.1",
      "description": "Tests whether one path is inside another path",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "WTFPL",
            "url": "https://opensource.org/licenses/WTFPL",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Public Domain"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "false"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/path-is-inside@1.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/domenic/path-is-inside#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/domenic/path-is-inside.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/path-is-inside@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/path-is-inside/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Public Domain"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/path-is-inside/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/path-is-inside/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "osenv",
      "version": "0.1.3",
      "description": "Look up environment settings specific to different operating systems",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/osenv@0.1.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/npm/osenv#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/npm/osenv.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/osenv@0.1.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/osenv/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/osenv/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/osenv/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "os-tmpdir",
      "version": "1.0.1",
      "description": "Node.js os.tmpdir() ponyfill",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/os-tmpdir@1.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/sindresorhus/os-tmpdir#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/sindresorhus/os-tmpdir.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/os-tmpdir@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/osenv/node_modules/os-tmpdir/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/osenv/node_modules/os-tmpdir/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/osenv/node_modules/os-tmpdir/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "os-homedir",
      "version": "1.0.1",
      "description": "io.js 2.3.0 os.homedir() ponyfill",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/os-homedir@1.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/sindresorhus/os-homedir#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/sindresorhus/os-homedir.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/os-homedir@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/osenv/node_modules/os-homedir/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/osenv/node_modules/os-homedir/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/osenv/node_modules/os-homedir/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Domenic Denicola <d@domenic.me> (https://domenic.me/)"
        }
      ],
      "group": "",
      "name": "opener",
      "version": "1.4.1",
      "description": "Opens stuff, like webpages and files and executables, cross-platform",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "WTFPL",
            "url": "https://opensource.org/licenses/WTFPL",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Public Domain"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "false"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/opener@1.4.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/domenic/opener"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/domenic/opener.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/opener@1.4.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/opener/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Public Domain"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/opener/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/opener/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "npmlog",
      "version": "2.0.2",
      "description": "logger for npm",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/npmlog@2.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/npm/npmlog#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/npm/npmlog.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/npmlog@2.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/npmlog/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/npmlog/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/npmlog/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Rebecca Turner <me@re-becca.org>"
        }
      ],
      "group": "",
      "name": "gauge",
      "version": "1.2.5",
      "description": "A terminal based horizontal guage",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/gauge@1.2.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/iarna/gauge"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/iarna/gauge.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/gauge@1.2.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/npmlog/node_modules/gauge/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/npmlog/node_modules/gauge/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/npmlog/node_modules/gauge/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash.padright",
      "version": "3.1.1",
      "description": "The modern build of lodash’s `_.padRight` as a module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/lodash.padright@3.1.1",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/lodash/lodash.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash.padright@3.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padright/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padright/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padright/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padright/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash._createpadding",
      "version": "3.6.1",
      "description": "The modern build of lodash’s internal `createPadding` as a module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/lodash._createpadding@3.6.1",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/lodash/lodash.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash._createpadding@3.6.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padright/node_modules/lodash._createpadding/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padleft/node_modules/lodash._createpadding/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padright/node_modules/lodash._createpadding/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padleft/node_modules/lodash._createpadding/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padleft/node_modules/lodash._createpadding/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padleft/node_modules/lodash._createpadding/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash.repeat",
      "version": "3.1.1",
      "description": "The lodash method `_.repeat` exported as a module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/lodash.repeat@3.1.1",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/lodash/lodash.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash.repeat@3.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padright/node_modules/lodash._createpadding/node_modules/lodash.repeat/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padleft/node_modules/lodash._createpadding/node_modules/lodash.repeat/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/npmlog/node_modules/gauge/node_modules/lodash.pad/node_modules/lodash.repeat/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/npmlog/node_modules/gauge/node_modules/lodash.pad/node_modules/lodash.repeat/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/npmlog/node_modules/gauge/node_modules/lodash.pad/node_modules/lodash.repeat/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash._basetostring",
      "version": "3.0.1",
      "description": "The modern build of lodash’s internal `baseToString` as a module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/lodash._basetostring@3.0.1",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/lodash/lodash.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash._basetostring@3.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padright/node_modules/lodash._basetostring/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padleft/node_modules/lodash._basetostring/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padright/node_modules/lodash._basetostring/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padleft/node_modules/lodash._basetostring/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padleft/node_modules/lodash._basetostring/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padleft/node_modules/lodash._basetostring/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash.padleft",
      "version": "3.1.1",
      "description": "The modern build of lodash’s `_.padLeft` as a module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/lodash.padleft@3.1.1",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/lodash/lodash.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash.padleft@3.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padleft/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padleft/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padleft/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padleft/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash.pad",
      "version": "3.2.1",
      "description": "The lodash method `_.pad` exported as a module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/lodash.pad@3.2.1",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/lodash/lodash.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash.pad@3.2.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/npmlog/node_modules/gauge/node_modules/lodash.pad/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/npmlog/node_modules/gauge/node_modules/lodash.pad/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/npmlog/node_modules/gauge/node_modules/lodash.pad/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Rebecca Turner (http://re-becca.org)"
        }
      ],
      "group": "",
      "name": "are-we-there-yet",
      "version": "1.0.6",
      "description": "Keep track of the overall completion of many dispirate processes",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/are-we-there-yet@1.0.6",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/iarna/are-we-there-yet"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/iarna/are-we-there-yet.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/are-we-there-yet@1.0.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/npmlog/node_modules/are-we-there-yet/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/npmlog/node_modules/are-we-there-yet/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/npmlog/node_modules/are-we-there-yet/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "delegates",
      "version": "1.0.0",
      "description": "delegate methods and accessors to another property",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/delegates@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/visionmedia/node-delegates#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/visionmedia/node-delegates.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/delegates@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/npmlog/node_modules/are-we-there-yet/node_modules/delegates/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/npmlog/node_modules/are-we-there-yet/node_modules/delegates/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/npmlog/node_modules/are-we-there-yet/node_modules/delegates/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Nathan Rajlich <nathan@tootallnate.net> (http://tootallnate.net)"
        }
      ],
      "group": "",
      "name": "ansi",
      "version": "0.3.1",
      "description": "Advanced ANSI formatting tool for Node.js",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/ansi@0.3.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/TooTallNate/ansi.js#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/TooTallNate/ansi.js.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/ansi@0.3.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/npmlog/node_modules/ansi/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/ansi/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/ansi/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/ansi/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Robert Kowalski <rok@kowalski.gd>"
        }
      ],
      "group": "",
      "name": "npm-user-validate",
      "version": "0.1.2",
      "description": "User validations for npm",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-2-Clause",
            "url": "https://opensource.org/licenses/BSD-2-Clause",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/npm-user-validate@0.1.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/npm/npm-user-validate#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/npm/npm-user-validate.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/npm-user-validate@0.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/npm-user-validate/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/npm-user-validate/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/npm-user-validate/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "npm-registry-client",
      "version": "7.0.9",
      "description": "Client for the npm registry",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/npm-registry-client@7.0.9",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/npm/npm-registry-client#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/npm/npm-registry-client.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/npm-registry-client@7.0.9",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/npm-registry-client/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/npm-registry-client/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/npm-registry-client/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Tim Koschützki <tim@debuggable.com> (http://debuggable.com/)"
        }
      ],
      "group": "",
      "name": "retry",
      "version": "0.8.0",
      "description": "Abstraction for exponential and custom retry strategies for failed operations.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/retry@0.8.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/tim-kos/node-retry"
        },
        {
          "type": "vcs",
          "url": "git://github.com/tim-kos/node-retry.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/retry@0.8.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/npm-registry-client/node_modules/retry/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/npm-registry-client/node_modules/retry/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/npm-registry-client/node_modules/retry/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Max Ogden <max@maxogden.com>"
        }
      ],
      "group": "",
      "name": "concat-stream",
      "version": "1.5.1",
      "description": "writable stream that concatenates strings or binary data and calls a callback with the result",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/concat-stream@1.5.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/maxogden/concat-stream#readme"
        },
        {
          "type": "vcs",
          "url": "git+ssh://git@github.com/maxogden/concat-stream.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/concat-stream@1.5.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/npm-registry-client/node_modules/concat-stream/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/npm-registry-client/node_modules/concat-stream/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/npm-registry-client/node_modules/concat-stream/package.json"
          }
        ]
      },
      "tags": [
        "binary",
        "stream"
      ]
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "typedarray",
      "version": "0.0.6",
      "description": "TypedArray polyfill for old browsers",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/typedarray@0.0.6",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/typedarray"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/typedarray.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/typedarray@0.0.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/npm-registry-client/node_modules/concat-stream/node_modules/typedarray/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/npm-registry-client/node_modules/concat-stream/node_modules/typedarray/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/npm-registry-client/node_modules/concat-stream/node_modules/typedarray/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "npm-package-arg",
      "version": "4.1.0",
      "description": "Parse the things that can be arguments to `npm install`",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/npm-package-arg@4.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/npm/npm-package-arg"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/npm/npm-package-arg.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/npm-package-arg@4.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/npm-package-arg/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/npm-package-arg/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/npm-package-arg/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Robert Kowalski <rok@kowalski.gd>"
        }
      ],
      "group": "",
      "name": "npm-install-checks",
      "version": "3.0.0",
      "description": "checks that npm runs during the installation of a module",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-2-Clause",
            "url": "https://opensource.org/licenses/BSD-2-Clause",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/npm-install-checks@3.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/npm/npm-install-checks"
        },
        {
          "type": "vcs",
          "url": "git://github.com/npm/npm-install-checks.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/npm-install-checks@3.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/npm-install-checks/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/npm-install-checks/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/npm-install-checks/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "npm-cache-filename",
      "version": "1.0.2",
      "description": "Given a cache folder and url, return the appropriate cache folder.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/npm-cache-filename@1.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/npm/npm-cache-filename"
        },
        {
          "type": "vcs",
          "url": "git://github.com/npm/npm-cache-filename.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/npm-cache-filename@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/npm-cache-filename/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/npm-cache-filename/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/npm-cache-filename/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Meryn Stol <merynstol@gmail.com>"
        }
      ],
      "group": "",
      "name": "normalize-package-data",
      "version": "2.3.5",
      "description": "Normalizes data that can be found in package.json files.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-2-Clause",
            "url": "https://opensource.org/licenses/BSD-2-Clause",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/normalize-package-data@2.3.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/npm/normalize-package-data#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/npm/normalize-package-data.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/normalize-package-data@2.3.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/normalize-package-data/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/normalize-package-data/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/normalize-package-data/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "is-builtin-module",
      "version": "1.0.0",
      "description": "Check if a string matches the name of a Node.js builtin module",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/is-builtin-module@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/sindresorhus/is-builtin-module"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/sindresorhus/is-builtin-module.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/is-builtin-module@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/normalize-package-data/node_modules/is-builtin-module/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/normalize-package-data/node_modules/is-builtin-module/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/normalize-package-data/node_modules/is-builtin-module/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "builtin-modules",
      "version": "1.1.1",
      "description": "List of the Node.js builtin modules",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/builtin-modules@1.1.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/sindresorhus/builtin-modules#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/sindresorhus/builtin-modules.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/builtin-modules@1.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/normalize-package-data/node_modules/is-builtin-module/node_modules/builtin-modules/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/normalize-package-data/node_modules/is-builtin-module/node_modules/builtin-modules/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/normalize-package-data/node_modules/is-builtin-module/node_modules/builtin-modules/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Forrest L Norvell <ogd@aoaioxxysz.net>"
        }
      ],
      "group": "",
      "name": "normalize-git-url",
      "version": "3.0.1",
      "description": "Normalizes Git URLs. For npm, but you can use it too.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/normalize-git-url@3.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/npm/normalize-git-url"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/npm/normalize-git-url.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/normalize-git-url@3.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/normalize-git-url/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/normalize-git-url/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/normalize-git-url/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "nopt",
      "version": "3.0.6",
      "description": "Option parsing for Node, supporting types, shorthands, etc. Used by npm.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/nopt@3.0.6",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/npm/nopt#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/npm/nopt.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/nopt@3.0.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/nopt/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/nopt/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/nopt/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Nathan Rajlich <nathan@tootallnate.net> (http://tootallnate.net)"
        }
      ],
      "group": "",
      "name": "node-gyp",
      "version": "3.2.1",
      "description": "Node.js native addon build tool",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/node-gyp@3.2.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/nodejs/node-gyp#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/nodejs/node-gyp.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/node-gyp@3.2.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/node-gyp/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/node-gyp/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/node-gyp/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Nathan Rajlich <nathan@tootallnate.net> (http://n8.io/)"
        }
      ],
      "group": "",
      "name": "path-array",
      "version": "1.0.1",
      "description": "Treat your $PATH like a JavaScript Array",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/path-array@1.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/TooTallNate/node-path-array"
        },
        {
          "type": "vcs",
          "url": "git://github.com/TooTallNate/node-path-array.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/path-array@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/node-gyp/node_modules/path-array/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/node-gyp/node_modules/path-array/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/node-gyp/node_modules/path-array/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Nathan Rajlich <nathan@tootallnate.net> (http://tootallnate.net)"
        }
      ],
      "group": "",
      "name": "array-index",
      "version": "1.0.0",
      "description": "Invoke getter/setter functions on array-like objects",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/array-index@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/TooTallNate/array-index#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/TooTallNate/array-index.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/array-index@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/node-gyp/node_modules/path-array/node_modules/array-index/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/node-gyp/node_modules/path-array/node_modules/array-index/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/node-gyp/node_modules/path-array/node_modules/array-index/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mariusz Nowak <medyk@medikoo.com> (http://www.medikoo.com/)"
        }
      ],
      "group": "",
      "name": "es6-symbol",
      "version": "3.0.2",
      "description": "ECMAScript 6 Symbol polyfill",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/es6-symbol@3.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/medikoo/es6-symbol#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/medikoo/es6-symbol.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/es6-symbol@3.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/node-gyp/node_modules/path-array/node_modules/array-index/node_modules/es6-symbol/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/node-gyp/node_modules/path-array/node_modules/array-index/node_modules/es6-symbol/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/node-gyp/node_modules/path-array/node_modules/array-index/node_modules/es6-symbol/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mariusz Nowak <medyk@medikoo.com> (http://www.medikoo.com/)"
        }
      ],
      "group": "",
      "name": "es5-ext",
      "version": "0.10.11",
      "description": "ECMAScript extensions and shims",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/es5-ext@0.10.11",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/medikoo/es5-ext#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/medikoo/es5-ext.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/es5-ext@0.10.11",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/node-gyp/node_modules/path-array/node_modules/array-index/node_modules/es6-symbol/node_modules/es5-ext/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/node-gyp/node_modules/path-array/node_modules/array-index/node_modules/es6-symbol/node_modules/es5-ext/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/node-gyp/node_modules/path-array/node_modules/array-index/node_modules/es6-symbol/node_modules/es5-ext/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mariusz Nowak <medyk@medikoo.com> (http://www.medikoo.com/)"
        }
      ],
      "group": "",
      "name": "es6-iterator",
      "version": "2.0.0",
      "description": "Iterator abstraction based on ES6 specification",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/es6-iterator@2.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/medikoo/es6-iterator#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/medikoo/es6-iterator.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/es6-iterator@2.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/node-gyp/node_modules/path-array/node_modules/array-index/node_modules/es6-symbol/node_modules/es5-ext/node_modules/es6-iterator/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/node-gyp/node_modules/path-array/node_modules/array-index/node_modules/es6-symbol/node_modules/es5-ext/node_modules/es6-iterator/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/node-gyp/node_modules/path-array/node_modules/array-index/node_modules/es6-symbol/node_modules/es5-ext/node_modules/es6-iterator/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mariusz Nowak <medyk@medikoo.com> (http://www.medikoo.com/)"
        }
      ],
      "group": "",
      "name": "d",
      "version": "0.1.1",
      "description": "Property descriptor factory",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/d@0.1.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/medikoo/d"
        },
        {
          "type": "vcs",
          "url": "git://github.com/medikoo/d.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/d@0.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/node-gyp/node_modules/path-array/node_modules/array-index/node_modules/es6-symbol/node_modules/d/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/node-gyp/node_modules/path-array/node_modules/array-index/node_modules/es6-symbol/node_modules/d/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/node-gyp/node_modules/path-array/node_modules/array-index/node_modules/es6-symbol/node_modules/d/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "TJ Holowaychuk <tj@vision-media.ca>"
        }
      ],
      "group": "",
      "name": "debug",
      "version": "2.2.0",
      "description": "small debugging utility",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/debug@2.2.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/visionmedia/debug"
        },
        {
          "type": "vcs",
          "url": "git://github.com/visionmedia/debug.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/debug@2.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/node-gyp/node_modules/path-array/node_modules/array-index/node_modules/debug/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/node-gyp/node_modules/path-array/node_modules/array-index/node_modules/debug/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/node-gyp/node_modules/path-array/node_modules/array-index/node_modules/debug/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "ms",
      "version": "0.7.1",
      "description": "Tiny ms conversion utility",
      "scope": "optional",
      "purl": "pkg:npm/ms@0.7.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/guille/ms.js"
        },
        {
          "type": "vcs",
          "url": "git://github.com/guille/ms.js.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/ms@0.7.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/node-gyp/node_modules/path-array/node_modules/array-index/node_modules/debug/node_modules/ms/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/node-gyp/node_modules/path-array/node_modules/array-index/node_modules/debug/node_modules/ms/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/node-gyp/node_modules/path-array/node_modules/array-index/node_modules/debug/node_modules/ms/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "npmlog",
      "version": "1.2.1",
      "description": "logger for npm",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/npmlog@1.2.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/npmlog#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/npmlog.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/npmlog@1.2.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/node-gyp/node_modules/npmlog/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/node-gyp/node_modules/npmlog/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/node-gyp/node_modules/npmlog/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Rebecca Turner <me@re-becca.org>"
        }
      ],
      "group": "",
      "name": "gauge",
      "version": "1.2.4",
      "description": "A terminal based horizontal guage",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/gauge@1.2.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/iarna/gauge"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/iarna/gauge.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/gauge@1.2.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/gauge/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/gauge/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/gauge/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash.repeat",
      "version": "3.1.0",
      "description": "The lodash method `_.repeat` exported as a module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/lodash.repeat@3.1.0",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/lodash/lodash.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash.repeat@3.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padright/node_modules/lodash._createpadding/node_modules/lodash.repeat/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/gauge/node_modules/lodash.padleft/node_modules/lodash._createpadding/node_modules/lodash.repeat/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/gauge/node_modules/lodash.pad/node_modules/lodash.repeat/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/gauge/node_modules/lodash.pad/node_modules/lodash.repeat/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/gauge/node_modules/lodash.pad/node_modules/lodash.repeat/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash.pad",
      "version": "3.2.0",
      "description": "The lodash method `_.pad` exported as a module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/lodash.pad@3.2.0",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/lodash/lodash.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash.pad@3.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/gauge/node_modules/lodash.pad/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/gauge/node_modules/lodash.pad/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/gauge/node_modules/lodash.pad/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Rebecca Turner (http://re-becca.org)"
        }
      ],
      "group": "",
      "name": "are-we-there-yet",
      "version": "1.0.5",
      "description": "Keep track of the overall completion of many dispirate processes",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/are-we-there-yet@1.0.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/iarna/are-we-there-yet"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/iarna/are-we-there-yet.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/are-we-there-yet@1.0.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/are-we-there-yet/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/are-we-there-yet/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/are-we-there-yet/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "delegates",
      "version": "0.1.0",
      "description": "delegate methods and accessors to another property",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/delegates@0.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/visionmedia/node-delegates"
        },
        {
          "type": "vcs",
          "url": "git://github.com/visionmedia/node-delegates.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/delegates@0.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/are-we-there-yet/node_modules/delegates/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/are-we-there-yet/node_modules/delegates/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/node-gyp/node_modules/npmlog/node_modules/are-we-there-yet/node_modules/delegates/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me)"
        }
      ],
      "group": "",
      "name": "minimatch",
      "version": "1.0.0",
      "description": "a glob matcher in javascript",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/minimatch@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/minimatch"
        },
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/minimatch.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/minimatch@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/node-gyp/node_modules/minimatch/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/node-gyp/node_modules/minimatch/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/node-gyp/node_modules/minimatch/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "sigmund",
      "version": "1.0.1",
      "description": "Quick and dirty signatures for Objects.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/sigmund@1.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/sigmund#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/sigmund.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/sigmund@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/node-gyp/node_modules/minimatch/node_modules/sigmund/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/node-gyp/node_modules/minimatch/node_modules/sigmund/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/node-gyp/node_modules/minimatch/node_modules/sigmund/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "glob",
      "version": "4.5.3",
      "description": "a little globber",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/glob@4.5.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/node-glob"
        },
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/node-glob.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/glob@4.5.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/node-gyp/node_modules/glob/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/node-gyp/node_modules/glob/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/node-gyp/node_modules/glob/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me)"
        }
      ],
      "group": "",
      "name": "minimatch",
      "version": "2.0.10",
      "description": "a glob matcher in javascript",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/minimatch@2.0.10",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/minimatch#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/minimatch.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/minimatch@2.0.10",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/node-gyp/node_modules/glob/node_modules/minimatch/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/node-gyp/node_modules/glob/node_modules/minimatch/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/node-gyp/node_modules/glob/node_modules/minimatch/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Julian Gruber <mail@juliangruber.com> (http://juliangruber.com)"
        }
      ],
      "group": "",
      "name": "brace-expansion",
      "version": "1.1.2",
      "description": "Brace expansion as known from sh/bash",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/brace-expansion@1.1.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/juliangruber/brace-expansion"
        },
        {
          "type": "vcs",
          "url": "git://github.com/juliangruber/brace-expansion.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/brace-expansion@1.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/node-gyp/node_modules/glob/node_modules/minimatch/node_modules/brace-expansion/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/glob/node_modules/minimatch/node_modules/brace-expansion/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/fstream-npm/node_modules/fstream-ignore/node_modules/minimatch/node_modules/brace-expansion/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/fstream-npm/node_modules/fstream-ignore/node_modules/minimatch/node_modules/brace-expansion/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/fstream-npm/node_modules/fstream-ignore/node_modules/minimatch/node_modules/brace-expansion/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "concat-map",
      "version": "0.0.1",
      "description": "concatenative mapdashery",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/concat-map@0.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/node-concat-map"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/node-concat-map.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/concat-map@0.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/node-gyp/node_modules/glob/node_modules/minimatch/node_modules/brace-expansion/node_modules/concat-map/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/glob/node_modules/minimatch/node_modules/brace-expansion/node_modules/concat-map/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/fstream-npm/node_modules/fstream-ignore/node_modules/minimatch/node_modules/brace-expansion/node_modules/concat-map/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/concat-map/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/concat-map/package.json"
              }
            ],
            "concludedValue": "node_modules/concat-map/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Julian Gruber <mail@juliangruber.com> (http://juliangruber.com)"
        }
      ],
      "group": "",
      "name": "balanced-match",
      "version": "0.3.0",
      "description": "Match balanced character pairs, like \"{\" and \"}\"",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/balanced-match@0.3.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/juliangruber/balanced-match"
        },
        {
          "type": "vcs",
          "url": "git://github.com/juliangruber/balanced-match.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/balanced-match@0.3.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/node-gyp/node_modules/glob/node_modules/minimatch/node_modules/brace-expansion/node_modules/balanced-match/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/glob/node_modules/minimatch/node_modules/brace-expansion/node_modules/balanced-match/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/fstream-npm/node_modules/fstream-ignore/node_modules/minimatch/node_modules/brace-expansion/node_modules/balanced-match/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/balanced-match/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/balanced-match/package.json"
              }
            ],
            "concludedValue": "node_modules/balanced-match/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "mkdirp",
      "version": "0.5.1",
      "description": "Recursively mkdir, like `mkdir -p`",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/mkdirp@0.5.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/node-mkdirp#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/substack/node-mkdirp.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/mkdirp@0.5.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/mkdirp/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/mkdirp/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/mkdirp/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "minimist",
      "version": "0.0.8",
      "description": "parse argument options",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/minimist@0.0.8",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/minimist"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/minimist.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/minimist@0.0.8",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/mkdirp/node_modules/minimist/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/mkdirp/node_modules/minimist/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/mkdirp/node_modules/minimist/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash.without",
      "version": "4.0.2",
      "description": "The lodash method `_.without` exported as a module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/lodash.without@4.0.2",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/lodash/lodash.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash.without@4.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash.without/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/lodash.without/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/lodash.without/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash.rest",
      "version": "4.0.1",
      "description": "The lodash method `_.rest` exported as a module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/lodash.rest@4.0.1",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/lodash/lodash.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash.rest@4.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash.without/node_modules/lodash.rest/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash.union/node_modules/lodash.rest/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/lodash.union/node_modules/lodash.rest/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/lodash.union/node_modules/lodash.rest/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash._setcache",
      "version": "4.0.1",
      "description": "The internal lodash function `SetCache` exported as a module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/lodash._setcache@4.0.1",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/lodash/lodash.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash._setcache@4.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash.without/node_modules/lodash._setcache/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash.uniq/node_modules/lodash._setcache/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash.union/node_modules/lodash._setcache/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/lodash.union/node_modules/lodash._setcache/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/lodash.union/node_modules/lodash._setcache/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash._mapcache",
      "version": "4.0.1",
      "description": "The internal lodash function `MapCache` exported as a module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/lodash._mapcache@4.0.1",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/lodash/lodash.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash._mapcache@4.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash.without/node_modules/lodash._setcache/node_modules/lodash._mapcache/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/lodash.without/node_modules/lodash._setcache/node_modules/lodash._mapcache/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/lodash.without/node_modules/lodash._setcache/node_modules/lodash._mapcache/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash._cachehas",
      "version": "4.0.0",
      "description": "The internal lodash function `cacheHas` exported as a module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/lodash._cachehas@4.0.0",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/lodash/lodash.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash._cachehas@4.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash.without/node_modules/lodash._cachehas/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash.uniq/node_modules/lodash._cachehas/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash.union/node_modules/lodash._cachehas/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/lodash.union/node_modules/lodash._cachehas/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/lodash.union/node_modules/lodash._cachehas/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash._arraymap",
      "version": "3.0.0",
      "description": "The modern build of lodash’s internal `arrayMap` as a module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/lodash._arraymap@3.0.0",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/lodash/lodash.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash._arraymap@3.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash.without/node_modules/lodash._arraymap/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/lodash.without/node_modules/lodash._arraymap/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/lodash.without/node_modules/lodash._arraymap/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash._arrayincludeswith",
      "version": "4.0.0",
      "description": "The internal lodash function `arrayIncludesWith` exported as a module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/lodash._arrayincludeswith@4.0.0",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/lodash/lodash.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash._arrayincludeswith@4.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash.without/node_modules/lodash._arrayincludeswith/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash.uniq/node_modules/lodash._arrayincludeswith/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash.union/node_modules/lodash._arrayincludeswith/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/lodash.union/node_modules/lodash._arrayincludeswith/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/lodash.union/node_modules/lodash._arrayincludeswith/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash._arrayincludes",
      "version": "4.0.0",
      "description": "The internal lodash function `arrayIncludes` exported as a module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/lodash._arrayincludes@4.0.0",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/lodash/lodash.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash._arrayincludes@4.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash.without/node_modules/lodash._arrayincludes/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash.uniq/node_modules/lodash._arrayincludes/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash.union/node_modules/lodash._arrayincludes/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/lodash.union/node_modules/lodash._arrayincludes/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/lodash.union/node_modules/lodash._arrayincludes/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash.uniq",
      "version": "4.1.0",
      "description": "The lodash method `_.uniq` exported as a module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/lodash.uniq@4.1.0",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/lodash/lodash.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash.uniq@4.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash.uniq/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/lodash.uniq/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/lodash.uniq/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash._mapcache",
      "version": "4.1.0",
      "description": "The internal lodash function `MapCache` exported as a module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/lodash._mapcache@4.1.0",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/lodash/lodash.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash._mapcache@4.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash.uniq/node_modules/lodash._setcache/node_modules/lodash._mapcache/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash.union/node_modules/lodash._setcache/node_modules/lodash._mapcache/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash.clonedeep/node_modules/lodash._stack/node_modules/lodash._mapcache/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/lodash.clonedeep/node_modules/lodash._stack/node_modules/lodash._mapcache/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/lodash.clonedeep/node_modules/lodash._stack/node_modules/lodash._mapcache/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash._root",
      "version": "3.0.0",
      "description": "The internal lodash function `root` exported as a module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/lodash._root@3.0.0",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/lodash/lodash.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash._root@3.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash.uniq/node_modules/lodash._root/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash.union/node_modules/lodash._root/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash.clonedeep/node_modules/lodash._root/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/lodash.clonedeep/node_modules/lodash._root/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/lodash.clonedeep/node_modules/lodash._root/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash.union",
      "version": "4.1.0",
      "description": "The lodash method `_.union` exported as a module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/lodash.union@4.1.0",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/lodash/lodash.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash.union@4.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash.union/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/lodash.union/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/lodash.union/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash._baseflatten",
      "version": "4.0.1",
      "description": "The internal lodash function `baseFlatten` exported as a module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/lodash._baseflatten@4.0.1",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/lodash/lodash.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash._baseflatten@4.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash.union/node_modules/lodash._baseflatten/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/lodash.union/node_modules/lodash._baseflatten/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/lodash.union/node_modules/lodash._baseflatten/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash.restparam",
      "version": "3.6.1",
      "description": "The modern build of lodash’s `_.restParam` as a module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/lodash.restparam@3.6.1",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/lodash/lodash.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash.restparam@3.6.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash.restparam/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/lodash.restparam/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/lodash.restparam/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash.keys",
      "version": "4.0.2",
      "description": "The lodash method `_.keys` exported as a module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/lodash.keys@4.0.2",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/lodash/lodash.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash.keys@4.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash.keys/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/lodash.keys/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/lodash.keys/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash.isarray",
      "version": "4.0.0",
      "description": "The lodash method `_.isArray` exported as a module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/lodash.isarray@4.0.0",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/lodash/lodash.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash.isarray@4.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash.isarray/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/lodash.isarray/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/lodash.isarray/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash.isarguments",
      "version": "3.0.6",
      "description": "The lodash method `_.isArguments` exported as a module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/lodash.isarguments@3.0.6",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/lodash/lodash.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash.isarguments@3.0.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash.isarguments/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/lodash.isarguments/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/lodash.isarguments/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash.clonedeep",
      "version": "4.1.0",
      "description": "The lodash method `_.cloneDeep` exported as a module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/lodash.clonedeep@4.1.0",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/lodash/lodash.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash.clonedeep@4.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash.clonedeep/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/lodash.clonedeep/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/lodash.clonedeep/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash._stack",
      "version": "4.0.2",
      "description": "The internal lodash function `Stack` exported as a module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/lodash._stack@4.0.2",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/lodash/lodash.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash._stack@4.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash.clonedeep/node_modules/lodash._stack/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/lodash.clonedeep/node_modules/lodash._stack/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/lodash.clonedeep/node_modules/lodash._stack/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash._basefor",
      "version": "3.0.3",
      "description": "The internal lodash function `baseFor` exported as a module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/lodash._basefor@3.0.3",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/lodash/lodash.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash._basefor@3.0.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash.clonedeep/node_modules/lodash._basefor/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/lodash.clonedeep/node_modules/lodash._basefor/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/lodash.clonedeep/node_modules/lodash._basefor/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash._arrayeach",
      "version": "3.0.0",
      "description": "The modern build of lodash’s internal `arrayEach` as a module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/lodash._arrayeach@3.0.0",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/lodash/lodash.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash._arrayeach@3.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash.clonedeep/node_modules/lodash._arrayeach/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/lodash.clonedeep/node_modules/lodash._arrayeach/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/lodash.clonedeep/node_modules/lodash._arrayeach/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash._getnative",
      "version": "3.9.1",
      "description": "The modern build of lodash’s internal `getNative` as a module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/lodash._getnative@3.9.1",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/lodash/lodash.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash._getnative@3.9.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash._getnative/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/lodash._getnative/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/lodash._getnative/package.json"
          }
        ]
      },
      "tags": [
        "native"
      ]
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash._createcache",
      "version": "3.1.2",
      "description": "The modern build of lodash’s internal `createCache` as a module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/lodash._createcache@3.1.2",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/lodash/lodash.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash._createcache@3.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash._createcache/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/lodash._createcache/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/lodash._createcache/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash._cacheindexof",
      "version": "3.0.2",
      "description": "The modern build of lodash’s internal `cacheIndexOf` as a module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/lodash._cacheindexof@3.0.2",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/lodash/lodash.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash._cacheindexof@3.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash._cacheindexof/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/lodash._cacheindexof/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/lodash._cacheindexof/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash._bindcallback",
      "version": "3.0.1",
      "description": "The modern build of lodash’s internal `bindCallback` as a module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/lodash._bindcallback@3.0.1",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/lodash/lodash.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash._bindcallback@3.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash._bindcallback/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/lodash._bindcallback/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/lodash._bindcallback/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash._baseuniq",
      "version": "3.0.3",
      "description": "The modern build of lodash’s internal `baseUniq` as a module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/lodash._baseuniq@3.0.3",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/lodash/lodash.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash._baseuniq@3.0.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash._baseuniq/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/lodash._baseuniq/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/lodash._baseuniq/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash._baseindexof",
      "version": "3.1.0",
      "description": "The modern build of lodash’s internal `baseIndexOf` as a module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/lodash._baseindexof@3.1.0",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/lodash/lodash.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash._baseindexof@3.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lodash._baseindexof/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/lodash._baseindexof/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/lodash._baseindexof/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "lockfile",
      "version": "1.0.1",
      "description": "A very polite lock file utility, which endeavors to not litter, and to wait patiently for others.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/lockfile@1.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/lockfile#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/lockfile.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lockfile@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/lockfile/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/lockfile/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/lockfile/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "init-package-json",
      "version": "1.9.3",
      "description": "A node module to get your node module started",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/init-package-json@1.9.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/npm/init-package-json#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/npm/init-package-json.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/init-package-json@1.9.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/init-package-json/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/init-package-json/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/init-package-json/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "promzard",
      "version": "0.3.0",
      "description": "prompting wizardly",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/promzard@0.3.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/promzard"
        },
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/promzard.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/promzard@0.3.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/init-package-json/node_modules/promzard/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/init-package-json/node_modules/promzard/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/init-package-json/node_modules/promzard/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "npm-init",
      "version": "0.0.0",
      "description": "an initter you init wit, innit?",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "name": "BSD",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Unstated License"
              },
              {
                "name": "cdx:license:foss",
                "value": "false"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "false"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "false"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/npm-init@0.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/npm-init@0.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/init-package-json/node_modules/promzard/example/npm-init/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Unstated License"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/init-package-json/node_modules/promzard/example/npm-init/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/init-package-json/node_modules/promzard/example/npm-init/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "ini",
      "version": "1.3.4",
      "description": "An ini encoder/decoder for node",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/ini@1.3.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/ini#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/ini.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/ini@1.3.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/ini/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/ini/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/ini/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "inherits",
      "version": "2.0.1",
      "description": "Browser-friendly inheritance fully compatible with standard node.js inherits()",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/inherits@2.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/inherits#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/inherits.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/inherits@2.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/inherits/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/inherits/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/inherits/package.json"
              }
            ],
            "concludedValue": "node_modules/inherits/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "inflight",
      "version": "1.0.4",
      "description": "Add callbacks to requests in flight to avoid async duplication",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/inflight@1.0.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/inflight"
        },
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/inflight.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/inflight@1.0.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/inflight/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/inflight/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/inflight/package.json"
              }
            ],
            "concludedValue": "node_modules/inflight/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jens Taylor <jensyt@gmail.com> (https://github.com/homebrewing)"
        }
      ],
      "group": "",
      "name": "imurmurhash",
      "version": "0.1.4",
      "description": "An incremental implementation of MurmurHash3",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/imurmurhash@0.1.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jensyt/imurmurhash-js"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/jensyt/imurmurhash-js.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/imurmurhash@0.1.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/imurmurhash/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/imurmurhash/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/imurmurhash/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Nadav Ivgi"
        }
      ],
      "group": "",
      "name": "iferr",
      "version": "0.1.5",
      "description": "Higher-order functions for easier error handling",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/iferr@0.1.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/shesek/iferr"
        },
        {
          "type": "vcs",
          "url": "https://github.com/shesek/iferr"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/iferr@0.1.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/iferr/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/iferr/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/iferr/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Rebecca Turner <me@re-becca.org> (http://re-becca.org)"
        }
      ],
      "group": "",
      "name": "hosted-git-info",
      "version": "2.1.4",
      "description": "Provides metadata and conversions from repository urls for Github, Bitbucket and Gitlab",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/hosted-git-info@2.1.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/npm/hosted-git-info"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/npm/hosted-git-info.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/hosted-git-info@2.1.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/hosted-git-info/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/hosted-git-info/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/hosted-git-info/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Rebecca Turner <me@re-becca.org>"
        }
      ],
      "group": "",
      "name": "has-unicode",
      "version": "2.0.0",
      "description": "Try to guess if your terminal supports unicode",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/has-unicode@2.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/iarna/has-unicode"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/iarna/has-unicode.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/has-unicode@2.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/has-unicode/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/has-unicode/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/has-unicode/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "graceful-fs",
      "version": "4.1.3",
      "description": "A drop-in replacement for fs, making various improvements.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/graceful-fs@4.1.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/node-graceful-fs#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/isaacs/node-graceful-fs.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/graceful-fs@4.1.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/graceful-fs/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/graceful-fs/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/graceful-fs/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "glob",
      "version": "6.0.4",
      "description": "a little globber",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/glob@6.0.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/node-glob#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/node-glob.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/glob@6.0.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/glob/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/glob/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/glob/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me)"
        }
      ],
      "group": "",
      "name": "minimatch",
      "version": "3.0.0",
      "description": "a glob matcher in javascript",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/minimatch@3.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/minimatch#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/minimatch.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/minimatch@3.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/glob/node_modules/minimatch/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/fstream-npm/node_modules/fstream-ignore/node_modules/minimatch/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/minimatch/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/minimatch/package.json"
              }
            ],
            "concludedValue": "node_modules/minimatch/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "fstream-npm",
      "version": "1.0.7",
      "description": "fstream class for creating npm packages",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/fstream-npm@1.0.7",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/npm/fstream-npm#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/npm/fstream-npm.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/fstream-npm@1.0.7",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/fstream-npm/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/fstream-npm/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/fstream-npm/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "fstream-ignore",
      "version": "1.0.3",
      "description": "A thing for ignoring files based on globs",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/fstream-ignore@1.0.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/fstream-ignore#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/fstream-ignore.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/fstream-ignore@1.0.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/fstream-npm/node_modules/fstream-ignore/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/fstream-npm/node_modules/fstream-ignore/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/fstream-npm/node_modules/fstream-ignore/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "fstream",
      "version": "1.0.8",
      "description": "Advanced file system stream things",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/fstream@1.0.8",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/fstream#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/fstream.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/fstream@1.0.8",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/fstream/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/fstream/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/fstream/package.json"
          }
        ]
      },
      "tags": [
        "stream"
      ]
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "fs-write-stream-atomic",
      "version": "1.0.8",
      "description": "Like `fs.createWriteStream(...)`, but atomic.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/fs-write-stream-atomic@1.0.8",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/npm/fs-write-stream-atomic"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/npm/fs-write-stream-atomic.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/fs-write-stream-atomic@1.0.8",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/fs-write-stream-atomic/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/fs-write-stream-atomic/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/fs-write-stream-atomic/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Forrest L Norvell <ogd@aoaioxxysz.net>"
        }
      ],
      "group": "",
      "name": "fs-vacuum",
      "version": "1.2.7",
      "description": "recursively remove empty directories -- to a point",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/fs-vacuum@1.2.7",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/npm/fs-vacuum"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/npm/fs-vacuum.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/fs-vacuum@1.2.7",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/fs-vacuum/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/fs-vacuum/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/fs-vacuum/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "editor",
      "version": "1.0.0",
      "description": "launch $EDITOR in your program",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/editor@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/node-editor"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/node-editor.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/editor@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/editor/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/editor/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/editor/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "dezalgo",
      "version": "1.0.3",
      "description": "Contain async insanity so that the dark pony lord doesn't eat souls",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/dezalgo@1.0.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/npm/dezalgo"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/npm/dezalgo.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/dezalgo@1.0.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/dezalgo/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/dezalgo/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/dezalgo/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "asap",
      "version": "2.0.3",
      "description": "High-priority task queue for Node.js and browsers",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/asap@2.0.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/kriskowal/asap#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/kriskowal/asap.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/asap@2.0.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/dezalgo/node_modules/asap/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/dezalgo/node_modules/asap/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/dezalgo/node_modules/asap/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sam Roberts <sam@strongloop.com>"
        }
      ],
      "group": "",
      "name": "debuglog",
      "version": "1.0.1",
      "description": "backport of util.debuglog from node v0.11",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/debuglog@1.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/sam-github/node-debuglog"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/sam-github/node-debuglog.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/debuglog@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/debuglog/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/debuglog/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/debuglog/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Dominic Tarr <dominic.tarr@gmail.com> (http://dominictarr.com)"
        }
      ],
      "group": "",
      "name": "config-chain",
      "version": "1.1.10",
      "description": "HANDLE CONFIGURATION ONCE AND FOR ALL",
      "scope": "optional",
      "purl": "pkg:npm/config-chain@1.1.10",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/dominictarr/config-chain"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/dominictarr/config-chain.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/config-chain@1.1.10",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/config-chain/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/config-chain/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/config-chain/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "proto-list",
      "version": "1.2.4",
      "description": "A utility for managing a prototype chain",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/proto-list@1.2.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/proto-list#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/isaacs/proto-list.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/proto-list@1.2.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/config-chain/node_modules/proto-list/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/config-chain/node_modules/proto-list/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/config-chain/node_modules/proto-list/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Tim Oxley"
        }
      ],
      "group": "",
      "name": "columnify",
      "version": "1.5.4",
      "description": "Render data in text columns. Supports in-column text-wrap.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/columnify@1.5.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/timoxley/columnify"
        },
        {
          "type": "vcs",
          "url": "git://github.com/timoxley/columnify.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/columnify@1.5.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/columnify/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/columnify/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/columnify/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Tim Oxley"
        }
      ],
      "group": "",
      "name": "wcwidth",
      "version": "1.0.0",
      "description": "Port of C's wcwidth() and wcswidth()",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/wcwidth@1.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/wcwidth@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/columnify/node_modules/wcwidth/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/columnify/node_modules/wcwidth/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/columnify/node_modules/wcwidth/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Elijah Insua <tmpvar@gmail.com>"
        }
      ],
      "group": "",
      "name": "defaults",
      "version": "1.0.3",
      "description": "merge single level defaults over a config object",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/defaults@1.0.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/tmpvar/defaults#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/tmpvar/defaults.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/defaults@1.0.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/columnify/node_modules/wcwidth/node_modules/defaults/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/columnify/node_modules/wcwidth/node_modules/defaults/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/columnify/node_modules/wcwidth/node_modules/defaults/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Paul Vorbach <paul@vorba.ch> (http://paul.vorba.ch/)"
        }
      ],
      "group": "",
      "name": "clone",
      "version": "1.0.2",
      "description": "deep cloning of objects and arrays",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/clone@1.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/pvorb/node-clone#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/pvorb/node-clone.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/clone@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/columnify/node_modules/wcwidth/node_modules/defaults/node_modules/clone/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/columnify/node_modules/wcwidth/node_modules/defaults/node_modules/clone/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/columnify/node_modules/wcwidth/node_modules/defaults/node_modules/clone/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "cmd-shim",
      "version": "2.0.2",
      "description": "Used in npm for command line application support",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-2-Clause",
            "url": "https://opensource.org/licenses/BSD-2-Clause",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/cmd-shim@2.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/ForbesLindesay/cmd-shim"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/ForbesLindesay/cmd-shim.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/cmd-shim@2.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/cmd-shim/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/cmd-shim/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/cmd-shim/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "chownr",
      "version": "1.0.1",
      "description": "like `chown -R`",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/chownr@1.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/chownr#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/chownr.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/chownr@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/chownr/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/chownr/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/chownr/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Forrest L Norvell <ogd@aoaioxxysz.net>"
        }
      ],
      "group": "",
      "name": "async-some",
      "version": "1.0.2",
      "description": "short-circuited, asynchronous version of Array.protototype.some",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/async-some@1.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/othiym23/async-some"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/othiym23/async-some.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/async-some@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/async-some/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/async-some/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/async-some/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "archy",
      "version": "1.0.0",
      "description": "render nested hierarchies `npm ls` style with unicode pipes",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/archy@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/node-archy"
        },
        {
          "type": "vcs",
          "url": "git+ssh://git@github.com/substack/node-archy.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/archy@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/archy/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/archy/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/archy/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Rebecca Turner <me@re-becca.org>"
        }
      ],
      "group": "",
      "name": "aproba",
      "version": "1.0.1",
      "description": "A rediculously light-weight argument validator",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/aproba@1.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/iarna/aproba"
        },
        {
          "type": "vcs",
          "url": "https://github.com/iarna/aproba"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/aproba@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/aproba/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/aproba/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/aproba/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Thorsten Lorenz <thlorenz@gmx.de> (thlorenz.com)"
        }
      ],
      "group": "",
      "name": "ansistyles",
      "version": "0.1.3",
      "description": "Functions that surround a string with ansistyle codes so it prints in style.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/ansistyles@0.1.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/thlorenz/ansistyles.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/ansistyles@0.1.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/ansistyles/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/ansistyles/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/ansistyles/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Thorsten Lorenz <thlorenz@gmx.de> (thlorenz.com)"
        }
      ],
      "group": "",
      "name": "ansicolors",
      "version": "0.3.2",
      "description": "Functions that surround a string with ansicolor codes so it prints in color.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/ansicolors@0.3.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/thlorenz/ansicolors.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/ansicolors@0.3.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/ansicolors/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/ansicolors/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/ansicolors/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "ansi-regex",
      "version": "2.0.0",
      "description": "Regular expression for matching ANSI escape codes",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/ansi-regex@2.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/sindresorhus/ansi-regex#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/sindresorhus/ansi-regex.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/ansi-regex@2.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/ansi-regex/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/ansi-regex/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/ansi-regex/package.json"
          }
        ]
      },
      "tags": [
        "escape"
      ]
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me>"
        }
      ],
      "group": "",
      "name": "abbrev",
      "version": "1.0.7",
      "description": "Like ruby's abbrev module, but in js",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/abbrev@1.0.7",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/abbrev-js#readme"
        },
        {
          "type": "vcs",
          "url": "git+ssh://git@github.com/isaacs/abbrev-js.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/abbrev@1.0.7",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm/node_modules/abbrev/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm/node_modules/abbrev/package.json"
              }
            ],
            "concludedValue": "node_modules/npm/node_modules/abbrev/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "minimist",
      "version": "0.0.5",
      "description": "parse argument options",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/minimist@0.0.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/minimist"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/minimist.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/minimist@0.0.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/minimist/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/minimist/package.json"
              }
            ],
            "concludedValue": "node_modules/minimist/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Douglas Crockford (http://crockford.com/)"
        }
      ],
      "group": "",
      "name": "jsonify",
      "version": "0.0.0",
      "description": "JSON without touching any globals",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "name": "Public Domain",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Public Domain"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "false"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "false"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/jsonify@0.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/substack/jsonify.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/jsonify@0.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/jsonify/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Public Domain"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/jsonify/package.json"
              }
            ],
            "concludedValue": "node_modules/jsonify/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "isexe",
      "version": "1.1.2",
      "description": "Minimal module to check if a file is executable.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/isexe@1.1.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/isexe#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/isaacs/isexe.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/isexe@1.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/isexe/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/isexe/package.json"
              }
            ],
            "concludedValue": "node_modules/isexe/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jordan Harband"
        }
      ],
      "group": "",
      "name": "is-symbol",
      "version": "1.0.1",
      "description": "Determine if a value is an ES6 Symbol or not.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/is-symbol@1.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/ljharb/is-symbol.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/is-symbol@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-symbol/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-symbol/package.json"
              }
            ],
            "concludedValue": "node_modules/is-symbol/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jordan Harband"
        }
      ],
      "group": "",
      "name": "is-regex",
      "version": "1.0.3",
      "description": "Is this value a JS regex? Works cross-realm/iframe, and despite ES6 @@toStringTag",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/is-regex@1.0.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/ljharb/is-regex"
        },
        {
          "type": "vcs",
          "url": "git://github.com/ljharb/is-regex.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/is-regex@1.0.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-regex/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-regex/package.json"
              }
            ],
            "concludedValue": "node_modules/is-regex/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jordan Harband"
        }
      ],
      "group": "",
      "name": "is-date-object",
      "version": "1.0.1",
      "description": "Is this value a JS Date object? This module works cross-realm/iframe, and despite ES6 @@toStringTag.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/is-date-object@1.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/ljharb/is-date-object.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/is-date-object@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-date-object/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-date-object/package.json"
              }
            ],
            "concludedValue": "node_modules/is-date-object/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jordan Harband <ljharb@gmail.com> (http://ljharb.codes)"
        }
      ],
      "group": "",
      "name": "is-callable",
      "version": "1.1.2",
      "description": "Is this JS value callable? Works with Functions and GeneratorFunctions, despite ES6 @@toStringTag.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/is-callable@1.1.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/ljharb/is-callable.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/is-callable@1.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-callable/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-callable/package.json"
              }
            ],
            "concludedValue": "node_modules/is-callable/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Thiago de Arruda <tpadilha84@gmail.com>"
        }
      ],
      "group": "",
      "name": "has",
      "version": "1.0.1",
      "description": "Object.prototype.hasOwnProperty.call shortcut",
      "scope": "optional",
      "purl": "pkg:npm/has@1.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/tarruda/has"
        },
        {
          "type": "vcs",
          "url": "git://github.com/tarruda/has.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/has@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/has/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/has/package.json"
              }
            ],
            "concludedValue": "node_modules/has/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "glob",
      "version": "5.0.15",
      "description": "a little globber",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/glob@5.0.15",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/node-glob.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/glob@5.0.15",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/glob/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/glob/package.json"
              }
            ],
            "concludedValue": "node_modules/glob/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Raynos <raynos2@gmail.com>"
        }
      ],
      "group": "",
      "name": "function-bind",
      "version": "1.0.2",
      "description": "Implementation of Function.prototype.bind",
      "scope": "optional",
      "purl": "pkg:npm/function-bind@1.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/Raynos/function-bind"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/function-bind@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/function-bind/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/function-bind/package.json"
              }
            ],
            "concludedValue": "node_modules/function-bind/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Manuel Stofer <manuel@takimata.ch>"
        }
      ],
      "group": "",
      "name": "foreach",
      "version": "2.0.5",
      "description": "foreach component + npm package",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/foreach@2.0.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/manuelstofer/foreach"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/foreach@2.0.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/foreach/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/foreach/package.json"
              }
            ],
            "concludedValue": "node_modules/foreach/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "faucet",
      "version": "0.0.1",
      "description": "human-readable TAP summarizer",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/faucet@0.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/faucet"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/faucet.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/faucet@0.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/faucet/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/faucet/package.json"
              }
            ],
            "concludedValue": "node_modules/faucet/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "tape",
      "version": "2.3.3",
      "description": "tap-producing test harness for node and browsers",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/tape@2.3.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/tape"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/tape.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/tape@2.3.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/faucet/node_modules/tape/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/faucet/node_modules/tape/package.json"
              }
            ],
            "concludedValue": "node_modules/faucet/node_modules/tape/package.json"
          }
        ]
      },
      "tags": [
        "test"
      ]
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "deep-equal",
      "version": "0.1.2",
      "description": "node's assert.deepEqual algorithm",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/deep-equal@0.1.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/substack/node-deep-equal.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/deep-equal@0.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/faucet/node_modules/deep-equal/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/faucet/node_modules/deep-equal/package.json"
              }
            ],
            "concludedValue": "node_modules/faucet/node_modules/deep-equal/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jordan Harband"
        }
      ],
      "group": "",
      "name": "es-to-primitive",
      "version": "1.1.1",
      "description": "ECMAScript “ToPrimitive” algorithm. Provides ES5 and ES6 versions.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/es-to-primitive@1.1.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/ljharb/es-to-primitive.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/es-to-primitive@1.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/es-to-primitive/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/es-to-primitive/package.json"
              }
            ],
            "concludedValue": "node_modules/es-to-primitive/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jordan Harband <ljharb@gmail.com> (http://ljharb.codes)"
        }
      ],
      "group": "",
      "name": "es-abstract",
      "version": "1.5.0",
      "description": "ECMAScript spec abstract operations.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/es-abstract@1.5.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/ljharb/es-abstract.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/es-abstract@1.5.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/es-abstract/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/es-abstract/package.json"
              }
            ],
            "concludedValue": "node_modules/es-abstract/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Raynos <raynos2@gmail.com>"
        }
      ],
      "group": "",
      "name": "duplexer",
      "version": "0.1.1",
      "description": "Creates a duplex stream",
      "scope": "optional",
      "purl": "pkg:npm/duplexer@0.1.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/Raynos/duplexer"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/duplexer@0.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/duplexer/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/duplexer/package.json"
              }
            ],
            "concludedValue": "node_modules/duplexer/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "defined",
      "version": "0.0.0",
      "description": "return the first argument that is `!== undefined`",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/defined@0.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/defined"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/defined.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/defined@0.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/defined/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/defined/package.json"
              }
            ],
            "concludedValue": "node_modules/defined/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jordan Harband"
        }
      ],
      "group": "",
      "name": "define-properties",
      "version": "1.1.2",
      "description": "Define multiple non-enumerable properties at once. Uses `Object.defineProperty` when available; falls back to standard assignment in older engines.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/define-properties@1.1.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/ljharb/define-properties.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/define-properties@1.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/define-properties/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/define-properties/package.json"
              }
            ],
            "concludedValue": "node_modules/define-properties/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "deep-equal",
      "version": "1.0.1",
      "description": "node's assert.deepEqual algorithm",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/deep-equal@1.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/substack/node-deep-equal.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/deep-equal@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/deep-equal/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/deep-equal/package.json"
              }
            ],
            "concludedValue": "node_modules/deep-equal/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Julian Gruber <mail@juliangruber.com> (http://juliangruber.com)"
        }
      ],
      "group": "",
      "name": "brace-expansion",
      "version": "1.1.3",
      "description": "Brace expansion as known from sh/bash",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/brace-expansion@1.1.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/juliangruber/brace-expansion"
        },
        {
          "type": "vcs",
          "url": "git://github.com/juliangruber/brace-expansion.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/brace-expansion@1.1.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/brace-expansion/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/brace-expansion/package.json"
              }
            ],
            "concludedValue": "node_modules/brace-expansion/package.json"
          }
        ]
      }
    }
  ],
  "dependencies": [],
  "annotations": [
    {
      "bom-ref": "metadata-annotations",
      "subjects": [
        "pkg:npm/npm-path@1.1.0"
      ],
      "annotator": {
        "component": {
          "group": "@cyclonedx",
          "name": "cdxgen",
          "version": "12.8.4",
          "purl": "pkg:npm/%40cyclonedx/cdxgen@12.8.4",
          "type": "application",
          "bom-ref": "pkg:npm/@cyclonedx/cdxgen@12.8.4",
          "publisher": "OWASP Foundation",
          "authors": [
            {
              "name": "OWASP Foundation"
            }
          ]
        }
      },
      "timestamp": "2026-09-09T18:26:21Z",
      "text": "This Software Bill-of-Materials (SBOM) document was created on Wednesday, September 9, 2026 with cdxgen. The data was captured during the pre-build lifecycle phase without building the application. The document describes an application named 'npm-path' with version '1.1.0'."
    }
  ]
}