{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b7814199-5015-5f1e-bf30-9588be3b5c86",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.6",
      "type": "library",
      "name": "@astrojs/upgrade",
      "version": "3.6.5-tuxcare.6",
      "purl": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:831e8c35-2565-5171-89a5-cc63801a2838",
      "id": "CVE-2024-47885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47885 is fixed in version 3.6.5-tuxcare.6 of @astrojs/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18033c57-732a-5ea3-9932-ea90d9ec01db",
      "id": "CVE-2024-56140",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56140 is fixed in version 3.6.5-tuxcare.6 of @astrojs/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9912d3d5-1b91-5be5-b2e9-9b7956f1bee5",
      "id": "CVE-2024-56159",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56159 is fixed in version 3.6.5-tuxcare.6 of @astrojs/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96201f64-aea3-5159-86e1-561a727772b8",
      "id": "CVE-2025-55303",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55303 is fixed in version 3.6.5-tuxcare.6 of @astrojs/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8905fbd0-93bb-53e6-8ef4-bf89f8f3495f",
      "id": "CVE-2025-61925",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61925 is fixed in version 3.6.5-tuxcare.6 of @astrojs/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3025a96b-2ca4-5cfd-8324-6b890d9069ec",
      "id": "CVE-2025-64525",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64525 is fixed in version 3.6.5-tuxcare.6 of @astrojs/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17ca8ee2-68f9-519c-b541-b4952ca99c0b",
      "id": "CVE-2025-64757",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64757 is fixed in version 3.6.5-tuxcare.6 of @astrojs/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b309e63-7ef2-5554-94c3-58083fb6be1a",
      "id": "CVE-2025-64764",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64764 is fixed in version 3.6.5-tuxcare.6 of @astrojs/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:529a7dfa-e4c3-5ab8-8d3d-b12376488a1c",
      "id": "CVE-2025-64765",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64765 is fixed in version 3.6.5-tuxcare.6 of @astrojs/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4de1e9bb-54e6-5d03-9ca2-aa3e80d13ee9",
      "id": "CVE-2025-65019",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-65019 is fixed in version 3.6.5-tuxcare.6 of @astrojs/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bd73da3-13b5-5b31-b98c-e9d25a18fcac",
      "id": "CVE-2025-66202",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66202 is fixed in version 3.6.5-tuxcare.6 of @astrojs/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b810e43e-df71-57f0-be85-6e55a83cf276",
      "id": "CVE-2026-33769",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33769 is fixed in version 3.6.5-tuxcare.6 of @astrojs/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6781b3ba-0659-5aff-b44e-17b90632a0f4",
      "id": "CVE-2026-41067",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41067 is fixed in version 3.6.5-tuxcare.6 of @astrojs/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58756dc4-fb98-53de-8f8c-a1961168a17f",
      "id": "CVE-2026-45028",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-45028 does not affect version 3.6.5-tuxcare.6 of @astrojs/upgrade. not_affected \u2014 Astro version 3.6.5 is NOT AFFECTED by CVE-2026-45028. The vulnerability concerns server islands encryption (AES-GCM ciphertext replay between props and slots), but server islands functionality does not exist in version 3.6.5. The feature was introduced in later versions (~May 2025, v5.x/6.x), and the vulnerability was fixed in v6.1.10 (April 2026). Exhaustive search across 327 source files con..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d3fe501-25e9-56e8-a9d9-81e40b09404a",
      "id": "CVE-2026-50146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50146 is fixed in version 3.6.5-tuxcare.6 of @astrojs/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17d9c9f6-93c2-5eba-80de-c143e3fb4230",
      "id": "CVE-2026-54298",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54298 is fixed in version 3.6.5-tuxcare.6 of @astrojs/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:773a570a-16e9-5001-bba1-9677d239d831",
      "id": "CVE-2026-54299",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54299 is fixed in version 3.6.5-tuxcare.6 of @astrojs/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95f48dc8-485b-51f5-9fcb-3b6ab39f9459",
      "id": "CVE-2026-59728",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59728 is fixed in version 3.6.5-tuxcare.6 of @astrojs/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d93a0369-4890-5379-8dfe-d0c0fe186ec8",
      "id": "CVE-2026-59729",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59729 is fixed in version 3.6.5-tuxcare.6 of @astrojs/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78b2fbe4-bded-599d-a848-b94cedb93da9",
      "id": "CVE-2026-73422",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-73422 affects version 3.6.5-tuxcare.6 of @astrojs/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba4b0a2d-7775-5fca-8ecf-04883200a096",
      "id": "CVE-2026-84376",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-84376 affects version 3.6.5-tuxcare.6 of @astrojs/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9ea1503-af15-5130-8a94-36d89aa309db",
      "id": "GHSA-26w7-cxv4-gfx2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-26w7-cxv4-gfx2 affects version 3.6.5-tuxcare.6 of @astrojs/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:173f6640-cbe1-59ac-951b-89609b097a0b",
      "id": "GHSA-4g3v-8h47-v7g6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-4g3v-8h47-v7g6 affects version 3.6.5-tuxcare.6 of @astrojs/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.6"
    }
  ]
}