{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:44017401-fe9d-5aa5-ba49-4c8a2ae6f7c8",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
      "type": "library",
      "name": "gitpython",
      "version": "3.1.31.post4+tuxcare",
      "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f537edd3-a626-56df-b83c-6b5757b5dd33",
      "id": "CVE-2023-40267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-40267 is fixed in version 3.1.31.post4+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ab034b2-6d95-513a-9baa-2ff429074a92",
      "id": "CVE-2023-40590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40590 affects version 3.1.31.post4+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f17a9e95-f32d-5a0a-b07c-de25f401d6f2",
      "id": "CVE-2023-41040",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41040 is fixed in version 3.1.31.post4+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cdc17724-fdb8-5bfb-bd98-0781204e4931",
      "id": "CVE-2024-22190",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22190 affects version 3.1.31.post4+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb13f74b-7901-5525-9f5c-0e1a0b044178",
      "id": "CVE-2026-42215",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42215 is fixed in version 3.1.31.post4+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63f86c95-56a7-5a03-a54a-08287db74e7c",
      "id": "CVE-2026-42284",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42284 affects version 3.1.31.post4+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6ef6a68-2f0a-51d5-96bb-b1112d85b4d7",
      "id": "CVE-2026-44243",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44243 affects version 3.1.31.post4+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8345d782-0723-57eb-a4d7-184ddedd5ff6",
      "id": "CVE-2026-44244",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44244 is fixed in version 3.1.31.post4+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e05891e-a249-5a2d-a63b-6f2554585cb8",
      "id": "CVE-2026-67322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-67322 affects version 3.1.31.post4+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12a6dd17-60d7-53e9-97c9-89a58d23ab8f",
      "id": "CVE-2026-67323",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-67323 affects version 3.1.31.post4+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e72ca6a-a32e-5343-9795-bd1781b8d67b",
      "id": "CVE-2026-67325",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-67325 affects version 3.1.31.post4+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:438355f3-13b8-5982-940f-9d1bc7e3e7bc",
      "id": "CVE-2026-76217",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-76217 affects version 3.1.31.post4+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a08460e9-876a-58c4-b218-3b7e39876d80",
      "id": "CVE-2026-76218",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-76218 affects version 3.1.31.post4+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a8db65b-0fd8-5829-a0ba-f6739c5040d5",
      "id": "CVE-2026-76219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-76219 affects version 3.1.31.post4+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7297ac46-adbe-5477-a3a3-90a3627d050b",
      "id": "CVE-2026-76220",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-76220 affects version 3.1.31.post4+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73eddd66-a037-54e7-a3d6-258428f67e3e",
      "id": "CVE-2026-76222",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-76222 affects version 3.1.31.post4+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bb46162-f7a0-536d-82f0-aff6d6f79362",
      "id": "CVE-2026-78675",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-78675 affects version 3.1.31.post4+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36fa53df-87d6-5f10-8018-e9ebd6128503",
      "id": "CVE-2026-78676",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-78676 affects version 3.1.31.post4+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fac2607-57de-5659-b284-993a296f7d8a",
      "id": "CVE-2026-78677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-78677 affects version 3.1.31.post4+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e40a79cb-dade-5a9a-a81e-eeca499adc9e",
      "id": "CVE-2026-78678",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-78678 affects version 3.1.31.post4+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd8b39c4-6108-560b-8471-3f3de3a668b7",
      "id": "CVE-2026-78679",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-78679 affects version 3.1.31.post4+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a825f86-c6a0-5339-8ab1-b334519e35d5",
      "id": "GHSA-298h-jpq4-m665",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-298h-jpq4-m665 is a false positive for gitpython 3.1.31.post4+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:690ba0e9-6044-57b2-8ef2-1b7c3fbaadd9",
      "id": "GHSA-2f96-g7mh-g2hx",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-2f96-g7mh-g2hx affects version 3.1.31.post4+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcd53198-e40a-5ef8-a5c3-e93125ddeb0b",
      "id": "GHSA-3f7w-8rr8-f37f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-3f7w-8rr8-f37f affects version 3.1.31.post4+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95812ec2-d36b-548e-a6a8-5813c493b728",
      "id": "GHSA-3rp5-jjmw-4wv2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-3rp5-jjmw-4wv2 affects version 3.1.31.post4+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f407b895-4f17-5249-b86e-52edfdd8707d",
      "id": "GHSA-3vrx-526r-64rm",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-3vrx-526r-64rm is a false positive for gitpython 3.1.31.post4+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29b58108-2806-50da-99e9-79c6a16184be",
      "id": "GHSA-4gmw-gg2m-w46p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-4gmw-gg2m-w46p affects version 3.1.31.post4+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1de23032-aaa8-5c9c-b067-f8957f8433f8",
      "id": "GHSA-4vpg-pfj8-m33q",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-4vpg-pfj8-m33q is a false positive for gitpython 3.1.31.post4+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2ab6438-8e05-54bd-afae-a0b2a557758f",
      "id": "GHSA-539m-9xh6-q6rr",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-539m-9xh6-q6rr affects version 3.1.31.post4+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fc97dd9-bdfb-5771-bc57-4850ce8ee55f",
      "id": "GHSA-6p8h-3wgx-97gf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-6p8h-3wgx-97gf is fixed in version 3.1.31.post4+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ce9f47a-827d-57e4-8c6b-f45d5eaec5e4",
      "id": "GHSA-6r2r-ww24-7h52",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-6r2r-ww24-7h52 is a false positive for gitpython 3.1.31.post4+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1db5df8f-0086-5a5e-abe0-c43f294bf8c8",
      "id": "GHSA-6rj2-96f5-chj9",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-6rj2-96f5-chj9 is a false positive for gitpython 3.1.31.post4+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b305531b-c8a9-5ef6-8de8-64a9df08db66",
      "id": "GHSA-7jx3-jqcp-hhgc",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-7jx3-jqcp-hhgc is a false positive for gitpython 3.1.31.post4+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46b97a91-0d79-517c-a9d2-3e63bcd75c69",
      "id": "GHSA-7r39-6q8m-qw68",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-7r39-6q8m-qw68 is a false positive for gitpython 3.1.31.post4+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60c8660a-8c1f-58c9-b4b3-d27a4bd32fd7",
      "id": "GHSA-89ff-m8wv-p99r",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-89ff-m8wv-p99r is a false positive for gitpython 3.1.31.post4+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f17179c7-37d7-5254-aa57-9f709ac3c7b5",
      "id": "GHSA-94p4-4cq8-9g67",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-94p4-4cq8-9g67 affects version 3.1.31.post4+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0136b890-c9fd-5bfb-8048-09fc5f63f7c8",
      "id": "GHSA-9557-234j-7rv9",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-9557-234j-7rv9 is a false positive for gitpython 3.1.31.post4+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcdd842a-056b-5264-bb6a-a75db8abfbbd",
      "id": "GHSA-956x-8gvw-wg5v",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-956x-8gvw-wg5v affects version 3.1.31.post4+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6795f4f5-f985-57d5-9ff4-a6092f640a90",
      "id": "GHSA-9rj7-rf2p-w77r",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-9rj7-rf2p-w77r affects version 3.1.31.post4+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97bc94d1-2b37-5618-87a9-e53acf762ec1",
      "id": "GHSA-crmc-f4m7-33fj",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-crmc-f4m7-33fj is a false positive for gitpython 3.1.31.post4+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a652cde6-f8bf-5981-828a-b6aee8d83a64",
      "id": "GHSA-fjr4-x663-mwxc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-fjr4-x663-mwxc affects version 3.1.31.post4+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9d07faa-07eb-5957-9774-182b170455aa",
      "id": "GHSA-hh9p-6wh2-4mfc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-hh9p-6wh2-4mfc affects version 3.1.31.post4+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:816320a2-440c-51ee-8103-92d2f2346d5e",
      "id": "GHSA-hmq2-w58f-27jc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-hmq2-w58f-27jc affects version 3.1.31.post4+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f060aad-af77-545d-bd16-c72555897760",
      "id": "GHSA-jm78-9fvv-mhgr",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-jm78-9fvv-mhgr affects version 3.1.31.post4+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58f8df38-511d-55e0-ae20-6edfd8401db1",
      "id": "GHSA-m4f3-g4cq-hqrx",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-m4f3-g4cq-hqrx is a false positive for gitpython 3.1.31.post4+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80f8730b-2918-5b43-a6bc-0ccc281688f2",
      "id": "GHSA-mv93-w799-cj2w",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-mv93-w799-cj2w is fixed in version 3.1.31.post4+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b50f7af-e063-5f7f-b989-302338e0283b",
      "id": "GHSA-p538-c434-8v24",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-p538-c434-8v24 affects version 3.1.31.post4+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f85f30f-f21f-525d-9067-4257c21b9eed",
      "id": "GHSA-r9mr-m37c-5fr3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-r9mr-m37c-5fr3 is fixed in version 3.1.31.post4+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6058f1ef-3172-541e-96dc-97d53ec27d54",
      "id": "GHSA-rwj8-pgh3-r573",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-rwj8-pgh3-r573 affects version 3.1.31.post4+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7807b3bb-2c7f-56b7-a53b-a152a347813b",
      "id": "GHSA-w672-239g-c3gr",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-w672-239g-c3gr is a false positive for gitpython 3.1.31.post4+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5901e03f-8b46-5a53-8728-36b7aab6ddfb",
      "id": "GHSA-wv46-xpj8-pw53",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-wv46-xpj8-pw53 is a false positive for gitpython 3.1.31.post4+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc0e9cef-9cc6-53c0-8eb0-4f10aded2b3e",
      "id": "GHSA-wvpp-8hx9-p66j",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-wvpp-8hx9-p66j is fixed in version 3.1.31.post4+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
    }
  ]
}