{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ee95cec1-956b-5fcc-95b2-46738ec629e2",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@vitest/snapshot",
      "purl": "pkg:npm/%40vitest/snapshot@3.2.7-tuxcare.1",
      "type": "library",
      "bom-ref": "pkg:npm/%40vitest/snapshot@3.2.7-tuxcare.1",
      "version": "3.2.7-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2026-53633",
      "affects": [
        {
          "ref": "pkg:npm/%40vitest/snapshot@3.2.7-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8c80d758-e78a-5fa8-859a-b6376dd5d9dc",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-53633 does not affect version 3.2.7-tuxcare.1 of @vitest/snapshot. Target vitest 3.2.7-tuxcare.1 is NOT VULNERABLE to CVE-2026-53633. The CDP (Chrome DevTools Protocol) security fix is present in HEAD. The vulnerable pattern (unguarded CDP API forwarding allowing arbitrary file writes and code execution) has been eliminated by commit 385a1aefd, which adds assertCdpAllowed() permission checks before all CDP operations. However, this fix was authored by upstream contributor Hiroshi Ogawa (hi.ogawa.zz@gmail.com) and was already included in upstream Vitest v3.2.7. TuxCare based their 3.2.7-tuxcare.1 release on this upstream version, inheriting the fix rather than actively backporting it. The fix is a vendor/upstream fix, not a TuxCare backport, as no TuxCare merge commit brought this specific fix into tuxcare-current/3.2.7. Note: TuxCare did create a backport for version 4.0.18 (commit 6f0f32e5d by ddanylov@cloudlinux.com) but not for 3.2.7.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-84373",
      "affects": [
        {
          "ref": "pkg:npm/%40vitest/snapshot@3.2.7-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fdd56577-03d9-53c2-adcf-254634bcaeb5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-84373 affects version 3.2.7-tuxcare.1 of @vitest/snapshot."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40vitest/snapshot@3.2.7-tuxcare.1"
    }
  ]
}