{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a12a1fea-e143-57b7-bea9-b8fa1f599cbd",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "devalue",
      "purl": "pkg:npm/devalue@5.9.0-tuxcare.3",
      "type": "library",
      "bom-ref": "pkg:npm/devalue@5.9.0-tuxcare.3",
      "version": "5.9.0-tuxcare.3",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2026-92708",
      "affects": [
        {
          "ref": "pkg:npm/devalue@5.9.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:b89b9e78-5afc-5493-901b-a4dc59999f99",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-92708 is fixed in version 5.9.0-tuxcare.3 of devalue."
      }
    },
    {
      "id": "GHSA-4q55-j62x-fr9h",
      "affects": [
        {
          "ref": "pkg:npm/devalue@5.9.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:0b5e8dee-906b-5d8d-b375-c279a618d3e7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4q55-j62x-fr9h is fixed in version 5.9.0-tuxcare.3 of devalue."
      }
    },
    {
      "id": "GHSA-hx4r-w6wj-j8fg",
      "affects": [
        {
          "ref": "pkg:npm/devalue@5.9.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:abe419e1-6c8d-5b79-977a-12cb2ef8df1c",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-hx4r-w6wj-j8fg does not affect version 5.9.0-tuxcare.3 of devalue. not_affected \u2014 The target repository (devalue v5.9.0) is not affected by GHSA-hx4r-w6wj-j8fg (sparse array DoS in uneval). The vulnerability was fixed in upstream commit 819f1ac7 (2026-02-18) by Elliott Johnson, which added Object.assign optimization to avoid O(n) iteration through sparse array indices. This fix is already present in the shipped v5.9.0 release. The vulnerable pattern (for loop iterating from ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "GHSA-mcm9-63f2-9j32",
      "affects": [
        {
          "ref": "pkg:npm/devalue@5.9.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:519f1b77-f7e3-52ca-8019-663240b65ee6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-mcm9-63f2-9j32 is fixed in version 5.9.0-tuxcare.3 of devalue."
      }
    },
    {
      "id": "GHSA-r9w8-h9r3-54w4",
      "affects": [
        {
          "ref": "pkg:npm/devalue@5.9.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:7f379e31-9cb0-572c-8539-a1fe2baf8287",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-r9w8-h9r3-54w4 is fixed in version 5.9.0-tuxcare.3 of devalue."
      }
    },
    {
      "id": "GHSA-wf3x-273g-mvxv",
      "affects": [
        {
          "ref": "pkg:npm/devalue@5.9.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:9ebc4ec1-d85f-5f25-b101-c9d5078db4c3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-wf3x-273g-mvxv affects version 5.9.0-tuxcare.3 of devalue."
      }
    },
    {
      "id": "GHSA-x5rw-q4pp-hg5g",
      "affects": [
        {
          "ref": "pkg:npm/devalue@5.9.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:54a527f5-6659-5596-a1eb-c02f8ebebd68",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-x5rw-q4pp-hg5g is fixed in version 5.9.0-tuxcare.3 of devalue."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/devalue@5.9.0-tuxcare.3"
    }
  ]
}