{
  "@id": "urn:uuid:b411ca3f-fb88-47d7-971e-d64ad4eeb5d7",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/trim-newlines@1.0.0-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/trim-newlines@1.0.0-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2016-2515 is a false positive for trim-newlines 1.0.0-tuxcare.1. false_positive \u2014 CVE-2016-2515 concerns the 'hawk' HTTP authentication library, but this repository is 'trim-newlines', a simple string utility for trimming newline characters. These are completely different packages with no relationship.",
      "vulnerability": {
        "name": "CVE-2016-2515"
      },
      "impact_statement": "false_positive \u2014 CVE-2016-2515 concerns the 'hawk' HTTP authentication library, but this repository is 'trim-newlines', a simple string utility for trimming newline characters. These are completely different packages with no relationship."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/trim-newlines@1.0.0-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/trim-newlines@1.0.0-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2017-20162 is a false positive for trim-newlines 1.0.0-tuxcare.1. false_positive \u2014 CVE-2017-20162 is a wrong-project match. The CVE affects the vercel/ms time parsing package, but the target repository is sindresorhus/trim-newlines, a completely different package for trimming newline characters. The affected component (ms package's parse function with ReDoS vulnerability) does not exist in this repository.",
      "vulnerability": {
        "name": "CVE-2017-20162"
      },
      "impact_statement": "false_positive \u2014 CVE-2017-20162 is a wrong-project match. The CVE affects the vercel/ms time parsing package, but the target repository is sindresorhus/trim-newlines, a completely different package for trimming newline characters. The affected component (ms package's parse function with ReDoS vulnerability) does not exist in this repository."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/trim-newlines@1.0.0-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/trim-newlines@1.0.0-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2018-3739 is a false positive for trim-newlines 1.0.0-tuxcare.1. false_positive \u2014 CVE-2018-3739 concerns the package 'https-proxy-agent', but the target repository is 'trim-newlines' - a completely different package for string manipulation. This is a wrong-project match. The affected component's code is absent from the entire repository.",
      "vulnerability": {
        "name": "CVE-2018-3739"
      },
      "impact_statement": "false_positive \u2014 CVE-2018-3739 concerns the package 'https-proxy-agent', but the target repository is 'trim-newlines' - a completely different package for string manipulation. This is a wrong-project match. The affected component's code is absent from the entire repository."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/trim-newlines@1.0.0-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/trim-newlines@1.0.0-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-33623 is fixed in version 1.0.0-tuxcare.1 of trim-newlines.",
      "vulnerability": {
        "name": "CVE-2021-33623"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/trim-newlines@1.0.0-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/trim-newlines@1.0.0-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-29167 is a false positive for trim-newlines 1.0.0-tuxcare.1. false_positive \u2014 CVE-2022-29167 concerns the Hawk HTTP authentication library's ReDoS vulnerability in Host header parsing. The target repository is 'trim-newlines', a completely different project that provides simple newline trimming utilities. No Hawk code, HTTP functionality, or Host header parsing exists anywhere in this repository.",
      "vulnerability": {
        "name": "CVE-2022-29167"
      },
      "impact_statement": "false_positive \u2014 CVE-2022-29167 concerns the Hawk HTTP authentication library's ReDoS vulnerability in Host header parsing. The target repository is 'trim-newlines', a completely different project that provides simple newline trimming utilities. No Hawk code, HTTP functionality, or Host header parsing exists anywhere in this repository."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/trim-newlines@1.0.0-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/trim-newlines@1.0.0-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-47178 is a false positive for trim-newlines 1.0.0-tuxcare.1. false_positive \u2014 CVE-2024-47178 concerns basic-auth-connect (HTTP authentication middleware), but the target repository is trim-newlines (string trimming utility). Wrong-project match with no code relationship.",
      "vulnerability": {
        "name": "CVE-2024-47178"
      },
      "impact_statement": "false_positive \u2014 CVE-2024-47178 concerns basic-auth-connect (HTTP authentication middleware), but the target repository is trim-newlines (string trimming utility). Wrong-project match with no code relationship."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/trim-newlines@1.0.0-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/trim-newlines@1.0.0-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pc5p-h8pf-mvwp is a false positive for trim-newlines 1.0.0-tuxcare.1. false_positive \u2014 This CVE advisory (GHSA-pc5p-h8pf-mvwp) was matched to the wrong project. The advisory concerns 'https-proxy-agent' (an HTTPS proxy connection handler), but this repository is 'trim-newlines' (a string manipulation utility). The affected component is completely absent from this repository.",
      "vulnerability": {
        "name": "GHSA-pc5p-h8pf-mvwp"
      },
      "impact_statement": "false_positive \u2014 This CVE advisory (GHSA-pc5p-h8pf-mvwp) was matched to the wrong project. The advisory concerns 'https-proxy-agent' (an HTTPS proxy connection handler), but this repository is 'trim-newlines' (a string manipulation utility). The affected component is completely absent from this repository."
    }
  ]
}
