{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:759d442c-7756-51a0-9147-2700623fe906",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@astrojs/upgrade",
      "purl": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.7",
      "type": "library",
      "bom-ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.7",
      "version": "3.6.5-tuxcare.7",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2024-47885",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:55e3de70-6a8b-538b-ae52-f887aace4ebd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47885 is fixed in version 3.6.5-tuxcare.7 of @astrojs/upgrade."
      }
    },
    {
      "id": "CVE-2024-56140",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:4649d12f-a377-5315-8daf-9206cdbc335e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56140 is fixed in version 3.6.5-tuxcare.7 of @astrojs/upgrade."
      }
    },
    {
      "id": "CVE-2024-56159",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:f5c7417a-e80d-5ae2-82e0-838696e320db",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56159 is fixed in version 3.6.5-tuxcare.7 of @astrojs/upgrade."
      }
    },
    {
      "id": "CVE-2025-55303",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:b6a5fcda-dca1-5f52-90f5-9c114a91a597",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55303 is fixed in version 3.6.5-tuxcare.7 of @astrojs/upgrade."
      }
    },
    {
      "id": "CVE-2025-61925",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:10658747-82a7-5d83-b64b-f2924c3f2c77",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61925 is fixed in version 3.6.5-tuxcare.7 of @astrojs/upgrade."
      }
    },
    {
      "id": "CVE-2025-64525",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:1cb9e9f4-109b-514b-a514-3e5a6e5bcb61",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64525 is fixed in version 3.6.5-tuxcare.7 of @astrojs/upgrade."
      }
    },
    {
      "id": "CVE-2025-64757",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:a2729672-3762-5673-8bb7-571c45b48280",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64757 is fixed in version 3.6.5-tuxcare.7 of @astrojs/upgrade."
      }
    },
    {
      "id": "CVE-2025-64764",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:62a1d068-087e-5494-8dcf-a18ac56cc362",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64764 is fixed in version 3.6.5-tuxcare.7 of @astrojs/upgrade."
      }
    },
    {
      "id": "CVE-2025-64765",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:5c70e51c-295d-5511-8efc-720097c4a1a1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64765 is fixed in version 3.6.5-tuxcare.7 of @astrojs/upgrade."
      }
    },
    {
      "id": "CVE-2025-65019",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:33012e91-9c0c-5620-bfee-426944e724cc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-65019 is fixed in version 3.6.5-tuxcare.7 of @astrojs/upgrade."
      }
    },
    {
      "id": "CVE-2025-66202",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:86ddaea4-3825-5fb5-924d-45b1793ccd91",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66202 is fixed in version 3.6.5-tuxcare.7 of @astrojs/upgrade."
      }
    },
    {
      "id": "CVE-2026-33769",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:447a5e97-cfb8-57f0-8d75-98806ed25711",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33769 is fixed in version 3.6.5-tuxcare.7 of @astrojs/upgrade."
      }
    },
    {
      "id": "CVE-2026-41067",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:17f241d5-3fbf-56e6-bd5a-41c4d3a8848b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41067 is fixed in version 3.6.5-tuxcare.7 of @astrojs/upgrade."
      }
    },
    {
      "id": "CVE-2026-45028",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:ec8f10b4-afc3-5c2a-8b41-a9cce01f6c60",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-45028 does not affect version 3.6.5-tuxcare.7 of @astrojs/upgrade. not_affected \u2014 Astro version 3.6.5 is NOT AFFECTED by CVE-2026-45028. The vulnerability concerns server islands encryption (AES-GCM ciphertext replay between props and slots), but server islands functionality does not exist in version 3.6.5. The feature was introduced in later versions (~May 2025, v5.x/6.x), and the vulnerability was fixed in v6.1.10 (April 2026). Exhaustive search across 327 source files con...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-50146",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:35734f29-d1e9-5cbf-9095-3b5e8e9dab4f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50146 is fixed in version 3.6.5-tuxcare.7 of @astrojs/upgrade."
      }
    },
    {
      "id": "CVE-2026-54298",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:0a8e8186-df79-5c97-8816-98bb22464d7c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54298 is fixed in version 3.6.5-tuxcare.7 of @astrojs/upgrade."
      }
    },
    {
      "id": "CVE-2026-54299",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:59dec4ed-242d-5d85-8de9-a7e62298360a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54299 is fixed in version 3.6.5-tuxcare.7 of @astrojs/upgrade."
      }
    },
    {
      "id": "CVE-2026-59728",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:754641a5-965c-53a4-a519-87125108dcaa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59728 is fixed in version 3.6.5-tuxcare.7 of @astrojs/upgrade."
      }
    },
    {
      "id": "CVE-2026-59729",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:6e924515-687d-5a80-9bee-581d032868b0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59729 is fixed in version 3.6.5-tuxcare.7 of @astrojs/upgrade."
      }
    },
    {
      "id": "CVE-2026-73422",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:8788ac62-14e7-5010-904e-ce4f95d25930",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-73422 affects version 3.6.5-tuxcare.7 of @astrojs/upgrade, and is fixed in 3.6.5-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-84376",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:87deba29-bb9f-59c4-9517-52ae96a0b42c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-84376 affects version 3.6.5-tuxcare.7 of @astrojs/upgrade, and is fixed in 3.6.5-tuxcare.9."
      }
    },
    {
      "id": "GHSA-26w7-cxv4-gfx2",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:b44754f4-5581-53f2-a9d0-5f4d1a39ab80",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-26w7-cxv4-gfx2 affects version 3.6.5-tuxcare.7 of @astrojs/upgrade, and is fixed in 3.6.5-tuxcare.9."
      }
    },
    {
      "id": "GHSA-4g3v-8h47-v7g6",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:c21638cc-8310-538c-9b53-0a06c4988d7d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-4g3v-8h47-v7g6 affects version 3.6.5-tuxcare.7 of @astrojs/upgrade, and is fixed in 3.6.5-tuxcare.8."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40astrojs/upgrade@3.6.5-tuxcare.7"
    }
  ]
}