{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f1a5bb0c-624b-5100-b984-22eb52caaa36",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "astro",
      "purl": "pkg:npm/astro@2.10.15-tuxcare.8",
      "type": "library",
      "bom-ref": "pkg:npm/astro@2.10.15-tuxcare.8",
      "version": "2.10.15-tuxcare.8",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2024-56140",
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:6bb8348e-d050-56a0-bc91-46e75e3ef1ca",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56140 is fixed in version 2.10.15-tuxcare.8 of astro."
      }
    },
    {
      "id": "CVE-2024-56159",
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:22f6e899-569b-55db-bc11-9756ece5347c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56159 is fixed in version 2.10.15-tuxcare.8 of astro."
      }
    },
    {
      "id": "CVE-2025-55303",
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:35557abf-ae87-5ae2-95d8-f6b4558e1d2e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55303 is fixed in version 2.10.15-tuxcare.8 of astro."
      }
    },
    {
      "id": "CVE-2025-61925",
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:6c3d2a3d-d10b-5247-8b4f-7a7df43b20dc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61925 is fixed in version 2.10.15-tuxcare.8 of astro."
      }
    },
    {
      "id": "CVE-2025-64757",
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:447ae930-dddb-510b-9edf-c36c72fd0b13",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64757 is fixed in version 2.10.15-tuxcare.8 of astro."
      }
    },
    {
      "id": "CVE-2025-64764",
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:e84f9a45-beda-5f3c-8551-21ba0d2d6914",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64764 is fixed in version 2.10.15-tuxcare.8 of astro."
      }
    },
    {
      "id": "CVE-2025-64765",
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:afd04bc1-869f-5646-bcb6-b2a954173207",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64765 is fixed in version 2.10.15-tuxcare.8 of astro."
      }
    },
    {
      "id": "CVE-2025-65019",
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:f5326d86-b1d6-563f-b25a-322038340a76",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-65019 is fixed in version 2.10.15-tuxcare.8 of astro."
      }
    },
    {
      "id": "CVE-2025-66202",
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:467a014b-2af1-55bb-bbc7-9236396dab22",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66202 is fixed in version 2.10.15-tuxcare.8 of astro."
      }
    },
    {
      "id": "CVE-2026-33769",
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:9f0d37b3-98a3-54e4-938b-7149d8294acd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33769 is fixed in version 2.10.15-tuxcare.8 of astro."
      }
    },
    {
      "id": "CVE-2026-41067",
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:29515fe4-b06c-57ff-a4bb-27a2c3a6372d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41067 is fixed in version 2.10.15-tuxcare.8 of astro."
      }
    },
    {
      "id": "CVE-2026-45028",
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:40440fe4-0a1a-51f1-9724-3fcc047d2f35",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-45028 does not affect version 2.10.15-tuxcare.8 of astro. not_affected \u2014 Astro version 2.10.14 is not affected by CVE-2026-45028. The server islands feature with encrypted parameter handling does not exist in this version. The vulnerability requires server islands (introduced in later versions) to be present, specifically the encryption/decryption of props and slots parameters via AES-GCM. Version 2.10.14 predates this feature entirely. While the repository contains...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-50146",
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:a608ae18-3193-5ab2-844e-46dda4a0bcfc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50146 is fixed in version 2.10.15-tuxcare.8 of astro."
      }
    },
    {
      "id": "CVE-2026-54298",
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:94abd367-c75c-5be9-a2f8-47168435a83a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54298 is fixed in version 2.10.15-tuxcare.8 of astro."
      }
    },
    {
      "id": "CVE-2026-54299",
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:6298ab02-4953-5b1d-9f43-fb29c436a2ca",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54299 is fixed in version 2.10.15-tuxcare.8 of astro."
      }
    },
    {
      "id": "CVE-2026-59728",
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:734930be-2547-5340-83fd-e0c44c90dcda",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59728 is fixed in version 2.10.15-tuxcare.8 of astro."
      }
    },
    {
      "id": "CVE-2026-59729",
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:f1bf3812-0fbb-51b3-98e8-12bd24c4e5c1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59729 is fixed in version 2.10.15-tuxcare.8 of astro."
      }
    },
    {
      "id": "CVE-2026-73422",
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:2e466140-4871-5fb3-bf6b-cbc6b5f5f2ab",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-73422 is fixed in version 2.10.15-tuxcare.8 of astro."
      }
    },
    {
      "id": "CVE-2026-84376",
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:62536abb-6701-5583-967f-e3ce4a420059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-84376 affects version 2.10.15-tuxcare.8 of astro, and is fixed in 2.10.15-tuxcare.9."
      }
    },
    {
      "id": "GHSA-26w7-cxv4-gfx2",
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:895b70d6-210d-5c31-a47c-ce0472e1d020",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-26w7-cxv4-gfx2 affects version 2.10.15-tuxcare.8 of astro, and is fixed in 2.10.15-tuxcare.9."
      }
    },
    {
      "id": "GHSA-4g3v-8h47-v7g6",
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:072854e6-9993-532d-b260-978ccd5df23c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4g3v-8h47-v7g6 is fixed in version 2.10.15-tuxcare.8 of astro."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/astro@2.10.15-tuxcare.8"
    }
  ]
}