{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:76bafe28-b97b-55b3-8463-fa46e5272e76",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "astro",
      "purl": "pkg:npm/astro@3.6.5-tuxcare.8",
      "type": "library",
      "bom-ref": "pkg:npm/astro@3.6.5-tuxcare.8",
      "version": "3.6.5-tuxcare.8",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2024-47885",
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:71dd4c43-9731-548a-874b-44644f8d739e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47885 is fixed in version 3.6.5-tuxcare.8 of astro."
      }
    },
    {
      "id": "CVE-2024-56140",
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:60e89a03-a15b-50aa-8962-7a8b6e7dcc92",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56140 is fixed in version 3.6.5-tuxcare.8 of astro."
      }
    },
    {
      "id": "CVE-2024-56159",
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:818aaa8e-000a-5ed4-b7ec-f151d38e6af2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56159 is fixed in version 3.6.5-tuxcare.8 of astro."
      }
    },
    {
      "id": "CVE-2025-55303",
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:57b12abf-3494-578c-b7c6-2aff63783098",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55303 is fixed in version 3.6.5-tuxcare.8 of astro."
      }
    },
    {
      "id": "CVE-2025-61925",
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:12ebc87f-1bb6-5943-afff-c41b62b7fde4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61925 is fixed in version 3.6.5-tuxcare.8 of astro."
      }
    },
    {
      "id": "CVE-2025-64525",
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:11ee5c3b-a8f1-5104-b325-935e93400116",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64525 is fixed in version 3.6.5-tuxcare.8 of astro."
      }
    },
    {
      "id": "CVE-2025-64757",
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:473da920-a9ac-572f-a7fb-a74f6c68a138",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64757 is fixed in version 3.6.5-tuxcare.8 of astro."
      }
    },
    {
      "id": "CVE-2025-64764",
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:b92a324d-4f93-500a-88b3-adefe793668c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64764 is fixed in version 3.6.5-tuxcare.8 of astro."
      }
    },
    {
      "id": "CVE-2025-64765",
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:6fd83cb1-b768-515f-888f-f89b08d293f7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64765 is fixed in version 3.6.5-tuxcare.8 of astro."
      }
    },
    {
      "id": "CVE-2025-65019",
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:19bbf6e0-1193-546a-967f-65f666bc647a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-65019 is fixed in version 3.6.5-tuxcare.8 of astro."
      }
    },
    {
      "id": "CVE-2025-66202",
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:0386dbc8-3303-5169-b244-d047ba052e3b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66202 is fixed in version 3.6.5-tuxcare.8 of astro."
      }
    },
    {
      "id": "CVE-2026-33769",
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:fec4ac2a-dd2e-5f50-8139-acd577120402",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33769 is fixed in version 3.6.5-tuxcare.8 of astro."
      }
    },
    {
      "id": "CVE-2026-41067",
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:6200e1c9-8609-5c5f-a053-74210ebe6f8b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41067 is fixed in version 3.6.5-tuxcare.8 of astro."
      }
    },
    {
      "id": "CVE-2026-45028",
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:aaf2528e-1fc5-59a1-b7b5-1d5a018799df",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-45028 does not affect version 3.6.5-tuxcare.8 of astro. not_affected \u2014 Astro version 3.6.5 is NOT AFFECTED by CVE-2026-45028. The vulnerability concerns server islands encryption (AES-GCM ciphertext replay between props and slots), but server islands functionality does not exist in version 3.6.5. The feature was introduced in later versions (~May 2025, v5.x/6.x), and the vulnerability was fixed in v6.1.10 (April 2026). Exhaustive search across 327 source files con...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-50146",
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:c48a7df8-2077-501c-b6b1-3301f7b2d996",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50146 is fixed in version 3.6.5-tuxcare.8 of astro."
      }
    },
    {
      "id": "CVE-2026-54298",
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:1f4f9036-3717-5eb0-8fba-4df073169d0b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54298 is fixed in version 3.6.5-tuxcare.8 of astro."
      }
    },
    {
      "id": "CVE-2026-54299",
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:cff344d6-5815-506d-a0ba-80d4b682141b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54299 is fixed in version 3.6.5-tuxcare.8 of astro."
      }
    },
    {
      "id": "CVE-2026-59728",
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:d1d679b8-febb-5691-9abf-2327a83ff761",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59728 is fixed in version 3.6.5-tuxcare.8 of astro."
      }
    },
    {
      "id": "CVE-2026-59729",
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:a8b68b88-79da-5ae2-9ddb-49ff8c4629b6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59729 is fixed in version 3.6.5-tuxcare.8 of astro."
      }
    },
    {
      "id": "CVE-2026-73422",
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:3ae737c9-78bc-544f-bfec-d50b41cc5585",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-73422 is fixed in version 3.6.5-tuxcare.8 of astro."
      }
    },
    {
      "id": "CVE-2026-84376",
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:059f7e71-05a1-5040-a760-1264ad110ee9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-84376 affects version 3.6.5-tuxcare.8 of astro."
      }
    },
    {
      "id": "GHSA-26w7-cxv4-gfx2",
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:d18a3858-7a4c-592b-a42c-3f05932a3eff",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-26w7-cxv4-gfx2 affects version 3.6.5-tuxcare.8 of astro."
      }
    },
    {
      "id": "GHSA-4g3v-8h47-v7g6",
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:2feea158-fdc3-53d7-b1aa-493f7dcdbdf2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4g3v-8h47-v7g6 is fixed in version 3.6.5-tuxcare.8 of astro."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/astro@3.6.5-tuxcare.8"
    }
  ]
}