{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:27101b39-a93f-5efd-b597-1a80aca71123",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@astrojs/rss",
      "purl": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.10",
      "type": "library",
      "bom-ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.10",
      "version": "3.6.5-tuxcare.10",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2024-47885",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:804c15db-db4d-5d7e-bb5d-c1c530b6e1c5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47885 is fixed in version 3.6.5-tuxcare.10 of @astrojs/rss."
      }
    },
    {
      "id": "CVE-2024-56140",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:d0e3c17a-b08d-5ec3-881a-0074a08fa713",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56140 is fixed in version 3.6.5-tuxcare.10 of @astrojs/rss."
      }
    },
    {
      "id": "CVE-2024-56159",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:86ba3ea5-84b1-54db-8d3a-57d522b91fd7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56159 is fixed in version 3.6.5-tuxcare.10 of @astrojs/rss."
      }
    },
    {
      "id": "CVE-2025-55303",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:3e432cfd-ceda-53e4-9262-d79fc6344564",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55303 is fixed in version 3.6.5-tuxcare.10 of @astrojs/rss."
      }
    },
    {
      "id": "CVE-2025-61925",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:8b631872-1c88-5de0-bbc1-645de46db94d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61925 is fixed in version 3.6.5-tuxcare.10 of @astrojs/rss."
      }
    },
    {
      "id": "CVE-2025-64525",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:973ab2ae-ff43-5117-acb0-d862f1e04fc0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64525 is fixed in version 3.6.5-tuxcare.10 of @astrojs/rss."
      }
    },
    {
      "id": "CVE-2025-64757",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:68194e34-b8cb-5eea-92e2-1a5c3a0fc789",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64757 is fixed in version 3.6.5-tuxcare.10 of @astrojs/rss."
      }
    },
    {
      "id": "CVE-2025-64764",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:e265b5f9-53c9-5f55-aaf9-b8d3fff55ebd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64764 is fixed in version 3.6.5-tuxcare.10 of @astrojs/rss."
      }
    },
    {
      "id": "CVE-2025-64765",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:00ef119a-e5d7-5621-837b-c7e88d615254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64765 is fixed in version 3.6.5-tuxcare.10 of @astrojs/rss."
      }
    },
    {
      "id": "CVE-2025-65019",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:9239ce15-eb61-5708-933e-c7a195d19dcd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-65019 is fixed in version 3.6.5-tuxcare.10 of @astrojs/rss."
      }
    },
    {
      "id": "CVE-2025-66202",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:e7b4044a-1329-5567-94b5-83382647910b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66202 is fixed in version 3.6.5-tuxcare.10 of @astrojs/rss."
      }
    },
    {
      "id": "CVE-2026-33769",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:09d3056b-a08a-5cc7-9c44-cbaa1c36dc25",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33769 is fixed in version 3.6.5-tuxcare.10 of @astrojs/rss."
      }
    },
    {
      "id": "CVE-2026-41067",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:333d3b21-cfda-522f-8ed0-ef64184407e4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41067 is fixed in version 3.6.5-tuxcare.10 of @astrojs/rss."
      }
    },
    {
      "id": "CVE-2026-45028",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:0a3bab21-40ac-5403-aebb-9f3c3a4cc5d3",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-45028 does not affect version 3.6.5-tuxcare.10 of @astrojs/rss. not_affected \u2014 Astro version 3.6.5 is NOT AFFECTED by CVE-2026-45028. The vulnerability concerns server islands encryption (AES-GCM ciphertext replay between props and slots), but server islands functionality does not exist in version 3.6.5. The feature was introduced in later versions (~May 2025, v5.x/6.x), and the vulnerability was fixed in v6.1.10 (April 2026). Exhaustive search across 327 source files con...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-50146",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:fabb20ab-9e63-595c-bcb7-15de8c47f445",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50146 is fixed in version 3.6.5-tuxcare.10 of @astrojs/rss."
      }
    },
    {
      "id": "CVE-2026-54298",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:d520d022-e01f-5533-a4df-572a21a62ea6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54298 is fixed in version 3.6.5-tuxcare.10 of @astrojs/rss."
      }
    },
    {
      "id": "CVE-2026-54299",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:34e7bdc4-5383-52f6-9275-7eb2f08c61eb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54299 is fixed in version 3.6.5-tuxcare.10 of @astrojs/rss."
      }
    },
    {
      "id": "CVE-2026-59728",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:4eaad6b3-9858-5eec-ad89-5e84bd0a1662",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59728 is fixed in version 3.6.5-tuxcare.10 of @astrojs/rss."
      }
    },
    {
      "id": "CVE-2026-59729",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:aa3c9a72-8be8-5866-96de-150c0c536d84",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59729 is fixed in version 3.6.5-tuxcare.10 of @astrojs/rss."
      }
    },
    {
      "id": "CVE-2026-73422",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:a41ae0c0-afd7-5405-8f78-887f2a561e09",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-73422 is fixed in version 3.6.5-tuxcare.10 of @astrojs/rss."
      }
    },
    {
      "id": "CVE-2026-84376",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:6b14209c-14bd-5df9-b7df-6c950bb671e3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-84376 is fixed in version 3.6.5-tuxcare.10 of @astrojs/rss."
      }
    },
    {
      "id": "GHSA-26w7-cxv4-gfx2",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:59f36338-3d3d-5870-a0fa-738c4ebd8e0f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-26w7-cxv4-gfx2 is fixed in version 3.6.5-tuxcare.10 of @astrojs/rss."
      }
    },
    {
      "id": "GHSA-4g3v-8h47-v7g6",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:7229f606-ef1b-5057-b51f-324aa16ad059",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4g3v-8h47-v7g6 is fixed in version 3.6.5-tuxcare.10 of @astrojs/rss."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.10"
    }
  ]
}