{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7ee5eddc-f575-5f4f-8791-b6e43ce7a84a",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "framework",
      "purl": "pkg:composer/laravel/framework@7.30.7-p4+tuxcare",
      "type": "library",
      "group": "laravel",
      "bom-ref": "pkg:composer/laravel/framework@7.30.7-p4+tuxcare",
      "version": "7.30.7-p4+tuxcare",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "AIKIDO-2026-10659",
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@7.30.7-p4+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:084cdbc3-3835-5c66-a70d-b6c513058852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2026-10659 is fixed in version 7.30.7-p4+tuxcare of laravel/framework."
      }
    },
    {
      "id": "CVE-2021-43617",
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@7.30.7-p4+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:047a9a65-0d2e-51cc-afd7-604bd38d56d9",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 7.30.7-p4+tuxcare."
      }
    },
    {
      "id": "CVE-2025-27515",
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@7.30.7-p4+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:19997b0d-61ff-5e21-9d07-3e62140d0b00",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27515 is fixed in version 7.30.7-p4+tuxcare of laravel/framework."
      }
    },
    {
      "id": "CVE-2026-102279",
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@7.30.7-p4+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:2af40bd2-5213-5fa6-b92a-f228d0f6daf7",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-102279 does not affect version 7.30.7-p4+tuxcare of laravel/framework. not_affected \u2014 Laravel 7.30.7 is NOT affected by CVE-2026-102279. The vulnerability exists in Laravel 12.x's exception renderer system which uses Tippy.js tooltips with `allowHTML: true` on user-controlled data. Laravel 7.30.7 predates this feature entirely and uses the Whoops library for debug mode exception handling - a completely different architecture with no Tippy.js tooltips, no `data-tippy-content` att...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "GHSA-5vg9-5847-vvmq",
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@7.30.7-p4+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:9a58deab-a4fc-5ad5-bfe4-49da93d5c283",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 7.30.7-p4+tuxcare of laravel/framework."
      }
    },
    {
      "id": "GHSA-crmm-hgp2-wgrp",
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@7.30.7-p4+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:39d32aac-659d-5cb8-9534-21a8c7e9b09c",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 7.30.7-p4+tuxcare of laravel/framework. not_affected \u2014 Laravel 7.30.7-p1+tuxcare is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability exists in the LocalFilesystemAdapter class which provides temporary signed URL generation for local filesystems. This class and the associated local file serving feature were introduced in Laravel 9.x and do not exist in Laravel 7.x.",
        "justification": "code_not_present"
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:composer/laravel/framework@7.30.7-p4+tuxcare"
    }
  ]
}