{
  "bomFormat": "CycloneDX",
  "specVersion": "1.7",
  "serialNumber": "urn:uuid:30cada11-37e3-4d4a-9225-9968564d1505",
  "version": 1,
  "metadata": {
    "timestamp": "2026-07-29T09:09:03Z",
    "tools": {
      "components": [
        {
          "group": "@cyclonedx",
          "name": "cdxgen",
          "version": "12.3.3",
          "purl": "pkg:npm/%40cyclonedx/cdxgen@12.3.3",
          "type": "application",
          "bom-ref": "pkg:npm/@cyclonedx/cdxgen@12.3.3",
          "publisher": "OWASP Foundation",
          "authors": [
            {
              "name": "OWASP Foundation"
            }
          ]
        }
      ]
    },
    "authors": [
      {
        "name": "OWASP Foundation"
      }
    ],
    "lifecycles": [
      {
        "phase": "pre-build"
      }
    ],
    "component": {
      "name": "degit",
      "group": "",
      "version": "2.8.6",
      "description": "Straightforward project scaffolding",
      "purl": "pkg:npm/degit@2.8.6",
      "bom-ref": "pkg:npm/degit@2.8.6",
      "author": "Rich Harris",
      "properties": [
        {
          "name": "cdx:npm:bin",
          "value": "degit"
        },
        {
          "name": "cdx:npm:has_binary",
          "value": "true"
        },
        {
          "name": "cdx:npm:scripts",
          "value": "lint, lint:ci, knip:ci, format, format:ci, duplicates:ci, dev, build, test, test:live, test:coverage, pretest, prepublishOnly"
        }
      ],
      "type": "application",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/Rich-Harris/degit#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/Rich-Harris/degit.git"
        }
      ]
    },
    "properties": [
      {
        "name": "cdx:bom:componentTypes",
        "value": "npm"
      },
      {
        "name": "cdx:bom:componentNamespaces",
        "value": "@babel\\n@bcoe\\n@colors\\n@jridgewell\\n@jscpd\\n@my-scope\\n@nodelib\\n@oxc-parser\\n@oxc-project\\n@oxc-resolver\\n@oxfmt\\n@oxlint\\n@rolldown\\n@rollup\\n@standard-schema\\n@types\\n@vitest"
      },
      {
        "name": "cdx:bom:componentSrcFiles",
        "value": "node_modules/@babel/code-frame/package.json\\nnode_modules/@babel/helper-string-parser/package.json\\nnode_modules/@babel/helper-validator-identifier/package.json\\nnode_modules/@babel/highlight/node_modules/chalk/node_modules/ansi-styles/node_modules/color-convert/node_modules/color-name/package.json\\nnode_modules/@babel/highlight/node_modules/chalk/node_modules/ansi-styles/node_modules/color-convert/package.json\\nnode_modules/@babel/highlight/node_modules/chalk/node_modules/ansi-styles/package.json\\nnode_modules/@babel/highlight/node_modules/chalk/node_modules/supports-color/node_modules/has-flag/package.json\\nnode_modules/@babel/highlight/node_modules/chalk/node_modules/supports-color/package.json\\nnode_modules/@babel/highlight/node_modules/chalk/package.json\\nnode_modules/@babel/highlight/node_modules/js-tokens/package.json\\nnode_modules/@babel/highlight/package.json\\nnode_modules/@babel/parser/package.json\\nnode_modules/@babel/types/package.json\\nnode_modules/@bcoe/v8-coverage/package.json\\nnode_modules/@colors/colors/package.json\\nnode_modules/@jridgewell/resolve-uri/package.json\\nnode_modules/@jridgewell/sourcemap-codec/package.json\\nnode_modules/@jridgewell/trace-mapping/package.json\\nnode_modules/@jscpd/badge-reporter/package.json\\nnode_modules/@jscpd/core/package.json\\nnode_modules/@jscpd/finder/package.json\\nnode_modules/@jscpd/html-reporter/package.json\\nnode_modules/@jscpd/tokenizer/package.json\\nnode_modules/@nodelib/fs.scandir/package.json\\nnode_modules/@nodelib/fs.stat/package.json\\nnode_modules/@nodelib/fs.walk/package.json\\nnode_modules/@oxc-parser/binding-linux-x64-gnu/package.json\\nnode_modules/@oxc-parser/binding-linux-x64-musl/package.json\\nnode_modules/@oxc-project/types/package.json\\nnode_modules/@oxc-resolver/binding-linux-x64-gnu/package.json\\nnode_modules/@oxc-resolver/binding-linux-x64-musl/package.json\\nnode_modules/@oxfmt/binding-linux-x64-gnu/package.json\\nnode_modules/@oxfmt/binding-linux-x64-musl/package.json\\nnode_modules/@oxlint/binding-linux-x64-gnu/package.json\\nnode_modules/@oxlint/binding-linux-x64-musl/package.json\\nnode_modules/@rolldown/binding-linux-x64-gnu/package.json\\nnode_modules/@rolldown/binding-linux-x64-musl/package.json\\nnode_modules/@rolldown/pluginutils/package.json\\nnode_modules/@rollup/plugin-commonjs/package.json\\nnode_modules/@rollup/plugin-node-resolve/package.json\\nnode_modules/@rollup/pluginutils/node_modules/estree-walker/package.json\\nnode_modules/@rollup/pluginutils/node_modules/picomatch/package.json\\nnode_modules/@rollup/pluginutils/package.json\\nnode_modules/@standard-schema/spec/package.json\\nnode_modules/@types/chai/package.json\\nnode_modules/@types/deep-eql/package.json\\nnode_modules/@types/estree/package.json\\nnode_modules/@types/node/package.json\\nnode_modules/@types/parse-json/package.json\\nnode_modules/@types/resolve/package.json\\nnode_modules/@types/sarif/package.json\\nnode_modules/@vitest/coverage-v8/package.json\\nnode_modules/@vitest/expect/package.json\\nnode_modules/@vitest/mocker/node_modules/estree-walker/node_modules/@types/estree/package.json\\nnode_modules/@vitest/mocker/node_modules/estree-walker/package.json\\nnode_modules/@vitest/mocker/node_modules/magic-string/package.json\\nnode_modules/@vitest/mocker/package.json\\nnode_modules/@vitest/pretty-format/package.json\\nnode_modules/@vitest/runner/package.json\\nnode_modules/@vitest/snapshot/node_modules/magic-string/package.json\\nnode_modules/@vitest/snapshot/package.json\\nnode_modules/@vitest/spy/package.json\\nnode_modules/@vitest/utils/package.json\\nnode_modules/acorn/package.json\\nnode_modules/agent-base/package.json\\nnode_modules/aggregate-error/package.json\\nnode_modules/ansi-colors/package.json\\nnode_modules/ansi-escapes/package.json\\nnode_modules/ansi-regex/package.json\\nnode_modules/ansi-styles/package.json\\nnode_modules/asap/package.json\\nnode_modules/assert-never/package.json\\nnode_modules/assertion-error/package.json\\nnode_modules/ast-v8-to-istanbul/node_modules/estree-walker/node_modules/@types/estree/package.json\\nnode_modules/ast-v8-to-istanbul/node_modules/estree-walker/package.json\\nnode_modules/ast-v8-to-istanbul/package.json\\nnode_modules/astral-regex/package.json\\nnode_modules/babel-walk/package.json\\nnode_modules/badgen/package.json\\nnode_modules/balanced-match/package.json\\nnode_modules/blamer/package.json\\nnode_modules/brace-expansion/package.json\\nnode_modules/braces/package.json\\nnode_modules/buffer-from/package.json\\nnode_modules/builtin-modules/package.json\\nnode_modules/bytes/package.json\\nnode_modules/call-bind-apply-helpers/package.json\\nnode_modules/call-bound/package.json\\nnode_modules/callsites/package.json\\nnode_modules/chai/package.json\\nnode_modules/chalk/package.json\\nnode_modules/character-parser/package.json\\nnode_modules/chownr/package.json\\nnode_modules/clean-stack/package.json\\nnode_modules/cli-cursor/package.json\\nnode_modules/cli-table3/package.json\\nnode_modules/cli-truncate/package.json\\nnode_modules/color-convert/package.json\\nnode_modules/color-name/package.json\\nnode_modules/colorette/package.json\\nnode_modules/colors/package.json\\nnode_modules/commander/package.json\\nnode_modules/commondir/package.json\\nnode_modules/concat-map/package.json\\nnode_modules/constantinople/package.json\\nnode_modules/convert-source-map/package.json\\nnode_modules/cosmiconfig/node_modules/yaml/package.json\\nnode_modules/cosmiconfig/package.json\\nnode_modules/cross-spawn/package.json\\nnode_modules/debug/package.json\\nnode_modules/dedent/package.json\\nnode_modules/deepmerge/package.json\\nnode_modules/detect-libc/package.json\\nnode_modules/doctypes/package.json\\nnode_modules/dunder-proto/package.json\\nnode_modules/emoji-regex/package.json\\nnode_modules/end-of-stream/package.json\\nnode_modules/enquirer/package.json\\nnode_modules/error-ex/package.json\\nnode_modules/es-define-property/package.json\\nnode_modules/es-errors/package.json\\nnode_modules/es-module-lexer/package.json\\nnode_modules/es-object-atoms/package.json\\nnode_modules/escape-string-regexp/package.json\\nnode_modules/eslint-plugin-security/package.json\\nnode_modules/estree-walker/package.json\\nnode_modules/eventemitter3/package.json\\nnode_modules/execa/package.json\\nnode_modules/expect-type/package.json\\nnode_modules/fast-glob/package.json\\nnode_modules/fastq/package.json\\nnode_modules/fd-package-json/package.json\\nnode_modules/fdir/package.json\\nnode_modules/fill-range/package.json\\nnode_modules/formatly/package.json\\nnode_modules/fs-extra/package.json\\nnode_modules/fs-minipass/package.json\\nnode_modules/fs.realpath/package.json\\nnode_modules/function-bind/package.json\\nnode_modules/fuzzysearch/package.json\\nnode_modules/get-intrinsic/package.json\\nnode_modules/get-own-enumerable-property-symbols/package.json\\nnode_modules/get-proto/package.json\\nnode_modules/get-stream/package.json\\nnode_modules/get-tsconfig/package.json\\nnode_modules/glob-parent/package.json\\nnode_modules/glob/package.json\\nnode_modules/globalyzer/package.json\\nnode_modules/globrex/package.json\\nnode_modules/gopd/package.json\\nnode_modules/graceful-fs/package.json\\nnode_modules/has-flag/package.json\\nnode_modules/has-symbols/package.json\\nnode_modules/has-tostringtag/package.json\\nnode_modules/hasown/package.json\\nnode_modules/home-or-tmp/package.json\\nnode_modules/html-escaper/package.json\\nnode_modules/https-proxy-agent/package.json\\nnode_modules/human-signals/package.json\\nnode_modules/husky/package.json\\nnode_modules/import-fresh/package.json\\nnode_modules/indent-string/package.json\\nnode_modules/inflight/package.json\\nnode_modules/inherits/package.json\\nnode_modules/is-arrayish/package.json\\nnode_modules/is-core-module/package.json\\nnode_modules/is-expression/package.json\\nnode_modules/is-extglob/package.json\\nnode_modules/is-fullwidth-code-point/package.json\\nnode_modules/is-glob/package.json\\nnode_modules/is-module/package.json\\nnode_modules/is-number/package.json\\nnode_modules/is-obj/package.json\\nnode_modules/is-promise/package.json\\nnode_modules/is-reference/node_modules/@types/estree/package.json\\nnode_modules/is-reference/package.json\\nnode_modules/is-regex/package.json\\nnode_modules/is-regexp/package.json\\nnode_modules/is-stream/package.json\\nnode_modules/is-unicode-supported/package.json\\nnode_modules/isexe/package.json\\nnode_modules/istanbul-lib-coverage/package.json\\nnode_modules/istanbul-lib-report/package.json\\nnode_modules/istanbul-reports/package.json\\nnode_modules/jiti/package.json\\nnode_modules/js-stringify/package.json\\nnode_modules/js-tokens/package.json\\nnode_modules/jscpd-sarif-reporter/package.json\\nnode_modules/jscpd/package.json\\nnode_modules/json-parse-even-better-errors/package.json\\nnode_modules/jsonfile/package.json\\nnode_modules/jstransformer/package.json\\nnode_modules/knip/package.json\\nnode_modules/lightningcss-linux-x64-gnu/package.json\\nnode_modules/lightningcss-linux-x64-musl/package.json\\nnode_modules/lightningcss/package.json\\nnode_modules/lines-and-columns/package.json\\nnode_modules/lint-staged/node_modules/commander/package.json\\nnode_modules/lint-staged/package.json\\nnode_modules/listr2/package.json\\nnode_modules/log-symbols/package.json\\nnode_modules/log-update/node_modules/slice-ansi/package.json\\nnode_modules/log-update/node_modules/wrap-ansi/package.json\\nnode_modules/log-update/package.json\\nnode_modules/magic-string/package.json\\nnode_modules/magicast/package.json\\nnode_modules/make-dir/package.json\\nnode_modules/markdown-table/package.json\\nnode_modules/math-intrinsics/package.json\\nnode_modules/merge-stream/package.json\\nnode_modules/merge2/package.json\\nnode_modules/micromatch/node_modules/picomatch/package.json\\nnode_modules/micromatch/package.json\\nnode_modules/mimic-fn/package.json\\nnode_modules/minimatch/package.json\\nnode_modules/minimist/package.json\\nnode_modules/minipass/package.json\\nnode_modules/minizlib/package.json\\nnode_modules/mkdirp/package.json\\nnode_modules/mri/package.json\\nnode_modules/ms/package.json\\nnode_modules/nanoid/package.json\\nnode_modules/node-sarif-builder/package.json\\nnode_modules/normalize-path/package.json\\nnode_modules/npm-run-path/package.json\\nnode_modules/object-assign/package.json\\nnode_modules/obug/package.json\\nnode_modules/once/package.json\\nnode_modules/onetime/package.json\\nnode_modules/oxc-parser/package.json\\nnode_modules/oxc-resolver/package.json\\nnode_modules/oxfmt/package.json\\nnode_modules/oxlint/package.json\\nnode_modules/p-map/package.json\\nnode_modules/parent-module/package.json\\nnode_modules/parse-json/package.json\\nnode_modules/path-is-absolute/package.json\\nnode_modules/path-key/package.json\\nnode_modules/path-parse/package.json\\nnode_modules/path-type/package.json\\nnode_modules/pathe/package.json\\nnode_modules/picocolors/package.json\\nnode_modules/picomatch/package.json\\nnode_modules/please-upgrade-node/package.json\\nnode_modules/postcss/package.json\\nnode_modules/promise/package.json\\nnode_modules/pug-attrs/package.json\\nnode_modules/pug-code-gen/package.json\\nnode_modules/pug-error/package.json\\nnode_modules/pug-filters/package.json\\nnode_modules/pug-lexer/package.json\\nnode_modules/pug-linker/package.json\\nnode_modules/pug-load/package.json\\nnode_modules/pug-parser/package.json\\nnode_modules/pug-runtime/package.json\\nnode_modules/pug-strip-comments/package.json\\nnode_modules/pug-walk/package.json\\nnode_modules/pug/package.json\\nnode_modules/pump/package.json\\nnode_modules/queue-microtask/package.json\\nnode_modules/regexp-tree/package.json\\nnode_modules/repeat-string/package.json\\nnode_modules/reprism/package.json\\nnode_modules/resolve-from/package.json\\nnode_modules/resolve-pkg-maps/package.json\\nnode_modules/resolve/package.json\\nnode_modules/resolve/test/resolver/baz/package.json\\nnode_modules/resolve/test/resolver/browser_field/package.json\\nnode_modules/resolve/test/resolver/false_main/package.json\\nnode_modules/resolve/test/resolver/invalid_main/package.json\\nnode_modules/resolve/test/resolver/multirepo/package.json\\nnode_modules/resolve/test/resolver/multirepo/packages/package-a/package.json\\nnode_modules/resolve/test/resolver/multirepo/packages/package-b/package.json\\nnode_modules/resolve/test/resolver/nested_symlinks/mylib/package.json\\nnode_modules/restore-cursor/package.json\\nnode_modules/reusify/package.json\\nnode_modules/rfdc/package.json\\nnode_modules/rimraf/package.json\\nnode_modules/rolldown/node_modules/@oxc-project/types/package.json\\nnode_modules/rolldown/package.json\\nnode_modules/rollup/package.json\\nnode_modules/run-parallel/package.json\\nnode_modules/rxjs/ajax/package.json\\nnode_modules/rxjs/fetch/package.json\\nnode_modules/rxjs/operators/package.json\\nnode_modules/rxjs/package.json\\nnode_modules/rxjs/testing/package.json\\nnode_modules/rxjs/webSocket/package.json\\nnode_modules/safe-regex/package.json\\nnode_modules/sander/node_modules/rimraf/package.json\\nnode_modules/sander/package.json\\nnode_modules/semver-compare/package.json\\nnode_modules/semver/package.json\\nnode_modules/shebang-command/package.json\\nnode_modules/shebang-regex/package.json\\nnode_modules/siginfo/package.json\\nnode_modules/signal-exit/package.json\\nnode_modules/slice-ansi/package.json\\nnode_modules/smol-toml/package.json\\nnode_modules/source-map-js/package.json\\nnode_modules/source-map-support/package.json\\nnode_modules/source-map/package.json\\nnode_modules/sourcemap-codec/package.json\\nnode_modules/spark-md5/package.json\\nnode_modules/stackback/package.json\\nnode_modules/std-env/package.json\\nnode_modules/string-argv/package.json\\nnode_modules/string-width/package.json\\nnode_modules/stringify-object/package.json\\nnode_modules/strip-ansi/package.json\\nnode_modules/strip-final-newline/package.json\\nnode_modules/strip-json-comments/package.json\\nnode_modules/supports-color/package.json\\nnode_modules/supports-preserve-symlinks-flag/package.json\\nnode_modules/tar/node_modules/mkdirp/package.json\\nnode_modules/tar/package.json\\nnode_modules/through/package.json\\nnode_modules/tiny-glob/package.json\\nnode_modules/tinybench/package.json\\nnode_modules/tinyexec/package.json\\nnode_modules/tinyglobby/package.json\\nnode_modules/tinypool/package.json\\nnode_modules/tinyrainbow/package.json\\nnode_modules/to-regex-range/package.json\\nnode_modules/token-stream/package.json\\nnode_modules/tslib/package.json\\nnode_modules/type-fest/package.json\\nnode_modules/unbash/package.json\\nnode_modules/undici-types/package.json\\nnode_modules/universalify/package.json\\nnode_modules/vite/package.json\\nnode_modules/vitest/node_modules/magic-string/package.json\\nnode_modules/vitest/package.json\\nnode_modules/void-elements/package.json\\nnode_modules/walk-up-path/package.json\\nnode_modules/which/package.json\\nnode_modules/why-is-node-running/package.json\\nnode_modules/with/package.json\\nnode_modules/wrap-ansi/package.json\\nnode_modules/wrappy/package.json\\nnode_modules/yallist/package.json\\nnode_modules/yaml/package.json\\nnode_modules/zod/package.json"
      }
    ]
  },
  "components": [
    {
      "authors": [
        {
          "name": "Colin McDonnell <zod@colinhacks.com>"
        }
      ],
      "group": "",
      "name": "zod",
      "version": "4.4.3",
      "description": "TypeScript-first schema declaration and validation library with static type inference",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/zod@4.4.3",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://zod.dev"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/colinhacks/zod.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/zod@4.4.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/zod/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/zod/package.json"
              }
            ],
            "concludedValue": "node_modules/zod/package.json"
          }
        ]
      },
      "tags": [
        "validation"
      ]
    },
    {
      "authors": [
        {
          "name": "Eemeli Aro <eemeli@gmail.com>"
        }
      ],
      "group": "",
      "name": "yaml",
      "version": "2.8.4",
      "description": "JavaScript parser and stringifier for YAML",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/yaml@2.8.4",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://eemeli.org/yaml/"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/yaml@2.8.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/yaml/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/yaml/package.json"
              }
            ],
            "concludedValue": "node_modules/yaml/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "yallist",
      "version": "4.0.0",
      "description": "Yet Another Linked List",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/yallist@4.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git+https://github.com/isaacs/yallist.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/yallist@4.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/yallist/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/yallist/package.json"
              }
            ],
            "concludedValue": "node_modules/yallist/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "wrappy",
      "version": "1.0.2",
      "description": "Callback wrapping utility",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/wrappy@1.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/npm/wrappy"
        },
        {
          "type": "vcs",
          "url": "https://github.com/npm/wrappy"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/wrappy@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/wrappy/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/wrappy/package.json"
              }
            ],
            "concludedValue": "node_modules/wrappy/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "wrap-ansi",
      "version": "7.0.0",
      "description": "Wordwrap a string with ANSI escape codes",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/wrap-ansi@7.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/wrap-ansi@7.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/wrap-ansi/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/wrap-ansi/package.json"
              }
            ],
            "concludedValue": "node_modules/wrap-ansi/package.json"
          }
        ]
      },
      "tags": [
        "escape"
      ]
    },
    {
      "authors": [
        {
          "name": "ForbesLindesay"
        }
      ],
      "group": "",
      "name": "with",
      "version": "7.0.2",
      "description": "Compile time `with` for strict mode JavaScript",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/with@7.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/pugjs/with.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/with@7.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/with/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/with/package.json"
              }
            ],
            "concludedValue": "node_modules/with/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mathias Buus (@mafintosh)"
        }
      ],
      "group": "",
      "name": "why-is-node-running",
      "version": "2.3.0",
      "description": "Node is running but you don't know why? why-is-node-running is here to help you.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/why-is-node-running@2.3.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mafintosh/why-is-node-running"
        },
        {
          "type": "vcs",
          "url": "https://github.com/mafintosh/why-is-node-running.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/why-is-node-running@2.3.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/why-is-node-running/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/why-is-node-running/package.json"
              }
            ],
            "concludedValue": "node_modules/why-is-node-running/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me)"
        }
      ],
      "group": "",
      "name": "which",
      "version": "2.0.2",
      "description": "Like which(1) unix command. Find the first instance of an executable in the PATH.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/which@2.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/node-which.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/which@2.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/which/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/which/package.json"
              }
            ],
            "concludedValue": "node_modules/which/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (https://izs.me)"
        }
      ],
      "group": "",
      "name": "walk-up-path",
      "version": "4.0.0",
      "description": "Given a path string, return a generator that walks up the path, emitting each dirname.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/walk-up-path@4.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git+https://github.com/isaacs/walk-up-path"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/walk-up-path@4.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/walk-up-path/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/walk-up-path/package.json"
              }
            ],
            "concludedValue": "node_modules/walk-up-path/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "hemanth.hm"
        }
      ],
      "group": "",
      "name": "void-elements",
      "version": "3.1.0",
      "description": "Array of \"void elements\" defined by the HTML specification.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/void-elements@3.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jadejs/void-elements"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/void-elements@3.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/void-elements/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/void-elements/package.json"
              }
            ],
            "concludedValue": "node_modules/void-elements/package.json"
          }
        ]
      },
      "tags": [
        "html"
      ]
    },
    {
      "authors": [
        {
          "name": "Anthony Fu <anthonyfu117@hotmail.com>"
        }
      ],
      "group": "",
      "name": "vitest",
      "version": "4.1.5",
      "description": "Next generation testing framework powered by Vite",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/vitest@4.1.5",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://vitest.dev"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/vitest-dev/vitest.git"
        }
      ],
      "type": "framework",
      "bom-ref": "pkg:npm/vitest@4.1.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/vitest/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/vitest/package.json"
              }
            ],
            "concludedValue": "node_modules/vitest/package.json"
          }
        ]
      },
      "tags": [
        "framework"
      ]
    },
    {
      "authors": [
        {
          "name": "Rich Harris"
        }
      ],
      "group": "",
      "name": "magic-string",
      "version": "0.30.21",
      "description": "Modify strings, generate sourcemaps",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/magic-string@0.30.21",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git+https://github.com/Rich-Harris/magic-string.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/magic-string@0.30.21",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/vitest/node_modules/magic-string/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/@vitest/snapshot/node_modules/magic-string/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/@vitest/mocker/node_modules/magic-string/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/vitest/node_modules/magic-string/package.json"
              },
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@vitest/snapshot/node_modules/magic-string/package.json"
              },
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@vitest/mocker/node_modules/magic-string/package.json"
              }
            ]
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Evan You"
        }
      ],
      "group": "",
      "name": "vite",
      "version": "8.0.10",
      "description": "Native-ESM powered web dev build tool",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/vite@8.0.10",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://vite.dev"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/vitejs/vite.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/vite@8.0.10",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/vite/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/vite/package.json"
              }
            ],
            "concludedValue": "node_modules/vite/package.json"
          }
        ]
      },
      "tags": [
        "web"
      ]
    },
    {
      "authors": [
        {
          "name": "Ryan Zimmerman <opensrc@ryanzim.com>"
        }
      ],
      "group": "",
      "name": "universalify",
      "version": "2.0.1",
      "description": "Make a callback- or promise-based function support both promises and callbacks.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/universalify@2.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/RyanZim/universalify#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/RyanZim/universalify.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/universalify@2.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/universalify/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/universalify/package.json"
              }
            ],
            "concludedValue": "node_modules/universalify/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "undici-types",
      "version": "7.19.2",
      "description": "A stand-alone types package for Undici",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/undici-types@7.19.2",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://undici.nodejs.org"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/nodejs/undici.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/undici-types@7.19.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/undici-types/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/undici-types/package.json"
              }
            ],
            "concludedValue": "node_modules/undici-types/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Lars Kappert <lars@webpro.nl>"
        }
      ],
      "group": "",
      "name": "unbash",
      "version": "3.0.0",
      "description": "Fast 0-deps bash parser written in TypeScript",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/unbash@3.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git+https://github.com/webpro-nl/unbash.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/unbash@3.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/unbash/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/unbash/package.json"
              }
            ],
            "concludedValue": "node_modules/unbash/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "type-fest",
      "version": "0.21.3",
      "description": "A collection of essential TypeScript types",
      "scope": "optional",
      "licenses": [
        {
          "expression": "(MIT OR CC0-1.0)"
        }
      ],
      "purl": "pkg:npm/type-fest@0.21.3",
      "type": "library",
      "bom-ref": "pkg:npm/type-fest@0.21.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/type-fest/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/type-fest/package.json"
              }
            ],
            "concludedValue": "node_modules/type-fest/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Microsoft Corp."
        }
      ],
      "group": "",
      "name": "tslib",
      "version": "2.8.1",
      "description": "Runtime library for TypeScript helper functions",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "0BSD",
            "url": "https://opensource.org/licenses/0BSD"
          }
        }
      ],
      "purl": "pkg:npm/tslib@2.8.1",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://www.typescriptlang.org/"
        },
        {
          "type": "vcs",
          "url": "https://github.com/Microsoft/tslib.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/tslib@2.8.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tslib/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tslib/package.json"
              }
            ],
            "concludedValue": "node_modules/tslib/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "ForbesLindesay"
        }
      ],
      "group": "",
      "name": "token-stream",
      "version": "1.0.0",
      "description": "Take an array of token and produce a more useful API to give to a parser",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/token-stream@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/pugjs/token-stream.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/token-stream@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/token-stream/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/token-stream/package.json"
              }
            ],
            "concludedValue": "node_modules/token-stream/package.json"
          }
        ]
      },
      "tags": [
        "api",
        "token"
      ]
    },
    {
      "authors": [
        {
          "name": "Jon Schlinkert (https://github.com/jonschlinkert)"
        }
      ],
      "group": "",
      "name": "to-regex-range",
      "version": "5.0.1",
      "description": "Pass two numbers, get a regex-compatible source string for matching ranges. Validated against more than 2.78 million test assertions.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/to-regex-range@5.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/micromatch/to-regex-range"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/to-regex-range@5.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/to-regex-range/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/to-regex-range/package.json"
              }
            ],
            "concludedValue": "node_modules/to-regex-range/package.json"
          }
        ]
      },
      "tags": [
        "test"
      ]
    },
    {
      "group": "",
      "name": "tinyrainbow",
      "version": "3.1.0",
      "description": "A small library to print colourful messages.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/tinyrainbow@3.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/tinylibs/tinyrainbow#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/tinylibs/tinyrainbow.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/tinyrainbow@3.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tinyrainbow/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tinyrainbow/package.json"
              }
            ],
            "concludedValue": "node_modules/tinyrainbow/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "tinypool",
      "version": "2.1.0",
      "description": "A minimal and tiny Node.js Worker Thread Pool implementation, a fork of piscina, but with fewer features",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/tinypool@2.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/tinylibs/tinypool#readme"
        },
        {
          "type": "vcs",
          "url": "https://github.com/tinylibs/tinypool.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/tinypool@2.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tinypool/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tinypool/package.json"
              }
            ],
            "concludedValue": "node_modules/tinypool/package.json"
          }
        ]
      },
      "tags": [
        "pool"
      ]
    },
    {
      "authors": [
        {
          "name": "Superchupu"
        }
      ],
      "group": "",
      "name": "tinyglobby",
      "version": "0.2.16",
      "description": "A fast and minimal alternative to globby and fast-glob",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/tinyglobby@0.2.16",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://superchupu.dev/tinyglobby"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/SuperchupuDev/tinyglobby.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/tinyglobby@0.2.16",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tinyglobby/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tinyglobby/package.json"
              }
            ],
            "concludedValue": "node_modules/tinyglobby/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Garbutt (https://github.com/43081j)"
        }
      ],
      "group": "",
      "name": "tinyexec",
      "version": "1.1.2",
      "description": "A minimal library for executing processes in Node",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/tinyexec@1.1.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/tinylibs/tinyexec#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/tinylibs/tinyexec.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/tinyexec@1.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tinyexec/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tinyexec/package.json"
              }
            ],
            "concludedValue": "node_modules/tinyexec/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "tinybench",
      "version": "2.9.0",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/tinybench@2.9.0",
      "type": "library",
      "bom-ref": "pkg:npm/tinybench@2.9.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tinybench/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tinybench/package.json"
              }
            ],
            "concludedValue": "node_modules/tinybench/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Terkel Gjervig <terkel@terkel.com> (https://terkel.com)"
        }
      ],
      "group": "",
      "name": "tiny-glob",
      "version": "0.2.8",
      "description": "Tiny and extremely fast globbing",
      "scope": "required",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/tiny-glob@0.2.8",
      "type": "library",
      "bom-ref": "pkg:npm/tiny-glob@0.2.8",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tiny-glob/package.json"
        },
        {
          "name": "ImportedModules",
          "value": "tiny-glob/sync.js"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tiny-glob/package.json"
              }
            ],
            "concludedValue": "node_modules/tiny-glob/package.json"
          }
        ],
        "occurrences": [
          {
            "location": "src/bin.js#5"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Dominic Tarr <dominic.tarr@gmail.com> (dominictarr.com)"
        }
      ],
      "group": "",
      "name": "through",
      "version": "2.3.8",
      "description": "simplified stream construction",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/through@2.3.8",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/dominictarr/through"
        },
        {
          "type": "vcs",
          "url": "https://github.com/dominictarr/through.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/through@2.3.8",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/through/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/through/package.json"
              }
            ],
            "concludedValue": "node_modules/through/package.json"
          }
        ]
      },
      "tags": [
        "stream"
      ]
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "tar",
      "version": "6.1.0",
      "description": "tar for node",
      "scope": "required",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/tar@6.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/npm/node-tar.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/tar@6.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tar/package.json"
        },
        {
          "name": "ImportedModules",
          "value": "tar"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tar/package.json"
              }
            ],
            "concludedValue": "node_modules/tar/package.json"
          }
        ],
        "occurrences": [
          {
            "location": "src/index.js#3"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "mkdirp",
      "version": "1.0.4",
      "description": "Recursively mkdir, like `mkdir -p`",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/mkdirp@1.0.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/node-mkdirp.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/mkdirp@1.0.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tar/node_modules/mkdirp/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tar/node_modules/mkdirp/package.json"
              }
            ],
            "concludedValue": "node_modules/tar/node_modules/mkdirp/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jordan Harband <ljharb@gmail.com>"
        }
      ],
      "group": "",
      "name": "supports-preserve-symlinks-flag",
      "version": "1.0.0",
      "description": "Determine if the current node version supports the `--preserve-symlinks` flag.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/supports-preserve-symlinks-flag@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/inspect-js/node-supports-preserve-symlinks-flag#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/inspect-js/node-supports-preserve-symlinks-flag.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/supports-preserve-symlinks-flag@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/supports-preserve-symlinks-flag/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/supports-preserve-symlinks-flag/package.json"
              }
            ],
            "concludedValue": "node_modules/supports-preserve-symlinks-flag/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "supports-color",
      "version": "7.2.0",
      "description": "Detect whether a terminal supports color",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/supports-color@7.2.0",
      "type": "library",
      "bom-ref": "pkg:npm/supports-color@7.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/supports-color/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/supports-color/package.json"
              }
            ],
            "concludedValue": "node_modules/supports-color/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "strip-json-comments",
      "version": "5.0.3",
      "description": "Strip comments from JSON. Lets you use comments in your JSON files!",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/strip-json-comments@5.0.3",
      "type": "library",
      "bom-ref": "pkg:npm/strip-json-comments@5.0.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/strip-json-comments/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/strip-json-comments/package.json"
              }
            ],
            "concludedValue": "node_modules/strip-json-comments/package.json"
          }
        ]
      },
      "tags": [
        "json"
      ]
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "strip-final-newline",
      "version": "2.0.0",
      "description": "Strip the final newline character from a string/buffer",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/strip-final-newline@2.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/strip-final-newline@2.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/strip-final-newline/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/strip-final-newline/package.json"
              }
            ],
            "concludedValue": "node_modules/strip-final-newline/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "strip-ansi",
      "version": "6.0.1",
      "description": "Strip ANSI escape codes from a string",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/strip-ansi@6.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/strip-ansi@6.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/strip-ansi/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/strip-ansi/package.json"
              }
            ],
            "concludedValue": "node_modules/strip-ansi/package.json"
          }
        ]
      },
      "tags": [
        "escape"
      ]
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "stringify-object",
      "version": "3.3.0",
      "description": "Stringify an object/array like JSON.stringify just without all the double-quotes",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-2-Clause",
            "url": "https://opensource.org/licenses/BSD-2-Clause"
          }
        }
      ],
      "purl": "pkg:npm/stringify-object@3.3.0",
      "type": "library",
      "bom-ref": "pkg:npm/stringify-object@3.3.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/stringify-object/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/stringify-object/package.json"
              }
            ],
            "concludedValue": "node_modules/stringify-object/package.json"
          }
        ]
      },
      "tags": [
        "json"
      ]
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "string-width",
      "version": "4.2.3",
      "description": "Get the visual width of a string - the number of columns required to display it",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/string-width@4.2.3",
      "type": "library",
      "bom-ref": "pkg:npm/string-width@4.2.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/string-width/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/string-width/package.json"
              }
            ],
            "concludedValue": "node_modules/string-width/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Anthony McCormick <anthony.mccormick@gmail.com>"
        }
      ],
      "group": "",
      "name": "string-argv",
      "version": "0.3.1",
      "description": "string-argv parses a string into an argument array to mimic process.argv. This is useful when testing Command Line Utilities that you want to pass arguments to.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/string-argv@0.3.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mccormicka/string-argv"
        },
        {
          "type": "vcs",
          "url": "https://github.com/mccormicka/string-argv"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/string-argv@0.3.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/string-argv/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/string-argv/package.json"
              }
            ],
            "concludedValue": "node_modules/string-argv/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "std-env",
      "version": "4.1.0",
      "description": "Runtime agnostic JS utils",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/std-env@4.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/std-env@4.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/std-env/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/std-env/package.json"
              }
            ],
            "concludedValue": "node_modules/std-env/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Roman Shtylman <shtylman@gmail.com>"
        }
      ],
      "group": "",
      "name": "stackback",
      "version": "0.0.2",
      "description": "return list of CallSite objects from a captured stacktrace",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/stackback@0.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/shtylman/node-stackback.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/stackback@0.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/stackback/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/stackback/package.json"
              }
            ],
            "concludedValue": "node_modules/stackback/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "André Cruz <andremiguelcruz@msn.com>"
        }
      ],
      "group": "",
      "name": "spark-md5",
      "version": "3.0.2",
      "description": "Lightning fast normal and incremental md5 for javascript",
      "scope": "optional",
      "licenses": [
        {
          "expression": "(WTFPL OR MIT)"
        }
      ],
      "purl": "pkg:npm/spark-md5@3.0.2",
      "type": "framework",
      "bom-ref": "pkg:npm/spark-md5@3.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/spark-md5/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/spark-md5/package.json"
              }
            ],
            "concludedValue": "node_modules/spark-md5/package.json"
          }
        ]
      },
      "tags": [
        "framework"
      ]
    },
    {
      "authors": [
        {
          "name": "Rich Harris"
        }
      ],
      "group": "",
      "name": "sourcemap-codec",
      "version": "1.4.8",
      "description": "Encode/decode sourcemap mappings",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/sourcemap-codec@1.4.8",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/Rich-Harris/sourcemap-codec"
        },
        {
          "type": "vcs",
          "url": "https://github.com/Rich-Harris/sourcemap-codec"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/sourcemap-codec@1.4.8",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/sourcemap-codec/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/sourcemap-codec/package.json"
              }
            ],
            "concludedValue": "node_modules/sourcemap-codec/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "source-map-support",
      "version": "0.5.19",
      "description": "Fixes stack traces for files with source maps",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/source-map-support@0.5.19",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/evanw/node-source-map-support"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/source-map-support@0.5.19",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/source-map-support/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/source-map-support/package.json"
              }
            ],
            "concludedValue": "node_modules/source-map-support/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Valentin 7rulnik Semirulnik <v7rulnik@gmail.com>"
        }
      ],
      "group": "",
      "name": "source-map-js",
      "version": "1.2.1",
      "description": "Generates and consumes source maps",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-3-Clause",
            "url": "https://opensource.org/licenses/BSD-3-Clause"
          }
        }
      ],
      "purl": "pkg:npm/source-map-js@1.2.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/7rulnik/source-map-js"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/source-map-js@1.2.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/source-map-js/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/source-map-js/package.json"
              }
            ],
            "concludedValue": "node_modules/source-map-js/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Nick Fitzgerald <nfitzgerald@mozilla.com>"
        }
      ],
      "group": "",
      "name": "source-map",
      "version": "0.6.1",
      "description": "Generates and consumes source maps",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-3-Clause",
            "url": "https://opensource.org/licenses/BSD-3-Clause"
          }
        }
      ],
      "purl": "pkg:npm/source-map@0.6.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mozilla/source-map"
        },
        {
          "type": "vcs",
          "url": "http://github.com/mozilla/source-map.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/source-map@0.6.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/source-map/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/source-map/package.json"
              }
            ],
            "concludedValue": "node_modules/source-map/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Cynthia <cyyynthia@borkenware.com>"
        }
      ],
      "group": "",
      "name": "smol-toml",
      "version": "1.6.1",
      "description": "A small, fast, and correct TOML parser/serializer",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-3-Clause",
            "url": "https://opensource.org/licenses/BSD-3-Clause"
          }
        }
      ],
      "purl": "pkg:npm/smol-toml@1.6.1",
      "type": "library",
      "bom-ref": "pkg:npm/smol-toml@1.6.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/smol-toml/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/smol-toml/package.json"
              }
            ],
            "concludedValue": "node_modules/smol-toml/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "slice-ansi",
      "version": "3.0.0",
      "description": "Slice a string with ANSI escape codes",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/slice-ansi@3.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/slice-ansi@3.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/slice-ansi/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/slice-ansi/package.json"
              }
            ],
            "concludedValue": "node_modules/slice-ansi/package.json"
          }
        ]
      },
      "tags": [
        "escape"
      ]
    },
    {
      "authors": [
        {
          "name": "Ben Coe <ben@npmjs.com>"
        }
      ],
      "group": "",
      "name": "signal-exit",
      "version": "3.0.7",
      "description": "when you want to fire an event no matter how a process exits.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/signal-exit@3.0.7",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/tapjs/signal-exit"
        },
        {
          "type": "vcs",
          "url": "https://github.com/tapjs/signal-exit.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/signal-exit@3.0.7",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/signal-exit/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/signal-exit/package.json"
              }
            ],
            "concludedValue": "node_modules/signal-exit/package.json"
          }
        ]
      },
      "tags": [
        "event"
      ]
    },
    {
      "authors": [
        {
          "name": "Emil Bay <github@tixz.dk>"
        }
      ],
      "group": "",
      "name": "siginfo",
      "version": "2.0.0",
      "description": "Utility module to print pretty messages on SIGINFO/SIGUSR1",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/siginfo@2.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/emilbayes/siginfo#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/emilbayes/siginfo.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/siginfo@2.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/siginfo/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/siginfo/package.json"
              }
            ],
            "concludedValue": "node_modules/siginfo/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "shebang-regex",
      "version": "3.0.0",
      "description": "Regular expression for matching a shebang line",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/shebang-regex@3.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/shebang-regex@3.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/shebang-regex/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/shebang-regex/package.json"
              }
            ],
            "concludedValue": "node_modules/shebang-regex/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Kevin Mårtensson <kevinmartensson@gmail.com> (github.com/kevva)"
        }
      ],
      "group": "",
      "name": "shebang-command",
      "version": "2.0.0",
      "description": "Get the command from a shebang",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/shebang-command@2.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/shebang-command@2.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/shebang-command/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/shebang-command/package.json"
              }
            ],
            "concludedValue": "node_modules/shebang-command/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "semver-compare",
      "version": "1.0.0",
      "description": "compare two semver version strings, returning -1, 0, or 1",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/semver-compare@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/semver-compare"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/semver-compare.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/semver-compare@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/semver-compare/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/semver-compare/package.json"
              }
            ],
            "concludedValue": "node_modules/semver-compare/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "GitHub Inc."
        }
      ],
      "group": "",
      "name": "semver",
      "version": "7.7.4",
      "description": "The semantic version parser used by npm.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/semver@7.7.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git+https://github.com/npm/node-semver.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/semver@7.7.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/semver/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/semver/package.json"
              }
            ],
            "concludedValue": "node_modules/semver/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Rich Harris"
        }
      ],
      "group": "",
      "name": "sander",
      "version": "0.6.0",
      "description": "Promise-based power tool for common filesystem tasks",
      "scope": "required",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/sander@0.6.0",
      "type": "library",
      "bom-ref": "pkg:npm/sander@0.6.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/sander/package.json"
        },
        {
          "name": "ImportedModules",
          "value": "sander,rimrafSync,sander/rimrafSync,copydirSync,sander/copydirSync"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/sander/package.json"
              }
            ],
            "concludedValue": "node_modules/sander/package.json"
          }
        ],
        "occurrences": [
          {
            "location": "src/index.js#6"
          },
          {
            "location": "src/utils.js#8"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "rimraf",
      "version": "2.7.1",
      "description": "A deep deletion module for node (like `rm -rf`)",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/rimraf@2.7.1",
      "type": "library",
      "bom-ref": "pkg:npm/rimraf@2.7.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/sander/node_modules/rimraf/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/sander/node_modules/rimraf/package.json"
              }
            ],
            "concludedValue": "node_modules/sander/node_modules/rimraf/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James C. (Jamie) Davis <davisjam@vt.edu> (http://people.cs.vt.edu/~davisjam)"
        }
      ],
      "group": "",
      "name": "safe-regex",
      "version": "2.1.1",
      "description": "detect possibly catastrophic, exponential-time regular expressions",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/safe-regex@2.1.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/davisjam/safe-regex"
        },
        {
          "type": "vcs",
          "url": "git://github.com/davisjam/safe-regex.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/safe-regex@2.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/safe-regex/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/safe-regex/package.json"
              }
            ],
            "concludedValue": "node_modules/safe-regex/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Ben Lesh <ben@benlesh.com>"
        }
      ],
      "group": "",
      "name": "rxjs",
      "version": "7.8.2",
      "description": "Reactive Extensions for modern JavaScript",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0",
            "url": "https://opensource.org/licenses/Apache-2.0"
          }
        }
      ],
      "purl": "pkg:npm/rxjs@7.8.2",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://rxjs.dev"
        },
        {
          "type": "vcs",
          "url": "https://github.com/reactivex/rxjs.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/rxjs@7.8.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/rxjs/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/rxjs/package.json"
              }
            ],
            "concludedValue": "node_modules/rxjs/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "rxjs/webSocket",
      "version": "",
      "scope": "optional",
      "purl": "pkg:npm/rxjs%2FwebSocket",
      "type": "library",
      "bom-ref": "pkg:npm/rxjs/webSocket",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/rxjs/webSocket/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/rxjs/webSocket/package.json"
              }
            ],
            "concludedValue": "node_modules/rxjs/webSocket/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "rxjs/testing",
      "version": "",
      "scope": "optional",
      "purl": "pkg:npm/rxjs%2Ftesting",
      "type": "library",
      "bom-ref": "pkg:npm/rxjs/testing",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/rxjs/testing/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/rxjs/testing/package.json"
              }
            ],
            "concludedValue": "node_modules/rxjs/testing/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "rxjs/operators",
      "version": "",
      "scope": "optional",
      "purl": "pkg:npm/rxjs%2Foperators",
      "type": "library",
      "bom-ref": "pkg:npm/rxjs/operators",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/rxjs/operators/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/rxjs/operators/package.json"
              }
            ],
            "concludedValue": "node_modules/rxjs/operators/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "rxjs/fetch",
      "version": "",
      "scope": "optional",
      "purl": "pkg:npm/rxjs%2Ffetch",
      "type": "library",
      "bom-ref": "pkg:npm/rxjs/fetch",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/rxjs/fetch/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/rxjs/fetch/package.json"
              }
            ],
            "concludedValue": "node_modules/rxjs/fetch/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "rxjs/ajax",
      "version": "",
      "scope": "optional",
      "purl": "pkg:npm/rxjs%2Fajax",
      "type": "library",
      "bom-ref": "pkg:npm/rxjs/ajax",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/rxjs/ajax/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/rxjs/ajax/package.json"
              }
            ],
            "concludedValue": "node_modules/rxjs/ajax/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Feross Aboukhadijeh <feross@feross.org> (https://feross.org)"
        }
      ],
      "group": "",
      "name": "run-parallel",
      "version": "1.2.0",
      "description": "Run an array of functions in parallel",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/run-parallel@1.2.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/feross/run-parallel"
        },
        {
          "type": "vcs",
          "url": "git://github.com/feross/run-parallel.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/run-parallel@1.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/run-parallel/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/run-parallel/package.json"
              }
            ],
            "concludedValue": "node_modules/run-parallel/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Rich Harris"
        }
      ],
      "group": "",
      "name": "rollup",
      "version": "2.44.0",
      "description": "Next-generation ES module bundler",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/rollup@2.44.0",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://rollupjs.org/"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/rollup@2.44.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/rollup/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/rollup/package.json"
              }
            ],
            "concludedValue": "node_modules/rollup/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "rolldown",
      "version": "1.0.0-rc.17",
      "description": "Fast JavaScript/TypeScript bundler in Rust with Rollup-compatible API.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/rolldown@1.0.0-rc.17",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://rolldown.rs/"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/rolldown/rolldown.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/rolldown@1.0.0-rc.17",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/rolldown/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/rolldown/package.json"
              }
            ],
            "concludedValue": "node_modules/rolldown/package.json"
          }
        ]
      },
      "tags": [
        "api"
      ]
    },
    {
      "authors": [
        {
          "name": "Boshen and oxc contributors"
        }
      ],
      "group": "@oxc-project",
      "name": "types",
      "version": "0.127.0",
      "description": "Types for Oxc AST nodes",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40oxc-project/types@0.127.0",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://oxc.rs"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/oxc-project/oxc.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@oxc-project/types@0.127.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/rolldown/node_modules/@oxc-project/types/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/rolldown/node_modules/@oxc-project/types/package.json"
              }
            ],
            "concludedValue": "node_modules/rolldown/node_modules/@oxc-project/types/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "rimraf",
      "version": "3.0.2",
      "description": "A deep deletion module for node (like `rm -rf`)",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/rimraf@3.0.2",
      "type": "library",
      "bom-ref": "pkg:npm/rimraf@3.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/rimraf/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/rimraf/package.json"
              }
            ],
            "concludedValue": "node_modules/rimraf/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "David Mark Clements <david.clements@nearform.com>"
        }
      ],
      "group": "",
      "name": "rfdc",
      "version": "1.4.1",
      "description": "Really Fast Deep Clone",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/rfdc@1.4.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/davidmarkclements/rfdc#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/davidmarkclements/rfdc.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/rfdc@1.4.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/rfdc/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/rfdc/package.json"
              }
            ],
            "concludedValue": "node_modules/rfdc/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Matteo Collina <hello@matteocollina.com>"
        }
      ],
      "group": "",
      "name": "reusify",
      "version": "1.1.0",
      "description": "Reuse objects and functions with style",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/reusify@1.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mcollina/reusify#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/mcollina/reusify.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/reusify@1.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/reusify/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/reusify/package.json"
              }
            ],
            "concludedValue": "node_modules/reusify/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "restore-cursor",
      "version": "3.1.0",
      "description": "Gracefully restore the CLI cursor on exit",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/restore-cursor@3.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/restore-cursor@3.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/restore-cursor/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/restore-cursor/package.json"
              }
            ],
            "concludedValue": "node_modules/restore-cursor/package.json"
          }
        ]
      },
      "tags": [
        "cli"
      ]
    },
    {
      "authors": [
        {
          "name": "Hiroki Osame <hiroki.osame@gmail.com>"
        }
      ],
      "group": "",
      "name": "resolve-pkg-maps",
      "version": "1.0.0",
      "description": "Resolve package.json exports & imports maps",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/resolve-pkg-maps@1.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/resolve-pkg-maps@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/resolve-pkg-maps/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/resolve-pkg-maps/package.json"
              }
            ],
            "concludedValue": "node_modules/resolve-pkg-maps/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "resolve-from",
      "version": "4.0.0",
      "description": "Resolve the path of a module like `require.resolve()` but from a given path",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/resolve-from@4.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/resolve-from@4.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/resolve-from/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/resolve-from/package.json"
              }
            ],
            "concludedValue": "node_modules/resolve-from/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "resolve",
      "version": "1.22.12",
      "description": "resolve like require.resolve() on behalf of files asynchronously and synchronously",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/resolve@1.22.12",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "ssh://github.com/browserify/resolve.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/resolve@1.22.12",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/resolve/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/resolve/package.json"
              }
            ],
            "concludedValue": "node_modules/resolve/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "mylib",
      "version": "0.0.0",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/mylib@0.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/mylib@0.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/resolve/test/resolver/nested_symlinks/mylib/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/resolve/test/resolver/nested_symlinks/mylib/package.json"
              }
            ],
            "concludedValue": "node_modules/resolve/test/resolver/nested_symlinks/mylib/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "ljharb-monorepo-symlink-test",
      "version": "0.0.0",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/ljharb-monorepo-symlink-test@0.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/ljharb-monorepo-symlink-test@0.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/resolve/test/resolver/multirepo/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/resolve/test/resolver/multirepo/package.json"
              }
            ],
            "concludedValue": "node_modules/resolve/test/resolver/multirepo/package.json"
          }
        ]
      }
    },
    {
      "group": "@my-scope",
      "name": "package-b",
      "version": "0.0.0",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40my-scope/package-b@0.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/@my-scope/package-b@0.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/resolve/test/resolver/multirepo/packages/package-b/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/resolve/test/resolver/multirepo/packages/package-b/package.json"
              }
            ],
            "concludedValue": "node_modules/resolve/test/resolver/multirepo/packages/package-b/package.json"
          }
        ]
      }
    },
    {
      "group": "@my-scope",
      "name": "package-a",
      "version": "0.0.0",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40my-scope/package-a@0.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/@my-scope/package-a@0.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/resolve/test/resolver/multirepo/packages/package-a/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/resolve/test/resolver/multirepo/packages/package-a/package.json"
              }
            ],
            "concludedValue": "node_modules/resolve/test/resolver/multirepo/packages/package-a/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "invalid_main",
      "version": "",
      "scope": "optional",
      "purl": "pkg:npm/invalid_main",
      "type": "library",
      "bom-ref": "pkg:npm/invalid_main",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/resolve/test/resolver/invalid_main/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/resolve/test/resolver/invalid_main/package.json"
              }
            ],
            "concludedValue": "node_modules/resolve/test/resolver/invalid_main/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "false_main",
      "version": "",
      "scope": "optional",
      "purl": "pkg:npm/false_main",
      "type": "library",
      "bom-ref": "pkg:npm/false_main",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/resolve/test/resolver/false_main/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/resolve/test/resolver/false_main/package.json"
              }
            ],
            "concludedValue": "node_modules/resolve/test/resolver/false_main/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "browser_field",
      "version": "",
      "scope": "optional",
      "purl": "pkg:npm/browser_field",
      "type": "library",
      "bom-ref": "pkg:npm/browser_field",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/resolve/test/resolver/browser_field/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/resolve/test/resolver/browser_field/package.json"
              }
            ],
            "concludedValue": "node_modules/resolve/test/resolver/browser_field/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "baz",
      "version": "",
      "scope": "optional",
      "purl": "pkg:npm/baz",
      "type": "library",
      "bom-ref": "pkg:npm/baz",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/resolve/test/resolver/baz/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/resolve/test/resolver/baz/package.json"
              }
            ],
            "concludedValue": "node_modules/resolve/test/resolver/baz/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Tanner Linsley <tannerlinsley@gmail.com>"
        }
      ],
      "group": "",
      "name": "reprism",
      "version": "0.0.11",
      "description": "Modular Syntax highlighting for the web",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/reprism@0.0.11",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/tannerlinsley/reprism"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/reprism@0.0.11",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/reprism/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/reprism/package.json"
              }
            ],
            "concludedValue": "node_modules/reprism/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jon Schlinkert (http://github.com/jonschlinkert)"
        }
      ],
      "group": "",
      "name": "repeat-string",
      "version": "1.6.1",
      "description": "Repeat the given string n times. Fastest implementation for repeating a string.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/repeat-string@1.6.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jonschlinkert/repeat-string"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/repeat-string@1.6.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/repeat-string/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/repeat-string/package.json"
              }
            ],
            "concludedValue": "node_modules/repeat-string/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Dmitry Soshnikov"
        }
      ],
      "group": "",
      "name": "regexp-tree",
      "version": "0.1.27",
      "description": "Regular Expressions parser in JavaScript",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/regexp-tree@0.1.27",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/DmitrySoshnikov/regexp-tree"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/regexp-tree@0.1.27",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/regexp-tree/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/regexp-tree/package.json"
              }
            ],
            "concludedValue": "node_modules/regexp-tree/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Feross Aboukhadijeh <feross@feross.org> (https://feross.org)"
        }
      ],
      "group": "",
      "name": "queue-microtask",
      "version": "1.2.3",
      "description": "fast, tiny `queueMicrotask` shim for modern engines",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/queue-microtask@1.2.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/feross/queue-microtask"
        },
        {
          "type": "vcs",
          "url": "git://github.com/feross/queue-microtask.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/queue-microtask@1.2.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/queue-microtask/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/queue-microtask/package.json"
              }
            ],
            "concludedValue": "node_modules/queue-microtask/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mathias Buus Madsen <mathiasbuus@gmail.com>"
        }
      ],
      "group": "",
      "name": "pump",
      "version": "3.0.4",
      "description": "pipe streams together and close all of them if one of them closes",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/pump@3.0.4",
      "type": "library",
      "bom-ref": "pkg:npm/pump@3.0.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/pump/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/pump/package.json"
              }
            ],
            "concludedValue": "node_modules/pump/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "ForbesLindesay"
        }
      ],
      "group": "",
      "name": "pug-walk",
      "version": "2.0.0",
      "description": "Walk and transform a pug AST",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/pug-walk@2.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/pugjs/pug/tree/master/packages/pug-walk"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/pug-walk@2.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/pug-walk/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/pug-walk/package.json"
              }
            ],
            "concludedValue": "node_modules/pug-walk/package.json"
          }
        ]
      },
      "tags": [
        "transform"
      ]
    },
    {
      "authors": [
        {
          "name": "Timothy Gu <timothygu99@gmail.com>"
        }
      ],
      "group": "",
      "name": "pug-strip-comments",
      "version": "2.0.0",
      "description": "Strip comments from a Pug token stream (from the lexer)",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/pug-strip-comments@2.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/pugjs/pug/tree/master/packages/pug-strip-comments"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/pug-strip-comments@2.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/pug-strip-comments/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/pug-strip-comments/package.json"
              }
            ],
            "concludedValue": "node_modules/pug-strip-comments/package.json"
          }
        ]
      },
      "tags": [
        "stream",
        "token"
      ]
    },
    {
      "authors": [
        {
          "name": "ForbesLindesay"
        }
      ],
      "group": "",
      "name": "pug-runtime",
      "version": "3.0.1",
      "description": "The runtime components for the pug templating language",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/pug-runtime@3.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/pugjs/pug/tree/master/packages/pug-runtime"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/pug-runtime@3.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/pug-runtime/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/pug-runtime/package.json"
              }
            ],
            "concludedValue": "node_modules/pug-runtime/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "ForbesLindesay"
        }
      ],
      "group": "",
      "name": "pug-parser",
      "version": "6.0.0",
      "description": "The pug parser (takes an array of tokens and converts it to an abstract syntax tree)",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/pug-parser@6.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/pugjs/pug/tree/master/packages/pug-parser"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/pug-parser@6.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/pug-parser/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/pug-parser/package.json"
              }
            ],
            "concludedValue": "node_modules/pug-parser/package.json"
          }
        ]
      },
      "tags": [
        "parse"
      ]
    },
    {
      "authors": [
        {
          "name": "ForbesLindesay"
        }
      ],
      "group": "",
      "name": "pug-load",
      "version": "3.0.0",
      "description": "The Pug loader is responsible for loading the depenendencies of a given Pug file.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/pug-load@3.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/pugjs/pug/tree/master/packages/pug-load"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/pug-load@3.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/pug-load/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/pug-load/package.json"
              }
            ],
            "concludedValue": "node_modules/pug-load/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Forbes Lindesay"
        }
      ],
      "group": "",
      "name": "pug-linker",
      "version": "4.0.0",
      "description": "Link multiple pug ASTs together using include/extends",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/pug-linker@4.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/pugjs/pug/tree/master/packages/pug-linker"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/pug-linker@4.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/pug-linker/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/pug-linker/package.json"
              }
            ],
            "concludedValue": "node_modules/pug-linker/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "ForbesLindesay"
        }
      ],
      "group": "",
      "name": "pug-lexer",
      "version": "5.0.1",
      "description": "The pug lexer (takes a string and converts it to an array of tokens)",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/pug-lexer@5.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/pugjs/pug/tree/master/packages/pug-lexer"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/pug-lexer@5.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/pug-lexer/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/pug-lexer/package.json"
              }
            ],
            "concludedValue": "node_modules/pug-lexer/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Forbes Lindesay"
        }
      ],
      "group": "",
      "name": "pug-filters",
      "version": "4.0.0",
      "description": "Code for processing filters in pug templates",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/pug-filters@4.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/pugjs/pug/tree/master/packages/pug-filters"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/pug-filters@4.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/pug-filters/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/pug-filters/package.json"
              }
            ],
            "concludedValue": "node_modules/pug-filters/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Forbes Lindesay"
        }
      ],
      "group": "",
      "name": "pug-error",
      "version": "2.1.0",
      "description": "Standard error objects for pug",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/pug-error@2.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/pugjs/pug/tree/master/packages/pug-error"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/pug-error@2.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/pug-error/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/pug-error/package.json"
              }
            ],
            "concludedValue": "node_modules/pug-error/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Forbes Lindesay"
        }
      ],
      "group": "",
      "name": "pug-code-gen",
      "version": "3.0.4",
      "description": "Default code-generator for pug.  It generates HTML via a JavaScript template function.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/pug-code-gen@3.0.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/pugjs/pug/tree/master/packages/pug-code-gen"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/pug-code-gen@3.0.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/pug-code-gen/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/pug-code-gen/package.json"
              }
            ],
            "concludedValue": "node_modules/pug-code-gen/package.json"
          }
        ]
      },
      "tags": [
        "html",
        "template"
      ]
    },
    {
      "authors": [
        {
          "name": "Forbes Lindesay"
        }
      ],
      "group": "",
      "name": "pug-attrs",
      "version": "3.0.0",
      "description": "Generate code for Pug attributes",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/pug-attrs@3.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/pugjs/pug/tree/master/packages/pug-attrs"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/pug-attrs@3.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/pug-attrs/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/pug-attrs/package.json"
              }
            ],
            "concludedValue": "node_modules/pug-attrs/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "TJ Holowaychuk <tj@vision-media.ca>"
        }
      ],
      "group": "",
      "name": "pug",
      "version": "3.0.4",
      "description": "A clean, whitespace-sensitive template language for writing HTML",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/pug@3.0.4",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://pugjs.org"
        },
        {
          "type": "vcs",
          "url": "https://github.com/pugjs/pug/tree/master/packages/pug"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/pug@3.0.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/pug/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/pug/package.json"
              }
            ],
            "concludedValue": "node_modules/pug/package.json"
          }
        ]
      },
      "tags": [
        "template"
      ]
    },
    {
      "authors": [
        {
          "name": "ForbesLindesay"
        }
      ],
      "group": "",
      "name": "promise",
      "version": "7.3.1",
      "description": "Bare bones Promises/A+ implementation",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/promise@7.3.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/then/promise.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/promise@7.3.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/promise/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/promise/package.json"
              }
            ],
            "concludedValue": "node_modules/promise/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Andrey Sitnik <andrey@sitnik.es>"
        }
      ],
      "group": "",
      "name": "postcss",
      "version": "8.5.13",
      "description": "Tool for transforming styles with JS plugins",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/postcss@8.5.13",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://postcss.org/"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/postcss@8.5.13",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/postcss/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/postcss/package.json"
              }
            ],
            "concludedValue": "node_modules/postcss/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "typicode"
        }
      ],
      "group": "",
      "name": "please-upgrade-node",
      "version": "3.2.0",
      "description": "Displays a beginner-friendly message telling your user to upgrade their version of Node",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/please-upgrade-node@3.2.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/typicode/please-upgrade-node#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/typicode/please-upgrade-node.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/please-upgrade-node@3.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/please-upgrade-node/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/please-upgrade-node/package.json"
              }
            ],
            "concludedValue": "node_modules/please-upgrade-node/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jon Schlinkert (https://github.com/jonschlinkert)"
        }
      ],
      "group": "",
      "name": "picomatch",
      "version": "4.0.4",
      "description": "Blazing fast and accurate glob matcher written in JavaScript, with no dependencies and full support for standard and extended Bash glob features, including braces, extglobs, POSIX brackets, and regular expressions.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/picomatch@4.0.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/micromatch/picomatch"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/picomatch@4.0.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/picomatch/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/picomatch/package.json"
              }
            ],
            "concludedValue": "node_modules/picomatch/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Alexey Raspopov"
        }
      ],
      "group": "",
      "name": "picocolors",
      "version": "1.1.1",
      "description": "The tiniest and the fastest library for terminal output formatting with ANSI colors",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/picocolors@1.1.1",
      "type": "library",
      "bom-ref": "pkg:npm/picocolors@1.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/picocolors/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/picocolors/package.json"
              }
            ],
            "concludedValue": "node_modules/picocolors/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "pathe",
      "version": "2.0.3",
      "description": "Universal filesystem path utils",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/pathe@2.0.3",
      "type": "library",
      "bom-ref": "pkg:npm/pathe@2.0.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/pathe/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/pathe/package.json"
              }
            ],
            "concludedValue": "node_modules/pathe/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "path-type",
      "version": "4.0.0",
      "description": "Check if a path is a file, directory, or symlink",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/path-type@4.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/path-type@4.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/path-type/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/path-type/package.json"
              }
            ],
            "concludedValue": "node_modules/path-type/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Javier Blanco <http://jbgutierrez.info>"
        }
      ],
      "group": "",
      "name": "path-parse",
      "version": "1.0.7",
      "description": "Node.js path.parse() ponyfill",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/path-parse@1.0.7",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jbgutierrez/path-parse#readme"
        },
        {
          "type": "vcs",
          "url": "https://github.com/jbgutierrez/path-parse.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/path-parse@1.0.7",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/path-parse/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/path-parse/package.json"
              }
            ],
            "concludedValue": "node_modules/path-parse/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "path-key",
      "version": "3.1.1",
      "description": "Get the PATH environment variable key cross-platform",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/path-key@3.1.1",
      "type": "library",
      "bom-ref": "pkg:npm/path-key@3.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/path-key/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/path-key/package.json"
              }
            ],
            "concludedValue": "node_modules/path-key/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "path-is-absolute",
      "version": "1.0.1",
      "description": "Node.js 0.12 path.isAbsolute() ponyfill",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/path-is-absolute@1.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/path-is-absolute@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/path-is-absolute/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/path-is-absolute/package.json"
              }
            ],
            "concludedValue": "node_modules/path-is-absolute/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "parse-json",
      "version": "5.2.0",
      "description": "Parse JSON with more helpful errors",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/parse-json@5.2.0",
      "type": "library",
      "bom-ref": "pkg:npm/parse-json@5.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/parse-json/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/parse-json/package.json"
              }
            ],
            "concludedValue": "node_modules/parse-json/package.json"
          }
        ]
      },
      "tags": [
        "json"
      ]
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "parent-module",
      "version": "1.0.1",
      "description": "Get the path of the parent module",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/parent-module@1.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/parent-module@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/parent-module/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/parent-module/package.json"
              }
            ],
            "concludedValue": "node_modules/parent-module/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "p-map",
      "version": "4.0.0",
      "description": "Map over promises concurrently",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/p-map@4.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/p-map@4.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/p-map/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/p-map/package.json"
              }
            ],
            "concludedValue": "node_modules/p-map/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Boshen and oxc contributors"
        }
      ],
      "group": "",
      "name": "oxlint",
      "version": "1.62.0",
      "description": "Linter for the JavaScript Oxidation Compiler",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/oxlint@1.62.0",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://oxc.rs/docs/guide/usage/linter"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/oxc-project/oxc"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/oxlint@1.62.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/oxlint/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/oxlint/package.json"
              }
            ],
            "concludedValue": "node_modules/oxlint/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Boshen and oxc contributors"
        }
      ],
      "group": "",
      "name": "oxfmt",
      "version": "0.47.0",
      "description": "Formatter for the JavaScript Oxidation Compiler",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/oxfmt@0.47.0",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://oxc.rs/docs/guide/usage/formatter"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/oxc-project/oxc"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/oxfmt@0.47.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/oxfmt/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/oxfmt/package.json"
              }
            ],
            "concludedValue": "node_modules/oxfmt/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "oxc-resolver",
      "version": "11.19.1",
      "description": "Oxc Resolver Node API",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/oxc-resolver@11.19.1",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://oxc.rs"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/oxc-project/oxc-resolver.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/oxc-resolver@11.19.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/oxc-resolver/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/oxc-resolver/package.json"
              }
            ],
            "concludedValue": "node_modules/oxc-resolver/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Boshen and oxc contributors"
        }
      ],
      "group": "",
      "name": "oxc-parser",
      "version": "0.128.0",
      "description": "Oxc Parser Node API",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/oxc-parser@0.128.0",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://oxc.rs/docs/guide/usage/parser"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/oxc-project/oxc.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/oxc-parser@0.128.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/oxc-parser/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/oxc-parser/package.json"
              }
            ],
            "concludedValue": "node_modules/oxc-parser/package.json"
          }
        ]
      },
      "tags": [
        "parse"
      ]
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "onetime",
      "version": "5.1.2",
      "description": "Ensure a function is only called once",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/onetime@5.1.2",
      "type": "library",
      "bom-ref": "pkg:npm/onetime@5.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/onetime/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/onetime/package.json"
              }
            ],
            "concludedValue": "node_modules/onetime/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "once",
      "version": "1.4.0",
      "description": "Run a function exactly one time",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/once@1.4.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/once"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/once@1.4.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/once/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/once/package.json"
              }
            ],
            "concludedValue": "node_modules/once/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Kevin Deng <sxzz@sxzz.moe>"
        }
      ],
      "group": "",
      "name": "obug",
      "version": "2.1.1",
      "description": "A lightweight JavaScript debugging utility, forked from debug, featuring TypeScript and ESM support.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/obug@2.1.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/sxzz/obug#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/sxzz/obug.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/obug@2.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/obug/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/obug/package.json"
              }
            ],
            "concludedValue": "node_modules/obug/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "object-assign",
      "version": "4.1.1",
      "description": "ES2015 `Object.assign()` ponyfill",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/object-assign@4.1.1",
      "type": "library",
      "bom-ref": "pkg:npm/object-assign@4.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/object-assign/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/object-assign/package.json"
              }
            ],
            "concludedValue": "node_modules/object-assign/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "npm-run-path",
      "version": "4.0.1",
      "description": "Get your PATH prepended with locally installed binaries",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/npm-run-path@4.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/npm-run-path@4.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm-run-path/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm-run-path/package.json"
              }
            ],
            "concludedValue": "node_modules/npm-run-path/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jon Schlinkert (https://github.com/jonschlinkert)"
        }
      ],
      "group": "",
      "name": "normalize-path",
      "version": "3.0.0",
      "description": "Normalize slashes in a file path to be posix/unix-like forward slashes. Also condenses repeat slashes to a single slash and removes and trailing slashes, unless disabled.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/normalize-path@3.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jonschlinkert/normalize-path"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/normalize-path@3.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/normalize-path/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/normalize-path/package.json"
              }
            ],
            "concludedValue": "node_modules/normalize-path/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Nicolas Vuillamy <nicolas.vuillamy@gmail.com> (http://nicolas.vuillamy.fr)"
        }
      ],
      "group": "",
      "name": "node-sarif-builder",
      "version": "3.4.0",
      "description": "Module to help building SARIF log files",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/node-sarif-builder@3.4.0",
      "type": "library",
      "bom-ref": "pkg:npm/node-sarif-builder@3.4.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/node-sarif-builder/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/node-sarif-builder/package.json"
              }
            ],
            "concludedValue": "node_modules/node-sarif-builder/package.json"
          }
        ]
      },
      "tags": [
        "log"
      ]
    },
    {
      "authors": [
        {
          "name": "Andrey Sitnik <andrey@sitnik.ru>"
        }
      ],
      "group": "",
      "name": "nanoid",
      "version": "3.3.12",
      "description": "A tiny (116 bytes), secure URL-friendly unique string ID generator",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/nanoid@3.3.12",
      "type": "library",
      "bom-ref": "pkg:npm/nanoid@3.3.12",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/nanoid/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/nanoid/package.json"
              }
            ],
            "concludedValue": "node_modules/nanoid/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "ms",
      "version": "2.1.3",
      "description": "Tiny millisecond conversion utility",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/ms@2.1.3",
      "type": "library",
      "bom-ref": "pkg:npm/ms@2.1.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/ms/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/ms/package.json"
              }
            ],
            "concludedValue": "node_modules/ms/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Luke Edwards <luke.edwards05@gmail.com> (https://lukeed.com)"
        }
      ],
      "group": "",
      "name": "mri",
      "version": "1.1.6",
      "description": "Quickly scan for CLI flags and arguments",
      "scope": "required",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/mri@1.1.6",
      "type": "library",
      "bom-ref": "pkg:npm/mri@1.1.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/mri/package.json"
        },
        {
          "name": "ImportedModules",
          "value": "mri"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/mri/package.json"
              }
            ],
            "concludedValue": "node_modules/mri/package.json"
          }
        ],
        "occurrences": [
          {
            "location": "src/bin.js#4"
          }
        ]
      },
      "tags": [
        "cli"
      ]
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "mkdirp",
      "version": "0.5.6",
      "description": "Recursively mkdir, like `mkdir -p`",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/mkdirp@0.5.6",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/node-mkdirp.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/mkdirp@0.5.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/mkdirp/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/mkdirp/package.json"
              }
            ],
            "concludedValue": "node_modules/mkdirp/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "minizlib",
      "version": "2.1.2",
      "description": "A small fast zlib stream built on [minipass](http://npm.im/minipass) and Node.js's zlib binding.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/minizlib@2.1.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git+https://github.com/isaacs/minizlib.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/minizlib@2.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/minizlib/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/minizlib/package.json"
              }
            ],
            "concludedValue": "node_modules/minizlib/package.json"
          }
        ]
      },
      "tags": [
        "stream"
      ]
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "minipass",
      "version": "3.3.6",
      "description": "minimal implementation of a PassThrough stream",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/minipass@3.3.6",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git+https://github.com/isaacs/minipass.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/minipass@3.3.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/minipass/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/minipass/package.json"
              }
            ],
            "concludedValue": "node_modules/minipass/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "minimist",
      "version": "1.2.8",
      "description": "parse argument options",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/minimist@1.2.8",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/minimistjs/minimist"
        },
        {
          "type": "vcs",
          "url": "git://github.com/minimistjs/minimist.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/minimist@1.2.8",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/minimist/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/minimist/package.json"
              }
            ],
            "concludedValue": "node_modules/minimist/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me)"
        }
      ],
      "group": "",
      "name": "minimatch",
      "version": "3.1.5",
      "description": "a glob matcher in javascript",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/minimatch@3.1.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/minimatch.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/minimatch@3.1.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/minimatch/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/minimatch/package.json"
              }
            ],
            "concludedValue": "node_modules/minimatch/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "mimic-fn",
      "version": "2.1.0",
      "description": "Make a function mimic another one",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/mimic-fn@2.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/mimic-fn@2.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/mimic-fn/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/mimic-fn/package.json"
              }
            ],
            "concludedValue": "node_modules/mimic-fn/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jon Schlinkert (https://github.com/jonschlinkert)"
        }
      ],
      "group": "",
      "name": "micromatch",
      "version": "4.0.8",
      "description": "Glob matching for javascript/node.js. A replacement and faster alternative to minimatch and multimatch.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/micromatch@4.0.8",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/micromatch/micromatch"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/micromatch@4.0.8",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/micromatch/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/micromatch/package.json"
              }
            ],
            "concludedValue": "node_modules/micromatch/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jon Schlinkert (https://github.com/jonschlinkert)"
        }
      ],
      "group": "",
      "name": "picomatch",
      "version": "2.3.2",
      "description": "Blazing fast and accurate glob matcher written in JavaScript, with no dependencies and full support for standard and extended Bash glob features, including braces, extglobs, POSIX brackets, and regular expressions.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/picomatch@2.3.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/micromatch/picomatch"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/picomatch@2.3.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/micromatch/node_modules/picomatch/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/@rollup/pluginutils/node_modules/picomatch/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/micromatch/node_modules/picomatch/package.json"
              },
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@rollup/pluginutils/node_modules/picomatch/package.json"
              }
            ]
          }
        ]
      }
    },
    {
      "group": "",
      "name": "merge2",
      "version": "1.4.1",
      "description": "Merge multiple streams into one stream in sequence or parallel.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/merge2@1.4.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/teambition/merge2"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/merge2@1.4.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/merge2/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/merge2/package.json"
              }
            ],
            "concludedValue": "node_modules/merge2/package.json"
          }
        ]
      },
      "tags": [
        "stream"
      ]
    },
    {
      "authors": [
        {
          "name": "Stephen Sugden <me@stephensugden.com>"
        }
      ],
      "group": "",
      "name": "merge-stream",
      "version": "2.0.0",
      "description": "Create a stream that emits events from multiple other streams",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/merge-stream@2.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/merge-stream@2.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/merge-stream/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/merge-stream/package.json"
              }
            ],
            "concludedValue": "node_modules/merge-stream/package.json"
          }
        ]
      },
      "tags": [
        "stream"
      ]
    },
    {
      "authors": [
        {
          "name": "Jordan Harband <ljharb@gmail.com>"
        }
      ],
      "group": "",
      "name": "math-intrinsics",
      "version": "1.1.0",
      "description": "ES Math-related intrinsics and helpers, robustly cached.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/math-intrinsics@1.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/es-shims/math-intrinsics#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/es-shims/math-intrinsics.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/math-intrinsics@1.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/math-intrinsics/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/math-intrinsics/package.json"
              }
            ],
            "concludedValue": "node_modules/math-intrinsics/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Titus Wormer <tituswormer@gmail.com> (https://wooorm.com)"
        }
      ],
      "group": "",
      "name": "markdown-table",
      "version": "2.0.0",
      "description": "Markdown tables",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/markdown-table@2.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/markdown-table@2.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/markdown-table/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/markdown-table/package.json"
              }
            ],
            "concludedValue": "node_modules/markdown-table/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "make-dir",
      "version": "4.0.0",
      "description": "Make a directory and its parents if needed - Think `mkdir -p`",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/make-dir@4.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/make-dir@4.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/make-dir/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/make-dir/package.json"
              }
            ],
            "concludedValue": "node_modules/make-dir/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "magicast",
      "version": "0.5.2",
      "description": "Modify a JS/TS file and write back magically just like JSON!",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/magicast@0.5.2",
      "type": "library",
      "bom-ref": "pkg:npm/magicast@0.5.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/magicast/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/magicast/package.json"
              }
            ],
            "concludedValue": "node_modules/magicast/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Rich Harris"
        }
      ],
      "group": "",
      "name": "magic-string",
      "version": "0.25.9",
      "description": "Modify strings, generate sourcemaps",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/magic-string@0.25.9",
      "type": "library",
      "bom-ref": "pkg:npm/magic-string@0.25.9",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/magic-string/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/magic-string/package.json"
              }
            ],
            "concludedValue": "node_modules/magic-string/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "log-update",
      "version": "4.0.0",
      "description": "Log by overwriting the previous output in the terminal. Useful for rendering progress bars, animations, etc.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/log-update@4.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/log-update@4.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/log-update/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/log-update/package.json"
              }
            ],
            "concludedValue": "node_modules/log-update/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "wrap-ansi",
      "version": "6.2.0",
      "description": "Wordwrap a string with ANSI escape codes",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/wrap-ansi@6.2.0",
      "type": "library",
      "bom-ref": "pkg:npm/wrap-ansi@6.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/log-update/node_modules/wrap-ansi/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/log-update/node_modules/wrap-ansi/package.json"
              }
            ],
            "concludedValue": "node_modules/log-update/node_modules/wrap-ansi/package.json"
          }
        ]
      },
      "tags": [
        "escape"
      ]
    },
    {
      "group": "",
      "name": "slice-ansi",
      "version": "4.0.0",
      "description": "Slice a string with ANSI escape codes",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/slice-ansi@4.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/slice-ansi@4.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/log-update/node_modules/slice-ansi/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/log-update/node_modules/slice-ansi/package.json"
              }
            ],
            "concludedValue": "node_modules/log-update/node_modules/slice-ansi/package.json"
          }
        ]
      },
      "tags": [
        "escape"
      ]
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "log-symbols",
      "version": "4.1.0",
      "description": "Colored symbols for various log levels. Example: `✔︎ Success`",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/log-symbols@4.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/log-symbols@4.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/log-symbols/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/log-symbols/package.json"
              }
            ],
            "concludedValue": "node_modules/log-symbols/package.json"
          }
        ]
      },
      "tags": [
        "log"
      ]
    },
    {
      "authors": [
        {
          "name": "Cenk Kilic <cenk@kilic.dev> (https://srcs.kilic.dev)"
        }
      ],
      "group": "",
      "name": "listr2",
      "version": "3.14.0",
      "description": "Terminal task list reborn! Create beautiful CLI interfaces via easy and logical to implement task lists that feel alive and interactive.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/listr2@3.14.0",
      "type": "library",
      "bom-ref": "pkg:npm/listr2@3.14.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/listr2/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/listr2/package.json"
              }
            ],
            "concludedValue": "node_modules/listr2/package.json"
          }
        ]
      },
      "tags": [
        "cli"
      ]
    },
    {
      "authors": [
        {
          "name": "Andrey Okonetchnikov <andrey@okonet.ru>"
        }
      ],
      "group": "",
      "name": "lint-staged",
      "version": "10.5.4",
      "description": "Lint files staged by git",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/lint-staged@10.5.4",
      "type": "library",
      "bom-ref": "pkg:npm/lint-staged@10.5.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/lint-staged/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/lint-staged/package.json"
              }
            ],
            "concludedValue": "node_modules/lint-staged/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "TJ Holowaychuk <tj@vision-media.ca>"
        }
      ],
      "group": "",
      "name": "commander",
      "version": "6.2.1",
      "description": "the complete solution for node.js command-line programs",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/commander@6.2.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/tj/commander.js.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/commander@6.2.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/lint-staged/node_modules/commander/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/lint-staged/node_modules/commander/package.json"
              }
            ],
            "concludedValue": "node_modules/lint-staged/node_modules/commander/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Brian Donovan <brian@donovans.cc>"
        }
      ],
      "group": "",
      "name": "lines-and-columns",
      "version": "1.2.4",
      "description": "Maps lines and columns to character offsets and back.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/lines-and-columns@1.2.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/eventualbuddha/lines-and-columns#readme"
        },
        {
          "type": "vcs",
          "url": "https://github.com/eventualbuddha/lines-and-columns.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lines-and-columns@1.2.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/lines-and-columns/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/lines-and-columns/package.json"
              }
            ],
            "concludedValue": "node_modules/lines-and-columns/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "lightningcss-linux-x64-musl",
      "version": "1.32.0",
      "description": "A CSS parser, transformer, and minifier written in Rust",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MPL-2.0",
            "url": "https://opensource.org/licenses/MPL-2.0"
          }
        }
      ],
      "purl": "pkg:npm/lightningcss-linux-x64-musl@1.32.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/parcel-bundler/lightningcss.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lightningcss-linux-x64-musl@1.32.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/lightningcss-linux-x64-musl/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/lightningcss-linux-x64-musl/package.json"
              }
            ],
            "concludedValue": "node_modules/lightningcss-linux-x64-musl/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "lightningcss-linux-x64-gnu",
      "version": "1.32.0",
      "description": "A CSS parser, transformer, and minifier written in Rust",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MPL-2.0",
            "url": "https://opensource.org/licenses/MPL-2.0"
          }
        }
      ],
      "purl": "pkg:npm/lightningcss-linux-x64-gnu@1.32.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/parcel-bundler/lightningcss.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lightningcss-linux-x64-gnu@1.32.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/lightningcss-linux-x64-gnu/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/lightningcss-linux-x64-gnu/package.json"
              }
            ],
            "concludedValue": "node_modules/lightningcss-linux-x64-gnu/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "lightningcss",
      "version": "1.32.0",
      "description": "A CSS parser, transformer, and minifier written in Rust",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MPL-2.0",
            "url": "https://opensource.org/licenses/MPL-2.0"
          }
        }
      ],
      "purl": "pkg:npm/lightningcss@1.32.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/parcel-bundler/lightningcss.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lightningcss@1.32.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/lightningcss/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/lightningcss/package.json"
              }
            ],
            "concludedValue": "node_modules/lightningcss/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Lars Kappert <lars@webpro.nl>"
        }
      ],
      "group": "",
      "name": "knip",
      "version": "6.11.0",
      "description": "Find and fix unused dependencies, exports and files in your TypeScript and JavaScript projects",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/knip@6.11.0",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://knip.dev"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/webpro-nl/knip.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/knip@6.11.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/knip/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/knip/package.json"
              }
            ],
            "concludedValue": "node_modules/knip/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "ForbesLindesay"
        }
      ],
      "group": "",
      "name": "jstransformer",
      "version": "1.0.0",
      "description": "Normalize the API of any jstransformer",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/jstransformer@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jstransformers/jstransformer.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/jstransformer@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/jstransformer/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/jstransformer/package.json"
              }
            ],
            "concludedValue": "node_modules/jstransformer/package.json"
          }
        ]
      },
      "tags": [
        "api",
        "transform"
      ]
    },
    {
      "authors": [
        {
          "name": "JP Richardson <jprichardson@gmail.com>"
        }
      ],
      "group": "",
      "name": "jsonfile",
      "version": "6.2.1",
      "description": "Easily read/write JSON files.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/jsonfile@6.2.1",
      "type": "library",
      "bom-ref": "pkg:npm/jsonfile@6.2.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/jsonfile/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/jsonfile/package.json"
              }
            ],
            "concludedValue": "node_modules/jsonfile/package.json"
          }
        ]
      },
      "tags": [
        "json"
      ]
    },
    {
      "authors": [
        {
          "name": "Kat Marchán <kzm@zkat.tech>"
        }
      ],
      "group": "",
      "name": "json-parse-even-better-errors",
      "version": "2.3.1",
      "description": "JSON.parse with context information on error",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/json-parse-even-better-errors@2.3.1",
      "type": "library",
      "bom-ref": "pkg:npm/json-parse-even-better-errors@2.3.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/json-parse-even-better-errors/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/json-parse-even-better-errors/package.json"
              }
            ],
            "concludedValue": "node_modules/json-parse-even-better-errors/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Andrey Kucherenko <kucherenko.andrey@gmail.com>"
        }
      ],
      "group": "",
      "name": "jscpd-sarif-reporter",
      "version": "4.0.7",
      "description": "Reporter for jscpd. Generate a report in SARIF format (https://github.com/oasis-tcs/sarif-spec).",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/jscpd-sarif-reporter@4.0.7",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/kucherenko/jscpd#readme"
        },
        {
          "type": "vcs",
          "url": "git+ssh://git@github.com/kucherenko/jscpd.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/jscpd-sarif-reporter@4.0.7",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/jscpd-sarif-reporter/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/jscpd-sarif-reporter/package.json"
              }
            ],
            "concludedValue": "node_modules/jscpd-sarif-reporter/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Andrey Kucherenko <kucherenko.andrey@gmail.com>"
        }
      ],
      "group": "",
      "name": "jscpd",
      "version": "4.0.9",
      "description": "detector of copy/paste in files",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/jscpd@4.0.9",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/kucherenko/jscpd#readme"
        },
        {
          "type": "vcs",
          "url": "git+ssh://git@github.com/kucherenko/jscpd.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/jscpd@4.0.9",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/jscpd/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/jscpd/package.json"
              }
            ],
            "concludedValue": "node_modules/jscpd/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Simon Lydell"
        }
      ],
      "group": "",
      "name": "js-tokens",
      "version": "10.0.0",
      "description": "Tiny JavaScript tokenizer.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/js-tokens@10.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/js-tokens@10.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/js-tokens/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/js-tokens/package.json"
              }
            ],
            "concludedValue": "node_modules/js-tokens/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "ForbesLindesay"
        }
      ],
      "group": "",
      "name": "js-stringify",
      "version": "1.0.2",
      "description": "Stringify an object so it can be safely inlined in JavaScript code",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/js-stringify@1.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jadejs/js-stringify.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/js-stringify@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/js-stringify/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/js-stringify/package.json"
              }
            ],
            "concludedValue": "node_modules/js-stringify/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "jiti",
      "version": "2.7.0",
      "description": "Runtime typescript and ESM support for Node.js",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/jiti@2.7.0",
      "type": "library",
      "bom-ref": "pkg:npm/jiti@2.7.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/jiti/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/jiti/package.json"
              }
            ],
            "concludedValue": "node_modules/jiti/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Krishnan Anantheswaran <kananthmail-github@yahoo.com>"
        }
      ],
      "group": "",
      "name": "istanbul-reports",
      "version": "3.2.0",
      "description": "istanbul reports",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-3-Clause",
            "url": "https://opensource.org/licenses/BSD-3-Clause"
          }
        }
      ],
      "purl": "pkg:npm/istanbul-reports@3.2.0",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://istanbul.js.org/"
        },
        {
          "type": "vcs",
          "url": "git+ssh://git@github.com/istanbuljs/istanbuljs.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/istanbul-reports@3.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/istanbul-reports/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/istanbul-reports/package.json"
              }
            ],
            "concludedValue": "node_modules/istanbul-reports/package.json"
          }
        ]
      },
      "tags": [
        "test"
      ]
    },
    {
      "authors": [
        {
          "name": "Krishnan Anantheswaran <kananthmail-github@yahoo.com>"
        }
      ],
      "group": "",
      "name": "istanbul-lib-report",
      "version": "3.0.1",
      "description": "Base reporting library for istanbul",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-3-Clause",
            "url": "https://opensource.org/licenses/BSD-3-Clause"
          }
        }
      ],
      "purl": "pkg:npm/istanbul-lib-report@3.0.1",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://istanbul.js.org/"
        },
        {
          "type": "vcs",
          "url": "git+ssh://git@github.com/istanbuljs/istanbuljs.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/istanbul-lib-report@3.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/istanbul-lib-report/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/istanbul-lib-report/package.json"
              }
            ],
            "concludedValue": "node_modules/istanbul-lib-report/package.json"
          }
        ]
      },
      "tags": [
        "test"
      ]
    },
    {
      "authors": [
        {
          "name": "Krishnan Anantheswaran <kananthmail-github@yahoo.com>"
        }
      ],
      "group": "",
      "name": "istanbul-lib-coverage",
      "version": "3.2.2",
      "description": "Data library for istanbul coverage objects",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-3-Clause",
            "url": "https://opensource.org/licenses/BSD-3-Clause"
          }
        }
      ],
      "purl": "pkg:npm/istanbul-lib-coverage@3.2.2",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://istanbul.js.org/"
        },
        {
          "type": "vcs",
          "url": "git+ssh://git@github.com/istanbuljs/istanbuljs.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/istanbul-lib-coverage@3.2.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/istanbul-lib-coverage/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/istanbul-lib-coverage/package.json"
              }
            ],
            "concludedValue": "node_modules/istanbul-lib-coverage/package.json"
          }
        ]
      },
      "tags": [
        "test"
      ]
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "isexe",
      "version": "2.0.0",
      "description": "Minimal module to check if a file is executable.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/isexe@2.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/isexe#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/isaacs/isexe.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/isexe@2.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/isexe/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/isexe/package.json"
              }
            ],
            "concludedValue": "node_modules/isexe/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "is-unicode-supported",
      "version": "0.1.0",
      "description": "Detect whether the terminal supports Unicode",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-unicode-supported@0.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/is-unicode-supported@0.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-unicode-supported/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-unicode-supported/package.json"
              }
            ],
            "concludedValue": "node_modules/is-unicode-supported/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "is-stream",
      "version": "2.0.1",
      "description": "Check if something is a Node.js stream",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-stream@2.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/is-stream@2.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-stream/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-stream/package.json"
              }
            ],
            "concludedValue": "node_modules/is-stream/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (http://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "is-regexp",
      "version": "1.0.0",
      "description": "Check whether a variable is a regular expression",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-regexp@1.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/is-regexp@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-regexp/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-regexp/package.json"
              }
            ],
            "concludedValue": "node_modules/is-regexp/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jordan Harband <ljharb@gmail.com>"
        }
      ],
      "group": "",
      "name": "is-regex",
      "version": "1.2.1",
      "description": "Is this value a JS regex? Works cross-realm/iframe, and despite ES6 @@toStringTag",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-regex@1.2.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/inspect-js/is-regex"
        },
        {
          "type": "vcs",
          "url": "git://github.com/inspect-js/is-regex.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/is-regex@1.2.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-regex/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-regex/package.json"
              }
            ],
            "concludedValue": "node_modules/is-regex/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Rich Harris"
        }
      ],
      "group": "",
      "name": "is-reference",
      "version": "1.2.1",
      "description": "Determine whether an AST node is a reference",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-reference@1.2.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/Rich-Harris/is-reference#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/Rich-Harris/is-reference.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/is-reference@1.2.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-reference/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-reference/package.json"
              }
            ],
            "concludedValue": "node_modules/is-reference/package.json"
          }
        ]
      }
    },
    {
      "group": "@types",
      "name": "estree",
      "version": "1.0.8",
      "description": "TypeScript definitions for estree",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40types/estree@1.0.8",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/estree"
        },
        {
          "type": "vcs",
          "url": "https://github.com/DefinitelyTyped/DefinitelyTyped.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@types/estree@1.0.8",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-reference/node_modules/@types/estree/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/ast-v8-to-istanbul/node_modules/estree-walker/node_modules/@types/estree/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/@vitest/mocker/node_modules/estree-walker/node_modules/@types/estree/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-reference/node_modules/@types/estree/package.json"
              },
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/ast-v8-to-istanbul/node_modules/estree-walker/node_modules/@types/estree/package.json"
              },
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@vitest/mocker/node_modules/estree-walker/node_modules/@types/estree/package.json"
              }
            ]
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "ForbesLindesay"
        }
      ],
      "group": "",
      "name": "is-promise",
      "version": "2.2.2",
      "description": "Test whether an object looks like a promises-a+ promise",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-promise@2.2.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/then/is-promise.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/is-promise@2.2.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-promise/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-promise/package.json"
              }
            ],
            "concludedValue": "node_modules/is-promise/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "is-obj",
      "version": "1.0.1",
      "description": "Check if a value is an object",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-obj@1.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/is-obj@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-obj/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-obj/package.json"
              }
            ],
            "concludedValue": "node_modules/is-obj/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jon Schlinkert (https://github.com/jonschlinkert)"
        }
      ],
      "group": "",
      "name": "is-number",
      "version": "7.0.0",
      "description": "Returns true if a number or string value is a finite number. Useful for regex matches, parsing, user input, etc.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-number@7.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jonschlinkert/is-number"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/is-number@7.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-number/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-number/package.json"
              }
            ],
            "concludedValue": "node_modules/is-number/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jonathan Ong <me@jongleberry.com> (http://jongleberry.com)"
        }
      ],
      "group": "",
      "name": "is-module",
      "version": "1.0.0",
      "description": "check if a source string is an es6 module",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-module@1.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/is-module@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-module/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-module/package.json"
              }
            ],
            "concludedValue": "node_modules/is-module/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jon Schlinkert (https://github.com/jonschlinkert)"
        }
      ],
      "group": "",
      "name": "is-glob",
      "version": "4.0.3",
      "description": "Returns `true` if the given string looks like a glob pattern or an extglob pattern. This makes it easy to create code that only uses external modules like node-glob when necessary, resulting in much faster code execution and initialization time, and a better user experience.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-glob@4.0.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/micromatch/is-glob"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/is-glob@4.0.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-glob/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-glob/package.json"
              }
            ],
            "concludedValue": "node_modules/is-glob/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "is-fullwidth-code-point",
      "version": "3.0.0",
      "description": "Check if the character represented by a given Unicode code point is fullwidth",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-fullwidth-code-point@3.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/is-fullwidth-code-point@3.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-fullwidth-code-point/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-fullwidth-code-point/package.json"
              }
            ],
            "concludedValue": "node_modules/is-fullwidth-code-point/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jon Schlinkert (https://github.com/jonschlinkert)"
        }
      ],
      "group": "",
      "name": "is-extglob",
      "version": "2.1.1",
      "description": "Returns true if a string has an extglob.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-extglob@2.1.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jonschlinkert/is-extglob"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/is-extglob@2.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-extglob/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-extglob/package.json"
              }
            ],
            "concludedValue": "node_modules/is-extglob/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Timothy Gu <timothygu99@gmail.com>"
        }
      ],
      "group": "",
      "name": "is-expression",
      "version": "4.0.0",
      "description": "Check if a string is a valid JavaScript expression",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-expression@4.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/pugjs/is-expression.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/is-expression@4.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-expression/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-expression/package.json"
              }
            ],
            "concludedValue": "node_modules/is-expression/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jordan Harband <ljharb@gmail.com>"
        }
      ],
      "group": "",
      "name": "is-core-module",
      "version": "2.16.1",
      "description": "Is this specifier a node.js core module?",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-core-module@2.16.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/inspect-js/is-core-module"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/inspect-js/is-core-module.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/is-core-module@2.16.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-core-module/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-core-module/package.json"
              }
            ],
            "concludedValue": "node_modules/is-core-module/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Qix (http://github.com/qix-)"
        }
      ],
      "group": "",
      "name": "is-arrayish",
      "version": "0.2.1",
      "description": "Determines if an object can be used as an array",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-arrayish@0.2.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/qix-/node-is-arrayish.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/is-arrayish@0.2.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-arrayish/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-arrayish/package.json"
              }
            ],
            "concludedValue": "node_modules/is-arrayish/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "inherits",
      "version": "2.0.4",
      "description": "Browser-friendly inheritance fully compatible with standard node.js inherits()",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/inherits@2.0.4",
      "type": "library",
      "bom-ref": "pkg:npm/inherits@2.0.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/inherits/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/inherits/package.json"
              }
            ],
            "concludedValue": "node_modules/inherits/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "inflight",
      "version": "1.0.6",
      "description": "Add callbacks to requests in flight to avoid async duplication",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/inflight@1.0.6",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/inflight"
        },
        {
          "type": "vcs",
          "url": "https://github.com/npm/inflight.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/inflight@1.0.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/inflight/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/inflight/package.json"
              }
            ],
            "concludedValue": "node_modules/inflight/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "indent-string",
      "version": "4.0.0",
      "description": "Indent each line in a string",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/indent-string@4.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/indent-string@4.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/indent-string/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/indent-string/package.json"
              }
            ],
            "concludedValue": "node_modules/indent-string/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "import-fresh",
      "version": "3.3.1",
      "description": "Import a module while bypassing the cache",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/import-fresh@3.3.1",
      "type": "library",
      "bom-ref": "pkg:npm/import-fresh@3.3.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/import-fresh/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/import-fresh/package.json"
              }
            ],
            "concludedValue": "node_modules/import-fresh/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Typicode <typicode@gmail.com>"
        }
      ],
      "group": "",
      "name": "husky",
      "version": "6.0.0",
      "description": "Modern native Git hooks made easy",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/husky@6.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://typicode.github.io/husky"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/husky@6.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/husky/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/husky/package.json"
              }
            ],
            "concludedValue": "node_modules/husky/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "ehmicky <ehmicky@gmail.com> (https://github.com/ehmicky)"
        }
      ],
      "group": "",
      "name": "human-signals",
      "version": "1.1.1",
      "description": "Human-friendly process signals",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0",
            "url": "https://opensource.org/licenses/Apache-2.0"
          }
        }
      ],
      "purl": "pkg:npm/human-signals@1.1.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://git.io/JeluP"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/human-signals@1.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/human-signals/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/human-signals/package.json"
              }
            ],
            "concludedValue": "node_modules/human-signals/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Nathan Rajlich <nathan@tootallnate.net> (http://n8.io/)"
        }
      ],
      "group": "",
      "name": "https-proxy-agent",
      "version": "5.0.0",
      "description": "An HTTP(s) proxy `http.Agent` implementation for HTTPS",
      "scope": "required",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/https-proxy-agent@5.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/TooTallNate/node-https-proxy-agent.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/https-proxy-agent@5.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/https-proxy-agent/package.json"
        },
        {
          "name": "ImportedModules",
          "value": "https-proxy-agent"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/https-proxy-agent/package.json"
              }
            ],
            "concludedValue": "node_modules/https-proxy-agent/package.json"
          }
        ],
        "occurrences": [
          {
            "location": "src/utils.js#7"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Andrea Giammarchi"
        }
      ],
      "group": "",
      "name": "html-escaper",
      "version": "2.0.2",
      "description": "fast and safe way to escape and unescape &<>'\" chars",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/html-escaper@2.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/WebReflection/html-escaper"
        },
        {
          "type": "vcs",
          "url": "https://github.com/WebReflection/html-escaper.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/html-escaper@2.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/html-escaper/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/html-escaper/package.json"
              }
            ],
            "concludedValue": "node_modules/html-escaper/package.json"
          }
        ]
      },
      "tags": [
        "escape",
        "unescape"
      ]
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "home-or-tmp",
      "version": "3.0.0",
      "description": "Get the user home directory with fallback to the system temp directory",
      "scope": "required",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/home-or-tmp@3.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/home-or-tmp@3.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/home-or-tmp/package.json"
        },
        {
          "name": "ImportedModules",
          "value": "home-or-tmp"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/home-or-tmp/package.json"
              }
            ],
            "concludedValue": "node_modules/home-or-tmp/package.json"
          }
        ],
        "occurrences": [
          {
            "location": "src/utils.js#3"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jordan Harband <ljharb@gmail.com>"
        }
      ],
      "group": "",
      "name": "hasown",
      "version": "2.0.3",
      "description": "A robust, ES3 compatible, \"has own property\" predicate.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/hasown@2.0.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/inspect-js/hasOwn#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/inspect-js/hasOwn.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/hasown@2.0.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/hasown/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/hasown/package.json"
              }
            ],
            "concludedValue": "node_modules/hasown/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jordan Harband <ljharb@gmail.com> (http://ljharb.codes)"
        }
      ],
      "group": "",
      "name": "has-tostringtag",
      "version": "1.0.2",
      "description": "Determine if the JS environment has `Symbol.toStringTag` support. Supports spec, or shams.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/has-tostringtag@1.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/inspect-js/has-tostringtag#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/inspect-js/has-tostringtag.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/has-tostringtag@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/has-tostringtag/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/has-tostringtag/package.json"
              }
            ],
            "concludedValue": "node_modules/has-tostringtag/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jordan Harband <ljharb@gmail.com> (http://ljharb.codes)"
        }
      ],
      "group": "",
      "name": "has-symbols",
      "version": "1.1.0",
      "description": "Determine if the JS environment has Symbol support. Supports spec, or shams.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/has-symbols@1.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/ljharb/has-symbols#readme"
        },
        {
          "type": "vcs",
          "url": "git://github.com/inspect-js/has-symbols.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/has-symbols@1.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/has-symbols/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/has-symbols/package.json"
              }
            ],
            "concludedValue": "node_modules/has-symbols/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "has-flag",
      "version": "4.0.0",
      "description": "Check if argv has a specific flag",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/has-flag@4.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/has-flag@4.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/has-flag/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/has-flag/package.json"
              }
            ],
            "concludedValue": "node_modules/has-flag/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "graceful-fs",
      "version": "4.2.11",
      "description": "A drop-in replacement for fs, making various improvements.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/graceful-fs@4.2.11",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/node-graceful-fs"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/graceful-fs@4.2.11",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/graceful-fs/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/graceful-fs/package.json"
              }
            ],
            "concludedValue": "node_modules/graceful-fs/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jordan Harband <ljharb@gmail.com>"
        }
      ],
      "group": "",
      "name": "gopd",
      "version": "1.2.0",
      "description": "`Object.getOwnPropertyDescriptor`, but accounts for IE's broken implementation.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/gopd@1.2.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/ljharb/gopd#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/ljharb/gopd.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/gopd@1.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/gopd/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/gopd/package.json"
              }
            ],
            "concludedValue": "node_modules/gopd/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Terkel Gjervig"
        }
      ],
      "group": "",
      "name": "globrex",
      "version": "0.1.2",
      "description": "Glob to regular expression with support for extended globs",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/globrex@0.1.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/terkelg/globrex"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/globrex@0.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/globrex/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/globrex/package.json"
              }
            ],
            "concludedValue": "node_modules/globrex/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Terkel Gjervig"
        }
      ],
      "group": "",
      "name": "globalyzer",
      "version": "0.1.0",
      "description": "Detects and extract the glob part of a string",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/globalyzer@0.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/terkelg/globalyzer"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/globalyzer@0.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/globalyzer/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/globalyzer/package.json"
              }
            ],
            "concludedValue": "node_modules/globalyzer/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Gulp Team <team@gulpjs.com> (https://gulpjs.com/)"
        }
      ],
      "group": "",
      "name": "glob-parent",
      "version": "5.1.2",
      "description": "Extract the non-magic parent path from a glob string.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/glob-parent@5.1.2",
      "type": "library",
      "bom-ref": "pkg:npm/glob-parent@5.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/glob-parent/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/glob-parent/package.json"
              }
            ],
            "concludedValue": "node_modules/glob-parent/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "glob",
      "version": "7.2.3",
      "description": "a little globber",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/glob@7.2.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/node-glob.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/glob@7.2.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/glob/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/glob/package.json"
              }
            ],
            "concludedValue": "node_modules/glob/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Hiroki Osame <hiroki.osame@gmail.com>"
        }
      ],
      "group": "",
      "name": "get-tsconfig",
      "version": "4.14.0",
      "description": "Find and parse the tsconfig.json file from a directory path",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/get-tsconfig@4.14.0",
      "type": "library",
      "bom-ref": "pkg:npm/get-tsconfig@4.14.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/get-tsconfig/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/get-tsconfig/package.json"
              }
            ],
            "concludedValue": "node_modules/get-tsconfig/package.json"
          }
        ]
      },
      "tags": [
        "parse"
      ]
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "get-stream",
      "version": "5.2.0",
      "description": "Get a stream as a string, buffer, or array",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/get-stream@5.2.0",
      "type": "library",
      "bom-ref": "pkg:npm/get-stream@5.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/get-stream/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/get-stream/package.json"
              }
            ],
            "concludedValue": "node_modules/get-stream/package.json"
          }
        ]
      },
      "tags": [
        "stream"
      ]
    },
    {
      "authors": [
        {
          "name": "Jordan Harband <ljharb@gmail.com>"
        }
      ],
      "group": "",
      "name": "get-proto",
      "version": "1.0.1",
      "description": "Robustly get the [[Prototype]] of an object",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/get-proto@1.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/ljharb/get-proto#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/ljharb/get-proto.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/get-proto@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/get-proto/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/get-proto/package.json"
              }
            ],
            "concludedValue": "node_modules/get-proto/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Shahar Or <mightyiampresence@gmail.com> (mightyiam)"
        }
      ],
      "group": "",
      "name": "get-own-enumerable-property-symbols",
      "version": "3.0.2",
      "description": "Returns an array of all enumerable symbol properties found directly upon a given object",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/get-own-enumerable-property-symbols@3.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mightyiam/get-own-enumerable-property-symbols#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/mightyiam/get-own-enumerable-property-symbols.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/get-own-enumerable-property-symbols@3.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/get-own-enumerable-property-symbols/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/get-own-enumerable-property-symbols/package.json"
              }
            ],
            "concludedValue": "node_modules/get-own-enumerable-property-symbols/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jordan Harband <ljharb@gmail.com>"
        }
      ],
      "group": "",
      "name": "get-intrinsic",
      "version": "1.3.0",
      "description": "Get and robustly cache all JS language-level intrinsics at first require time",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/get-intrinsic@1.3.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/ljharb/get-intrinsic#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/ljharb/get-intrinsic.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/get-intrinsic@1.3.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/get-intrinsic/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/get-intrinsic/package.json"
              }
            ],
            "concludedValue": "node_modules/get-intrinsic/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Nicolas Bevacqua <ng@bevacqua.io> (http://bevacqua.io)"
        }
      ],
      "group": "",
      "name": "fuzzysearch",
      "version": "1.0.3",
      "description": "Tiny and blazing-fast fuzzy search in JavaScript",
      "scope": "required",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/fuzzysearch@1.0.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/bevacqua/fuzzysearch"
        },
        {
          "type": "vcs",
          "url": "git://github.com/bevacqua/fuzzysearch.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/fuzzysearch@1.0.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/fuzzysearch/package.json"
        },
        {
          "name": "ImportedModules",
          "value": "fuzzysearch"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/fuzzysearch/package.json"
              }
            ],
            "concludedValue": "node_modules/fuzzysearch/package.json"
          }
        ],
        "occurrences": [
          {
            "location": "src/bin.js#6"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Raynos <raynos2@gmail.com>"
        }
      ],
      "group": "",
      "name": "function-bind",
      "version": "1.1.2",
      "description": "Implementation of Function.prototype.bind",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/function-bind@1.1.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/Raynos/function-bind"
        },
        {
          "type": "vcs",
          "url": "https://github.com/Raynos/function-bind.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/function-bind@1.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/function-bind/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/function-bind/package.json"
              }
            ],
            "concludedValue": "node_modules/function-bind/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "fs.realpath",
      "version": "1.0.0",
      "description": "Use node's fs.realpath, but fall back to the JS implementation if the native one fails",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/fs.realpath@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git+https://github.com/isaacs/fs.realpath.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/fs.realpath@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/fs.realpath/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/fs.realpath/package.json"
              }
            ],
            "concludedValue": "node_modules/fs.realpath/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "fs-minipass",
      "version": "2.1.0",
      "description": "fs read and write streams based on minipass",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/fs-minipass@2.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/npm/fs-minipass#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/npm/fs-minipass.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/fs-minipass@2.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/fs-minipass/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/fs-minipass/package.json"
              }
            ],
            "concludedValue": "node_modules/fs-minipass/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "JP Richardson <jprichardson@gmail.com>"
        }
      ],
      "group": "",
      "name": "fs-extra",
      "version": "11.3.4",
      "description": "fs-extra contains methods that aren't included in the vanilla Node.js fs package. Such as recursive mkdir, copy, and remove.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/fs-extra@11.3.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jprichardson/node-fs-extra"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/jprichardson/node-fs-extra.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/fs-extra@11.3.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/fs-extra/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/fs-extra/package.json"
              }
            ],
            "concludedValue": "node_modules/fs-extra/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Josh Goldberg ✨ <npm@joshuakgoldberg.com>"
        }
      ],
      "group": "",
      "name": "formatly",
      "version": "0.3.0",
      "description": "Formats your code with whatever formatter your project is already using. 🧼",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/formatly@0.3.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git+https://github.com/JoshuaKGoldberg/formatly.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/formatly@0.3.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/formatly/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/formatly/package.json"
              }
            ],
            "concludedValue": "node_modules/formatly/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jon Schlinkert (https://github.com/jonschlinkert)"
        }
      ],
      "group": "",
      "name": "fill-range",
      "version": "7.1.1",
      "description": "Fill in a range of numbers or letters, optionally passing an increment or `step` to use, or create a regex-compatible range with `options.toRegex`",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/fill-range@7.1.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jonschlinkert/fill-range"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/fill-range@7.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/fill-range/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/fill-range/package.json"
              }
            ],
            "concludedValue": "node_modules/fill-range/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "thecodrr <thecodrr@protonmail.com>"
        }
      ],
      "group": "",
      "name": "fdir",
      "version": "6.5.0",
      "description": "The fastest directory crawler & globbing alternative to glob, fast-glob, & tiny-glob. Crawls 1m files in < 1s",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/fdir@6.5.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/thecodrr/fdir#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/thecodrr/fdir.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/fdir@6.5.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/fdir/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/fdir/package.json"
              }
            ],
            "concludedValue": "node_modules/fdir/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Garbutt (https://github.com/43081j)"
        }
      ],
      "group": "",
      "name": "fd-package-json",
      "version": "2.0.0",
      "description": "Utilities for finding the closest package.json file",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/fd-package-json@2.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/es-tooling/fd-package-json#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/es-tooling/fd-package-json.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/fd-package-json@2.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/fd-package-json/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/fd-package-json/package.json"
              }
            ],
            "concludedValue": "node_modules/fd-package-json/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Matteo Collina <hello@matteocollina.com>"
        }
      ],
      "group": "",
      "name": "fastq",
      "version": "1.20.1",
      "description": "Fast, in memory work queue",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/fastq@1.20.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mcollina/fastq#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/mcollina/fastq.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/fastq@1.20.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/fastq/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/fastq/package.json"
              }
            ],
            "concludedValue": "node_modules/fastq/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Denis Malinochkin (https://mrmlnc.com)"
        }
      ],
      "group": "",
      "name": "fast-glob",
      "version": "3.3.3",
      "description": "It's a very fast and efficient glob library for Node.js",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/fast-glob@3.3.3",
      "type": "library",
      "bom-ref": "pkg:npm/fast-glob@3.3.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/fast-glob/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/fast-glob/package.json"
              }
            ],
            "concludedValue": "node_modules/fast-glob/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "expect-type",
      "version": "1.3.0",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0",
            "url": "https://opensource.org/licenses/Apache-2.0"
          }
        }
      ],
      "purl": "pkg:npm/expect-type@1.3.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mmkal/expect-type#readme"
        },
        {
          "type": "vcs",
          "url": "https://github.com/mmkal/expect-type.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/expect-type@1.3.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/expect-type/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/expect-type/package.json"
              }
            ],
            "concludedValue": "node_modules/expect-type/package.json"
          }
        ]
      },
      "tags": [
        "test"
      ]
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "execa",
      "version": "4.1.0",
      "description": "Process execution for humans",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/execa@4.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/execa@4.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/execa/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/execa/package.json"
              }
            ],
            "concludedValue": "node_modules/execa/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Arnout Kazemier"
        }
      ],
      "group": "",
      "name": "eventemitter3",
      "version": "5.0.4",
      "description": "EventEmitter3 focuses on performance while maintaining a Node.js AND browser compatible interface.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/eventemitter3@5.0.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/primus/eventemitter3.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/eventemitter3@5.0.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/eventemitter3/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/eventemitter3/package.json"
              }
            ],
            "concludedValue": "node_modules/eventemitter3/package.json"
          }
        ]
      },
      "tags": [
        "performance"
      ]
    },
    {
      "authors": [
        {
          "name": "Rich Harris"
        }
      ],
      "group": "",
      "name": "estree-walker",
      "version": "2.0.2",
      "description": "Traverse an ESTree-compliant AST",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/estree-walker@2.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/Rich-Harris/estree-walker"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/estree-walker@2.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/estree-walker/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/estree-walker/package.json"
              }
            ],
            "concludedValue": "node_modules/estree-walker/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Node Security Project"
        }
      ],
      "group": "",
      "name": "eslint-plugin-security",
      "version": "4.0.0",
      "description": "Security rules for eslint",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0",
            "url": "https://opensource.org/licenses/Apache-2.0"
          }
        }
      ],
      "purl": "pkg:npm/eslint-plugin-security@4.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/eslint-community/eslint-plugin-security#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/eslint-community/eslint-plugin-security.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/eslint-plugin-security@4.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/eslint-plugin-security/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/eslint-plugin-security/package.json"
              }
            ],
            "concludedValue": "node_modules/eslint-plugin-security/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "escape-string-regexp",
      "version": "1.0.5",
      "description": "Escape RegExp special characters",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/escape-string-regexp@1.0.5",
      "type": "library",
      "bom-ref": "pkg:npm/escape-string-regexp@1.0.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/escape-string-regexp/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/escape-string-regexp/package.json"
              }
            ],
            "concludedValue": "node_modules/escape-string-regexp/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jordan Harband <ljharb@gmail.com>"
        }
      ],
      "group": "",
      "name": "es-object-atoms",
      "version": "1.1.1",
      "description": "ES Object-related atoms: Object, ToObject, RequireObjectCoercible",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/es-object-atoms@1.1.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/ljharb/es-object-atoms#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/ljharb/es-object-atoms.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/es-object-atoms@1.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/es-object-atoms/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/es-object-atoms/package.json"
              }
            ],
            "concludedValue": "node_modules/es-object-atoms/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Guy Bedford"
        }
      ],
      "group": "",
      "name": "es-module-lexer",
      "version": "2.1.0",
      "description": "Lexes ES modules returning their import/export metadata",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/es-module-lexer@2.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/guybedford/es-module-lexer#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/guybedford/es-module-lexer.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/es-module-lexer@2.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/es-module-lexer/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/es-module-lexer/package.json"
              }
            ],
            "concludedValue": "node_modules/es-module-lexer/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jordan Harband <ljharb@gmail.com>"
        }
      ],
      "group": "",
      "name": "es-errors",
      "version": "1.3.0",
      "description": "A simple cache for a few of the JS Error constructors.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/es-errors@1.3.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/ljharb/es-errors#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/ljharb/es-errors.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/es-errors@1.3.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/es-errors/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/es-errors/package.json"
              }
            ],
            "concludedValue": "node_modules/es-errors/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jordan Harband <ljharb@gmail.com>"
        }
      ],
      "group": "",
      "name": "es-define-property",
      "version": "1.0.1",
      "description": "`Object.defineProperty`, but not IE 8's broken one.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/es-define-property@1.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/ljharb/es-define-property#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/ljharb/es-define-property.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/es-define-property@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/es-define-property/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/es-define-property/package.json"
              }
            ],
            "concludedValue": "node_modules/es-define-property/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "error-ex",
      "version": "1.3.4",
      "description": "Easy error subclassing and stack customization",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/error-ex@1.3.4",
      "type": "library",
      "bom-ref": "pkg:npm/error-ex@1.3.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/error-ex/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/error-ex/package.json"
              }
            ],
            "concludedValue": "node_modules/error-ex/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jon Schlinkert (https://github.com/jonschlinkert)"
        }
      ],
      "group": "",
      "name": "enquirer",
      "version": "2.3.6",
      "description": "Stylish, intuitive and user-friendly prompt system. Fast and lightweight enough for small projects, powerful and extensible enough for the most advanced use cases.",
      "scope": "required",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/enquirer@2.3.6",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/enquirer/enquirer"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/enquirer@2.3.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/enquirer/package.json"
        },
        {
          "name": "ImportedModules",
          "value": "enquirer"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/enquirer/package.json"
              }
            ],
            "concludedValue": "node_modules/enquirer/package.json"
          }
        ],
        "occurrences": [
          {
            "location": "src/bin.js#7"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mathias Buus <mathiasbuus@gmail.com>"
        }
      ],
      "group": "",
      "name": "end-of-stream",
      "version": "1.4.5",
      "description": "Call a callback when a readable/writable/duplex stream has completed or failed.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/end-of-stream@1.4.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mafintosh/end-of-stream"
        },
        {
          "type": "vcs",
          "url": "git://github.com/mafintosh/end-of-stream.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/end-of-stream@1.4.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/end-of-stream/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/end-of-stream/package.json"
              }
            ],
            "concludedValue": "node_modules/end-of-stream/package.json"
          }
        ]
      },
      "tags": [
        "stream"
      ]
    },
    {
      "authors": [
        {
          "name": "Mathias Bynens (https://mathiasbynens.be/)"
        }
      ],
      "group": "",
      "name": "emoji-regex",
      "version": "8.0.0",
      "description": "A regular expression to match all Emoji-only symbols as per the Unicode Standard.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/emoji-regex@8.0.0",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://mths.be/emoji-regex"
        },
        {
          "type": "vcs",
          "url": "https://github.com/mathiasbynens/emoji-regex.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/emoji-regex@8.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/emoji-regex/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/emoji-regex/package.json"
              }
            ],
            "concludedValue": "node_modules/emoji-regex/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jordan Harband <ljharb@gmail.com>"
        }
      ],
      "group": "",
      "name": "dunder-proto",
      "version": "1.0.1",
      "description": "If available, the `Object.prototype.__proto__` accessor and mutator, call-bound",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/dunder-proto@1.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/es-shims/dunder-proto#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/es-shims/dunder-proto.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/dunder-proto@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/dunder-proto/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/dunder-proto/package.json"
              }
            ],
            "concludedValue": "node_modules/dunder-proto/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "ForbesLindesay"
        }
      ],
      "group": "",
      "name": "doctypes",
      "version": "1.1.0",
      "description": "Shorthands for commonly used doctypes",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/doctypes@1.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/pugjs/doctypes.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/doctypes@1.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/doctypes/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/doctypes/package.json"
              }
            ],
            "concludedValue": "node_modules/doctypes/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Lovell Fuller <npm@lovell.info>"
        }
      ],
      "group": "",
      "name": "detect-libc",
      "version": "2.1.2",
      "description": "Node.js module to detect the C standard library (libc) implementation family and version",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0",
            "url": "https://opensource.org/licenses/Apache-2.0"
          }
        }
      ],
      "purl": "pkg:npm/detect-libc@2.1.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/lovell/detect-libc.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/detect-libc@2.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/detect-libc/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/detect-libc/package.json"
              }
            ],
            "concludedValue": "node_modules/detect-libc/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "deepmerge",
      "version": "4.3.1",
      "description": "A library for deep (recursive) merging of Javascript objects",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/deepmerge@4.3.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/TehShrike/deepmerge"
        },
        {
          "type": "vcs",
          "url": "git://github.com/TehShrike/deepmerge.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/deepmerge@4.3.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/deepmerge/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/deepmerge/package.json"
              }
            ],
            "concludedValue": "node_modules/deepmerge/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Desmond Brand <dmnd@desmondbrand.com> (http://desmondbrand.com)"
        }
      ],
      "group": "",
      "name": "dedent",
      "version": "0.7.0",
      "description": "An ES6 string tag that strips indentation from multi-line strings",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/dedent@0.7.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/dmnd/dedent"
        },
        {
          "type": "vcs",
          "url": "git://github.com/dmnd/dedent.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/dedent@0.7.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/dedent/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/dedent/package.json"
              }
            ],
            "concludedValue": "node_modules/dedent/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Josh Junon (https://github.com/qix-)"
        }
      ],
      "group": "",
      "name": "debug",
      "version": "4.4.3",
      "description": "Lightweight debugging utility for Node.js and the browser",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/debug@4.4.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/debug-js/debug.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/debug@4.4.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/debug/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/debug/package.json"
              }
            ],
            "concludedValue": "node_modules/debug/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "André Cruz <andre@moxy.studio>"
        }
      ],
      "group": "",
      "name": "cross-spawn",
      "version": "7.0.6",
      "description": "Cross platform child_process#spawn and child_process#spawnSync",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/cross-spawn@7.0.6",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/moxystudio/node-cross-spawn"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/cross-spawn@7.0.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/cross-spawn/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/cross-spawn/package.json"
              }
            ],
            "concludedValue": "node_modules/cross-spawn/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "David Clark <david.dave.clark@gmail.com>"
        }
      ],
      "group": "",
      "name": "cosmiconfig",
      "version": "7.1.0",
      "description": "Find and load configuration from a package.json property, rc file, or CommonJS module",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/cosmiconfig@7.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/davidtheclark/cosmiconfig#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/davidtheclark/cosmiconfig.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/cosmiconfig@7.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/cosmiconfig/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/cosmiconfig/package.json"
              }
            ],
            "concludedValue": "node_modules/cosmiconfig/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Eemeli Aro <eemeli@gmail.com>"
        }
      ],
      "group": "",
      "name": "yaml",
      "version": "1.10.3",
      "description": "JavaScript parser and stringifier for YAML",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/yaml@1.10.3",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://eemeli.org/yaml/v1/"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/yaml@1.10.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/cosmiconfig/node_modules/yaml/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/cosmiconfig/node_modules/yaml/package.json"
              }
            ],
            "concludedValue": "node_modules/cosmiconfig/node_modules/yaml/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Thorsten Lorenz <thlorenz@gmx.de> (http://thlorenz.com)"
        }
      ],
      "group": "",
      "name": "convert-source-map",
      "version": "2.0.0",
      "description": "Converts a source-map from/to  different formats and allows adding/changing properties.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/convert-source-map@2.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/thlorenz/convert-source-map"
        },
        {
          "type": "vcs",
          "url": "git://github.com/thlorenz/convert-source-map.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/convert-source-map@2.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/convert-source-map/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/convert-source-map/package.json"
              }
            ],
            "concludedValue": "node_modules/convert-source-map/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "ForbesLindesay"
        }
      ],
      "group": "",
      "name": "constantinople",
      "version": "4.0.1",
      "description": "Determine whether a JavaScript expression evaluates to a constant",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/constantinople@4.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/ForbesLindesay/constantinople.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/constantinople@4.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/constantinople/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/constantinople/package.json"
              }
            ],
            "concludedValue": "node_modules/constantinople/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "concat-map",
      "version": "0.0.1",
      "description": "concatenative mapdashery",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/concat-map@0.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/substack/node-concat-map.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/concat-map@0.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/concat-map/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/concat-map/package.json"
              }
            ],
            "concludedValue": "node_modules/concat-map/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "commondir",
      "version": "1.0.1",
      "description": "compute the closest common parent for file paths",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/commondir@1.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/substack/node-commondir.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/commondir@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/commondir/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/commondir/package.json"
              }
            ],
            "concludedValue": "node_modules/commondir/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "TJ Holowaychuk <tj@vision-media.ca>"
        }
      ],
      "group": "",
      "name": "commander",
      "version": "5.1.0",
      "description": "the complete solution for node.js command-line programs",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/commander@5.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/tj/commander.js.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/commander@5.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/commander/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/commander/package.json"
              }
            ],
            "concludedValue": "node_modules/commander/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Marak Squires"
        }
      ],
      "group": "",
      "name": "colors",
      "version": "1.4.0",
      "description": "get colors in your node.js console",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/colors@1.4.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/Marak/colors.js"
        },
        {
          "type": "vcs",
          "url": "http://github.com/Marak/colors.js.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/colors@1.4.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/colors/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/colors/package.json"
              }
            ],
            "concludedValue": "node_modules/colors/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jorge Bucaran"
        }
      ],
      "group": "",
      "name": "colorette",
      "version": "2.0.20",
      "description": "🌈Easily set your terminal text color & styles.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/colorette@2.0.20",
      "type": "library",
      "bom-ref": "pkg:npm/colorette@2.0.20",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/colorette/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/colorette/package.json"
              }
            ],
            "concludedValue": "node_modules/colorette/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "DY <dfcreative@gmail.com>"
        }
      ],
      "group": "",
      "name": "color-name",
      "version": "1.1.4",
      "description": "A list of color names and its values",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/color-name@1.1.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/colorjs/color-name"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/color-name@1.1.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/color-name/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/color-name/package.json"
              }
            ],
            "concludedValue": "node_modules/color-name/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Heather Arthur <fayearthur@gmail.com>"
        }
      ],
      "group": "",
      "name": "color-convert",
      "version": "2.0.1",
      "description": "Plain color conversion functions",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/color-convert@2.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/color-convert@2.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/color-convert/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/color-convert/package.json"
              }
            ],
            "concludedValue": "node_modules/color-convert/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "cli-truncate",
      "version": "2.1.0",
      "description": "Truncate a string to a specific width in the terminal",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/cli-truncate@2.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/cli-truncate@2.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/cli-truncate/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/cli-truncate/package.json"
              }
            ],
            "concludedValue": "node_modules/cli-truncate/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Talmage"
        }
      ],
      "group": "",
      "name": "cli-table3",
      "version": "0.6.5",
      "description": "Pretty unicode tables for the command line. Based on the original cli-table.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/cli-table3@0.6.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/cli-table/cli-table3"
        },
        {
          "type": "vcs",
          "url": "https://github.com/cli-table/cli-table3.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/cli-table3@0.6.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/cli-table3/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/cli-table3/package.json"
              }
            ],
            "concludedValue": "node_modules/cli-table3/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "cli-cursor",
      "version": "3.1.0",
      "description": "Toggle the CLI cursor",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/cli-cursor@3.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/cli-cursor@3.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/cli-cursor/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/cli-cursor/package.json"
              }
            ],
            "concludedValue": "node_modules/cli-cursor/package.json"
          }
        ]
      },
      "tags": [
        "cli"
      ]
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "clean-stack",
      "version": "2.2.0",
      "description": "Clean up error stack traces",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/clean-stack@2.2.0",
      "type": "library",
      "bom-ref": "pkg:npm/clean-stack@2.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/clean-stack/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/clean-stack/package.json"
              }
            ],
            "concludedValue": "node_modules/clean-stack/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "chownr",
      "version": "2.0.0",
      "description": "like `chown -R`",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/chownr@2.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/chownr.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/chownr@2.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/chownr/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/chownr/package.json"
              }
            ],
            "concludedValue": "node_modules/chownr/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "ForbesLindesay"
        }
      ],
      "group": "",
      "name": "character-parser",
      "version": "2.2.0",
      "description": "Parse JavaScript one character at a time to look for snippets in Templates.  This is not a validator, it's just designed to allow you to have sections of JavaScript delimited by brackets robustly.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/character-parser@2.2.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/ForbesLindesay/character-parser.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/character-parser@2.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/character-parser/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/character-parser/package.json"
              }
            ],
            "concludedValue": "node_modules/character-parser/package.json"
          }
        ]
      },
      "tags": [
        "parse",
        "templates"
      ]
    },
    {
      "group": "",
      "name": "chalk",
      "version": "4.1.0",
      "description": "Terminal string styling done right",
      "scope": "required",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/chalk@4.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/chalk@4.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/chalk/package.json"
        },
        {
          "name": "ImportedModules",
          "value": "chalk"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/chalk/package.json"
              }
            ],
            "concludedValue": "node_modules/chalk/package.json"
          }
        ],
        "occurrences": [
          {
            "location": "src/bin.js#3"
          },
          {
            "location": "src/index.js#5"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jake Luer <jake@alogicalparadox.com>"
        }
      ],
      "group": "",
      "name": "chai",
      "version": "6.2.2",
      "description": "BDD/TDD assertion library for node.js and the browser. Test framework agnostic.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/chai@6.2.2",
      "externalReferences": [
        {
          "type": "website",
          "url": "http://chaijs.com"
        },
        {
          "type": "vcs",
          "url": "https://github.com/chaijs/chai"
        }
      ],
      "type": "framework",
      "bom-ref": "pkg:npm/chai@6.2.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/chai/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/chai/package.json"
              }
            ],
            "concludedValue": "node_modules/chai/package.json"
          }
        ]
      },
      "tags": [
        "framework",
        "test"
      ]
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "callsites",
      "version": "3.1.0",
      "description": "Get callsites from the V8 stack trace API",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/callsites@3.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/callsites@3.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/callsites/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/callsites/package.json"
              }
            ],
            "concludedValue": "node_modules/callsites/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jordan Harband <ljharb@gmail.com>"
        }
      ],
      "group": "",
      "name": "call-bound",
      "version": "1.0.4",
      "description": "Robust call-bound JavaScript intrinsics, using `call-bind` and `get-intrinsic`.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/call-bound@1.0.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/ljharb/call-bound#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/ljharb/call-bound.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/call-bound@1.0.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/call-bound/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/call-bound/package.json"
              }
            ],
            "concludedValue": "node_modules/call-bound/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jordan Harband <ljharb@gmail.com>"
        }
      ],
      "group": "",
      "name": "call-bind-apply-helpers",
      "version": "1.0.2",
      "description": "Helper functions around Function call/apply/bind, for use in `call-bind`",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/call-bind-apply-helpers@1.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/ljharb/call-bind-apply-helpers#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/ljharb/call-bind-apply-helpers.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/call-bind-apply-helpers@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/call-bind-apply-helpers/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/call-bind-apply-helpers/package.json"
              }
            ],
            "concludedValue": "node_modules/call-bind-apply-helpers/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "TJ Holowaychuk <tj@vision-media.ca> (http://tjholowaychuk.com)"
        }
      ],
      "group": "",
      "name": "bytes",
      "version": "3.1.2",
      "description": "Utility to parse a string bytes to bytes and vice-versa",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/bytes@3.1.2",
      "type": "library",
      "bom-ref": "pkg:npm/bytes@3.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/bytes/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/bytes/package.json"
              }
            ],
            "concludedValue": "node_modules/bytes/package.json"
          }
        ]
      },
      "tags": [
        "parse"
      ]
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "builtin-modules",
      "version": "3.3.0",
      "description": "List of the Node.js builtin modules",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/builtin-modules@3.3.0",
      "type": "library",
      "bom-ref": "pkg:npm/builtin-modules@3.3.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/builtin-modules/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/builtin-modules/package.json"
              }
            ],
            "concludedValue": "node_modules/builtin-modules/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "buffer-from",
      "version": "1.1.2",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/buffer-from@1.1.2",
      "type": "library",
      "bom-ref": "pkg:npm/buffer-from@1.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/buffer-from/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/buffer-from/package.json"
              }
            ],
            "concludedValue": "node_modules/buffer-from/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jon Schlinkert (https://github.com/jonschlinkert)"
        }
      ],
      "group": "",
      "name": "braces",
      "version": "3.0.3",
      "description": "Bash-like brace expansion, implemented in JavaScript. Safer than other brace expansion libs, with complete support for the Bash 4.3 braces specification, without sacrificing speed.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/braces@3.0.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/micromatch/braces"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/braces@3.0.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/braces/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/braces/package.json"
              }
            ],
            "concludedValue": "node_modules/braces/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Julian Gruber <mail@juliangruber.com> (http://juliangruber.com)"
        }
      ],
      "group": "",
      "name": "brace-expansion",
      "version": "1.1.14",
      "description": "Brace expansion as known from sh/bash",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/brace-expansion@1.1.14",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/juliangruber/brace-expansion"
        },
        {
          "type": "vcs",
          "url": "git://github.com/juliangruber/brace-expansion.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/brace-expansion@1.1.14",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/brace-expansion/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/brace-expansion/package.json"
              }
            ],
            "concludedValue": "node_modules/brace-expansion/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "blamer",
      "version": "1.0.7",
      "description": "blamer is a tool for getting information about author of code from version control system",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/blamer@1.0.7",
      "type": "library",
      "bom-ref": "pkg:npm/blamer@1.0.7",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/blamer/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/blamer/package.json"
              }
            ],
            "concludedValue": "node_modules/blamer/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Julian Gruber <mail@juliangruber.com> (http://juliangruber.com)"
        }
      ],
      "group": "",
      "name": "balanced-match",
      "version": "1.0.2",
      "description": "Match balanced character pairs, like \"{\" and \"}\"",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/balanced-match@1.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/juliangruber/balanced-match"
        },
        {
          "type": "vcs",
          "url": "git://github.com/juliangruber/balanced-match.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/balanced-match@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/balanced-match/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/balanced-match/package.json"
              }
            ],
            "concludedValue": "node_modules/balanced-match/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Amio <amio.cn@gmail.com>"
        }
      ],
      "group": "",
      "name": "badgen",
      "version": "3.2.3",
      "description": "Fast svg badge generator.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/badgen@3.2.3",
      "type": "library",
      "bom-ref": "pkg:npm/badgen@3.2.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/badgen/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/badgen/package.json"
              }
            ],
            "concludedValue": "node_modules/badgen/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Timothy Gu <timothygu99@gmail.com>"
        }
      ],
      "group": "",
      "name": "babel-walk",
      "version": "3.0.0-canary-5",
      "description": "Lightweight Babel AST traversal",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/babel-walk@3.0.0-canary-5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/pugjs/babel-walk.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/babel-walk@3.0.0-canary-5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/babel-walk/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/babel-walk/package.json"
              }
            ],
            "concludedValue": "node_modules/babel-walk/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Kevin Mårtensson <kevinmartensson@gmail.com> (github.com/kevva)"
        }
      ],
      "group": "",
      "name": "astral-regex",
      "version": "2.0.0",
      "description": "Regular expression for matching astral symbols",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/astral-regex@2.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/astral-regex@2.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/astral-regex/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/astral-regex/package.json"
              }
            ],
            "concludedValue": "node_modules/astral-regex/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Ari Perkkiö <ari.perkkio@gmail.com>"
        }
      ],
      "group": "",
      "name": "ast-v8-to-istanbul",
      "version": "1.0.0",
      "description": "AST-aware v8-to-istanbul",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/ast-v8-to-istanbul@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/AriPerkkio/ast-v8-to-istanbul"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/AriPerkkio/ast-v8-to-istanbul.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/ast-v8-to-istanbul@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/ast-v8-to-istanbul/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/ast-v8-to-istanbul/package.json"
              }
            ],
            "concludedValue": "node_modules/ast-v8-to-istanbul/package.json"
          }
        ]
      },
      "tags": [
        "test"
      ]
    },
    {
      "authors": [
        {
          "name": "Rich Harris"
        }
      ],
      "group": "",
      "name": "estree-walker",
      "version": "3.0.3",
      "description": "Traverse an ESTree-compliant AST",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/estree-walker@3.0.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/Rich-Harris/estree-walker"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/estree-walker@3.0.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/ast-v8-to-istanbul/node_modules/estree-walker/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/@vitest/mocker/node_modules/estree-walker/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/ast-v8-to-istanbul/node_modules/estree-walker/package.json"
              },
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@vitest/mocker/node_modules/estree-walker/package.json"
              }
            ]
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jake Luer <jake@qualiancy.com> (http://qualiancy.com)"
        }
      ],
      "group": "",
      "name": "assertion-error",
      "version": "2.0.1",
      "description": "Error constructor for test and validation frameworks that implements standardized AssertionError specification.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/assertion-error@2.0.1",
      "type": "framework",
      "bom-ref": "pkg:npm/assertion-error@2.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/assertion-error/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/assertion-error/package.json"
              }
            ],
            "concludedValue": "node_modules/assertion-error/package.json"
          }
        ]
      },
      "tags": [
        "framework",
        "test",
        "validation"
      ]
    },
    {
      "authors": [
        {
          "name": "Daniel Lytkin <dan.lytkin@gmail.com>"
        }
      ],
      "group": "",
      "name": "assert-never",
      "version": "1.4.0",
      "description": "Helper function for exhaustive checks of discriminated unions in TypeScript",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/assert-never@1.4.0",
      "type": "library",
      "bom-ref": "pkg:npm/assert-never@1.4.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/assert-never/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/assert-never/package.json"
              }
            ],
            "concludedValue": "node_modules/assert-never/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "asap",
      "version": "2.0.6",
      "description": "High-priority task queue for Node.js and browsers",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/asap@2.0.6",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/kriskowal/asap.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/asap@2.0.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/asap/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/asap/package.json"
              }
            ],
            "concludedValue": "node_modules/asap/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "ansi-styles",
      "version": "4.3.0",
      "description": "ANSI escape codes for styling strings in the terminal",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/ansi-styles@4.3.0",
      "type": "library",
      "bom-ref": "pkg:npm/ansi-styles@4.3.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/ansi-styles/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/ansi-styles/package.json"
              }
            ],
            "concludedValue": "node_modules/ansi-styles/package.json"
          }
        ]
      },
      "tags": [
        "escape"
      ]
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "ansi-regex",
      "version": "5.0.1",
      "description": "Regular expression for matching ANSI escape codes",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/ansi-regex@5.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/ansi-regex@5.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/ansi-regex/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/ansi-regex/package.json"
              }
            ],
            "concludedValue": "node_modules/ansi-regex/package.json"
          }
        ]
      },
      "tags": [
        "escape"
      ]
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "ansi-escapes",
      "version": "4.3.2",
      "description": "ANSI escape codes for manipulating the terminal",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/ansi-escapes@4.3.2",
      "type": "library",
      "bom-ref": "pkg:npm/ansi-escapes@4.3.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/ansi-escapes/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/ansi-escapes/package.json"
              }
            ],
            "concludedValue": "node_modules/ansi-escapes/package.json"
          }
        ]
      },
      "tags": [
        "escape"
      ]
    },
    {
      "authors": [
        {
          "name": "Brian Woodward (https://github.com/doowb)"
        }
      ],
      "group": "",
      "name": "ansi-colors",
      "version": "4.1.3",
      "description": "Easily add ANSI colors to your text and symbols in the terminal. A faster drop-in replacement for chalk, kleur and turbocolor (without the dependencies and rendering bugs).",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/ansi-colors@4.1.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/doowb/ansi-colors"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/ansi-colors@4.1.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/ansi-colors/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/ansi-colors/package.json"
              }
            ],
            "concludedValue": "node_modules/ansi-colors/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "aggregate-error",
      "version": "3.1.0",
      "description": "Create an error from multiple errors",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/aggregate-error@3.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/aggregate-error@3.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/aggregate-error/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/aggregate-error/package.json"
              }
            ],
            "concludedValue": "node_modules/aggregate-error/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Nathan Rajlich <nathan@tootallnate.net> (http://n8.io/)"
        }
      ],
      "group": "",
      "name": "agent-base",
      "version": "6.0.2",
      "description": "Turn a function into an `http.Agent` instance",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/agent-base@6.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/TooTallNate/node-agent-base.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/agent-base@6.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/agent-base/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/agent-base/package.json"
              }
            ],
            "concludedValue": "node_modules/agent-base/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "acorn",
      "version": "7.4.1",
      "description": "ECMAScript parser",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/acorn@7.4.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/acornjs/acorn"
        },
        {
          "type": "vcs",
          "url": "https://github.com/acornjs/acorn.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/acorn@7.4.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/acorn/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/acorn/package.json"
              }
            ],
            "concludedValue": "node_modules/acorn/package.json"
          }
        ]
      }
    },
    {
      "group": "@vitest",
      "name": "utils",
      "version": "4.1.5",
      "description": "Shared Vitest utility functions",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40vitest/utils@4.1.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/vitest-dev/vitest/tree/main/packages/utils"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/vitest-dev/vitest.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@vitest/utils@4.1.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@vitest/utils/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@vitest/utils/package.json"
              }
            ],
            "concludedValue": "node_modules/@vitest/utils/package.json"
          }
        ]
      }
    },
    {
      "group": "@vitest",
      "name": "spy",
      "version": "4.1.5",
      "description": "Lightweight Jest compatible spy implementation",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40vitest/spy@4.1.5",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://vitest.dev/api/mock"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/vitest-dev/vitest.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@vitest/spy@4.1.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@vitest/spy/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@vitest/spy/package.json"
              }
            ],
            "concludedValue": "node_modules/@vitest/spy/package.json"
          }
        ]
      }
    },
    {
      "group": "@vitest",
      "name": "snapshot",
      "version": "4.1.5",
      "description": "Vitest snapshot manager",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40vitest/snapshot@4.1.5",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://vitest.dev/guide/snapshot"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/vitest-dev/vitest.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@vitest/snapshot@4.1.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@vitest/snapshot/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@vitest/snapshot/package.json"
              }
            ],
            "concludedValue": "node_modules/@vitest/snapshot/package.json"
          }
        ]
      }
    },
    {
      "group": "@vitest",
      "name": "runner",
      "version": "4.1.5",
      "description": "Vitest test runner",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40vitest/runner@4.1.5",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://vitest.dev/api/advanced/runner"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/vitest-dev/vitest.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@vitest/runner@4.1.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@vitest/runner/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@vitest/runner/package.json"
              }
            ],
            "concludedValue": "node_modules/@vitest/runner/package.json"
          }
        ]
      },
      "tags": [
        "test"
      ]
    },
    {
      "group": "@vitest",
      "name": "pretty-format",
      "version": "4.1.5",
      "description": "Fork of pretty-format with support for ESM",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40vitest/pretty-format@4.1.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/vitest-dev/vitest/tree/main/packages/pretty-format"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/vitest-dev/vitest.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@vitest/pretty-format@4.1.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@vitest/pretty-format/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@vitest/pretty-format/package.json"
              }
            ],
            "concludedValue": "node_modules/@vitest/pretty-format/package.json"
          }
        ]
      }
    },
    {
      "group": "@vitest",
      "name": "mocker",
      "version": "4.1.5",
      "description": "Vitest module mocker implementation",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40vitest/mocker@4.1.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/vitest-dev/vitest/tree/main/packages/mocker"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/vitest-dev/vitest.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@vitest/mocker@4.1.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@vitest/mocker/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@vitest/mocker/package.json"
              }
            ],
            "concludedValue": "node_modules/@vitest/mocker/package.json"
          }
        ]
      }
    },
    {
      "group": "@vitest",
      "name": "expect",
      "version": "4.1.5",
      "description": "Jest's expect matchers as a Chai plugin",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40vitest/expect@4.1.5",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://vitest.dev/api/expect"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/vitest-dev/vitest.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@vitest/expect@4.1.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@vitest/expect/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@vitest/expect/package.json"
              }
            ],
            "concludedValue": "node_modules/@vitest/expect/package.json"
          }
        ]
      },
      "tags": [
        "test"
      ]
    },
    {
      "authors": [
        {
          "name": "Anthony Fu <anthonyfu117@hotmail.com>"
        }
      ],
      "group": "@vitest",
      "name": "coverage-v8",
      "version": "4.1.5",
      "description": "V8 coverage provider for Vitest",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40vitest/coverage-v8@4.1.5",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://vitest.dev/guide/coverage"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/vitest-dev/vitest.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@vitest/coverage-v8@4.1.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@vitest/coverage-v8/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@vitest/coverage-v8/package.json"
              }
            ],
            "concludedValue": "node_modules/@vitest/coverage-v8/package.json"
          }
        ]
      }
    },
    {
      "group": "@types",
      "name": "sarif",
      "version": "2.1.7",
      "description": "TypeScript definitions for sarif",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40types/sarif@2.1.7",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/sarif"
        },
        {
          "type": "vcs",
          "url": "https://github.com/DefinitelyTyped/DefinitelyTyped.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@types/sarif@2.1.7",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@types/sarif/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@types/sarif/package.json"
              }
            ],
            "concludedValue": "node_modules/@types/sarif/package.json"
          }
        ]
      }
    },
    {
      "group": "@types",
      "name": "resolve",
      "version": "1.17.1",
      "description": "TypeScript definitions for resolve",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40types/resolve@1.17.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/DefinitelyTyped/DefinitelyTyped.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@types/resolve@1.17.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@types/resolve/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@types/resolve/package.json"
              }
            ],
            "concludedValue": "node_modules/@types/resolve/package.json"
          }
        ]
      }
    },
    {
      "group": "@types",
      "name": "parse-json",
      "version": "4.0.2",
      "description": "TypeScript definitions for parse-json",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40types/parse-json@4.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/parse-json"
        },
        {
          "type": "vcs",
          "url": "https://github.com/DefinitelyTyped/DefinitelyTyped.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@types/parse-json@4.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@types/parse-json/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@types/parse-json/package.json"
              }
            ],
            "concludedValue": "node_modules/@types/parse-json/package.json"
          }
        ]
      }
    },
    {
      "group": "@types",
      "name": "node",
      "version": "25.6.0",
      "description": "TypeScript definitions for node",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40types/node@25.6.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/node"
        },
        {
          "type": "vcs",
          "url": "https://github.com/DefinitelyTyped/DefinitelyTyped.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@types/node@25.6.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@types/node/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@types/node/package.json"
              }
            ],
            "concludedValue": "node_modules/@types/node/package.json"
          }
        ]
      }
    },
    {
      "group": "@types",
      "name": "estree",
      "version": "0.0.39",
      "description": "TypeScript definitions for ESTree AST specification",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40types/estree@0.0.39",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://www.github.com/DefinitelyTyped/DefinitelyTyped.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@types/estree@0.0.39",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@types/estree/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@types/estree/package.json"
              }
            ],
            "concludedValue": "node_modules/@types/estree/package.json"
          }
        ]
      }
    },
    {
      "group": "@types",
      "name": "deep-eql",
      "version": "4.0.2",
      "description": "TypeScript definitions for deep-eql",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40types/deep-eql@4.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/deep-eql"
        },
        {
          "type": "vcs",
          "url": "https://github.com/DefinitelyTyped/DefinitelyTyped.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@types/deep-eql@4.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@types/deep-eql/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@types/deep-eql/package.json"
              }
            ],
            "concludedValue": "node_modules/@types/deep-eql/package.json"
          }
        ]
      }
    },
    {
      "group": "@types",
      "name": "chai",
      "version": "5.2.3",
      "description": "TypeScript definitions for chai",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40types/chai@5.2.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/chai"
        },
        {
          "type": "vcs",
          "url": "https://github.com/DefinitelyTyped/DefinitelyTyped.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@types/chai@5.2.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@types/chai/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@types/chai/package.json"
              }
            ],
            "concludedValue": "node_modules/@types/chai/package.json"
          }
        ]
      },
      "tags": [
        "test"
      ]
    },
    {
      "authors": [
        {
          "name": "Colin McDonnell"
        }
      ],
      "group": "@standard-schema",
      "name": "spec",
      "version": "1.1.0",
      "description": "A family of specs for interoperable TypeScript",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40standard-schema/spec@1.1.0",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://standardschema.dev"
        },
        {
          "type": "vcs",
          "url": "https://github.com/standard-schema/standard-schema"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@standard-schema/spec@1.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@standard-schema/spec/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@standard-schema/spec/package.json"
              }
            ],
            "concludedValue": "node_modules/@standard-schema/spec/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Rich Harris <richard.a.harris@gmail.com>"
        }
      ],
      "group": "@rollup",
      "name": "pluginutils",
      "version": "3.1.0",
      "description": "A set of utility functions commonly used by Rollup plugins",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40rollup/pluginutils@3.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/rollup/plugins/tree/master/packages/pluginutils#readme"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@rollup/pluginutils@3.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@rollup/pluginutils/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@rollup/pluginutils/package.json"
              }
            ],
            "concludedValue": "node_modules/@rollup/pluginutils/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Rich Harris"
        }
      ],
      "group": "",
      "name": "estree-walker",
      "version": "1.0.1",
      "description": "Traverse an ESTree-compliant AST",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/estree-walker@1.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/Rich-Harris/estree-walker"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/estree-walker@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@rollup/pluginutils/node_modules/estree-walker/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@rollup/pluginutils/node_modules/estree-walker/package.json"
              }
            ],
            "concludedValue": "node_modules/@rollup/pluginutils/node_modules/estree-walker/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Rich Harris <richard.a.harris@gmail.com>"
        }
      ],
      "group": "@rollup",
      "name": "plugin-node-resolve",
      "version": "11.2.1",
      "description": "Locate and bundle third-party dependencies in node_modules",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40rollup/plugin-node-resolve@11.2.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/rollup/plugins/tree/master/packages/node-resolve/#readme"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@rollup/plugin-node-resolve@11.2.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@rollup/plugin-node-resolve/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@rollup/plugin-node-resolve/package.json"
              }
            ],
            "concludedValue": "node_modules/@rollup/plugin-node-resolve/package.json"
          }
        ]
      },
      "tags": [
        "bundle"
      ]
    },
    {
      "authors": [
        {
          "name": "Rich Harris <richard.a.harris@gmail.com>"
        }
      ],
      "group": "@rollup",
      "name": "plugin-commonjs",
      "version": "18.0.0",
      "description": "Convert CommonJS modules to ES2015",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40rollup/plugin-commonjs@18.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/rollup/plugins/tree/master/packages/commonjs/#readme"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@rollup/plugin-commonjs@18.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@rollup/plugin-commonjs/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@rollup/plugin-commonjs/package.json"
              }
            ],
            "concludedValue": "node_modules/@rollup/plugin-commonjs/package.json"
          }
        ]
      }
    },
    {
      "group": "@rolldown",
      "name": "pluginutils",
      "version": "1.0.0-rc.17",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40rolldown/pluginutils@1.0.0-rc.17",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://rolldown.rs/"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/rolldown/rolldown.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@rolldown/pluginutils@1.0.0-rc.17",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@rolldown/pluginutils/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@rolldown/pluginutils/package.json"
              }
            ],
            "concludedValue": "node_modules/@rolldown/pluginutils/package.json"
          }
        ]
      }
    },
    {
      "group": "@rolldown",
      "name": "binding-linux-x64-musl",
      "version": "1.0.0-rc.17",
      "description": "Fast JavaScript/TypeScript bundler in Rust with Rollup-compatible API.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40rolldown/binding-linux-x64-musl@1.0.0-rc.17",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://rolldown.rs/"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/rolldown/rolldown.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@rolldown/binding-linux-x64-musl@1.0.0-rc.17",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@rolldown/binding-linux-x64-musl/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@rolldown/binding-linux-x64-musl/package.json"
              }
            ],
            "concludedValue": "node_modules/@rolldown/binding-linux-x64-musl/package.json"
          }
        ]
      },
      "tags": [
        "api"
      ]
    },
    {
      "group": "@rolldown",
      "name": "binding-linux-x64-gnu",
      "version": "1.0.0-rc.17",
      "description": "Fast JavaScript/TypeScript bundler in Rust with Rollup-compatible API.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40rolldown/binding-linux-x64-gnu@1.0.0-rc.17",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://rolldown.rs/"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/rolldown/rolldown.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@rolldown/binding-linux-x64-gnu@1.0.0-rc.17",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@rolldown/binding-linux-x64-gnu/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@rolldown/binding-linux-x64-gnu/package.json"
              }
            ],
            "concludedValue": "node_modules/@rolldown/binding-linux-x64-gnu/package.json"
          }
        ]
      },
      "tags": [
        "api"
      ]
    },
    {
      "authors": [
        {
          "name": "Boshen and oxc contributors"
        }
      ],
      "group": "@oxlint",
      "name": "binding-linux-x64-musl",
      "version": "1.62.0",
      "description": "Linter for the JavaScript Oxidation Compiler",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40oxlint/binding-linux-x64-musl@1.62.0",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://oxc.rs/docs/guide/usage/linter"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/oxc-project/oxc"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@oxlint/binding-linux-x64-musl@1.62.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@oxlint/binding-linux-x64-musl/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@oxlint/binding-linux-x64-musl/package.json"
              }
            ],
            "concludedValue": "node_modules/@oxlint/binding-linux-x64-musl/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Boshen and oxc contributors"
        }
      ],
      "group": "@oxlint",
      "name": "binding-linux-x64-gnu",
      "version": "1.62.0",
      "description": "Linter for the JavaScript Oxidation Compiler",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40oxlint/binding-linux-x64-gnu@1.62.0",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://oxc.rs/docs/guide/usage/linter"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/oxc-project/oxc"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@oxlint/binding-linux-x64-gnu@1.62.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@oxlint/binding-linux-x64-gnu/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@oxlint/binding-linux-x64-gnu/package.json"
              }
            ],
            "concludedValue": "node_modules/@oxlint/binding-linux-x64-gnu/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Boshen and oxc contributors"
        }
      ],
      "group": "@oxfmt",
      "name": "binding-linux-x64-musl",
      "version": "0.47.0",
      "description": "Formatter for the JavaScript Oxidation Compiler",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40oxfmt/binding-linux-x64-musl@0.47.0",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://oxc.rs/docs/guide/usage/formatter"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/oxc-project/oxc"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@oxfmt/binding-linux-x64-musl@0.47.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@oxfmt/binding-linux-x64-musl/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@oxfmt/binding-linux-x64-musl/package.json"
              }
            ],
            "concludedValue": "node_modules/@oxfmt/binding-linux-x64-musl/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Boshen and oxc contributors"
        }
      ],
      "group": "@oxfmt",
      "name": "binding-linux-x64-gnu",
      "version": "0.47.0",
      "description": "Formatter for the JavaScript Oxidation Compiler",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40oxfmt/binding-linux-x64-gnu@0.47.0",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://oxc.rs/docs/guide/usage/formatter"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/oxc-project/oxc"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@oxfmt/binding-linux-x64-gnu@0.47.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@oxfmt/binding-linux-x64-gnu/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@oxfmt/binding-linux-x64-gnu/package.json"
              }
            ],
            "concludedValue": "node_modules/@oxfmt/binding-linux-x64-gnu/package.json"
          }
        ]
      }
    },
    {
      "group": "@oxc-resolver",
      "name": "binding-linux-x64-musl",
      "version": "11.19.1",
      "description": "Oxc Resolver Node API",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40oxc-resolver/binding-linux-x64-musl@11.19.1",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://oxc.rs"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/oxc-project/oxc-resolver.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@oxc-resolver/binding-linux-x64-musl@11.19.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@oxc-resolver/binding-linux-x64-musl/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@oxc-resolver/binding-linux-x64-musl/package.json"
              }
            ],
            "concludedValue": "node_modules/@oxc-resolver/binding-linux-x64-musl/package.json"
          }
        ]
      }
    },
    {
      "group": "@oxc-resolver",
      "name": "binding-linux-x64-gnu",
      "version": "11.19.1",
      "description": "Oxc Resolver Node API",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40oxc-resolver/binding-linux-x64-gnu@11.19.1",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://oxc.rs"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/oxc-project/oxc-resolver.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@oxc-resolver/binding-linux-x64-gnu@11.19.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@oxc-resolver/binding-linux-x64-gnu/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@oxc-resolver/binding-linux-x64-gnu/package.json"
              }
            ],
            "concludedValue": "node_modules/@oxc-resolver/binding-linux-x64-gnu/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Boshen and oxc contributors"
        }
      ],
      "group": "@oxc-project",
      "name": "types",
      "version": "0.128.0",
      "description": "Types for Oxc AST nodes",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40oxc-project/types@0.128.0",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://oxc.rs"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/oxc-project/oxc.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@oxc-project/types@0.128.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@oxc-project/types/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@oxc-project/types/package.json"
              }
            ],
            "concludedValue": "node_modules/@oxc-project/types/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Boshen and oxc contributors"
        }
      ],
      "group": "@oxc-parser",
      "name": "binding-linux-x64-musl",
      "version": "0.128.0",
      "description": "Oxc Parser Node API",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40oxc-parser/binding-linux-x64-musl@0.128.0",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://oxc.rs/docs/guide/usage/parser"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/oxc-project/oxc.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@oxc-parser/binding-linux-x64-musl@0.128.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@oxc-parser/binding-linux-x64-musl/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@oxc-parser/binding-linux-x64-musl/package.json"
              }
            ],
            "concludedValue": "node_modules/@oxc-parser/binding-linux-x64-musl/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Boshen and oxc contributors"
        }
      ],
      "group": "@oxc-parser",
      "name": "binding-linux-x64-gnu",
      "version": "0.128.0",
      "description": "Oxc Parser Node API",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40oxc-parser/binding-linux-x64-gnu@0.128.0",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://oxc.rs/docs/guide/usage/parser"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/oxc-project/oxc.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@oxc-parser/binding-linux-x64-gnu@0.128.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@oxc-parser/binding-linux-x64-gnu/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@oxc-parser/binding-linux-x64-gnu/package.json"
              }
            ],
            "concludedValue": "node_modules/@oxc-parser/binding-linux-x64-gnu/package.json"
          }
        ]
      }
    },
    {
      "group": "@nodelib",
      "name": "fs.walk",
      "version": "1.2.8",
      "description": "A library for efficiently walking a directory recursively",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40nodelib/fs.walk@1.2.8",
      "type": "library",
      "bom-ref": "pkg:npm/@nodelib/fs.walk@1.2.8",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@nodelib/fs.walk/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@nodelib/fs.walk/package.json"
              }
            ],
            "concludedValue": "node_modules/@nodelib/fs.walk/package.json"
          }
        ]
      }
    },
    {
      "group": "@nodelib",
      "name": "fs.stat",
      "version": "2.0.5",
      "description": "Get the status of a file with some features",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40nodelib/fs.stat@2.0.5",
      "type": "library",
      "bom-ref": "pkg:npm/@nodelib/fs.stat@2.0.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@nodelib/fs.stat/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@nodelib/fs.stat/package.json"
              }
            ],
            "concludedValue": "node_modules/@nodelib/fs.stat/package.json"
          }
        ]
      }
    },
    {
      "group": "@nodelib",
      "name": "fs.scandir",
      "version": "2.1.5",
      "description": "List files and directories inside the specified directory",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40nodelib/fs.scandir@2.1.5",
      "type": "library",
      "bom-ref": "pkg:npm/@nodelib/fs.scandir@2.1.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@nodelib/fs.scandir/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@nodelib/fs.scandir/package.json"
              }
            ],
            "concludedValue": "node_modules/@nodelib/fs.scandir/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Andrey Kucherenko <kucherenko.andrey@gmail.com>"
        }
      ],
      "group": "@jscpd",
      "name": "tokenizer",
      "version": "4.0.5",
      "description": "tokenizer of source code for jscpd",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40jscpd/tokenizer@4.0.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/kucherenko/jscpd#readme"
        },
        {
          "type": "vcs",
          "url": "git+ssh://git@github.com/kucherenko/jscpd.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@jscpd/tokenizer@4.0.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@jscpd/tokenizer/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@jscpd/tokenizer/package.json"
              }
            ],
            "concludedValue": "node_modules/@jscpd/tokenizer/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Andrey Kucherenko <kucherenko.andrey@gmail.com>"
        }
      ],
      "group": "@jscpd",
      "name": "html-reporter",
      "version": "4.0.5",
      "description": "html reporter for jscpd",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40jscpd/html-reporter@4.0.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/kucherenko/jscpd#readme"
        },
        {
          "type": "vcs",
          "url": "git+ssh://git@github.com/kucherenko/jscpd.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@jscpd/html-reporter@4.0.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@jscpd/html-reporter/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@jscpd/html-reporter/package.json"
              }
            ],
            "concludedValue": "node_modules/@jscpd/html-reporter/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Andrey Kucherenko <kucherenko.andrey@gmail.com>"
        }
      ],
      "group": "@jscpd",
      "name": "finder",
      "version": "4.0.5",
      "description": "detector of copy/paste in files",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40jscpd/finder@4.0.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/kucherenko/jscpd#readme"
        },
        {
          "type": "vcs",
          "url": "git+ssh://git@github.com/kucherenko/jscpd.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@jscpd/finder@4.0.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@jscpd/finder/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@jscpd/finder/package.json"
              }
            ],
            "concludedValue": "node_modules/@jscpd/finder/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Andrey Kucherenko <kucherenko.andrey@gmail.com>"
        }
      ],
      "group": "@jscpd",
      "name": "core",
      "version": "4.0.5",
      "description": "core functionality of copy/paste detector for jscpd",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40jscpd/core@4.0.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/kucherenko/jscpd#readme"
        },
        {
          "type": "vcs",
          "url": "git+ssh://git@github.com/kucherenko/jscpd.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@jscpd/core@4.0.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@jscpd/core/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@jscpd/core/package.json"
              }
            ],
            "concludedValue": "node_modules/@jscpd/core/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Andrey Kucherenko <kucherenko.andrey@gmail.com>"
        }
      ],
      "group": "@jscpd",
      "name": "badge-reporter",
      "version": "4.0.5",
      "description": "Reporter for jscpd. Generate a badges with copy/paste level.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40jscpd/badge-reporter@4.0.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/kucherenko/jscpd#readme"
        },
        {
          "type": "vcs",
          "url": "git+ssh://git@github.com/kucherenko/jscpd.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@jscpd/badge-reporter@4.0.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@jscpd/badge-reporter/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@jscpd/badge-reporter/package.json"
              }
            ],
            "concludedValue": "node_modules/@jscpd/badge-reporter/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Justin Ridgewell <justin@ridgewell.name>"
        }
      ],
      "group": "@jridgewell",
      "name": "trace-mapping",
      "version": "0.3.31",
      "description": "Trace the original position through a source map",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40jridgewell/trace-mapping@0.3.31",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jridgewell/sourcemaps/tree/main/packages/trace-mapping"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/jridgewell/sourcemaps.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@jridgewell/trace-mapping@0.3.31",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@jridgewell/trace-mapping/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@jridgewell/trace-mapping/package.json"
              }
            ],
            "concludedValue": "node_modules/@jridgewell/trace-mapping/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Justin Ridgewell <justin@ridgewell.name>"
        }
      ],
      "group": "@jridgewell",
      "name": "sourcemap-codec",
      "version": "1.5.5",
      "description": "Encode/decode sourcemap mappings",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40jridgewell/sourcemap-codec@1.5.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jridgewell/sourcemaps/tree/main/packages/sourcemap-codec"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/jridgewell/sourcemaps.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@jridgewell/sourcemap-codec@1.5.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@jridgewell/sourcemap-codec/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@jridgewell/sourcemap-codec/package.json"
              }
            ],
            "concludedValue": "node_modules/@jridgewell/sourcemap-codec/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Justin Ridgewell <justin@ridgewell.name>"
        }
      ],
      "group": "@jridgewell",
      "name": "resolve-uri",
      "version": "3.1.2",
      "description": "Resolve a URI relative to an optional base URI",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40jridgewell/resolve-uri@3.1.2",
      "type": "library",
      "bom-ref": "pkg:npm/@jridgewell/resolve-uri@3.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@jridgewell/resolve-uri/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@jridgewell/resolve-uri/package.json"
              }
            ],
            "concludedValue": "node_modules/@jridgewell/resolve-uri/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "DABH"
        }
      ],
      "group": "@colors",
      "name": "colors",
      "version": "1.5.0",
      "description": "get colors in your node.js console",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40colors/colors@1.5.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/DABH/colors.js"
        },
        {
          "type": "vcs",
          "url": "http://github.com/DABH/colors.js.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@colors/colors@1.5.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@colors/colors/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@colors/colors/package.json"
              }
            ],
            "concludedValue": "node_modules/@colors/colors/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Charles Samborski <demurgos@demurgos.net> (https://demurgos.net)"
        }
      ],
      "group": "@bcoe",
      "name": "v8-coverage",
      "version": "1.0.2",
      "description": "Helper functions for V8 coverage files.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40bcoe/v8-coverage@1.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/bcoe/v8-coverage.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@bcoe/v8-coverage@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@bcoe/v8-coverage/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@bcoe/v8-coverage/package.json"
              }
            ],
            "concludedValue": "node_modules/@bcoe/v8-coverage/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "The Babel Team (https://babel.dev/team)"
        }
      ],
      "group": "@babel",
      "name": "types",
      "version": "7.29.0",
      "description": "Babel Types is a Lodash-esque utility library for AST nodes",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40babel/types@7.29.0",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://babel.dev/docs/en/next/babel-types"
        },
        {
          "type": "vcs",
          "url": "https://github.com/babel/babel.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@babel/types@7.29.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@babel/types/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@babel/types/package.json"
              }
            ],
            "concludedValue": "node_modules/@babel/types/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "The Babel Team (https://babel.dev/team)"
        }
      ],
      "group": "@babel",
      "name": "parser",
      "version": "7.29.3",
      "description": "A JavaScript parser",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40babel/parser@7.29.3",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://babel.dev/docs/en/next/babel-parser"
        },
        {
          "type": "vcs",
          "url": "https://github.com/babel/babel.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@babel/parser@7.29.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@babel/parser/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@babel/parser/package.json"
              }
            ],
            "concludedValue": "node_modules/@babel/parser/package.json"
          }
        ]
      },
      "tags": [
        "parse"
      ]
    },
    {
      "authors": [
        {
          "name": "The Babel Team (https://babel.dev/team)"
        }
      ],
      "group": "@babel",
      "name": "highlight",
      "version": "7.25.9",
      "description": "Syntax highlight JavaScript strings for output in terminals.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40babel/highlight@7.25.9",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://babel.dev/docs/en/next/babel-highlight"
        },
        {
          "type": "vcs",
          "url": "https://github.com/babel/babel.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@babel/highlight@7.25.9",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@babel/highlight/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@babel/highlight/package.json"
              }
            ],
            "concludedValue": "node_modules/@babel/highlight/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Simon Lydell"
        }
      ],
      "group": "",
      "name": "js-tokens",
      "version": "4.0.0",
      "description": "A regex that tokenizes JavaScript.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/js-tokens@4.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/js-tokens@4.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@babel/highlight/node_modules/js-tokens/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@babel/highlight/node_modules/js-tokens/package.json"
              }
            ],
            "concludedValue": "node_modules/@babel/highlight/node_modules/js-tokens/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "chalk",
      "version": "2.4.2",
      "description": "Terminal string styling done right",
      "scope": "required",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/chalk@2.4.2",
      "type": "library",
      "bom-ref": "pkg:npm/chalk@2.4.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@babel/highlight/node_modules/chalk/package.json"
        },
        {
          "name": "ImportedModules",
          "value": "chalk"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@babel/highlight/node_modules/chalk/package.json"
              }
            ],
            "concludedValue": "node_modules/@babel/highlight/node_modules/chalk/package.json"
          }
        ],
        "occurrences": [
          {
            "location": "src/bin.js#3"
          },
          {
            "location": "src/index.js#5"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "supports-color",
      "version": "5.5.0",
      "description": "Detect whether a terminal supports color",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/supports-color@5.5.0",
      "type": "library",
      "bom-ref": "pkg:npm/supports-color@5.5.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@babel/highlight/node_modules/chalk/node_modules/supports-color/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@babel/highlight/node_modules/chalk/node_modules/supports-color/package.json"
              }
            ],
            "concludedValue": "node_modules/@babel/highlight/node_modules/chalk/node_modules/supports-color/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "has-flag",
      "version": "3.0.0",
      "description": "Check if argv has a specific flag",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/has-flag@3.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/has-flag@3.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@babel/highlight/node_modules/chalk/node_modules/supports-color/node_modules/has-flag/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@babel/highlight/node_modules/chalk/node_modules/supports-color/node_modules/has-flag/package.json"
              }
            ],
            "concludedValue": "node_modules/@babel/highlight/node_modules/chalk/node_modules/supports-color/node_modules/has-flag/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "ansi-styles",
      "version": "3.2.1",
      "description": "ANSI escape codes for styling strings in the terminal",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/ansi-styles@3.2.1",
      "type": "library",
      "bom-ref": "pkg:npm/ansi-styles@3.2.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@babel/highlight/node_modules/chalk/node_modules/ansi-styles/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@babel/highlight/node_modules/chalk/node_modules/ansi-styles/package.json"
              }
            ],
            "concludedValue": "node_modules/@babel/highlight/node_modules/chalk/node_modules/ansi-styles/package.json"
          }
        ]
      },
      "tags": [
        "escape"
      ]
    },
    {
      "authors": [
        {
          "name": "Heather Arthur <fayearthur@gmail.com>"
        }
      ],
      "group": "",
      "name": "color-convert",
      "version": "1.9.3",
      "description": "Plain color conversion functions",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/color-convert@1.9.3",
      "type": "library",
      "bom-ref": "pkg:npm/color-convert@1.9.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@babel/highlight/node_modules/chalk/node_modules/ansi-styles/node_modules/color-convert/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@babel/highlight/node_modules/chalk/node_modules/ansi-styles/node_modules/color-convert/package.json"
              }
            ],
            "concludedValue": "node_modules/@babel/highlight/node_modules/chalk/node_modules/ansi-styles/node_modules/color-convert/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "DY <dfcreative@gmail.com>"
        }
      ],
      "group": "",
      "name": "color-name",
      "version": "1.1.3",
      "description": "A list of color names and its values",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/color-name@1.1.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/dfcreative/color-name"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/color-name@1.1.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@babel/highlight/node_modules/chalk/node_modules/ansi-styles/node_modules/color-convert/node_modules/color-name/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@babel/highlight/node_modules/chalk/node_modules/ansi-styles/node_modules/color-convert/node_modules/color-name/package.json"
              }
            ],
            "concludedValue": "node_modules/@babel/highlight/node_modules/chalk/node_modules/ansi-styles/node_modules/color-convert/node_modules/color-name/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "The Babel Team (https://babel.dev/team)"
        }
      ],
      "group": "@babel",
      "name": "helper-validator-identifier",
      "version": "7.28.5",
      "description": "Validate identifier/keywords name",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40babel/helper-validator-identifier@7.28.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/babel/babel.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@babel/helper-validator-identifier@7.28.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@babel/helper-validator-identifier/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@babel/helper-validator-identifier/package.json"
              }
            ],
            "concludedValue": "node_modules/@babel/helper-validator-identifier/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "The Babel Team (https://babel.dev/team)"
        }
      ],
      "group": "@babel",
      "name": "helper-string-parser",
      "version": "7.27.1",
      "description": "A utility package to parse strings",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40babel/helper-string-parser@7.27.1",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://babel.dev/docs/en/next/babel-helper-string-parser"
        },
        {
          "type": "vcs",
          "url": "https://github.com/babel/babel.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@babel/helper-string-parser@7.27.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@babel/helper-string-parser/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@babel/helper-string-parser/package.json"
              }
            ],
            "concludedValue": "node_modules/@babel/helper-string-parser/package.json"
          }
        ]
      },
      "tags": [
        "parse"
      ]
    },
    {
      "authors": [
        {
          "name": "Sebastian McKenzie <sebmck@gmail.com>"
        }
      ],
      "group": "@babel",
      "name": "code-frame",
      "version": "7.12.11",
      "description": "Generate errors that contain a code frame that point to source locations.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40babel/code-frame@7.12.11",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://babeljs.io/"
        },
        {
          "type": "vcs",
          "url": "https://github.com/babel/babel.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@babel/code-frame@7.12.11",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@babel/code-frame/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@babel/code-frame/package.json"
              }
            ],
            "concludedValue": "node_modules/@babel/code-frame/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "AGENTS.md",
      "version": "",
      "purl": "pkg:npm/AGENTS.md",
      "type": "file",
      "bom-ref": "pkg:npm/AGENTS.md",
      "properties": [
        {
          "name": "SrcFile",
          "value": "AGENTS.md"
        },
        {
          "name": "cdx:file:kind",
          "value": "agent-instructions"
        },
        {
          "name": "cdx:agent:inventorySource",
          "value": "agent-file"
        },
        {
          "name": "cdx:agent:hasMcpReferences",
          "value": "false"
        },
        {
          "name": "cdx:agent:hiddenEndpointCount",
          "value": "0"
        }
      ]
    }
  ],
  "dependencies": [],
  "annotations": [
    {
      "bom-ref": "metadata-annotations",
      "subjects": [
        "pkg:npm/degit@2.8.6"
      ],
      "annotator": {
        "component": {
          "group": "@cyclonedx",
          "name": "cdxgen",
          "version": "12.3.3",
          "purl": "pkg:npm/%40cyclonedx/cdxgen@12.3.3",
          "type": "application",
          "bom-ref": "pkg:npm/@cyclonedx/cdxgen@12.3.3",
          "publisher": "OWASP Foundation",
          "authors": [
            {
              "name": "OWASP Foundation"
            }
          ]
        }
      },
      "timestamp": "2026-07-29T09:09:03Z",
      "text": "This Software Bill-of-Materials (SBOM) document was created on Wednesday, July 29, 2026 with cdxgen. The data was captured during the pre-build lifecycle phase without building the application. The document describes an application named 'degit' with version '2.8.6'. The package type in this SBOM is npm with 17 purl namespaces described under components. The components were identified from 343 source files."
    }
  ]
}