{
  "bomFormat": "CycloneDX",
  "specVersion": "1.7",
  "serialNumber": "urn:uuid:48b5ba1d-6dea-4cce-b61e-de218db34f2d",
  "version": 1,
  "metadata": {
    "timestamp": "2026-07-27T21:35:52Z",
    "tools": {
      "components": [
        {
          "group": "@cyclonedx",
          "name": "cdxgen",
          "version": "12.3.3",
          "purl": "pkg:npm/%40cyclonedx/cdxgen@12.3.3",
          "type": "application",
          "bom-ref": "pkg:npm/@cyclonedx/cdxgen@12.3.3",
          "publisher": "OWASP Foundation",
          "authors": [
            {
              "name": "OWASP Foundation"
            }
          ]
        }
      ]
    },
    "authors": [
      {
        "name": "OWASP Foundation"
      }
    ],
    "lifecycles": [
      {
        "phase": "pre-build"
      }
    ],
    "component": {
      "name": "glsl-token-assignments",
      "group": "",
      "version": "2.0.2",
      "description": "Take an array of GLSL tokens and determine which tokens are either assignments or variable declarations.",
      "purl": "pkg:npm/glsl-token-assignments@2.0.2",
      "bom-ref": "pkg:npm/glsl-token-assignments@2.0.2",
      "author": "Hugh Kennedy <hughskennedy@gmail.com> (http://hughsk.io/)",
      "properties": [
        {
          "name": "cdx:npm:scripts",
          "value": "test, test:node, test:eyeball, test:browser, test:browser:view"
        }
      ],
      "type": "application",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/stackgl/glsl-token-assignments"
        },
        {
          "type": "vcs",
          "url": "git://github.com/stackgl/glsl-token-assignments.git"
        }
      ]
    },
    "properties": [
      {
        "name": "cdx:bom:componentTypes",
        "value": "npm"
      },
      {
        "name": "cdx:bom:componentSrcFiles",
        "value": "node_modules/6to5-core/package.json\\nnode_modules/6to5/package.json\\nnode_modules/6to5ify/package.json\\nnode_modules/Base64/package.json\\nnode_modules/JSONStream/package.json\\nnode_modules/acorn-6to5/package.json\\nnode_modules/acorn/package.json\\nnode_modules/align-text/package.json\\nnode_modules/alter/package.json\\nnode_modules/amdefine/package.json\\nnode_modules/ansi-regex/package.json\\nnode_modules/ansi-styles/package.json\\nnode_modules/archiver/node_modules/async/package.json\\nnode_modules/archiver/node_modules/glob/package.json\\nnode_modules/archiver/node_modules/lodash/package.json\\nnode_modules/archiver/node_modules/readable-stream/package.json\\nnode_modules/archiver/package.json\\nnode_modules/array-find-index/package.json\\nnode_modules/asn1.js/package.json\\nnode_modules/asn1/package.json\\nnode_modules/assert-plus/package.json\\nnode_modules/assert/package.json\\nnode_modules/ast-traverse/package.json\\nnode_modules/ast-types/package.json\\nnode_modules/astw/package.json\\nnode_modules/async-each/package.json\\nnode_modules/async/node_modules/lodash/package.json\\nnode_modules/async/package.json\\nnode_modules/aws-sign2/package.json\\nnode_modules/balanced-match/package.json\\nnode_modules/base64-js/package.json\\nnode_modules/bl/node_modules/readable-stream/package.json\\nnode_modules/bl/package.json\\nnode_modules/bluebird/package.json\\nnode_modules/bn.js/package.json\\nnode_modules/boom/package.json\\nnode_modules/brace-expansion/package.json\\nnode_modules/breakable/package.json\\nnode_modules/brorand/package.json\\nnode_modules/browser-pack/node_modules/readable-stream/package.json\\nnode_modules/browser-pack/node_modules/through2/package.json\\nnode_modules/browser-pack/package.json\\nnode_modules/browser-resolve/node_modules/resolve/package.json\\nnode_modules/browser-resolve/node_modules/resolve/test/pathfilter/deep_ref/node_modules/deep/package.json\\nnode_modules/browser-resolve/package.json\\nnode_modules/browserify-aes/package.json\\nnode_modules/browserify-cipher/package.json\\nnode_modules/browserify-des/package.json\\nnode_modules/browserify-rsa/package.json\\nnode_modules/browserify-sign/package.json\\nnode_modules/browserify-zlib/package.json\\nnode_modules/browserify/package.json\\nnode_modules/buffer-crc32/package.json\\nnode_modules/buffer-xor/package.json\\nnode_modules/buffer/node_modules/isarray/package.json\\nnode_modules/buffer/package.json\\nnode_modules/builtin-modules/package.json\\nnode_modules/builtins/package.json\\nnode_modules/callsite/package.json\\nnode_modules/camelcase-keys/package.json\\nnode_modules/camelcase/package.json\\nnode_modules/caseless/package.json\\nnode_modules/center-align/package.json\\nnode_modules/chalk/package.json\\nnode_modules/chokidar/package.json\\nnode_modules/chrome-launch/package.json\\nnode_modules/chrome-location/package.json\\nnode_modules/cipher-base/package.json\\nnode_modules/cli/node_modules/glob/package.json\\nnode_modules/cli/node_modules/minimatch/package.json\\nnode_modules/cli/package.json\\nnode_modules/cliui/package.json\\nnode_modules/code-point-at/package.json\\nnode_modules/combine-source-map/package.json\\nnode_modules/combined-stream/package.json\\nnode_modules/commander/package.json\\nnode_modules/commondir/package.json\\nnode_modules/commoner/node_modules/ast-types/package.json\\nnode_modules/commoner/node_modules/esprima-fb/package.json\\nnode_modules/commoner/node_modules/glob/package.json\\nnode_modules/commoner/node_modules/recast/package.json\\nnode_modules/commoner/node_modules/source-map/package.json\\nnode_modules/commoner/package.json\\nnode_modules/compress-commons/node_modules/readable-stream/package.json\\nnode_modules/compress-commons/package.json\\nnode_modules/concat-map/package.json\\nnode_modules/concat-stream/package.json\\nnode_modules/console-browserify/package.json\\nnode_modules/constants-browserify/package.json\\nnode_modules/convert-source-map/package.json\\nnode_modules/core-js/package.json\\nnode_modules/core-util-is/package.json\\nnode_modules/crc32-stream/node_modules/readable-stream/package.json\\nnode_modules/crc32-stream/package.json\\nnode_modules/create-ecdh/package.json\\nnode_modules/create-hash/package.json\\nnode_modules/create-hmac/package.json\\nnode_modules/cryptiles/package.json\\nnode_modules/crypto-browserify/package.json\\nnode_modules/ctype/package.json\\nnode_modules/currently-unhandled/package.json\\nnode_modules/date-now/package.json\\nnode_modules/debug/package.json\\nnode_modules/decamelize/package.json\\nnode_modules/deep-equal/package.json\\nnode_modules/defined/package.json\\nnode_modules/defs/node_modules/esprima-fb/package.json\\nnode_modules/defs/package.json\\nnode_modules/delayed-stream/package.json\\nnode_modules/deps-sort/node_modules/JSONStream/package.json\\nnode_modules/deps-sort/node_modules/jsonparse/package.json\\nnode_modules/deps-sort/package.json\\nnode_modules/des.js/package.json\\nnode_modules/detective/node_modules/defined/package.json\\nnode_modules/detective/package.json\\nnode_modules/diffie-hellman/package.json\\nnode_modules/dom-serializer/node_modules/domelementtype/package.json\\nnode_modules/dom-serializer/node_modules/entities/package.json\\nnode_modules/dom-serializer/package.json\\nnode_modules/dom-walk/package.json\\nnode_modules/domain-browser/package.json\\nnode_modules/domelementtype/package.json\\nnode_modules/domhandler/package.json\\nnode_modules/domutils/package.json\\nnode_modules/duplexer/package.json\\nnode_modules/duplexer2/package.json\\nnode_modules/elliptic/package.json\\nnode_modules/end-of-stream/node_modules/once/package.json\\nnode_modules/end-of-stream/package.json\\nnode_modules/entities/package.json\\nnode_modules/error-ex/package.json\\nnode_modules/escape-string-regexp/package.json\\nnode_modules/esprima-fb/package.json\\nnode_modules/estraverse/package.json\\nnode_modules/esutils/package.json\\nnode_modules/esvalid/package.json\\nnode_modules/events/package.json\\nnode_modules/evp_bytestokey/package.json\\nnode_modules/exit/package.json\\nnode_modules/extend/package.json\\nnode_modules/faye-websocket/package.json\\nnode_modules/find-up/package.json\\nnode_modules/firefox-launch/package.json\\nnode_modules/firefox-location/package.json\\nnode_modules/first-match/package.json\\nnode_modules/for-each/package.json\\nnode_modules/forever-agent/package.json\\nnode_modules/form-data/package.json\\nnode_modules/fs-readdir-recursive/package.json\\nnode_modules/generate-function/package.json\\nnode_modules/generate-object-property/package.json\\nnode_modules/get-stdin/package.json\\nnode_modules/glob/package.json\\nnode_modules/global/node_modules/process/package.json\\nnode_modules/global/package.json\\nnode_modules/glsl-tokenizer/node_modules/readable-stream/package.json\\nnode_modules/glsl-tokenizer/node_modules/through2/package.json\\nnode_modules/glsl-tokenizer/node_modules/xtend/package.json\\nnode_modules/glsl-tokenizer/package.json\\nnode_modules/graceful-fs/package.json\\nnode_modules/graceful-readlink/package.json\\nnode_modules/har-validator/node_modules/ansi-regex/package.json\\nnode_modules/har-validator/node_modules/ansi-styles/package.json\\nnode_modules/har-validator/node_modules/chalk/package.json\\nnode_modules/har-validator/node_modules/commander/package.json\\nnode_modules/har-validator/node_modules/has-ansi/package.json\\nnode_modules/har-validator/node_modules/strip-ansi/package.json\\nnode_modules/har-validator/node_modules/supports-color/package.json\\nnode_modules/har-validator/package.json\\nnode_modules/has-ansi/package.json\\nnode_modules/hash.js/package.json\\nnode_modules/hawk/package.json\\nnode_modules/hoek/package.json\\nnode_modules/hosted-git-info/package.json\\nnode_modules/htmlparser2/package.json\\nnode_modules/http-browserify/package.json\\nnode_modules/http-signature/package.json\\nnode_modules/https-browserify/package.json\\nnode_modules/iconv-lite/package.json\\nnode_modules/ieee754/package.json\\nnode_modules/indent-string/package.json\\nnode_modules/indexof/package.json\\nnode_modules/inflight/package.json\\nnode_modules/inherits/package.json\\nnode_modules/inline-source-map/node_modules/source-map/package.json\\nnode_modules/inline-source-map/package.json\\nnode_modules/insert-module-globals/node_modules/JSONStream/package.json\\nnode_modules/insert-module-globals/node_modules/combine-source-map/package.json\\nnode_modules/insert-module-globals/node_modules/convert-source-map/package.json\\nnode_modules/insert-module-globals/node_modules/inline-source-map/package.json\\nnode_modules/insert-module-globals/node_modules/jsonparse/package.json\\nnode_modules/insert-module-globals/node_modules/process/package.json\\nnode_modules/insert-module-globals/node_modules/source-map/package.json\\nnode_modules/insert-module-globals/node_modules/xtend/package.json\\nnode_modules/insert-module-globals/package.json\\nnode_modules/invert-kv/package.json\\nnode_modules/is-arrayish/package.json\\nnode_modules/is-buffer/package.json\\nnode_modules/is-builtin-module/package.json\\nnode_modules/is-dom/package.json\\nnode_modules/is-finite/package.json\\nnode_modules/is-fullwidth-code-point/package.json\\nnode_modules/is-function/package.json\\nnode_modules/is-my-json-valid/node_modules/xtend/package.json\\nnode_modules/is-my-json-valid/package.json\\nnode_modules/is-property/package.json\\nnode_modules/is-utf8/package.json\\nnode_modules/isarray/package.json\\nnode_modules/isexe/package.json\\nnode_modules/isstream/package.json\\nnode_modules/jsesc/package.json\\nnode_modules/jshint/node_modules/minimatch/package.json\\nnode_modules/jshint/package.json\\nnode_modules/json-stable-stringify/package.json\\nnode_modules/json-stringify-safe/package.json\\nnode_modules/jsonify/package.json\\nnode_modules/jsonparse/package.json\\nnode_modules/jsonpointer/package.json\\nnode_modules/kind-of/package.json\\nnode_modules/labeled-stream-splicer/package.json\\nnode_modules/lazy-cache/package.json\\nnode_modules/lazystream/node_modules/readable-stream/package.json\\nnode_modules/lazystream/package.json\\nnode_modules/lcid/package.json\\nnode_modules/lexical-scope/package.json\\nnode_modules/load-json-file/package.json\\nnode_modules/localtunnel/node_modules/ansi-regex/package.json\\nnode_modules/localtunnel/node_modules/camelcase/package.json\\nnode_modules/localtunnel/node_modules/cliui/package.json\\nnode_modules/localtunnel/node_modules/strip-ansi/package.json\\nnode_modules/localtunnel/node_modules/yargs/package.json\\nnode_modules/localtunnel/package.json\\nnode_modules/lodash.memoize/package.json\\nnode_modules/lodash/package.json\\nnode_modules/longest/package.json\\nnode_modules/loud-rejection/package.json\\nnode_modules/lru-cache/package.json\\nnode_modules/map-obj/package.json\\nnode_modules/meow/node_modules/minimist/package.json\\nnode_modules/meow/node_modules/object-assign/package.json\\nnode_modules/meow/package.json\\nnode_modules/miller-rabin/package.json\\nnode_modules/mime-db/package.json\\nnode_modules/mime-types/package.json\\nnode_modules/min-document/package.json\\nnode_modules/minimalistic-assert/package.json\\nnode_modules/minimatch/package.json\\nnode_modules/minimist/package.json\\nnode_modules/mkdirp/package.json\\nnode_modules/module-deps/node_modules/JSONStream/package.json\\nnode_modules/module-deps/node_modules/defined/package.json\\nnode_modules/module-deps/node_modules/jsonparse/package.json\\nnode_modules/module-deps/node_modules/resolve/package.json\\nnode_modules/module-deps/node_modules/resolve/test/pathfilter/deep_ref/node_modules/deep/package.json\\nnode_modules/module-deps/node_modules/xtend/package.json\\nnode_modules/module-deps/package.json\\nnode_modules/ms/package.json\\nnode_modules/node-int64/package.json\\nnode_modules/node-uuid/package.json\\nnode_modules/normalize-package-data/package.json\\nnode_modules/number-is-nan/package.json\\nnode_modules/oauth-sign/package.json\\nnode_modules/object-assign/package.json\\nnode_modules/object-inspect/package.json\\nnode_modules/once/package.json\\nnode_modules/openurl/package.json\\nnode_modules/optimist/package.json\\nnode_modules/os-browserify/package.json\\nnode_modules/os-locale/package.json\\nnode_modules/osenv/package.json\\nnode_modules/output-file-sync/node_modules/object-assign/package.json\\nnode_modules/output-file-sync/package.json\\nnode_modules/pako/package.json\\nnode_modules/parents/package.json\\nnode_modules/parse-asn1/package.json\\nnode_modules/parse-headers/package.json\\nnode_modules/parse-json/package.json\\nnode_modules/parse-ms/package.json\\nnode_modules/path-browserify/package.json\\nnode_modules/path-exists/package.json\\nnode_modules/path-is-absolute/package.json\\nnode_modules/path-platform/package.json\\nnode_modules/path-type/package.json\\nnode_modules/pbkdf2/package.json\\nnode_modules/pify/package.json\\nnode_modules/pinkie-promise/package.json\\nnode_modules/pinkie/package.json\\nnode_modules/plur/package.json\\nnode_modules/pretty-ms/package.json\\nnode_modules/private/package.json\\nnode_modules/process-nextick-args/package.json\\nnode_modules/process/package.json\\nnode_modules/public-encrypt/package.json\\nnode_modules/punycode/package.json\\nnode_modules/q/package.json\\nnode_modules/qs/package.json\\nnode_modules/querystring-es3/package.json\\nnode_modules/querystring/package.json\\nnode_modules/quick-tmp/package.json\\nnode_modules/randombytes/package.json\\nnode_modules/read-pkg-up/package.json\\nnode_modules/read-pkg/package.json\\nnode_modules/readable-stream/package.json\\nnode_modules/readable-wrap/package.json\\nnode_modules/readdirp/examples/package.json\\nnode_modules/readdirp/node_modules/graceful-fs/package.json\\nnode_modules/readdirp/node_modules/minimatch/package.json\\nnode_modules/readdirp/node_modules/readable-stream/package.json\\nnode_modules/readdirp/package.json\\nnode_modules/recast/package.json\\nnode_modules/redent/package.json\\nnode_modules/regenerate/package.json\\nnode_modules/regenerator/node_modules/through/package.json\\nnode_modules/regenerator/package.json\\nnode_modules/regexpu/package.json\\nnode_modules/regjsgen/package.json\\nnode_modules/regjsparser/package.json\\nnode_modules/repeat-string/package.json\\nnode_modules/repeating/package.json\\nnode_modules/request/node_modules/bl/package.json\\nnode_modules/request/node_modules/isarray/package.json\\nnode_modules/request/node_modules/readable-stream/package.json\\nnode_modules/request/package.json\\nnode_modules/resolve/package.json\\nnode_modules/resumer/package.json\\nnode_modules/rfile/node_modules/resolve/package.json\\nnode_modules/rfile/package.json\\nnode_modules/right-align/package.json\\nnode_modules/rimraf/package.json\\nnode_modules/ripemd160/package.json\\nnode_modules/roadrunner/package.json\\nnode_modules/ruglify/node_modules/uglify-js/package.json\\nnode_modules/ruglify/package.json\\nnode_modules/semver/package.json\\nnode_modules/sha.js/package.json\\nnode_modules/shallow-copy/package.json\\nnode_modules/shasum/package.json\\nnode_modules/shell-quote/package.json\\nnode_modules/shelljs/package.json\\nnode_modules/shoe/example/dnode/package.json\\nnode_modules/shoe/example/invert/package.json\\nnode_modules/shoe/node_modules/sockjs-client/package.json\\nnode_modules/shoe/package.json\\nnode_modules/sigmund/package.json\\nnode_modules/signal-exit/package.json\\nnode_modules/simple-fmt/package.json\\nnode_modules/simple-is/package.json\\nnode_modules/smokestack/examples/capture/package.json\\nnode_modules/smokestack/examples/tape/package.json\\nnode_modules/smokestack/node_modules/convert-source-map/package.json\\nnode_modules/smokestack/node_modules/minimist/package.json\\nnode_modules/smokestack/node_modules/readable-stream/package.json\\nnode_modules/smokestack/node_modules/source-map-support/node_modules/source-map/package.json\\nnode_modules/smokestack/node_modules/source-map-support/package.json\\nnode_modules/smokestack/node_modules/source-map/package.json\\nnode_modules/smokestack/node_modules/through2/package.json\\nnode_modules/smokestack/node_modules/xtend/package.json\\nnode_modules/smokestack/package.json\\nnode_modules/sntp/package.json\\nnode_modules/sockjs/examples/echo/package.json\\nnode_modules/sockjs/examples/express-3.x/package.json\\nnode_modules/sockjs/examples/express/package.json\\nnode_modules/sockjs/examples/multiplex/package.json\\nnode_modules/sockjs/examples/test_server/package.json\\nnode_modules/sockjs/node_modules/node-uuid/package.json\\nnode_modules/sockjs/package.json\\nnode_modules/source-map-support/node_modules/source-map/package.json\\nnode_modules/source-map-support/package.json\\nnode_modules/source-map/package.json\\nnode_modules/spdx-correct/package.json\\nnode_modules/spdx-expression-parse/package.json\\nnode_modules/spdx-license-ids/package.json\\nnode_modules/split/package.json\\nnode_modules/stable/package.json\\nnode_modules/stream-browserify/package.json\\nnode_modules/stream-combiner2/node_modules/readable-stream/package.json\\nnode_modules/stream-combiner2/node_modules/through2/package.json\\nnode_modules/stream-combiner2/package.json\\nnode_modules/stream-splicer/package.json\\nnode_modules/string-width/node_modules/ansi-regex/package.json\\nnode_modules/string-width/node_modules/strip-ansi/package.json\\nnode_modules/string-width/package.json\\nnode_modules/string_decoder/package.json\\nnode_modules/stringmap/package.json\\nnode_modules/stringset/package.json\\nnode_modules/stringstream/package.json\\nnode_modules/strip-ansi/package.json\\nnode_modules/strip-bom/package.json\\nnode_modules/strip-indent/package.json\\nnode_modules/strip-json-comments/package.json\\nnode_modules/subarg/node_modules/minimist/package.json\\nnode_modules/subarg/package.json\\nnode_modules/supports-color/package.json\\nnode_modules/syntax-error/node_modules/acorn/package.json\\nnode_modules/syntax-error/package.json\\nnode_modules/synthetic-dom-events/package.json\\nnode_modules/tap-closer/package.json\\nnode_modules/tap-finished/package.json\\nnode_modules/tap-parser/node_modules/split/package.json\\nnode_modules/tap-parser/node_modules/through/package.json\\nnode_modules/tap-parser/package.json\\nnode_modules/tap-spec/node_modules/ansi-regex/package.json\\nnode_modules/tap-spec/node_modules/ansi-styles/package.json\\nnode_modules/tap-spec/node_modules/chalk/package.json\\nnode_modules/tap-spec/node_modules/has-ansi/package.json\\nnode_modules/tap-spec/node_modules/minimist/package.json\\nnode_modules/tap-spec/node_modules/strip-ansi/package.json\\nnode_modules/tap-spec/node_modules/supports-color/package.json\\nnode_modules/tap-spec/node_modules/tap-parser/package.json\\nnode_modules/tap-spec/node_modules/through2/node_modules/readable-stream/package.json\\nnode_modules/tap-spec/node_modules/through2/package.json\\nnode_modules/tap-spec/node_modules/xtend/package.json\\nnode_modules/tap-spec/package.json\\nnode_modules/tape/node_modules/glob/package.json\\nnode_modules/tape/node_modules/minimatch/package.json\\nnode_modules/tape/package.json\\nnode_modules/tar-stream/node_modules/readable-stream/package.json\\nnode_modules/tar-stream/node_modules/xtend/package.json\\nnode_modules/tar-stream/package.json\\nnode_modules/through/package.json\\nnode_modules/through2/node_modules/xtend/package.json\\nnode_modules/through2/package.json\\nnode_modules/timers-browserify/node_modules/process/package.json\\nnode_modules/timers-browserify/package.json\\nnode_modules/tough-cookie/package.json\\nnode_modules/trim-newlines/package.json\\nnode_modules/trim/package.json\\nnode_modules/tryor/package.json\\nnode_modules/tty-browserify/package.json\\nnode_modules/tunnel-agent/package.json\\nnode_modules/typedarray/package.json\\nnode_modules/uglify-js/node_modules/async/package.json\\nnode_modules/uglify-js/node_modules/camelcase/package.json\\nnode_modules/uglify-js/node_modules/source-map/package.json\\nnode_modules/uglify-js/node_modules/window-size/package.json\\nnode_modules/uglify-js/node_modules/yargs/package.json\\nnode_modules/uglify-js/package.json\\nnode_modules/uglify-to-browserify/package.json\\nnode_modules/umd/package.json\\nnode_modules/underscore.string/package.json\\nnode_modules/underscore/package.json\\nnode_modules/url/node_modules/punycode/package.json\\nnode_modules/url/package.json\\nnode_modules/userhome/package.json\\nnode_modules/util-deprecate/package.json\\nnode_modules/util/node_modules/inherits/package.json\\nnode_modules/util/package.json\\nnode_modules/validate-npm-package-license/package.json\\nnode_modules/vargs/package.json\\nnode_modules/vm-browserify/package.json\\nnode_modules/wd/node_modules/ansi-regex/package.json\\nnode_modules/wd/node_modules/ansi-styles/package.json\\nnode_modules/wd/node_modules/async/package.json\\nnode_modules/wd/node_modules/aws-sign2/package.json\\nnode_modules/wd/node_modules/caseless/package.json\\nnode_modules/wd/node_modules/chalk/package.json\\nnode_modules/wd/node_modules/combined-stream/package.json\\nnode_modules/wd/node_modules/commander/package.json\\nnode_modules/wd/node_modules/delayed-stream/package.json\\nnode_modules/wd/node_modules/form-data/node_modules/async/package.json\\nnode_modules/wd/node_modules/form-data/package.json\\nnode_modules/wd/node_modules/har-validator/package.json\\nnode_modules/wd/node_modules/has-ansi/package.json\\nnode_modules/wd/node_modules/hawk/package.json\\nnode_modules/wd/node_modules/http-signature/package.json\\nnode_modules/wd/node_modules/lodash/package.json\\nnode_modules/wd/node_modules/mime-db/package.json\\nnode_modules/wd/node_modules/mime-types/package.json\\nnode_modules/wd/node_modules/oauth-sign/package.json\\nnode_modules/wd/node_modules/qs/package.json\\nnode_modules/wd/node_modules/request/package.json\\nnode_modules/wd/node_modules/strip-ansi/package.json\\nnode_modules/wd/node_modules/supports-color/package.json\\nnode_modules/wd/package.json\\nnode_modules/which/package.json\\nnode_modules/window-size/package.json\\nnode_modules/wordwrap/package.json\\nnode_modules/wrap-ansi/package.json\\nnode_modules/wrappy/package.json\\nnode_modules/xhr/node_modules/xtend/package.json\\nnode_modules/xhr/package.json\\nnode_modules/xtend/package.json\\nnode_modules/y18n/package.json\\nnode_modules/yargs/node_modules/camelcase/package.json\\nnode_modules/yargs/package.json\\nnode_modules/zip-stream/node_modules/lodash/package.json\\nnode_modules/zip-stream/node_modules/readable-stream/package.json\\nnode_modules/zip-stream/package.json"
      }
    ]
  },
  "components": [
    {
      "authors": [
        {
          "name": "Chris Talkington (http://christalkington.com/)"
        }
      ],
      "group": "",
      "name": "zip-stream",
      "version": "0.5.2",
      "description": "a streaming zip archive generator.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/zip-stream@0.5.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/archiverjs/node-zip-stream"
        },
        {
          "type": "vcs",
          "url": "https://github.com/archiverjs/node-zip-stream.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/zip-stream@0.5.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/zip-stream/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/zip-stream/package.json"
              }
            ],
            "concludedValue": "node_modules/zip-stream/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "readable-stream",
      "version": "1.0.34",
      "description": "Streams2, a user-land copy of the stream library from Node.js v0.10.x",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/readable-stream@1.0.34",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/readable-stream"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/readable-stream@1.0.34",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/zip-stream/node_modules/readable-stream/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/tar-stream/node_modules/readable-stream/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/tap-spec/node_modules/through2/node_modules/readable-stream/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/stream-combiner2/node_modules/readable-stream/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/smokestack/node_modules/readable-stream/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/readdirp/node_modules/readable-stream/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/lazystream/node_modules/readable-stream/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/glsl-tokenizer/node_modules/readable-stream/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/crc32-stream/node_modules/readable-stream/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/compress-commons/node_modules/readable-stream/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/browser-pack/node_modules/readable-stream/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/bl/node_modules/readable-stream/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/archiver/node_modules/readable-stream/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/archiver/node_modules/readable-stream/package.json"
              }
            ],
            "concludedValue": "node_modules/archiver/node_modules/readable-stream/package.json"
          }
        ]
      },
      "tags": [
        "stream"
      ]
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash",
      "version": "3.2.0",
      "description": "The modern build of lodash modular utilities.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/lodash@3.2.0",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash@3.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/zip-stream/node_modules/lodash/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/archiver/node_modules/lodash/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/archiver/node_modules/lodash/package.json"
              }
            ],
            "concludedValue": "node_modules/archiver/node_modules/lodash/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Alex Ford <Alex.Ford@CodeTunnel.com> (http://CodeTunnel.com)"
        }
      ],
      "group": "",
      "name": "yargs",
      "version": "3.27.0",
      "description": "Light-weight option parsing with an argv hash. No optstrings attached.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/yargs@3.27.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/bcoe/yargs.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/yargs@3.27.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/yargs/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/yargs/package.json"
              }
            ],
            "concludedValue": "node_modules/yargs/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (http://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "camelcase",
      "version": "1.2.1",
      "description": "Convert a dash/dot/underscore/space separated string to camelCase: foo-bar → fooBar",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/camelcase@1.2.1",
      "type": "library",
      "bom-ref": "pkg:npm/camelcase@1.2.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/yargs/node_modules/camelcase/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/uglify-js/node_modules/camelcase/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/localtunnel/node_modules/camelcase/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/localtunnel/node_modules/camelcase/package.json"
              }
            ],
            "concludedValue": "node_modules/localtunnel/node_modules/camelcase/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Ben Coe <ben@npmjs.com>"
        }
      ],
      "group": "",
      "name": "y18n",
      "version": "3.2.1",
      "description": "the bare-bones internationalization library used by yargs",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/y18n@3.2.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/yargs/y18n"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/y18n@3.2.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/y18n/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/y18n/package.json"
              }
            ],
            "concludedValue": "node_modules/y18n/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Raynos <raynos2@gmail.com>"
        }
      ],
      "group": "",
      "name": "xtend",
      "version": "3.0.0",
      "description": "extend like a boss",
      "scope": "optional",
      "purl": "pkg:npm/xtend@3.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/Raynos/xtend"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/xtend@3.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/xtend/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/xtend/package.json"
              }
            ],
            "concludedValue": "node_modules/xtend/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Raynos <raynos2@gmail.com>"
        }
      ],
      "group": "",
      "name": "xhr",
      "version": "2.2.2",
      "description": "small xhr abstraction",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/xhr@2.2.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/Raynos/xhr"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/xhr@2.2.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/xhr/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/xhr/package.json"
              }
            ],
            "concludedValue": "node_modules/xhr/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Raynos <raynos2@gmail.com>"
        }
      ],
      "group": "",
      "name": "xtend",
      "version": "4.0.1",
      "description": "extend like a boss",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/xtend@4.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/Raynos/xtend"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/xtend@4.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/xhr/node_modules/xtend/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/through2/node_modules/xtend/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/tar-stream/node_modules/xtend/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/tap-spec/node_modules/xtend/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/smokestack/node_modules/xtend/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/module-deps/node_modules/xtend/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/is-my-json-valid/node_modules/xtend/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/insert-module-globals/node_modules/xtend/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/glsl-tokenizer/node_modules/xtend/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/glsl-tokenizer/node_modules/xtend/package.json"
              }
            ],
            "concludedValue": "node_modules/glsl-tokenizer/node_modules/xtend/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "wrappy",
      "version": "1.0.2",
      "description": "Callback wrapping utility",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/wrappy@1.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/npm/wrappy"
        },
        {
          "type": "vcs",
          "url": "https://github.com/npm/wrappy"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/wrappy@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/wrappy/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/wrappy/package.json"
              }
            ],
            "concludedValue": "node_modules/wrappy/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "wrap-ansi",
      "version": "2.0.0",
      "description": "Wordwrap a string with ANSI escape codes",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/wrap-ansi@2.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/wrap-ansi@2.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/wrap-ansi/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/wrap-ansi/package.json"
              }
            ],
            "concludedValue": "node_modules/wrap-ansi/package.json"
          }
        ]
      },
      "tags": [
        "escape"
      ]
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "wordwrap",
      "version": "0.0.2",
      "description": "Wrap those words. Show them at what columns to start and stop.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "name": "MIT/X11"
          }
        }
      ],
      "purl": "pkg:npm/wordwrap@0.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/substack/node-wordwrap.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/wordwrap@0.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/wordwrap/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/wordwrap/package.json"
              }
            ],
            "concludedValue": "node_modules/wordwrap/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jon Schlinkert (https://github.com/jonschlinkert)"
        }
      ],
      "group": "",
      "name": "window-size",
      "version": "0.1.4",
      "description": "Reliable way to to get the height and width of the terminal/console in a node.js environment.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/window-size@0.1.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jonschlinkert/window-size"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/window-size@0.1.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/window-size/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/window-size/package.json"
              }
            ],
            "concludedValue": "node_modules/window-size/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me)"
        }
      ],
      "group": "",
      "name": "which",
      "version": "1.2.11",
      "description": "Like which(1) unix command. Find the first instance of an executable in the PATH.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/which@1.2.11",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/node-which.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/which@1.2.11",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/which/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/which/package.json"
              }
            ],
            "concludedValue": "node_modules/which/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Adam Christian <adam.christian@gmail.com>"
        }
      ],
      "group": "",
      "name": "wd",
      "version": "0.3.12",
      "description": "WebDriver/Selenium 2 node.js client",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0",
            "url": "https://opensource.org/licenses/Apache-2.0"
          }
        }
      ],
      "purl": "pkg:npm/wd@0.3.12",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/admc/wd.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/wd@0.3.12",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/wd/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/wd/package.json"
              }
            ],
            "concludedValue": "node_modules/wd/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "supports-color",
      "version": "2.0.0",
      "description": "Detect whether a terminal supports color",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/supports-color@2.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/supports-color@2.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/wd/node_modules/supports-color/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/tap-spec/node_modules/supports-color/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/har-validator/node_modules/supports-color/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/har-validator/node_modules/supports-color/package.json"
              }
            ],
            "concludedValue": "node_modules/har-validator/node_modules/supports-color/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "strip-ansi",
      "version": "3.0.1",
      "description": "Strip ANSI escape codes",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/strip-ansi@3.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/strip-ansi@3.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/wd/node_modules/strip-ansi/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/tap-spec/node_modules/strip-ansi/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/string-width/node_modules/strip-ansi/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/localtunnel/node_modules/strip-ansi/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/har-validator/node_modules/strip-ansi/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/har-validator/node_modules/strip-ansi/package.json"
              }
            ],
            "concludedValue": "node_modules/har-validator/node_modules/strip-ansi/package.json"
          }
        ]
      },
      "tags": [
        "escape"
      ]
    },
    {
      "authors": [
        {
          "name": "Mikeal Rogers <mikeal.rogers@gmail.com>"
        }
      ],
      "group": "",
      "name": "request",
      "version": "2.55.0",
      "description": "Simplified HTTP request client.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0",
            "url": "https://opensource.org/licenses/Apache-2.0"
          }
        }
      ],
      "purl": "pkg:npm/request@2.55.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/request/request.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/request@2.55.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/wd/node_modules/request/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/wd/node_modules/request/package.json"
              }
            ],
            "concludedValue": "node_modules/wd/node_modules/request/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "qs",
      "version": "2.4.2",
      "description": "A querystring parser that supports nesting and arrays, with a depth limit",
      "scope": "optional",
      "purl": "pkg:npm/qs@2.4.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/hapijs/qs"
        },
        {
          "type": "vcs",
          "url": "https://github.com/hapijs/qs.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/qs@2.4.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/wd/node_modules/qs/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/wd/node_modules/qs/package.json"
              }
            ],
            "concludedValue": "node_modules/wd/node_modules/qs/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mikeal Rogers <mikeal.rogers@gmail.com> (http://www.futurealoof.com)"
        }
      ],
      "group": "",
      "name": "oauth-sign",
      "version": "0.6.0",
      "description": "OAuth 1 signing. Formerly a vendor lib in mikeal/request, now a standalone module.",
      "scope": "optional",
      "purl": "pkg:npm/oauth-sign@0.6.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mikeal/oauth-sign"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/oauth-sign@0.6.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/wd/node_modules/oauth-sign/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/wd/node_modules/oauth-sign/package.json"
              }
            ],
            "concludedValue": "node_modules/wd/node_modules/oauth-sign/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "mime-types",
      "version": "2.0.14",
      "description": "The ultimate javascript content-type utility.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/mime-types@2.0.14",
      "type": "library",
      "bom-ref": "pkg:npm/mime-types@2.0.14",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/wd/node_modules/mime-types/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/wd/node_modules/mime-types/package.json"
              }
            ],
            "concludedValue": "node_modules/wd/node_modules/mime-types/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "mime-db",
      "version": "1.12.0",
      "description": "Media Type Database",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/mime-db@1.12.0",
      "type": "library",
      "bom-ref": "pkg:npm/mime-db@1.12.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/wd/node_modules/mime-db/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/wd/node_modules/mime-db/package.json"
              }
            ],
            "concludedValue": "node_modules/wd/node_modules/mime-db/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash",
      "version": "3.9.3",
      "description": "The modern build of lodash modular utilities.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/lodash@3.9.3",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash@3.9.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/wd/node_modules/lodash/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/wd/node_modules/lodash/package.json"
              }
            ],
            "concludedValue": "node_modules/wd/node_modules/lodash/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Joyent"
        },
        {
          "name": " Inc"
        }
      ],
      "group": "",
      "name": "http-signature",
      "version": "0.10.1",
      "description": "Reference implementation of Joyent's HTTP Signature scheme.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/http-signature@0.10.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/joyent/node-http-signature/"
        },
        {
          "type": "vcs",
          "url": "git://github.com/joyent/node-http-signature.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/http-signature@0.10.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/wd/node_modules/http-signature/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/wd/node_modules/http-signature/package.json"
              }
            ],
            "concludedValue": "node_modules/wd/node_modules/http-signature/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Eran Hammer <eran@hammer.io> (http://hueniverse.com)"
        }
      ],
      "group": "",
      "name": "hawk",
      "version": "2.3.1",
      "description": "HTTP Hawk Authentication Scheme",
      "scope": "optional",
      "purl": "pkg:npm/hawk@2.3.1",
      "type": "library",
      "bom-ref": "pkg:npm/hawk@2.3.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/wd/node_modules/hawk/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/wd/node_modules/hawk/package.json"
              }
            ],
            "concludedValue": "node_modules/wd/node_modules/hawk/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "has-ansi",
      "version": "2.0.0",
      "description": "Check if a string has ANSI escape codes",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/has-ansi@2.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/has-ansi@2.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/wd/node_modules/has-ansi/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/tap-spec/node_modules/has-ansi/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/har-validator/node_modules/has-ansi/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/har-validator/node_modules/has-ansi/package.json"
              }
            ],
            "concludedValue": "node_modules/har-validator/node_modules/has-ansi/package.json"
          }
        ]
      },
      "tags": [
        "escape"
      ]
    },
    {
      "authors": [
        {
          "name": "Ahmad Nassri <ahmad@ahmadnassri.com> (https://www.ahmadnassri.com/)"
        }
      ],
      "group": "",
      "name": "har-validator",
      "version": "1.8.0",
      "description": "Extremely fast HTTP Archive (HAR) validator using JSON Schema",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/har-validator@1.8.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/ahmadnassri/har-validator"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/har-validator@1.8.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/wd/node_modules/har-validator/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/wd/node_modules/har-validator/package.json"
              }
            ],
            "concludedValue": "node_modules/wd/node_modules/har-validator/package.json"
          }
        ]
      },
      "tags": [
        "json"
      ]
    },
    {
      "authors": [
        {
          "name": "Felix Geisendörfer <felix@debuggable.com> (http://debuggable.com/)"
        }
      ],
      "group": "",
      "name": "form-data",
      "version": "0.2.0",
      "description": "A module to create readable \"multipart/form-data\" streams.  Can be used to submit forms and file uploads to other web applications.",
      "scope": "optional",
      "purl": "pkg:npm/form-data@0.2.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/felixge/node-form-data.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/form-data@0.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/wd/node_modules/form-data/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/wd/node_modules/form-data/package.json"
              }
            ],
            "concludedValue": "node_modules/wd/node_modules/form-data/package.json"
          }
        ]
      },
      "tags": [
        "web"
      ]
    },
    {
      "authors": [
        {
          "name": "Caolan McMahon"
        }
      ],
      "group": "",
      "name": "async",
      "version": "0.9.2",
      "description": "Higher-order functions and common patterns for asynchronous code",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/async@0.9.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/caolan/async.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/async@0.9.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/wd/node_modules/form-data/node_modules/async/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/archiver/node_modules/async/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/archiver/node_modules/async/package.json"
              }
            ],
            "concludedValue": "node_modules/archiver/node_modules/async/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Felix Geisendörfer <felix@debuggable.com> (http://debuggable.com/)"
        }
      ],
      "group": "",
      "name": "delayed-stream",
      "version": "0.0.5",
      "description": "Buffers events from a stream until you are ready to handle them.",
      "scope": "optional",
      "purl": "pkg:npm/delayed-stream@0.0.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/felixge/node-delayed-stream"
        },
        {
          "type": "vcs",
          "url": "git://github.com/felixge/node-delayed-stream.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/delayed-stream@0.0.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/wd/node_modules/delayed-stream/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/wd/node_modules/delayed-stream/package.json"
              }
            ],
            "concludedValue": "node_modules/wd/node_modules/delayed-stream/package.json"
          }
        ]
      },
      "tags": [
        "stream"
      ]
    },
    {
      "authors": [
        {
          "name": "TJ Holowaychuk <tj@vision-media.ca>"
        }
      ],
      "group": "",
      "name": "commander",
      "version": "2.9.0",
      "description": "the complete solution for node.js command-line programs",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/commander@2.9.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/tj/commander.js.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/commander@2.9.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/wd/node_modules/commander/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/har-validator/node_modules/commander/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/har-validator/node_modules/commander/package.json"
              }
            ],
            "concludedValue": "node_modules/har-validator/node_modules/commander/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Felix Geisendörfer <felix@debuggable.com> (http://debuggable.com/)"
        }
      ],
      "group": "",
      "name": "combined-stream",
      "version": "0.0.7",
      "description": "A stream that emits multiple other streams one after another.",
      "scope": "optional",
      "purl": "pkg:npm/combined-stream@0.0.7",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/felixge/node-combined-stream"
        },
        {
          "type": "vcs",
          "url": "git://github.com/felixge/node-combined-stream.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/combined-stream@0.0.7",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/wd/node_modules/combined-stream/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/wd/node_modules/combined-stream/package.json"
              }
            ],
            "concludedValue": "node_modules/wd/node_modules/combined-stream/package.json"
          }
        ]
      },
      "tags": [
        "stream"
      ]
    },
    {
      "group": "",
      "name": "chalk",
      "version": "1.1.3",
      "description": "Terminal string styling done right. Much color.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/chalk@1.1.3",
      "type": "library",
      "bom-ref": "pkg:npm/chalk@1.1.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/wd/node_modules/chalk/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/tap-spec/node_modules/chalk/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/har-validator/node_modules/chalk/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/har-validator/node_modules/chalk/package.json"
              }
            ],
            "concludedValue": "node_modules/har-validator/node_modules/chalk/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mikeal Rogers <mikeal.rogers@gmail.com>"
        }
      ],
      "group": "",
      "name": "caseless",
      "version": "0.9.0",
      "description": "Caseless object set/get/has, very useful when working with HTTP headers.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "name": "BSD"
          }
        }
      ],
      "purl": "pkg:npm/caseless@0.9.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mikeal/caseless"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/caseless@0.9.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/wd/node_modules/caseless/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/wd/node_modules/caseless/package.json"
              }
            ],
            "concludedValue": "node_modules/wd/node_modules/caseless/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mikeal Rogers <mikeal.rogers@gmail.com> (http://www.futurealoof.com)"
        }
      ],
      "group": "",
      "name": "aws-sign2",
      "version": "0.5.0",
      "description": "AWS signing. Originally pulled from LearnBoost/knox, maintained as vendor in request, now a standalone module.",
      "scope": "optional",
      "purl": "pkg:npm/aws-sign2@0.5.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mikeal/aws-sign"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/aws-sign2@0.5.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/wd/node_modules/aws-sign2/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/wd/node_modules/aws-sign2/package.json"
              }
            ],
            "concludedValue": "node_modules/wd/node_modules/aws-sign2/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Caolan McMahon"
        }
      ],
      "group": "",
      "name": "async",
      "version": "1.0.0",
      "description": "Higher-order functions and common patterns for asynchronous code",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/async@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/caolan/async.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/async@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/wd/node_modules/async/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/wd/node_modules/async/package.json"
              }
            ],
            "concludedValue": "node_modules/wd/node_modules/async/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "ansi-styles",
      "version": "2.2.1",
      "description": "ANSI escape codes for styling strings in the terminal",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/ansi-styles@2.2.1",
      "type": "library",
      "bom-ref": "pkg:npm/ansi-styles@2.2.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/wd/node_modules/ansi-styles/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/tap-spec/node_modules/ansi-styles/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/har-validator/node_modules/ansi-styles/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/har-validator/node_modules/ansi-styles/package.json"
              }
            ],
            "concludedValue": "node_modules/har-validator/node_modules/ansi-styles/package.json"
          }
        ]
      },
      "tags": [
        "escape"
      ]
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "ansi-regex",
      "version": "2.0.0",
      "description": "Regular expression for matching ANSI escape codes",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/ansi-regex@2.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/ansi-regex@2.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/wd/node_modules/ansi-regex/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/tap-spec/node_modules/ansi-regex/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/string-width/node_modules/ansi-regex/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/localtunnel/node_modules/ansi-regex/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/har-validator/node_modules/ansi-regex/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/har-validator/node_modules/ansi-regex/package.json"
              }
            ],
            "concludedValue": "node_modules/har-validator/node_modules/ansi-regex/package.json"
          }
        ]
      },
      "tags": [
        "escape"
      ]
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "vm-browserify",
      "version": "0.0.4",
      "description": "vm module for the browser",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/vm-browserify@0.0.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/substack/vm-browserify.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/vm-browserify@0.0.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/vm-browserify/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/vm-browserify/package.json"
              }
            ],
            "concludedValue": "node_modules/vm-browserify/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Alexis Sellier <self@cloudhead.net>"
        }
      ],
      "group": "",
      "name": "vargs",
      "version": "0.1.0",
      "description": "practical variable argument handling",
      "scope": "optional",
      "purl": "pkg:npm/vargs@0.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/vargs@0.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/vargs/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/vargs/package.json"
              }
            ],
            "concludedValue": "node_modules/vargs/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Kyle E. Mitchell <kyle@kemitchell.com> (https://kemitchell.com)"
        }
      ],
      "group": "",
      "name": "validate-npm-package-license",
      "version": "3.0.1",
      "description": "Give me a string and I'll tell you if it's a valid npm package license string",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0",
            "url": "https://opensource.org/licenses/Apache-2.0"
          }
        }
      ],
      "purl": "pkg:npm/validate-npm-package-license@3.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/validate-npm-package-license@3.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/validate-npm-package-license/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/validate-npm-package-license/package.json"
              }
            ],
            "concludedValue": "node_modules/validate-npm-package-license/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Nathan Rajlich <nathan@tootallnate.net> (http://n8.io/)"
        }
      ],
      "group": "",
      "name": "util-deprecate",
      "version": "1.0.2",
      "description": "The Node.js `util.deprecate()` function with browser support",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/util-deprecate@1.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/TooTallNate/util-deprecate"
        },
        {
          "type": "vcs",
          "url": "git://github.com/TooTallNate/util-deprecate.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/util-deprecate@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/util-deprecate/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/util-deprecate/package.json"
              }
            ],
            "concludedValue": "node_modules/util-deprecate/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Joyent (http://www.joyent.com)"
        }
      ],
      "group": "",
      "name": "util",
      "version": "0.10.3",
      "description": "Node.JS util module",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/util@0.10.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/defunctzombie/node-util"
        },
        {
          "type": "vcs",
          "url": "git://github.com/defunctzombie/node-util"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/util@0.10.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/util/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/util/package.json"
              }
            ],
            "concludedValue": "node_modules/util/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "inherits",
      "version": "2.0.1",
      "description": "Browser-friendly inheritance fully compatible with standard node.js inherits()",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/inherits@2.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/inherits@2.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/util/node_modules/inherits/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/util/node_modules/inherits/package.json"
              }
            ],
            "concludedValue": "node_modules/util/node_modules/inherits/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Kyle Robinson Young <kyle@dontkry.com> (http://dontkry.com)"
        }
      ],
      "group": "",
      "name": "userhome",
      "version": "1.0.0",
      "description": "A cross-platform path to the user's home",
      "scope": "optional",
      "purl": "pkg:npm/userhome@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/shama/userhome"
        },
        {
          "type": "vcs",
          "url": "git://github.com/shama/userhome.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/userhome@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/userhome/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/userhome/package.json"
              }
            ],
            "concludedValue": "node_modules/userhome/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "url",
      "version": "0.10.3",
      "description": "The core `url` packaged standalone for use with Browserify.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/url@0.10.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/defunctzombie/node-url.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/url@0.10.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/url/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/url/package.json"
              }
            ],
            "concludedValue": "node_modules/url/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mathias Bynens (https://mathiasbynens.be/)"
        }
      ],
      "group": "",
      "name": "punycode",
      "version": "1.3.2",
      "description": "A robust Punycode converter that fully complies to RFC 3492 and RFC 5891, and works on nearly all JavaScript platforms.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/punycode@1.3.2",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://mths.be/punycode"
        },
        {
          "type": "vcs",
          "url": "https://github.com/bestiejs/punycode.js.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/punycode@1.3.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/url/node_modules/punycode/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/url/node_modules/punycode/package.json"
              }
            ],
            "concludedValue": "node_modules/url/node_modules/punycode/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "underscore.string",
      "version": "3.0.3",
      "description": "String manipulation extensions for Underscore.js javascript library.",
      "scope": "optional",
      "purl": "pkg:npm/underscore.string@3.0.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://epeli.github.com/underscore.string/"
        },
        {
          "type": "vcs",
          "url": "https://github.com/epeli/underscore.string.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/underscore.string@3.0.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/underscore.string/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/underscore.string/package.json"
              }
            ],
            "concludedValue": "node_modules/underscore.string/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jeremy Ashkenas <jeremy@documentcloud.org>"
        }
      ],
      "group": "",
      "name": "underscore",
      "version": "1.6.0",
      "description": "JavaScript's functional programming helper library.",
      "scope": "optional",
      "purl": "pkg:npm/underscore@1.6.0",
      "externalReferences": [
        {
          "type": "website",
          "url": "http://underscorejs.org"
        },
        {
          "type": "vcs",
          "url": "git://github.com/jashkenas/underscore.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/underscore@1.6.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/underscore/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/underscore/package.json"
              }
            ],
            "concludedValue": "node_modules/underscore/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "ForbesLindesay"
        }
      ],
      "group": "",
      "name": "umd",
      "version": "2.1.0",
      "description": "Universal Module Definition for use in automated build systems",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/umd@2.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/ForbesLindesay/umd.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/umd@2.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/umd/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/umd/package.json"
              }
            ],
            "concludedValue": "node_modules/umd/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "ForbesLindesay"
        }
      ],
      "group": "",
      "name": "uglify-to-browserify",
      "version": "1.0.2",
      "description": "A transform to make UglifyJS work in browserify.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/uglify-to-browserify@1.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/ForbesLindesay/uglify-to-browserify.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/uglify-to-browserify@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/uglify-to-browserify/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/uglify-to-browserify/package.json"
              }
            ],
            "concludedValue": "node_modules/uglify-to-browserify/package.json"
          }
        ]
      },
      "tags": [
        "transform"
      ]
    },
    {
      "authors": [
        {
          "name": "Mihai Bazon <mihai.bazon@gmail.com> (http://lisperator.net/)"
        }
      ],
      "group": "",
      "name": "uglify-js",
      "version": "2.4.24",
      "description": "JavaScript parser, mangler/compressor and beautifier toolkit",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "name": "BSD"
          }
        }
      ],
      "purl": "pkg:npm/uglify-js@2.4.24",
      "externalReferences": [
        {
          "type": "website",
          "url": "http://lisperator.net/uglifyjs"
        },
        {
          "type": "vcs",
          "url": "https://github.com/mishoo/UglifyJS2.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/uglify-js@2.4.24",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/uglify-js/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/uglify-js/package.json"
              }
            ],
            "concludedValue": "node_modules/uglify-js/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Alex Ford <Alex.Ford@CodeTunnel.com> (http://CodeTunnel.com)"
        }
      ],
      "group": "",
      "name": "yargs",
      "version": "3.5.4",
      "description": "Light-weight option parsing with an argv hash. No optstrings attached.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "name": "MIT/X11"
          }
        }
      ],
      "purl": "pkg:npm/yargs@3.5.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/bcoe/yargs.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/yargs@3.5.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/uglify-js/node_modules/yargs/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/uglify-js/node_modules/yargs/package.json"
              }
            ],
            "concludedValue": "node_modules/uglify-js/node_modules/yargs/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jon Schlinkert (https://github.com/jonschlinkert)"
        }
      ],
      "group": "",
      "name": "window-size",
      "version": "0.1.0",
      "description": "Reliable way to to get the height and width of the terminal/console in a node.js environment.",
      "scope": "optional",
      "purl": "pkg:npm/window-size@0.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jonschlinkert/window-size"
        },
        {
          "type": "vcs",
          "url": "https://github.com/jonschlinkert/window-size.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/window-size@0.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/uglify-js/node_modules/window-size/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/uglify-js/node_modules/window-size/package.json"
              }
            ],
            "concludedValue": "node_modules/uglify-js/node_modules/window-size/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Nick Fitzgerald <nfitzgerald@mozilla.com>"
        }
      ],
      "group": "",
      "name": "source-map",
      "version": "0.1.34",
      "description": "Generates and consumes source maps",
      "scope": "optional",
      "purl": "pkg:npm/source-map@0.1.34",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mozilla/source-map"
        },
        {
          "type": "vcs",
          "url": "http://github.com/mozilla/source-map.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/source-map@0.1.34",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/uglify-js/node_modules/source-map/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/uglify-js/node_modules/source-map/package.json"
              }
            ],
            "concludedValue": "node_modules/uglify-js/node_modules/source-map/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Caolan McMahon"
        }
      ],
      "group": "",
      "name": "async",
      "version": "0.2.10",
      "description": "Higher-order functions and common patterns for asynchronous code",
      "scope": "optional",
      "purl": "pkg:npm/async@0.2.10",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/caolan/async.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/async@0.2.10",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/uglify-js/node_modules/async/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/uglify-js/node_modules/async/package.json"
              }
            ],
            "concludedValue": "node_modules/uglify-js/node_modules/async/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "typedarray",
      "version": "0.0.6",
      "description": "TypedArray polyfill for old browsers",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/typedarray@0.0.6",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/typedarray"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/typedarray.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/typedarray@0.0.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/typedarray/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/typedarray/package.json"
              }
            ],
            "concludedValue": "node_modules/typedarray/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mikeal Rogers <mikeal.rogers@gmail.com> (http://www.futurealoof.com)"
        }
      ],
      "group": "",
      "name": "tunnel-agent",
      "version": "0.4.3",
      "description": "HTTP proxy tunneling agent. Formerly part of mikeal/request, now a standalone module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0",
            "url": "https://opensource.org/licenses/Apache-2.0"
          }
        }
      ],
      "purl": "pkg:npm/tunnel-agent@0.4.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mikeal/tunnel-agent"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/tunnel-agent@0.4.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tunnel-agent/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tunnel-agent/package.json"
              }
            ],
            "concludedValue": "node_modules/tunnel-agent/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "tty-browserify",
      "version": "0.0.0",
      "description": "the tty module from node core for browsers",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/tty-browserify@0.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/tty-browserify"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/tty-browserify.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/tty-browserify@0.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tty-browserify/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tty-browserify/package.json"
              }
            ],
            "concludedValue": "node_modules/tty-browserify/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Olov Lassus <olov.lassus@gmail.com>"
        }
      ],
      "group": "",
      "name": "tryor",
      "version": "0.1.2",
      "description": "return fn() or default value (in case of exception)",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/tryor@0.1.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/olov/tryor.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/tryor@0.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tryor/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tryor/package.json"
              }
            ],
            "concludedValue": "node_modules/tryor/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "trim-newlines",
      "version": "1.0.0",
      "description": "Trim newlines from the start and/or end of a string",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/trim-newlines@1.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/trim-newlines@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/trim-newlines/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/trim-newlines/package.json"
              }
            ],
            "concludedValue": "node_modules/trim-newlines/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "TJ Holowaychuk <tj@vision-media.ca>"
        }
      ],
      "group": "",
      "name": "trim",
      "version": "0.0.1",
      "description": "Trim string whitespace",
      "scope": "optional",
      "purl": "pkg:npm/trim@0.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/trim@0.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/trim/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/trim/package.json"
              }
            ],
            "concludedValue": "node_modules/trim/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jeremy Stashewsky <jstashewsky@salesforce.com>"
        }
      ],
      "group": "",
      "name": "tough-cookie",
      "version": "2.2.2",
      "description": "RFC6265 Cookies and Cookie Jar for node.js",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-3-Clause",
            "url": "https://opensource.org/licenses/BSD-3-Clause"
          }
        }
      ],
      "purl": "pkg:npm/tough-cookie@2.2.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/SalesforceEng/tough-cookie"
        },
        {
          "type": "vcs",
          "url": "git://github.com/SalesforceEng/tough-cookie.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/tough-cookie@2.2.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tough-cookie/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tough-cookie/package.json"
              }
            ],
            "concludedValue": "node_modules/tough-cookie/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "J. Ryan Stinnett <jryans@gmail.com> (http://convolv.es/)"
        }
      ],
      "group": "",
      "name": "timers-browserify",
      "version": "1.4.2",
      "description": "timers module for browserify",
      "scope": "optional",
      "purl": "pkg:npm/timers-browserify@1.4.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jryans/timers-browserify"
        },
        {
          "type": "vcs",
          "url": "git://github.com/jryans/timers-browserify.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/timers-browserify@1.4.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/timers-browserify/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/timers-browserify/package.json"
              }
            ],
            "concludedValue": "node_modules/timers-browserify/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Roman Shtylman <shtylman@gmail.com>"
        }
      ],
      "group": "",
      "name": "process",
      "version": "0.11.9",
      "description": "process information for node.js and browsers",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/process@0.11.9",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/shtylman/node-process.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/process@0.11.9",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/timers-browserify/node_modules/process/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/insert-module-globals/node_modules/process/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/insert-module-globals/node_modules/process/package.json"
              }
            ],
            "concludedValue": "node_modules/insert-module-globals/node_modules/process/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Rod Vagg <r@va.gg> (https://github.com/rvagg)"
        }
      ],
      "group": "",
      "name": "through2",
      "version": "1.1.1",
      "description": "A tiny wrapper around Node streams2 Transform to avoid explicit subclassing noise",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/through2@1.1.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/rvagg/through2.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/through2@1.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/through2/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/through2/package.json"
              }
            ],
            "concludedValue": "node_modules/through2/package.json"
          }
        ]
      },
      "tags": [
        "transform"
      ]
    },
    {
      "authors": [
        {
          "name": "Dominic Tarr <dominic.tarr@gmail.com> (dominictarr.com)"
        }
      ],
      "group": "",
      "name": "through",
      "version": "2.3.4",
      "description": "simplified stream contsruction",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/through@2.3.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/dominictarr/through"
        },
        {
          "type": "vcs",
          "url": "https://github.com/dominictarr/through.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/through@2.3.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/through/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/through/package.json"
              }
            ],
            "concludedValue": "node_modules/through/package.json"
          }
        ]
      },
      "tags": [
        "stream"
      ]
    },
    {
      "authors": [
        {
          "name": "Mathias Buus <mathiasbuus@gmail.com>"
        }
      ],
      "group": "",
      "name": "tar-stream",
      "version": "1.1.5",
      "description": "tar-stream is a streaming tar parser and generator and nothing else. It is streams2 and operates purely using streams which means you can easily extract/parse tarballs without ever hitting the file system.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/tar-stream@1.1.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mafintosh/tar-stream"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/mafintosh/tar-stream.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/tar-stream@1.1.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tar-stream/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tar-stream/package.json"
              }
            ],
            "concludedValue": "node_modules/tar-stream/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "tape",
      "version": "3.6.1",
      "description": "tap-producing test harness for node and browsers",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/tape@3.6.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/tape"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/tape.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/tape@3.6.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tape/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tape/package.json"
              }
            ],
            "concludedValue": "node_modules/tape/package.json"
          }
        ]
      },
      "tags": [
        "test"
      ]
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me)"
        }
      ],
      "group": "",
      "name": "minimatch",
      "version": "0.3.0",
      "description": "a glob matcher in javascript",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/minimatch@0.3.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/minimatch.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/minimatch@0.3.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tape/node_modules/minimatch/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/cli/node_modules/minimatch/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/cli/node_modules/minimatch/package.json"
              }
            ],
            "concludedValue": "node_modules/cli/node_modules/minimatch/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "glob",
      "version": "3.2.11",
      "description": "a little globber",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "name": "BSD"
          }
        }
      ],
      "purl": "pkg:npm/glob@3.2.11",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/node-glob.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/glob@3.2.11",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tape/node_modules/glob/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/cli/node_modules/glob/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/cli/node_modules/glob/package.json"
              }
            ],
            "concludedValue": "node_modules/cli/node_modules/glob/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Scott Corgan"
        }
      ],
      "group": "",
      "name": "tap-spec",
      "version": "2.2.2",
      "description": "Formatted TAP output like Mocha's spec reporter",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/tap-spec@2.2.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/scottcorgan/tap-spec.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/tap-spec@2.2.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tap-spec/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tap-spec/package.json"
              }
            ],
            "concludedValue": "node_modules/tap-spec/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Rod Vagg <r@va.gg> (https://github.com/rvagg)"
        }
      ],
      "group": "",
      "name": "through2",
      "version": "0.6.5",
      "description": "A tiny wrapper around Node streams2 Transform to avoid explicit subclassing noise",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/through2@0.6.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/rvagg/through2.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/through2@0.6.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tap-spec/node_modules/through2/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/smokestack/node_modules/through2/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/glsl-tokenizer/node_modules/through2/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/glsl-tokenizer/node_modules/through2/package.json"
              }
            ],
            "concludedValue": "node_modules/glsl-tokenizer/node_modules/through2/package.json"
          }
        ]
      },
      "tags": [
        "transform"
      ]
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "tap-parser",
      "version": "0.7.0",
      "description": "parse the test anything protocol",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/tap-parser@0.7.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/tap-parser"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/tap-parser.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/tap-parser@0.7.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tap-spec/node_modules/tap-parser/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tap-spec/node_modules/tap-parser/package.json"
              }
            ],
            "concludedValue": "node_modules/tap-spec/node_modules/tap-parser/package.json"
          }
        ]
      },
      "tags": [
        "parse",
        "test"
      ]
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "minimist",
      "version": "0.2.0",
      "description": "parse argument options",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/minimist@0.2.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/minimist"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/minimist.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/minimist@0.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tap-spec/node_modules/minimist/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tap-spec/node_modules/minimist/package.json"
              }
            ],
            "concludedValue": "node_modules/tap-spec/node_modules/minimist/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "tap-parser",
      "version": "0.2.1",
      "description": "parse the test anything protocol",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/tap-parser@0.2.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/tap-parser"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/tap-parser.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/tap-parser@0.2.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tap-parser/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tap-parser/package.json"
              }
            ],
            "concludedValue": "node_modules/tap-parser/package.json"
          }
        ]
      },
      "tags": [
        "parse",
        "test"
      ]
    },
    {
      "authors": [
        {
          "name": "Dominic Tarr <dominic.tarr@gmail.com> (dominictarr.com)"
        }
      ],
      "group": "",
      "name": "through",
      "version": "1.1.2",
      "description": "simplified stream contruction",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/through@1.1.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/dominictarr/through"
        },
        {
          "type": "vcs",
          "url": "https://github.com/dominictarr/through.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/through@1.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tap-parser/node_modules/through/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tap-parser/node_modules/through/package.json"
              }
            ],
            "concludedValue": "node_modules/tap-parser/node_modules/through/package.json"
          }
        ]
      },
      "tags": [
        "stream"
      ]
    },
    {
      "authors": [
        {
          "name": "Dominic Tarr <dominic.tarr@gmail.com> (http://bit.ly/dominictarr)"
        }
      ],
      "group": "",
      "name": "split",
      "version": "0.1.2",
      "description": "split a Text Stream into a Line Stream",
      "scope": "optional",
      "purl": "pkg:npm/split@0.1.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/dominictarr/split"
        },
        {
          "type": "vcs",
          "url": "git://github.com/dominictarr/split.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/split@0.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tap-parser/node_modules/split/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tap-parser/node_modules/split/package.json"
              }
            ],
            "concludedValue": "node_modules/tap-parser/node_modules/split/package.json"
          }
        ]
      },
      "tags": [
        "stream"
      ]
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "tap-finished",
      "version": "0.0.1",
      "description": "detect when tap output is finished",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/tap-finished@0.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/tap-finished"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/tap-finished.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/tap-finished@0.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tap-finished/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tap-finished/package.json"
              }
            ],
            "concludedValue": "node_modules/tap-finished/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Hugh Kennedy <hughskennedy@gmail.com> (http://hughsk.io/)"
        }
      ],
      "group": "",
      "name": "tap-closer",
      "version": "1.0.0",
      "description": "Simple JS \"transform\" tool that will call window.close or process.exit when TAP output is complete",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/tap-closer@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/hughsk/tap-closer"
        },
        {
          "type": "vcs",
          "url": "git://github.com/hughsk/tap-closer.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/tap-closer@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tap-closer/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tap-closer/package.json"
              }
            ],
            "concludedValue": "node_modules/tap-closer/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Roman Shtylman <shtylman@gmail.com>"
        }
      ],
      "group": "",
      "name": "synthetic-dom-events",
      "version": "0.2.2",
      "description": "create DOM events for builtin event types",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/synthetic-dom-events@0.2.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/shtylman/synthetic-dom-events.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/synthetic-dom-events@0.2.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/synthetic-dom-events/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/synthetic-dom-events/package.json"
              }
            ],
            "concludedValue": "node_modules/synthetic-dom-events/package.json"
          }
        ]
      },
      "tags": [
        "event"
      ]
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "syntax-error",
      "version": "1.1.6",
      "description": "detect and report syntax errors in source code strings",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/syntax-error@1.1.6",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/node-syntax-error"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/node-syntax-error.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/syntax-error@1.1.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/syntax-error/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/syntax-error/package.json"
              }
            ],
            "concludedValue": "node_modules/syntax-error/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "acorn",
      "version": "2.7.0",
      "description": "ECMAScript parser",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/acorn@2.7.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/ternjs/acorn"
        },
        {
          "type": "vcs",
          "url": "https://github.com/ternjs/acorn.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/acorn@2.7.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/syntax-error/node_modules/acorn/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/syntax-error/node_modules/acorn/package.json"
              }
            ],
            "concludedValue": "node_modules/syntax-error/node_modules/acorn/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (http://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "supports-color",
      "version": "0.2.0",
      "description": "Detect whether a terminal supports color",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/supports-color@0.2.0",
      "type": "library",
      "bom-ref": "pkg:npm/supports-color@0.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/supports-color/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/supports-color/package.json"
              }
            ],
            "concludedValue": "node_modules/supports-color/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "subarg",
      "version": "1.0.0",
      "description": "parse arguments with recursive contexts",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/subarg@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/subarg"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/subarg.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/subarg@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/subarg/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/subarg/package.json"
              }
            ],
            "concludedValue": "node_modules/subarg/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "minimist",
      "version": "1.2.0",
      "description": "parse argument options",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/minimist@1.2.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/minimist"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/minimist.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/minimist@1.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/subarg/node_modules/minimist/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/meow/node_modules/minimist/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/meow/node_modules/minimist/package.json"
              }
            ],
            "concludedValue": "node_modules/meow/node_modules/minimist/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "strip-json-comments",
      "version": "1.0.4",
      "description": "Strip comments from JSON. Lets you use comments in your JSON files!",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/strip-json-comments@1.0.4",
      "type": "library",
      "bom-ref": "pkg:npm/strip-json-comments@1.0.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/strip-json-comments/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/strip-json-comments/package.json"
              }
            ],
            "concludedValue": "node_modules/strip-json-comments/package.json"
          }
        ]
      },
      "tags": [
        "json"
      ]
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (http://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "strip-indent",
      "version": "1.0.1",
      "description": "Strip leading whitespace from every line in a string",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/strip-indent@1.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/strip-indent@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/strip-indent/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/strip-indent/package.json"
              }
            ],
            "concludedValue": "node_modules/strip-indent/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "strip-bom",
      "version": "2.0.0",
      "description": "Strip UTF-8 byte order mark (BOM) from a string/buffer",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/strip-bom@2.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/strip-bom@2.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/strip-bom/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/strip-bom/package.json"
              }
            ],
            "concludedValue": "node_modules/strip-bom/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (http://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "strip-ansi",
      "version": "0.3.0",
      "description": "Strip ANSI escape codes",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/strip-ansi@0.3.0",
      "type": "library",
      "bom-ref": "pkg:npm/strip-ansi@0.3.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/strip-ansi/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/strip-ansi/package.json"
              }
            ],
            "concludedValue": "node_modules/strip-ansi/package.json"
          }
        ]
      },
      "tags": [
        "escape"
      ]
    },
    {
      "authors": [
        {
          "name": "Michael Hart <michael.hart.au@gmail.com> (http://github.com/mhart)"
        }
      ],
      "group": "",
      "name": "stringstream",
      "version": "0.0.5",
      "description": "Encode and decode streams into string streams",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/stringstream@0.0.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mhart/StringStream.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/stringstream@0.0.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/stringstream/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/stringstream/package.json"
              }
            ],
            "concludedValue": "node_modules/stringstream/package.json"
          }
        ]
      },
      "tags": [
        "decode"
      ]
    },
    {
      "authors": [
        {
          "name": "Olov Lassus <olov.lassus@gmail.com>"
        }
      ],
      "group": "",
      "name": "stringset",
      "version": "0.2.1",
      "description": "fast and robust stringset",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/stringset@0.2.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/olov/stringset.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/stringset@0.2.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/stringset/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/stringset/package.json"
              }
            ],
            "concludedValue": "node_modules/stringset/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Olov Lassus <olov.lassus@gmail.com>"
        }
      ],
      "group": "",
      "name": "stringmap",
      "version": "0.2.2",
      "description": "fast and robust stringmap",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/stringmap@0.2.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/olov/stringmap.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/stringmap@0.2.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/stringmap/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/stringmap/package.json"
              }
            ],
            "concludedValue": "node_modules/stringmap/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "string_decoder",
      "version": "0.10.31",
      "description": "The string_decoder module from Node core",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/string_decoder@0.10.31",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/rvagg/string_decoder"
        },
        {
          "type": "vcs",
          "url": "git://github.com/rvagg/string_decoder.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/string_decoder@0.10.31",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/string_decoder/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/string_decoder/package.json"
              }
            ],
            "concludedValue": "node_modules/string_decoder/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "string-width",
      "version": "1.0.2",
      "description": "Get the visual width of a string - the number of columns required to display it",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/string-width@1.0.2",
      "type": "library",
      "bom-ref": "pkg:npm/string-width@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/string-width/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/string-width/package.json"
              }
            ],
            "concludedValue": "node_modules/string-width/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "stream-splicer",
      "version": "1.3.2",
      "description": "streaming pipeline with a mutable configuration",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/stream-splicer@1.3.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/stream-splicer"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/stream-splicer.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/stream-splicer@1.3.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/stream-splicer/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/stream-splicer/package.json"
              }
            ],
            "concludedValue": "node_modules/stream-splicer/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "'Dominic Tarr' <dominic.tarr@gmail.com> (http://dominictarr.com)"
        }
      ],
      "group": "",
      "name": "stream-combiner2",
      "version": "1.0.2",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/stream-combiner2@1.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/stream-combiner2"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/stream-combiner2.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/stream-combiner2@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/stream-combiner2/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/stream-combiner2/package.json"
              }
            ],
            "concludedValue": "node_modules/stream-combiner2/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Rod Vagg <r@va.gg> (https://github.com/rvagg)"
        }
      ],
      "group": "",
      "name": "through2",
      "version": "0.5.1",
      "description": "A tiny wrapper around Node streams2 Transform to avoid explicit subclassing noise",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/through2@0.5.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/rvagg/through2.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/through2@0.5.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/stream-combiner2/node_modules/through2/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/browser-pack/node_modules/through2/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/browser-pack/node_modules/through2/package.json"
              }
            ],
            "concludedValue": "node_modules/browser-pack/node_modules/through2/package.json"
          }
        ]
      },
      "tags": [
        "transform"
      ]
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "stream-browserify",
      "version": "1.0.0",
      "description": "the stream module from node core for browsers",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/stream-browserify@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/stream-browserify"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/stream-browserify.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/stream-browserify@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/stream-browserify/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/stream-browserify/package.json"
              }
            ],
            "concludedValue": "node_modules/stream-browserify/package.json"
          }
        ]
      },
      "tags": [
        "stream"
      ]
    },
    {
      "authors": [
        {
          "name": "Angry Bytes <info@angrybytes.com>"
        }
      ],
      "group": "",
      "name": "stable",
      "version": "0.1.5",
      "description": "A stable array sort for JavaScript",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/stable@0.1.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/Two-Screen/stable.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/stable@0.1.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/stable/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/stable/package.json"
              }
            ],
            "concludedValue": "node_modules/stable/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Dominic Tarr <dominic.tarr@gmail.com> (http://bit.ly/dominictarr)"
        }
      ],
      "group": "",
      "name": "split",
      "version": "0.3.3",
      "description": "split a Text Stream into a Line Stream",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/split@0.3.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/dominictarr/split"
        },
        {
          "type": "vcs",
          "url": "git://github.com/dominictarr/split.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/split@0.3.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/split/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/split/package.json"
              }
            ],
            "concludedValue": "node_modules/split/package.json"
          }
        ]
      },
      "tags": [
        "stream"
      ]
    },
    {
      "authors": [
        {
          "name": "Shinnosuke Watanabe (https://github.com/shinnn)"
        }
      ],
      "group": "",
      "name": "spdx-license-ids",
      "version": "1.2.2",
      "description": "A list of SPDX license identifiers",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Unlicense",
            "url": "https://opensource.org/licenses/Unlicense"
          }
        }
      ],
      "purl": "pkg:npm/spdx-license-ids@1.2.2",
      "type": "library",
      "bom-ref": "pkg:npm/spdx-license-ids@1.2.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/spdx-license-ids/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/spdx-license-ids/package.json"
              }
            ],
            "concludedValue": "node_modules/spdx-license-ids/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Kyle E. Mitchell <kyle@kemitchell.com> (http://kemitchell.com)"
        }
      ],
      "group": "",
      "name": "spdx-expression-parse",
      "version": "1.0.3",
      "description": "parse SPDX license expressions",
      "scope": "optional",
      "licenses": [
        {
          "expression": "(MIT AND CC-BY-3.0)"
        }
      ],
      "purl": "pkg:npm/spdx-expression-parse@1.0.3",
      "type": "library",
      "bom-ref": "pkg:npm/spdx-expression-parse@1.0.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/spdx-expression-parse/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/spdx-expression-parse/package.json"
              }
            ],
            "concludedValue": "node_modules/spdx-expression-parse/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Kyle E. Mitchell <kyle@kemitchell.com> (https://kemitchell.com)"
        }
      ],
      "group": "",
      "name": "spdx-correct",
      "version": "1.0.2",
      "description": "correct invalid SPDX identifiers",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0",
            "url": "https://opensource.org/licenses/Apache-2.0"
          }
        }
      ],
      "purl": "pkg:npm/spdx-correct@1.0.2",
      "type": "library",
      "bom-ref": "pkg:npm/spdx-correct@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/spdx-correct/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/spdx-correct/package.json"
              }
            ],
            "concludedValue": "node_modules/spdx-correct/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "source-map-support",
      "version": "0.2.9",
      "description": "Fixes stack traces for files with source maps",
      "scope": "optional",
      "purl": "pkg:npm/source-map-support@0.2.9",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/evanw/node-source-map-support"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/source-map-support@0.2.9",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/source-map-support/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/source-map-support/package.json"
              }
            ],
            "concludedValue": "node_modules/source-map-support/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Nick Fitzgerald <nfitzgerald@mozilla.com>"
        }
      ],
      "group": "",
      "name": "source-map",
      "version": "0.1.32",
      "description": "Generates and consumes source maps",
      "scope": "optional",
      "purl": "pkg:npm/source-map@0.1.32",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mozilla/source-map"
        },
        {
          "type": "vcs",
          "url": "http://github.com/mozilla/source-map.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/source-map@0.1.32",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/source-map-support/node_modules/source-map/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/smokestack/node_modules/source-map-support/node_modules/source-map/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/smokestack/node_modules/source-map-support/node_modules/source-map/package.json"
              }
            ],
            "concludedValue": "node_modules/smokestack/node_modules/source-map-support/node_modules/source-map/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Nick Fitzgerald <nfitzgerald@mozilla.com>"
        }
      ],
      "group": "",
      "name": "source-map",
      "version": "0.1.43",
      "description": "Generates and consumes source maps",
      "scope": "optional",
      "purl": "pkg:npm/source-map@0.1.43",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mozilla/source-map"
        },
        {
          "type": "vcs",
          "url": "http://github.com/mozilla/source-map.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/source-map@0.1.43",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/source-map/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/source-map/package.json"
              }
            ],
            "concludedValue": "node_modules/source-map/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Marek Majkowski"
        }
      ],
      "group": "",
      "name": "sockjs",
      "version": "0.3.7",
      "description": "SockJS-node is a server counterpart of SockJS-client a JavaScript library that provides a WebSocket-like object in the browser. SockJS gives you a coherent, cross-browser, Javascript API which creates a low latency, full duplex, cross-domain communication channel between the browser and the web server.",
      "scope": "optional",
      "purl": "pkg:npm/sockjs@0.3.7",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/sockjs/sockjs-node"
        },
        {
          "type": "vcs",
          "url": "https://github.com/sockjs/sockjs-node.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/sockjs@0.3.7",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/sockjs/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/sockjs/package.json"
              }
            ],
            "concludedValue": "node_modules/sockjs/package.json"
          }
        ]
      },
      "tags": [
        "api",
        "web"
      ]
    },
    {
      "authors": [
        {
          "name": "Robert Kieffer <robert@broofa.com>"
        }
      ],
      "group": "",
      "name": "node-uuid",
      "version": "1.3.3",
      "description": "Rigorous implementation of RFC4122 (v1 and v4) UUIDs.",
      "scope": "optional",
      "purl": "pkg:npm/node-uuid@1.3.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/broofa/node-uuid.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/node-uuid@1.3.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/sockjs/node_modules/node-uuid/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/sockjs/node_modules/node-uuid/package.json"
              }
            ],
            "concludedValue": "node_modules/sockjs/node_modules/node-uuid/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "sockjs-test-server",
      "version": "0.0.0-unreleasable",
      "scope": "optional",
      "purl": "pkg:npm/sockjs-test-server@0.0.0-unreleasable",
      "type": "library",
      "bom-ref": "pkg:npm/sockjs-test-server@0.0.0-unreleasable",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/sockjs/examples/test_server/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/sockjs/examples/test_server/package.json"
              }
            ],
            "concludedValue": "node_modules/sockjs/examples/test_server/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "sockjs-multiplex",
      "version": "0.0.0-unreleasable",
      "scope": "optional",
      "purl": "pkg:npm/sockjs-multiplex@0.0.0-unreleasable",
      "type": "library",
      "bom-ref": "pkg:npm/sockjs-multiplex@0.0.0-unreleasable",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/sockjs/examples/multiplex/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/sockjs/examples/multiplex/package.json"
              }
            ],
            "concludedValue": "node_modules/sockjs/examples/multiplex/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "sockjs-express",
      "version": "0.0.0-unreleasable",
      "scope": "optional",
      "purl": "pkg:npm/sockjs-express@0.0.0-unreleasable",
      "type": "library",
      "bom-ref": "pkg:npm/sockjs-express@0.0.0-unreleasable",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/sockjs/examples/express-3.x/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/sockjs/examples/express/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/sockjs/examples/express/package.json"
              }
            ],
            "concludedValue": "node_modules/sockjs/examples/express/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "sockjs-echo",
      "version": "0.0.0-unreleasable",
      "scope": "optional",
      "purl": "pkg:npm/sockjs-echo@0.0.0-unreleasable",
      "type": "library",
      "bom-ref": "pkg:npm/sockjs-echo@0.0.0-unreleasable",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/sockjs/examples/echo/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/sockjs/examples/echo/package.json"
              }
            ],
            "concludedValue": "node_modules/sockjs/examples/echo/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Eran Hammer <eran@hammer.io> (http://hueniverse.com)"
        }
      ],
      "group": "",
      "name": "sntp",
      "version": "1.0.9",
      "description": "SNTP Client",
      "scope": "optional",
      "purl": "pkg:npm/sntp@1.0.9",
      "type": "library",
      "bom-ref": "pkg:npm/sntp@1.0.9",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/sntp/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/sntp/package.json"
              }
            ],
            "concludedValue": "node_modules/sntp/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Hugh Kennedy <hughskennedy@gmail.com> (http://hughsk.io/)"
        }
      ],
      "group": "",
      "name": "smokestack",
      "version": "3.4.1",
      "description": "Pipe your JavaScript into a browser, logging console output in Node",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/smokestack@3.4.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/hughsk/smokestack"
        },
        {
          "type": "vcs",
          "url": "git://github.com/hughsk/smokestack.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/smokestack@3.4.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/smokestack/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/smokestack/package.json"
              }
            ],
            "concludedValue": "node_modules/smokestack/package.json"
          }
        ]
      },
      "tags": [
        "logging"
      ]
    },
    {
      "group": "",
      "name": "source-map-support",
      "version": "0.2.10",
      "description": "Fixes stack traces for files with source maps",
      "scope": "optional",
      "purl": "pkg:npm/source-map-support@0.2.10",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/evanw/node-source-map-support"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/source-map-support@0.2.10",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/smokestack/node_modules/source-map-support/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/smokestack/node_modules/source-map-support/package.json"
              }
            ],
            "concludedValue": "node_modules/smokestack/node_modules/source-map-support/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Nick Fitzgerald <nfitzgerald@mozilla.com>"
        }
      ],
      "group": "",
      "name": "source-map",
      "version": "0.4.4",
      "description": "Generates and consumes source maps",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-3-Clause",
            "url": "https://opensource.org/licenses/BSD-3-Clause"
          }
        }
      ],
      "purl": "pkg:npm/source-map@0.4.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mozilla/source-map"
        },
        {
          "type": "vcs",
          "url": "http://github.com/mozilla/source-map.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/source-map@0.4.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/smokestack/node_modules/source-map/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/insert-module-globals/node_modules/source-map/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/insert-module-globals/node_modules/source-map/package.json"
              }
            ],
            "concludedValue": "node_modules/insert-module-globals/node_modules/source-map/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "minimist",
      "version": "1.1.3",
      "description": "parse argument options",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/minimist@1.1.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/minimist"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/minimist.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/minimist@1.1.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/smokestack/node_modules/minimist/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/smokestack/node_modules/minimist/package.json"
              }
            ],
            "concludedValue": "node_modules/smokestack/node_modules/minimist/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Thorsten Lorenz <thlorenz@gmx.de> (http://thlorenz.com)"
        }
      ],
      "group": "",
      "name": "convert-source-map",
      "version": "1.3.0",
      "description": "Converts a source-map from/to  different formats and allows adding/changing properties.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/convert-source-map@1.3.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/thlorenz/convert-source-map"
        },
        {
          "type": "vcs",
          "url": "git://github.com/thlorenz/convert-source-map.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/convert-source-map@1.3.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/smokestack/node_modules/convert-source-map/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/smokestack/node_modules/convert-source-map/package.json"
              }
            ],
            "concludedValue": "node_modules/smokestack/node_modules/convert-source-map/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "smokestack-tape",
      "version": "",
      "scope": "optional",
      "purl": "pkg:npm/smokestack-tape",
      "type": "library",
      "bom-ref": "pkg:npm/smokestack-tape",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/smokestack/examples/tape/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/smokestack/examples/tape/package.json"
              }
            ],
            "concludedValue": "node_modules/smokestack/examples/tape/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "smokestack-capture-example",
      "version": "1.0.0",
      "scope": "optional",
      "purl": "pkg:npm/smokestack-capture-example@1.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/smokestack-capture-example@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/smokestack/examples/capture/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/smokestack/examples/capture/package.json"
              }
            ],
            "concludedValue": "node_modules/smokestack/examples/capture/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Olov Lassus <olov.lassus@gmail.com>"
        }
      ],
      "group": "",
      "name": "simple-is",
      "version": "0.2.0",
      "description": "maximally minimal type-testing library",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/simple-is@0.2.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/olov/simple-is.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/simple-is@0.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/simple-is/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/simple-is/package.json"
              }
            ],
            "concludedValue": "node_modules/simple-is/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Olov Lassus <olov.lassus@gmail.com>"
        }
      ],
      "group": "",
      "name": "simple-fmt",
      "version": "0.1.0",
      "description": "maximally minimal string formatting library",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/simple-fmt@0.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/olov/simple-fmt.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/simple-fmt@0.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/simple-fmt/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/simple-fmt/package.json"
              }
            ],
            "concludedValue": "node_modules/simple-fmt/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Ben Coe <ben@npmjs.com>"
        }
      ],
      "group": "",
      "name": "signal-exit",
      "version": "3.0.1",
      "description": "when you want to fire an event no matter how a process exits.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/signal-exit@3.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/tapjs/signal-exit"
        },
        {
          "type": "vcs",
          "url": "https://github.com/tapjs/signal-exit.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/signal-exit@3.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/signal-exit/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/signal-exit/package.json"
              }
            ],
            "concludedValue": "node_modules/signal-exit/package.json"
          }
        ]
      },
      "tags": [
        "event"
      ]
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "sigmund",
      "version": "1.0.1",
      "description": "Quick and dirty signatures for Objects.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/sigmund@1.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/sigmund"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/sigmund@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/sigmund/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/sigmund/package.json"
              }
            ],
            "concludedValue": "node_modules/sigmund/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "shoe",
      "version": "0.0.15",
      "description": "streaming sockjs for node and the browser",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/shoe@0.0.15",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/shoe"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/shoe.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/shoe@0.0.15",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/shoe/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/shoe/package.json"
              }
            ],
            "concludedValue": "node_modules/shoe/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Marek Majkowski"
        }
      ],
      "group": "",
      "name": "sockjs-client",
      "version": "0.0.0-unreleasable",
      "description": "SockJS-client is a browser JavaScript library that provides a WebSocket-like object. SockJS gives you a coherent, cross-browser, Javascript API which creates a low latency, full duplex, cross-domain communication channel between the browser and the web server.",
      "scope": "optional",
      "purl": "pkg:npm/sockjs-client@0.0.0-unreleasable",
      "externalReferences": [
        {
          "type": "website",
          "url": "http://sockjs.org"
        },
        {
          "type": "vcs",
          "url": "https://github.com/sockjs/sockjs-client.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/sockjs-client@0.0.0-unreleasable",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/shoe/node_modules/sockjs-client/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/shoe/node_modules/sockjs-client/package.json"
              }
            ],
            "concludedValue": "node_modules/shoe/node_modules/sockjs-client/package.json"
          }
        ]
      },
      "tags": [
        "api",
        "web"
      ]
    },
    {
      "group": "",
      "name": "shoe-invert-example",
      "version": "0.0.0",
      "scope": "optional",
      "purl": "pkg:npm/shoe-invert-example@0.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/shoe-invert-example@0.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/shoe/example/invert/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/shoe/example/invert/package.json"
              }
            ],
            "concludedValue": "node_modules/shoe/example/invert/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "shoe-dnode-example",
      "version": "0.0.0",
      "scope": "optional",
      "purl": "pkg:npm/shoe-dnode-example@0.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/shoe-dnode-example@0.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/shoe/example/dnode/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/shoe/example/dnode/package.json"
              }
            ],
            "concludedValue": "node_modules/shoe/example/dnode/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Artur Adib <aadib@mozilla.com>"
        }
      ],
      "group": "",
      "name": "shelljs",
      "version": "0.3.0",
      "description": "Portable Unix shell commands for Node.js",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "name": "BSD*"
          }
        }
      ],
      "purl": "pkg:npm/shelljs@0.3.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/arturadib/shelljs"
        },
        {
          "type": "vcs",
          "url": "git://github.com/arturadib/shelljs.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/shelljs@0.3.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/shelljs/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/shelljs/package.json"
              }
            ],
            "concludedValue": "node_modules/shelljs/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "shell-quote",
      "version": "0.0.1",
      "description": "quote and parse shell commands",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/shell-quote@0.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/substack/node-shell-quote.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/shell-quote@0.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/shell-quote/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/shell-quote/package.json"
              }
            ],
            "concludedValue": "node_modules/shell-quote/package.json"
          }
        ]
      },
      "tags": [
        "parse"
      ]
    },
    {
      "authors": [
        {
          "name": "'Dominic Tarr' <dominic.tarr@gmail.com> (http://dominictarr.com)"
        }
      ],
      "group": "",
      "name": "shasum",
      "version": "1.0.2",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/shasum@1.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/dominictarr/shasum"
        },
        {
          "type": "vcs",
          "url": "git://github.com/dominictarr/shasum.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/shasum@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/shasum/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/shasum/package.json"
              }
            ],
            "concludedValue": "node_modules/shasum/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "shallow-copy",
      "version": "0.0.1",
      "description": "make a shallow copy of an object or array",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/shallow-copy@0.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/shallow-copy"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/shallow-copy.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/shallow-copy@0.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/shallow-copy/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/shallow-copy/package.json"
              }
            ],
            "concludedValue": "node_modules/shallow-copy/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Dominic Tarr <dominic.tarr@gmail.com> (dominictarr.com)"
        }
      ],
      "group": "",
      "name": "sha.js",
      "version": "2.4.5",
      "description": "Streamable SHA hashes in pure javascript",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/sha.js@2.4.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/crypto-browserify/sha.js"
        },
        {
          "type": "vcs",
          "url": "git://github.com/crypto-browserify/sha.js.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/sha.js@2.4.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/sha.js/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/sha.js/package.json"
              }
            ],
            "concludedValue": "node_modules/sha.js/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "semver",
      "version": "5.3.0",
      "description": "The semantic version parser used by npm.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/semver@5.3.0",
      "type": "library",
      "bom-ref": "pkg:npm/semver@5.3.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/semver/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/semver/package.json"
              }
            ],
            "concludedValue": "node_modules/semver/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "ForbesLindesay"
        }
      ],
      "group": "",
      "name": "ruglify",
      "version": "1.0.0",
      "description": "'Require' minified JavaScript as a string",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/ruglify@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/ForbesLindesay/ruglify.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/ruglify@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/ruglify/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/ruglify/package.json"
              }
            ],
            "concludedValue": "node_modules/ruglify/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "uglify-js",
      "version": "2.2.5",
      "description": "JavaScript parser, mangler/compressor and beautifier toolkit",
      "scope": "optional",
      "purl": "pkg:npm/uglify-js@2.2.5",
      "externalReferences": [
        {
          "type": "website",
          "url": "http://lisperator.net/uglifyjs"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/uglify-js@2.2.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/ruglify/node_modules/uglify-js/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/ruglify/node_modules/uglify-js/package.json"
              }
            ],
            "concludedValue": "node_modules/ruglify/node_modules/uglify-js/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "roadrunner",
      "version": "1.0.4",
      "description": "Cache require resolutions to heavily improve startup speed on subsequent loads",
      "scope": "optional",
      "purl": "pkg:npm/roadrunner@1.0.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/sebmck/roadrunner.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/roadrunner@1.0.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/roadrunner/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/roadrunner/package.json"
              }
            ],
            "concludedValue": "node_modules/roadrunner/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "ripemd160",
      "version": "1.0.1",
      "description": "Compute ripemd160 of bytes or strings.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-3-Clause",
            "url": "https://opensource.org/licenses/BSD-3-Clause"
          }
        }
      ],
      "purl": "pkg:npm/ripemd160@1.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/crypto-browserify/ripemd160"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/ripemd160@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/ripemd160/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/ripemd160/package.json"
              }
            ],
            "concludedValue": "node_modules/ripemd160/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "rimraf",
      "version": "2.3.4",
      "description": "A deep deletion module for node (like `rm -rf`)",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/rimraf@2.3.4",
      "type": "library",
      "bom-ref": "pkg:npm/rimraf@2.3.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/rimraf/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/rimraf/package.json"
              }
            ],
            "concludedValue": "node_modules/rimraf/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jon Schlinkert (https://github.com/jonschlinkert)"
        }
      ],
      "group": "",
      "name": "right-align",
      "version": "0.1.3",
      "description": "Right-align the text in a string.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/right-align@0.1.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jonschlinkert/right-align"
        },
        {
          "type": "vcs",
          "url": "git://github.com/jonschlinkert/right-align.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/right-align@0.1.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/right-align/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/right-align/package.json"
              }
            ],
            "concludedValue": "node_modules/right-align/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "ForbesLindesay"
        }
      ],
      "group": "",
      "name": "rfile",
      "version": "1.0.0",
      "description": "Require a plain text or binary file in node.js",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/rfile@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/ForbesLindesay/rfile.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/rfile@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/rfile/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/rfile/package.json"
              }
            ],
            "concludedValue": "node_modules/rfile/package.json"
          }
        ]
      },
      "tags": [
        "binary"
      ]
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "resolve",
      "version": "0.3.1",
      "description": "resolve like require.resolve() on behalf of files asynchronously and synchronously",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/resolve@0.3.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/substack/node-resolve.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/resolve@0.3.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/rfile/node_modules/resolve/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/rfile/node_modules/resolve/package.json"
              }
            ],
            "concludedValue": "node_modules/rfile/node_modules/resolve/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "resumer",
      "version": "0.0.0",
      "description": "a through stream that starts paused and resumes on the next tick",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/resumer@0.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/resumer"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/resumer.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/resumer@0.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/resumer/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/resumer/package.json"
              }
            ],
            "concludedValue": "node_modules/resumer/package.json"
          }
        ]
      },
      "tags": [
        "stream"
      ]
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "resolve",
      "version": "0.7.4",
      "description": "resolve like require.resolve() on behalf of files asynchronously and synchronously",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/resolve@0.7.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/substack/node-resolve.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/resolve@0.7.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/resolve/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/resolve/package.json"
              }
            ],
            "concludedValue": "node_modules/resolve/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mikeal Rogers <mikeal.rogers@gmail.com>"
        }
      ],
      "group": "",
      "name": "request",
      "version": "2.65.0",
      "description": "Simplified HTTP request client.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0",
            "url": "https://opensource.org/licenses/Apache-2.0"
          }
        }
      ],
      "purl": "pkg:npm/request@2.65.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/request/request.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/request@2.65.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/request/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/request/package.json"
              }
            ],
            "concludedValue": "node_modules/request/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "readable-stream",
      "version": "2.0.6",
      "description": "Streams3, a user-land copy of the stream library from Node.js",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/readable-stream@2.0.6",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/nodejs/readable-stream"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/readable-stream@2.0.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/request/node_modules/readable-stream/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/request/node_modules/readable-stream/package.json"
              }
            ],
            "concludedValue": "node_modules/request/node_modules/readable-stream/package.json"
          }
        ]
      },
      "tags": [
        "stream"
      ]
    },
    {
      "authors": [
        {
          "name": "Julian Gruber <mail@juliangruber.com> (http://juliangruber.com)"
        }
      ],
      "group": "",
      "name": "isarray",
      "version": "1.0.0",
      "description": "Array#isArray for older browsers",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/isarray@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/juliangruber/isarray"
        },
        {
          "type": "vcs",
          "url": "git://github.com/juliangruber/isarray.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/isarray@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/request/node_modules/isarray/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/buffer/node_modules/isarray/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/buffer/node_modules/isarray/package.json"
              }
            ],
            "concludedValue": "node_modules/buffer/node_modules/isarray/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "bl",
      "version": "1.0.3",
      "description": "Buffer List: collect buffers and access with a standard readable Buffer interface, streamable too!",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/bl@1.0.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/rvagg/bl"
        },
        {
          "type": "vcs",
          "url": "https://github.com/rvagg/bl.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/bl@1.0.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/request/node_modules/bl/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/request/node_modules/bl/package.json"
              }
            ],
            "concludedValue": "node_modules/request/node_modules/bl/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "repeating",
      "version": "2.0.1",
      "description": "Repeat a string - fast",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/repeating@2.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/repeating@2.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/repeating/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/repeating/package.json"
              }
            ],
            "concludedValue": "node_modules/repeating/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jon Schlinkert (http://github.com/jonschlinkert)"
        }
      ],
      "group": "",
      "name": "repeat-string",
      "version": "1.5.4",
      "description": "Repeat the given string n times. Fastest implementation for repeating a string.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/repeat-string@1.5.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jonschlinkert/repeat-string"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/repeat-string@1.5.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/repeat-string/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/repeat-string/package.json"
              }
            ],
            "concludedValue": "node_modules/repeat-string/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "'Julian Viereck' <julian.viereck@gmail.com>"
        }
      ],
      "group": "",
      "name": "regjsparser",
      "version": "0.1.5",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "name": "BSD"
          }
        }
      ],
      "purl": "pkg:npm/regjsparser@0.1.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jviereck/regjsparser"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/regjsparser@0.1.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/regjsparser/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/regjsparser/package.json"
              }
            ],
            "concludedValue": "node_modules/regjsparser/package.json"
          }
        ]
      },
      "tags": [
        "parse"
      ]
    },
    {
      "authors": [
        {
          "name": "Benjamin Tan <demoneaux@gmail.com> (https://d10.github.io/)"
        }
      ],
      "group": "",
      "name": "regjsgen",
      "version": "0.2.0",
      "description": "Generate `RegExp`s from RegJSParser’s AST",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/regjsgen@0.2.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/d10/regjsgen"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/regjsgen@0.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/regjsgen/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/regjsgen/package.json"
              }
            ],
            "concludedValue": "node_modules/regjsgen/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mathias Bynens (https://mathiasbynens.be/)"
        }
      ],
      "group": "",
      "name": "regexpu",
      "version": "1.0.0",
      "description": "A source code transpiler that enables the use of ES6 Unicode regular expressions in ES5.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/regexpu@1.0.0",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://mths.be/regexpu"
        },
        {
          "type": "vcs",
          "url": "https://github.com/mathiasbynens/regexpu.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/regexpu@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/regexpu/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/regexpu/package.json"
              }
            ],
            "concludedValue": "node_modules/regexpu/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Ben Newman <bn@cs.stanford.edu>"
        }
      ],
      "group": "",
      "name": "regenerator",
      "version": "0.8.9",
      "description": "Source transformer enabling ECMAScript 6 generator functions (yield) in JavaScript-of-today (ES5)",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "name": "BSD"
          }
        }
      ],
      "purl": "pkg:npm/regenerator@0.8.9",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/facebook/regenerator"
        },
        {
          "type": "vcs",
          "url": "git://github.com/facebook/regenerator.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/regenerator@0.8.9",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/regenerator/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/regenerator/package.json"
              }
            ],
            "concludedValue": "node_modules/regenerator/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Dominic Tarr <dominic.tarr@gmail.com> (dominictarr.com)"
        }
      ],
      "group": "",
      "name": "through",
      "version": "2.3.8",
      "description": "simplified stream construction",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/through@2.3.8",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/dominictarr/through"
        },
        {
          "type": "vcs",
          "url": "https://github.com/dominictarr/through.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/through@2.3.8",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/regenerator/node_modules/through/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/regenerator/node_modules/through/package.json"
              }
            ],
            "concludedValue": "node_modules/regenerator/node_modules/through/package.json"
          }
        ]
      },
      "tags": [
        "stream"
      ]
    },
    {
      "authors": [
        {
          "name": "Mathias Bynens (https://mathiasbynens.be/)"
        }
      ],
      "group": "",
      "name": "regenerate",
      "version": "1.3.1",
      "description": "Generate JavaScript-compatible regular expressions based on a given set of Unicode symbols or code points.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/regenerate@1.3.1",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://mths.be/regenerate"
        },
        {
          "type": "vcs",
          "url": "https://github.com/mathiasbynens/regenerate.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/regenerate@1.3.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/regenerate/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/regenerate/package.json"
              }
            ],
            "concludedValue": "node_modules/regenerate/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "redent",
      "version": "1.0.0",
      "description": "Strip redundant indentation and indent the string",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/redent@1.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/redent@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/redent/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/redent/package.json"
              }
            ],
            "concludedValue": "node_modules/redent/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Ben Newman <bn@cs.stanford.edu>"
        }
      ],
      "group": "",
      "name": "recast",
      "version": "0.9.18",
      "description": "JavaScript syntax tree transformer, conservative pretty-printer, and automatic source map generator",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/recast@0.9.18",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/benjamn/recast"
        },
        {
          "type": "vcs",
          "url": "git://github.com/benjamn/recast.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/recast@0.9.18",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/recast/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/recast/package.json"
              }
            ],
            "concludedValue": "node_modules/recast/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Thorsten Lorenz <thlorenz@gmx.de> (thlorenz.com)"
        }
      ],
      "group": "",
      "name": "readdirp",
      "version": "1.3.0",
      "description": "Recursive version of fs.readdir with streaming api.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/readdirp@1.3.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/thlorenz/readdirp"
        },
        {
          "type": "vcs",
          "url": "git://github.com/thlorenz/readdirp.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/readdirp@1.3.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/readdirp/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/readdirp/package.json"
              }
            ],
            "concludedValue": "node_modules/readdirp/package.json"
          }
        ]
      },
      "tags": [
        "api"
      ]
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me)"
        }
      ],
      "group": "",
      "name": "minimatch",
      "version": "0.2.14",
      "description": "a glob matcher in javascript",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/minimatch@0.2.14",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/minimatch.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/minimatch@0.2.14",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/readdirp/node_modules/minimatch/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/readdirp/node_modules/minimatch/package.json"
              }
            ],
            "concludedValue": "node_modules/readdirp/node_modules/minimatch/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me)"
        }
      ],
      "group": "",
      "name": "graceful-fs",
      "version": "2.0.3",
      "description": "A drop-in replacement for fs, making various improvements.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "name": "BSD"
          }
        }
      ],
      "purl": "pkg:npm/graceful-fs@2.0.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/node-graceful-fs.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/graceful-fs@2.0.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/readdirp/node_modules/graceful-fs/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/readdirp/node_modules/graceful-fs/package.json"
              }
            ],
            "concludedValue": "node_modules/readdirp/node_modules/graceful-fs/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "readdirp-examples",
      "version": "0.0.0",
      "description": "Examples for readdirp.",
      "scope": "optional",
      "purl": "pkg:npm/readdirp-examples@0.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/readdirp-examples@0.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/readdirp/examples/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/readdirp/examples/package.json"
              }
            ],
            "concludedValue": "node_modules/readdirp/examples/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "readable-wrap",
      "version": "1.0.0",
      "description": "upgrade streams1 to streams2 streams as a standalone module",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/readable-wrap@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/readable-wrap"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/readable-wrap.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/readable-wrap@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/readable-wrap/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/readable-wrap/package.json"
              }
            ],
            "concludedValue": "node_modules/readable-wrap/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "readable-stream",
      "version": "1.1.14",
      "description": "Streams3, a user-land copy of the stream library from Node.js v0.11.x",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/readable-stream@1.1.14",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/readable-stream"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/readable-stream@1.1.14",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/readable-stream/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/readable-stream/package.json"
              }
            ],
            "concludedValue": "node_modules/readable-stream/package.json"
          }
        ]
      },
      "tags": [
        "stream"
      ]
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "read-pkg-up",
      "version": "1.0.1",
      "description": "Read the closest package.json file",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/read-pkg-up@1.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/read-pkg-up@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/read-pkg-up/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/read-pkg-up/package.json"
              }
            ],
            "concludedValue": "node_modules/read-pkg-up/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "read-pkg",
      "version": "1.1.0",
      "description": "Read a package.json file",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/read-pkg@1.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/read-pkg@1.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/read-pkg/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/read-pkg/package.json"
              }
            ],
            "concludedValue": "node_modules/read-pkg/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "randombytes",
      "version": "2.0.3",
      "description": "random bytes from browserify stand alone",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/randombytes@2.0.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/crypto-browserify/randombytes"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/randombytes@2.0.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/randombytes/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/randombytes/package.json"
              }
            ],
            "concludedValue": "node_modules/randombytes/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Hugh Kennedy <hughskennedy@gmail.com> (http://hughsk.io/)"
        }
      ],
      "group": "",
      "name": "quick-tmp",
      "version": "0.0.0",
      "description": "Quickly and synchronously retrieve a temporary directory name for you to use",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/quick-tmp@0.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/hughsk/quick-tmp"
        },
        {
          "type": "vcs",
          "url": "git://github.com/hughsk/quick-tmp"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/quick-tmp@0.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/quick-tmp/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/quick-tmp/package.json"
              }
            ],
            "concludedValue": "node_modules/quick-tmp/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Irakli Gozalishvili <rfobic@gmail.com>"
        }
      ],
      "group": "",
      "name": "querystring-es3",
      "version": "0.2.1",
      "description": "Node's querystring module for all engines. (ES3 compat fork)",
      "scope": "optional",
      "purl": "pkg:npm/querystring-es3@0.2.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/mike-spainhower/querystring.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/querystring-es3@0.2.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/querystring-es3/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/querystring-es3/package.json"
              }
            ],
            "concludedValue": "node_modules/querystring-es3/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Irakli Gozalishvili <rfobic@gmail.com>"
        }
      ],
      "group": "",
      "name": "querystring",
      "version": "0.2.0",
      "description": "Node's querystring module for all engines.",
      "scope": "optional",
      "purl": "pkg:npm/querystring@0.2.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/Gozala/querystring.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/querystring@0.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/querystring/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/querystring/package.json"
              }
            ],
            "concludedValue": "node_modules/querystring/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "qs",
      "version": "5.2.1",
      "description": "A querystring parser that supports nesting and arrays, with a depth limit",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-3-Clause",
            "url": "https://opensource.org/licenses/BSD-3-Clause"
          }
        }
      ],
      "purl": "pkg:npm/qs@5.2.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/hapijs/qs"
        },
        {
          "type": "vcs",
          "url": "https://github.com/hapijs/qs.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/qs@5.2.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/qs/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/qs/package.json"
              }
            ],
            "concludedValue": "node_modules/qs/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Kris Kowal <kris@cixar.com> (https://github.com/kriskowal)"
        }
      ],
      "group": "",
      "name": "q",
      "version": "1.4.1",
      "description": "A library for promises (CommonJS/Promises/A,B,D)",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/q@1.4.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/kriskowal/q"
        },
        {
          "type": "vcs",
          "url": "git://github.com/kriskowal/q.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/q@1.4.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/q/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/q/package.json"
              }
            ],
            "concludedValue": "node_modules/q/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mathias Bynens <mathias@qiwi.be> (http://mathiasbynens.be/)"
        }
      ],
      "group": "",
      "name": "punycode",
      "version": "1.2.4",
      "description": "A robust Punycode converter that fully complies to RFC 3492 and RFC 5891, and works on nearly all JavaScript platforms.",
      "scope": "optional",
      "purl": "pkg:npm/punycode@1.2.4",
      "externalReferences": [
        {
          "type": "website",
          "url": "http://mths.be/punycode"
        },
        {
          "type": "vcs",
          "url": "https://github.com/bestiejs/punycode.js.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/punycode@1.2.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/punycode/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/punycode/package.json"
              }
            ],
            "concludedValue": "node_modules/punycode/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "public-encrypt",
      "version": "4.0.0",
      "description": "browserify version of publicEncrypt & privateDecrypt",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/public-encrypt@4.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/crypto-browserify/publicEncrypt"
        },
        {
          "type": "vcs",
          "url": "https://github.com/crypto-browserify/publicEncrypt.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/public-encrypt@4.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/public-encrypt/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/public-encrypt/package.json"
              }
            ],
            "concludedValue": "node_modules/public-encrypt/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "process-nextick-args",
      "version": "1.0.7",
      "description": "process.nextTick but always with args",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/process-nextick-args@1.0.7",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/calvinmetcalf/process-nextick-args"
        },
        {
          "type": "vcs",
          "url": "https://github.com/calvinmetcalf/process-nextick-args.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/process-nextick-args@1.0.7",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/process-nextick-args/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/process-nextick-args/package.json"
              }
            ],
            "concludedValue": "node_modules/process-nextick-args/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Roman Shtylman <shtylman@gmail.com>"
        }
      ],
      "group": "",
      "name": "process",
      "version": "0.10.1",
      "description": "process information for node.js and browsers",
      "scope": "optional",
      "purl": "pkg:npm/process@0.10.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/shtylman/node-process.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/process@0.10.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/process/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/process/package.json"
              }
            ],
            "concludedValue": "node_modules/process/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Ben Newman <bn@cs.stanford.edu>"
        }
      ],
      "group": "",
      "name": "private",
      "version": "0.1.6",
      "description": "Utility for associating truly private state with any JavaScript object",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/private@0.1.6",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/benjamn/private"
        },
        {
          "type": "vcs",
          "url": "git://github.com/benjamn/private.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/private@0.1.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/private/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/private/package.json"
              }
            ],
            "concludedValue": "node_modules/private/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "pretty-ms",
      "version": "1.4.0",
      "description": "Convert milliseconds to a human readable string: 1337000000 → 15d 11h 23m 20s",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/pretty-ms@1.4.0",
      "type": "library",
      "bom-ref": "pkg:npm/pretty-ms@1.4.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/pretty-ms/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/pretty-ms/package.json"
              }
            ],
            "concludedValue": "node_modules/pretty-ms/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "plur",
      "version": "1.0.0",
      "description": "Naively pluralize a word",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/plur@1.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/plur@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/plur/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/plur/package.json"
              }
            ],
            "concludedValue": "node_modules/plur/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Vsevolod Strukchinsky <floatdrop@gmail.com> (github.com/floatdrop)"
        }
      ],
      "group": "",
      "name": "pinkie-promise",
      "version": "2.0.1",
      "description": "ES2015 Promise ponyfill",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/pinkie-promise@2.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/pinkie-promise@2.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/pinkie-promise/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/pinkie-promise/package.json"
              }
            ],
            "concludedValue": "node_modules/pinkie-promise/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Vsevolod Strukchinsky <floatdrop@gmail.com> (github.com/floatdrop)"
        }
      ],
      "group": "",
      "name": "pinkie",
      "version": "2.0.4",
      "description": "Itty bitty little widdle twinkie pinkie ES2015 Promise implementation",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/pinkie@2.0.4",
      "type": "library",
      "bom-ref": "pkg:npm/pinkie@2.0.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/pinkie/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/pinkie/package.json"
              }
            ],
            "concludedValue": "node_modules/pinkie/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "pify",
      "version": "2.3.0",
      "description": "Promisify a callback-style function",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/pify@2.3.0",
      "type": "library",
      "bom-ref": "pkg:npm/pify@2.3.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/pify/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/pify/package.json"
              }
            ],
            "concludedValue": "node_modules/pify/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Daniel Cousens"
        }
      ],
      "group": "",
      "name": "pbkdf2",
      "version": "3.0.8",
      "description": "This library provides the functionality of PBKDF2 with the ability to use any supported hashing algorithm returned from crypto.getHashes()",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/pbkdf2@3.0.8",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/crypto-browserify/pbkdf2"
        },
        {
          "type": "vcs",
          "url": "https://github.com/crypto-browserify/pbkdf2.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/pbkdf2@3.0.8",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/pbkdf2/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/pbkdf2/package.json"
              }
            ],
            "concludedValue": "node_modules/pbkdf2/package.json"
          }
        ]
      },
      "tags": [
        "crypto"
      ]
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "path-type",
      "version": "1.1.0",
      "description": "Check if a path is a file, directory, or symlink",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/path-type@1.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/path-type@1.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/path-type/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/path-type/package.json"
              }
            ],
            "concludedValue": "node_modules/path-type/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Timothy J Fontaine <tjfontaine@gmail.com> (http://atxconsulting.com)"
        }
      ],
      "group": "",
      "name": "path-platform",
      "version": "0.11.15",
      "description": "Provide access to win32 and posix path operations; sourced directly from upstream Node.js",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/path-platform@0.11.15",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/tjfontaine/node-path-platform"
        },
        {
          "type": "vcs",
          "url": "http://github.com/tjfontaine/node-path-platform.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/path-platform@0.11.15",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/path-platform/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/path-platform/package.json"
              }
            ],
            "concludedValue": "node_modules/path-platform/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "path-is-absolute",
      "version": "1.0.0",
      "description": "Node.js 0.12 path.isAbsolute() ponyfill",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/path-is-absolute@1.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/path-is-absolute@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/path-is-absolute/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/path-is-absolute/package.json"
              }
            ],
            "concludedValue": "node_modules/path-is-absolute/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "path-exists",
      "version": "2.1.0",
      "description": "Check if a path exists",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/path-exists@2.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/path-exists@2.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/path-exists/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/path-exists/package.json"
              }
            ],
            "concludedValue": "node_modules/path-exists/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "path-browserify",
      "version": "0.0.0",
      "description": "the path module from node core for browsers",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/path-browserify@0.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/path-browserify"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/path-browserify.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/path-browserify@0.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/path-browserify/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/path-browserify/package.json"
              }
            ],
            "concludedValue": "node_modules/path-browserify/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (http://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "parse-ms",
      "version": "1.0.1",
      "description": "Parse milliseconds into an object",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/parse-ms@1.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/parse-ms@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/parse-ms/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/parse-ms/package.json"
              }
            ],
            "concludedValue": "node_modules/parse-ms/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "parse-json",
      "version": "2.2.0",
      "description": "Parse JSON with more helpful errors",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/parse-json@2.2.0",
      "type": "library",
      "bom-ref": "pkg:npm/parse-json@2.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/parse-json/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/parse-json/package.json"
              }
            ],
            "concludedValue": "node_modules/parse-json/package.json"
          }
        ]
      },
      "tags": [
        "json"
      ]
    },
    {
      "authors": [
        {
          "name": "David Björklund <david.bjorklund@gmail.com> (http://davidbjorklund.com/)"
        }
      ],
      "group": "",
      "name": "parse-headers",
      "version": "2.0.1",
      "description": "Parse http headers, works with browserify/xhr",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/parse-headers@2.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/kesla/parse-headers"
        },
        {
          "type": "vcs",
          "url": "https://github.com/kesla/parse-headers.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/parse-headers@2.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/parse-headers/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/parse-headers/package.json"
              }
            ],
            "concludedValue": "node_modules/parse-headers/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "parse-asn1",
      "version": "5.0.0",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/parse-asn1@5.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/crypto-browserify/parse-asn1.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/parse-asn1@5.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/parse-asn1/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/parse-asn1/package.json"
              }
            ],
            "concludedValue": "node_modules/parse-asn1/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "parents",
      "version": "1.0.1",
      "description": "return all the parent directories for a directory",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/parents@1.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/node-parents"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/node-parents.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/parents@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/parents/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/parents/package.json"
              }
            ],
            "concludedValue": "node_modules/parents/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "pako",
      "version": "0.2.9",
      "description": "zlib port to javascript - fast, modularized, with browser support",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/pako@0.2.9",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/nodeca/pako"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/pako@0.2.9",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/pako/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/pako/package.json"
              }
            ],
            "concludedValue": "node_modules/pako/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Shinnosuke Watanabe (https://github.com/shinnn)"
        }
      ],
      "group": "",
      "name": "output-file-sync",
      "version": "1.1.2",
      "description": "Synchronously write a file and create its ancestor directories if needed",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/output-file-sync@1.1.2",
      "type": "library",
      "bom-ref": "pkg:npm/output-file-sync@1.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/output-file-sync/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/output-file-sync/package.json"
              }
            ],
            "concludedValue": "node_modules/output-file-sync/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "object-assign",
      "version": "4.1.0",
      "description": "ES2015 Object.assign() ponyfill",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/object-assign@4.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/object-assign@4.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/output-file-sync/node_modules/object-assign/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/meow/node_modules/object-assign/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/meow/node_modules/object-assign/package.json"
              }
            ],
            "concludedValue": "node_modules/meow/node_modules/object-assign/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "osenv",
      "version": "0.0.3",
      "description": "Look up environment settings specific to different operating systems",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "name": "BSD"
          }
        }
      ],
      "purl": "pkg:npm/osenv@0.0.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/osenv"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/osenv@0.0.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/osenv/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/osenv/package.json"
              }
            ],
            "concludedValue": "node_modules/osenv/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "os-locale",
      "version": "1.4.0",
      "description": "Get the system locale",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/os-locale@1.4.0",
      "type": "library",
      "bom-ref": "pkg:npm/os-locale@1.4.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/os-locale/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/os-locale/package.json"
              }
            ],
            "concludedValue": "node_modules/os-locale/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Drew Young"
        }
      ],
      "group": "",
      "name": "os-browserify",
      "version": "0.1.2",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/os-browserify@0.1.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/drewyoung1/os-browserify.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/os-browserify@0.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/os-browserify/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/os-browserify/package.json"
              }
            ],
            "concludedValue": "node_modules/os-browserify/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "optimist",
      "version": "0.3.7",
      "description": "Light-weight option parsing with an argv hash. No optstrings attached.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "name": "MIT/X11"
          }
        }
      ],
      "purl": "pkg:npm/optimist@0.3.7",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/substack/node-optimist.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/optimist@0.3.7",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/optimist/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/optimist/package.json"
              }
            ],
            "concludedValue": "node_modules/optimist/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Axel Rauschmayer <axe@rauschma.de>"
        }
      ],
      "group": "",
      "name": "openurl",
      "version": "1.1.0",
      "description": "Open a URL via the operating system (http: in default browser, mailto: in mail client etc.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/openurl@1.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/rauschma/openurl"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/openurl@1.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/openurl/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/openurl/package.json"
              }
            ],
            "concludedValue": "node_modules/openurl/package.json"
          }
        ]
      },
      "tags": [
        "mail"
      ]
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "once",
      "version": "1.4.0",
      "description": "Run a function exactly one time",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/once@1.4.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/once"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/once@1.4.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/once/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/once/package.json"
              }
            ],
            "concludedValue": "node_modules/once/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "object-inspect",
      "version": "0.4.0",
      "description": "string representations of objects in node and the browser",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/object-inspect@0.4.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/object-inspect"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/object-inspect.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/object-inspect@0.4.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/object-inspect/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/object-inspect/package.json"
              }
            ],
            "concludedValue": "node_modules/object-inspect/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (http://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "object-assign",
      "version": "0.3.1",
      "description": "ES6 Object.assign() ponyfill",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/object-assign@0.3.1",
      "type": "library",
      "bom-ref": "pkg:npm/object-assign@0.3.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/object-assign/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/object-assign/package.json"
              }
            ],
            "concludedValue": "node_modules/object-assign/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mikeal Rogers <mikeal.rogers@gmail.com> (http://www.futurealoof.com)"
        }
      ],
      "group": "",
      "name": "oauth-sign",
      "version": "0.8.2",
      "description": "OAuth 1 signing. Formerly a vendor lib in mikeal/request, now a standalone module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0",
            "url": "https://opensource.org/licenses/Apache-2.0"
          }
        }
      ],
      "purl": "pkg:npm/oauth-sign@0.8.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mikeal/oauth-sign"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/oauth-sign@0.8.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/oauth-sign/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/oauth-sign/package.json"
              }
            ],
            "concludedValue": "node_modules/oauth-sign/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "number-is-nan",
      "version": "1.0.0",
      "description": "ES6 Number.isNaN() ponyfill",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/number-is-nan@1.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/number-is-nan@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/number-is-nan/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/number-is-nan/package.json"
              }
            ],
            "concludedValue": "node_modules/number-is-nan/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Meryn Stol <merynstol@gmail.com>"
        }
      ],
      "group": "",
      "name": "normalize-package-data",
      "version": "2.3.5",
      "description": "Normalizes data that can be found in package.json files.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-2-Clause",
            "url": "https://opensource.org/licenses/BSD-2-Clause"
          }
        }
      ],
      "purl": "pkg:npm/normalize-package-data@2.3.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/npm/normalize-package-data.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/normalize-package-data@2.3.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/normalize-package-data/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/normalize-package-data/package.json"
              }
            ],
            "concludedValue": "node_modules/normalize-package-data/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Robert Kieffer <robert@broofa.com>"
        }
      ],
      "group": "",
      "name": "node-uuid",
      "version": "1.4.7",
      "description": "Rigorous implementation of RFC4122 (v1 and v4) UUIDs.",
      "scope": "optional",
      "purl": "pkg:npm/node-uuid@1.4.7",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/broofa/node-uuid"
        },
        {
          "type": "vcs",
          "url": "https://github.com/broofa/node-uuid.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/node-uuid@1.4.7",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/node-uuid/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/node-uuid/package.json"
              }
            ],
            "concludedValue": "node_modules/node-uuid/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Robert Kieffer <robert@broofa.com>"
        }
      ],
      "group": "",
      "name": "node-int64",
      "version": "0.3.3",
      "description": "Support for representing 64-bit integers in JavaScript",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/node-int64@0.3.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/broofa/node-int64"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/node-int64@0.3.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/node-int64/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/node-int64/package.json"
              }
            ],
            "concludedValue": "node_modules/node-int64/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "ms",
      "version": "0.7.1",
      "description": "Tiny ms conversion utility",
      "scope": "optional",
      "purl": "pkg:npm/ms@0.7.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/guille/ms.js.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/ms@0.7.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/ms/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/ms/package.json"
              }
            ],
            "concludedValue": "node_modules/ms/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "module-deps",
      "version": "3.9.1",
      "description": "walk the dependency graph to generate json output that can be fed into browser-pack",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/module-deps@3.9.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/module-deps"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/module-deps.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/module-deps@3.9.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/module-deps/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/module-deps/package.json"
              }
            ],
            "concludedValue": "node_modules/module-deps/package.json"
          }
        ]
      },
      "tags": [
        "graph",
        "json"
      ]
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "resolve",
      "version": "1.1.7",
      "description": "resolve like require.resolve() on behalf of files asynchronously and synchronously",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/resolve@1.1.7",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/substack/node-resolve.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/resolve@1.1.7",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/module-deps/node_modules/resolve/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/browser-resolve/node_modules/resolve/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/browser-resolve/node_modules/resolve/package.json"
              }
            ],
            "concludedValue": "node_modules/browser-resolve/node_modules/resolve/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "deep",
      "version": "1.2.3",
      "scope": "optional",
      "purl": "pkg:npm/deep@1.2.3",
      "type": "library",
      "bom-ref": "pkg:npm/deep@1.2.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/module-deps/node_modules/resolve/test/pathfilter/deep_ref/node_modules/deep/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/browser-resolve/node_modules/resolve/test/pathfilter/deep_ref/node_modules/deep/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/browser-resolve/node_modules/resolve/test/pathfilter/deep_ref/node_modules/deep/package.json"
              }
            ],
            "concludedValue": "node_modules/browser-resolve/node_modules/resolve/test/pathfilter/deep_ref/node_modules/deep/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Tim Caswell <tim@creationix.com>"
        }
      ],
      "group": "",
      "name": "jsonparse",
      "version": "1.2.0",
      "description": "This is a pure-js JSON streaming parser for node.js",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/jsonparse@1.2.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/creationix/jsonparse.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/jsonparse@1.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/module-deps/node_modules/jsonparse/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/insert-module-globals/node_modules/jsonparse/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/deps-sort/node_modules/jsonparse/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/deps-sort/node_modules/jsonparse/package.json"
              }
            ],
            "concludedValue": "node_modules/deps-sort/node_modules/jsonparse/package.json"
          }
        ]
      },
      "tags": [
        "json"
      ]
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "defined",
      "version": "1.0.0",
      "description": "return the first argument that is `!== undefined`",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/defined@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/defined"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/defined.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/defined@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/module-deps/node_modules/defined/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/detective/node_modules/defined/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/detective/node_modules/defined/package.json"
              }
            ],
            "concludedValue": "node_modules/detective/node_modules/defined/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Dominic Tarr <dominic.tarr@gmail.com> (http://bit.ly/dominictarr)"
        }
      ],
      "group": "",
      "name": "JSONStream",
      "version": "1.2.1",
      "description": "rawStream.pipe(JSONStream.parse()).pipe(streamOfObjects)",
      "scope": "optional",
      "licenses": [
        {
          "expression": "(MIT OR Apache-2.0)"
        }
      ],
      "purl": "pkg:npm/JSONStream@1.2.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/dominictarr/JSONStream"
        },
        {
          "type": "vcs",
          "url": "git://github.com/dominictarr/JSONStream.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/JSONStream@1.2.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/module-deps/node_modules/JSONStream/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/insert-module-globals/node_modules/JSONStream/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/deps-sort/node_modules/JSONStream/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/deps-sort/node_modules/JSONStream/package.json"
              }
            ],
            "concludedValue": "node_modules/deps-sort/node_modules/JSONStream/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "mkdirp",
      "version": "0.5.1",
      "description": "Recursively mkdir, like `mkdir -p`",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/mkdirp@0.5.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/node-mkdirp.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/mkdirp@0.5.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/mkdirp/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/mkdirp/package.json"
              }
            ],
            "concludedValue": "node_modules/mkdirp/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "minimist",
      "version": "0.0.8",
      "description": "parse argument options",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/minimist@0.0.8",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/minimist"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/minimist.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/minimist@0.0.8",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/minimist/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/minimist/package.json"
              }
            ],
            "concludedValue": "node_modules/minimist/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me)"
        }
      ],
      "group": "",
      "name": "minimatch",
      "version": "2.0.10",
      "description": "a glob matcher in javascript",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/minimatch@2.0.10",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/minimatch.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/minimatch@2.0.10",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/minimatch/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/minimatch/package.json"
              }
            ],
            "concludedValue": "node_modules/minimatch/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "minimalistic-assert",
      "version": "1.0.0",
      "description": "minimalistic-assert ===",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/minimalistic-assert@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/calvinmetcalf/minimalistic-assert"
        },
        {
          "type": "vcs",
          "url": "https://github.com/calvinmetcalf/minimalistic-assert.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/minimalistic-assert@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/minimalistic-assert/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/minimalistic-assert/package.json"
              }
            ],
            "concludedValue": "node_modules/minimalistic-assert/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Raynos <raynos2@gmail.com>"
        }
      ],
      "group": "",
      "name": "min-document",
      "version": "2.19.0",
      "description": "A minimal DOM implementation",
      "scope": "optional",
      "purl": "pkg:npm/min-document@2.19.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/Raynos/min-document"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/min-document@2.19.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/min-document/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/min-document/package.json"
              }
            ],
            "concludedValue": "node_modules/min-document/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "mime-types",
      "version": "2.1.12",
      "description": "The ultimate javascript content-type utility.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/mime-types@2.1.12",
      "type": "library",
      "bom-ref": "pkg:npm/mime-types@2.1.12",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/mime-types/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/mime-types/package.json"
              }
            ],
            "concludedValue": "node_modules/mime-types/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "mime-db",
      "version": "1.24.0",
      "description": "Media Type Database",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/mime-db@1.24.0",
      "type": "library",
      "bom-ref": "pkg:npm/mime-db@1.24.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/mime-db/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/mime-db/package.json"
              }
            ],
            "concludedValue": "node_modules/mime-db/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Fedor Indutny <fedor@indutny.com>"
        }
      ],
      "group": "",
      "name": "miller-rabin",
      "version": "4.0.0",
      "description": "Miller Rabin algorithm for primality test",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/miller-rabin@4.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/indutny/miller-rabin"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/miller-rabin@4.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/miller-rabin/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/miller-rabin/package.json"
              }
            ],
            "concludedValue": "node_modules/miller-rabin/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "meow",
      "version": "3.7.0",
      "description": "CLI app helper",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/meow@3.7.0",
      "type": "library",
      "bom-ref": "pkg:npm/meow@3.7.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/meow/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/meow/package.json"
              }
            ],
            "concludedValue": "node_modules/meow/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "map-obj",
      "version": "1.0.1",
      "description": "Map object keys and values into a new object",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/map-obj@1.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/map-obj@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/map-obj/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/map-obj/package.json"
              }
            ],
            "concludedValue": "node_modules/map-obj/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me>"
        }
      ],
      "group": "",
      "name": "lru-cache",
      "version": "2.7.3",
      "description": "A cache object that deletes the least-recently-used items.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/lru-cache@2.7.3",
      "type": "library",
      "bom-ref": "pkg:npm/lru-cache@2.7.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/lru-cache/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/lru-cache/package.json"
              }
            ],
            "concludedValue": "node_modules/lru-cache/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "loud-rejection",
      "version": "1.6.0",
      "description": "Make unhandled promise rejections fail loudly instead of the default silent fail",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/loud-rejection@1.6.0",
      "type": "library",
      "bom-ref": "pkg:npm/loud-rejection@1.6.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/loud-rejection/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/loud-rejection/package.json"
              }
            ],
            "concludedValue": "node_modules/loud-rejection/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jon Schlinkert (https://github.com/jonschlinkert)"
        }
      ],
      "group": "",
      "name": "longest",
      "version": "1.0.1",
      "description": "Get the longest item in an array.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/longest@1.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jonschlinkert/longest"
        },
        {
          "type": "vcs",
          "url": "https://github.com/jonschlinkert/longest.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/longest@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/longest/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/longest/package.json"
              }
            ],
            "concludedValue": "node_modules/longest/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash.memoize",
      "version": "3.0.4",
      "description": "The modern build of lodash’s `_.memoize` as a module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/lodash.memoize@3.0.4",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash.memoize@3.0.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/lodash.memoize/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/lodash.memoize/package.json"
              }
            ],
            "concludedValue": "node_modules/lodash.memoize/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash",
      "version": "2.4.1",
      "description": "A utility library delivering consistency, customization, performance, & extras.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/lodash@2.4.1",
      "externalReferences": [
        {
          "type": "website",
          "url": "http://lodash.com/"
        },
        {
          "type": "vcs",
          "url": "https://github.com/lodash/lodash.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash@2.4.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/lodash/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/lodash/package.json"
              }
            ],
            "concludedValue": "node_modules/lodash/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Roman Shtylman <shtylman@gmail.com>"
        }
      ],
      "group": "",
      "name": "localtunnel",
      "version": "1.8.1",
      "description": "expose localhost to the world",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/localtunnel@1.8.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/shtylman/localtunnel.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/localtunnel@1.8.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/localtunnel/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/localtunnel/package.json"
              }
            ],
            "concludedValue": "node_modules/localtunnel/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Alex Ford <Alex.Ford@CodeTunnel.com> (http://CodeTunnel.com)"
        }
      ],
      "group": "",
      "name": "yargs",
      "version": "3.29.0",
      "description": "Light-weight option parsing with an argv hash. No optstrings attached.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/yargs@3.29.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/bcoe/yargs.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/yargs@3.29.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/localtunnel/node_modules/yargs/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/localtunnel/node_modules/yargs/package.json"
              }
            ],
            "concludedValue": "node_modules/localtunnel/node_modules/yargs/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Ben Coe <ben@npmjs.com>"
        }
      ],
      "group": "",
      "name": "cliui",
      "version": "3.2.0",
      "description": "easily create complex multi-column command-line-interfaces",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/cliui@3.2.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/yargs/cliui.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/cliui@3.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/localtunnel/node_modules/cliui/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/localtunnel/node_modules/cliui/package.json"
              }
            ],
            "concludedValue": "node_modules/localtunnel/node_modules/cliui/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "load-json-file",
      "version": "1.1.0",
      "description": "Read and parse a JSON file",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/load-json-file@1.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/load-json-file@1.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/load-json-file/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/load-json-file/package.json"
              }
            ],
            "concludedValue": "node_modules/load-json-file/package.json"
          }
        ]
      },
      "tags": [
        "json",
        "parse"
      ]
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "lexical-scope",
      "version": "1.2.0",
      "description": "detect global and local lexical identifiers from javascript source code",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/lexical-scope@1.2.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/lexical-scope"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/lexical-scope.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lexical-scope@1.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/lexical-scope/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/lexical-scope/package.json"
              }
            ],
            "concludedValue": "node_modules/lexical-scope/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "lcid",
      "version": "1.0.0",
      "description": "Mapping between standard locale identifiers and Windows locale identifiers (LCID)",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/lcid@1.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/lcid@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/lcid/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/lcid/package.json"
              }
            ],
            "concludedValue": "node_modules/lcid/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "J. Pommerening"
        }
      ],
      "group": "",
      "name": "lazystream",
      "version": "0.1.0",
      "description": "Open Node Streams on demand.",
      "scope": "optional",
      "purl": "pkg:npm/lazystream@0.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jpommerening/node-lazystream"
        },
        {
          "type": "vcs",
          "url": "https://github.com/jpommerening/node-lazystream.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lazystream@0.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/lazystream/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/lazystream/package.json"
              }
            ],
            "concludedValue": "node_modules/lazystream/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jon Schlinkert (https://github.com/jonschlinkert)"
        }
      ],
      "group": "",
      "name": "lazy-cache",
      "version": "1.0.4",
      "description": "Cache requires to be lazy-loaded when needed.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/lazy-cache@1.0.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jonschlinkert/lazy-cache"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lazy-cache@1.0.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/lazy-cache/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/lazy-cache/package.json"
              }
            ],
            "concludedValue": "node_modules/lazy-cache/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "labeled-stream-splicer",
      "version": "1.0.2",
      "description": "stream splicer with labels",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/labeled-stream-splicer@1.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/labeled-stream-splicer"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/labeled-stream-splicer.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/labeled-stream-splicer@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/labeled-stream-splicer/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/labeled-stream-splicer/package.json"
              }
            ],
            "concludedValue": "node_modules/labeled-stream-splicer/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jon Schlinkert (https://github.com/jonschlinkert)"
        }
      ],
      "group": "",
      "name": "kind-of",
      "version": "3.0.4",
      "description": "Get the native type of a value.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/kind-of@3.0.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jonschlinkert/kind-of"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/kind-of@3.0.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/kind-of/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/kind-of/package.json"
              }
            ],
            "concludedValue": "node_modules/kind-of/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jan Lehnardt <jan@apache.org>"
        }
      ],
      "group": "",
      "name": "jsonpointer",
      "version": "2.0.0",
      "description": "Simple JSON Addressing.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/jsonpointer@2.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/janl/node-jsonpointer.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/jsonpointer@2.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/jsonpointer/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/jsonpointer/package.json"
              }
            ],
            "concludedValue": "node_modules/jsonpointer/package.json"
          }
        ]
      },
      "tags": [
        "json"
      ]
    },
    {
      "authors": [
        {
          "name": "Tim Caswell <tim@creationix.com>"
        }
      ],
      "group": "",
      "name": "jsonparse",
      "version": "0.0.5",
      "description": "This is a pure-js JSON streaming parser for node.js",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/jsonparse@0.0.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/creationix/jsonparse.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/jsonparse@0.0.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/jsonparse/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/jsonparse/package.json"
              }
            ],
            "concludedValue": "node_modules/jsonparse/package.json"
          }
        ]
      },
      "tags": [
        "json"
      ]
    },
    {
      "authors": [
        {
          "name": "Douglas Crockford (http://crockford.com/)"
        }
      ],
      "group": "",
      "name": "jsonify",
      "version": "0.0.0",
      "description": "JSON without touching any globals",
      "scope": "optional",
      "licenses": [
        {
          "expression": "Public Domain"
        }
      ],
      "purl": "pkg:npm/jsonify@0.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/substack/jsonify.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/jsonify@0.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/jsonify/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/jsonify/package.json"
              }
            ],
            "concludedValue": "node_modules/jsonify/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me)"
        }
      ],
      "group": "",
      "name": "json-stringify-safe",
      "version": "5.0.1",
      "description": "Like JSON.stringify, but doesn't blow up on circular refs.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/json-stringify-safe@5.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/json-stringify-safe"
        },
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/json-stringify-safe"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/json-stringify-safe@5.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/json-stringify-safe/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/json-stringify-safe/package.json"
              }
            ],
            "concludedValue": "node_modules/json-stringify-safe/package.json"
          }
        ]
      },
      "tags": [
        "json"
      ]
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "json-stable-stringify",
      "version": "0.0.1",
      "description": "deterministic JSON.stringify() with custom sorting to get deterministic hashes from stringified results",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/json-stable-stringify@0.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/json-stable-stringify"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/json-stable-stringify.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/json-stable-stringify@0.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/json-stable-stringify/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/json-stable-stringify/package.json"
              }
            ],
            "concludedValue": "node_modules/json-stable-stringify/package.json"
          }
        ]
      },
      "tags": [
        "json"
      ]
    },
    {
      "authors": [
        {
          "name": "Anton Kovalyov <anton@kovalyov.net> (http://anton.kovalyov.net/)"
        }
      ],
      "group": "",
      "name": "jshint",
      "version": "2.5.11",
      "description": "Static analysis tool for JavaScript",
      "scope": "optional",
      "purl": "pkg:npm/jshint@2.5.11",
      "externalReferences": [
        {
          "type": "website",
          "url": "http://jshint.com/"
        },
        {
          "type": "vcs",
          "url": "https://github.com/jshint/jshint.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/jshint@2.5.11",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/jshint/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/jshint/package.json"
              }
            ],
            "concludedValue": "node_modules/jshint/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me)"
        }
      ],
      "group": "",
      "name": "minimatch",
      "version": "1.0.0",
      "description": "a glob matcher in javascript",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/minimatch@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/minimatch.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/minimatch@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/jshint/node_modules/minimatch/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/jshint/node_modules/minimatch/package.json"
              }
            ],
            "concludedValue": "node_modules/jshint/node_modules/minimatch/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mathias Bynens (http://mathiasbynens.be/)"
        }
      ],
      "group": "",
      "name": "jsesc",
      "version": "0.5.0",
      "description": "A JavaScript library for escaping JavaScript strings while generating the shortest possible valid output.",
      "scope": "optional",
      "purl": "pkg:npm/jsesc@0.5.0",
      "externalReferences": [
        {
          "type": "website",
          "url": "http://mths.be/jsesc"
        },
        {
          "type": "vcs",
          "url": "https://github.com/mathiasbynens/jsesc.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/jsesc@0.5.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/jsesc/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/jsesc/package.json"
              }
            ],
            "concludedValue": "node_modules/jsesc/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Rod Vagg <rod@vagg.org>"
        }
      ],
      "group": "",
      "name": "isstream",
      "version": "0.1.2",
      "description": "Determine if an object is a Stream",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/isstream@0.1.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/rvagg/isstream"
        },
        {
          "type": "vcs",
          "url": "https://github.com/rvagg/isstream.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/isstream@0.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/isstream/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/isstream/package.json"
              }
            ],
            "concludedValue": "node_modules/isstream/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "isexe",
      "version": "1.1.2",
      "description": "Minimal module to check if a file is executable.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/isexe@1.1.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/isexe#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/isaacs/isexe.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/isexe@1.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/isexe/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/isexe/package.json"
              }
            ],
            "concludedValue": "node_modules/isexe/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Julian Gruber <mail@juliangruber.com> (http://juliangruber.com)"
        }
      ],
      "group": "",
      "name": "isarray",
      "version": "0.0.1",
      "description": "Array#isArray for older browsers",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/isarray@0.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/juliangruber/isarray"
        },
        {
          "type": "vcs",
          "url": "git://github.com/juliangruber/isarray.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/isarray@0.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/isarray/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/isarray/package.json"
              }
            ],
            "concludedValue": "node_modules/isarray/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "wayfind"
        }
      ],
      "group": "",
      "name": "is-utf8",
      "version": "0.2.1",
      "description": "Detect if a buffer is utf8 encoded.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-utf8@0.2.1",
      "type": "library",
      "bom-ref": "pkg:npm/is-utf8@0.2.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-utf8/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-utf8/package.json"
              }
            ],
            "concludedValue": "node_modules/is-utf8/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mikola Lysenko"
        }
      ],
      "group": "",
      "name": "is-property",
      "version": "1.0.2",
      "description": "Tests if a JSON property can be accessed using . syntax",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-property@1.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/mikolalysenko/is-property.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/is-property@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-property/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-property/package.json"
              }
            ],
            "concludedValue": "node_modules/is-property/package.json"
          }
        ]
      },
      "tags": [
        "json"
      ]
    },
    {
      "authors": [
        {
          "name": "Mathias Buus"
        }
      ],
      "group": "",
      "name": "is-my-json-valid",
      "version": "2.14.0",
      "description": "A JSONSchema validator that uses code generation to be extremely fast",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-my-json-valid@2.14.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mafintosh/is-my-json-valid"
        },
        {
          "type": "vcs",
          "url": "https://github.com/mafintosh/is-my-json-valid"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/is-my-json-valid@2.14.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-my-json-valid/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-my-json-valid/package.json"
              }
            ],
            "concludedValue": "node_modules/is-my-json-valid/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Stephen Sugden <me@stephensugden.com>"
        }
      ],
      "group": "",
      "name": "is-function",
      "version": "1.0.1",
      "description": "is that thing a function? Use this module to find out",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-function@1.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/grncdr/js-is-function"
        },
        {
          "type": "vcs",
          "url": "git://github.com/grncdr/js-is-function.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/is-function@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-function/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-function/package.json"
              }
            ],
            "concludedValue": "node_modules/is-function/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "is-fullwidth-code-point",
      "version": "1.0.0",
      "description": "Check if the character represented by a given Unicode code point is fullwidth",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-fullwidth-code-point@1.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/is-fullwidth-code-point@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-fullwidth-code-point/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-fullwidth-code-point/package.json"
              }
            ],
            "concludedValue": "node_modules/is-fullwidth-code-point/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "is-finite",
      "version": "1.0.1",
      "description": "ES6 Number.isFinite() ponyfill",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-finite@1.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/is-finite@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-finite/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-finite/package.json"
              }
            ],
            "concludedValue": "node_modules/is-finite/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "is-dom",
      "version": "1.0.5",
      "description": "Check if the given object is a dom node",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-dom@1.0.5",
      "type": "library",
      "bom-ref": "pkg:npm/is-dom@1.0.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-dom/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-dom/package.json"
              }
            ],
            "concludedValue": "node_modules/is-dom/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "is-builtin-module",
      "version": "1.0.0",
      "description": "Check if a string matches the name of a Node.js builtin module",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-builtin-module@1.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/is-builtin-module@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-builtin-module/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-builtin-module/package.json"
              }
            ],
            "concludedValue": "node_modules/is-builtin-module/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Feross Aboukhadijeh <feross@feross.org> (http://feross.org/)"
        }
      ],
      "group": "",
      "name": "is-buffer",
      "version": "1.1.4",
      "description": "Determine if an object is a Buffer",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-buffer@1.1.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/feross/is-buffer.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/is-buffer@1.1.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-buffer/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-buffer/package.json"
              }
            ],
            "concludedValue": "node_modules/is-buffer/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Qix (http://github.com/qix-)"
        }
      ],
      "group": "",
      "name": "is-arrayish",
      "version": "0.2.1",
      "description": "Determines if an object can be used as an array",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-arrayish@0.2.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/qix-/node-is-arrayish.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/is-arrayish@0.2.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-arrayish/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-arrayish/package.json"
              }
            ],
            "concludedValue": "node_modules/is-arrayish/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (http://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "invert-kv",
      "version": "1.0.0",
      "description": "Invert the key/value of an object. Example: {foo: 'bar'} → {bar: 'foo'}",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/invert-kv@1.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/invert-kv@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/invert-kv/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/invert-kv/package.json"
              }
            ],
            "concludedValue": "node_modules/invert-kv/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "insert-module-globals",
      "version": "6.6.3",
      "description": "insert implicit module globals into a module-deps stream",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/insert-module-globals@6.6.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/insert-module-globals"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/insert-module-globals.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/insert-module-globals@6.6.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/insert-module-globals/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/insert-module-globals/package.json"
              }
            ],
            "concludedValue": "node_modules/insert-module-globals/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Thorsten Lorenz <thlorenz@gmx.de> (http://thlorenz.com)"
        }
      ],
      "group": "",
      "name": "inline-source-map",
      "version": "0.5.0",
      "description": "Adds source mappings and base64 encodes them, so they can be inlined in your generated file.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/inline-source-map@0.5.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/thlorenz/inline-source-map"
        },
        {
          "type": "vcs",
          "url": "git://github.com/thlorenz/inline-source-map.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/inline-source-map@0.5.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/insert-module-globals/node_modules/inline-source-map/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/insert-module-globals/node_modules/inline-source-map/package.json"
              }
            ],
            "concludedValue": "node_modules/insert-module-globals/node_modules/inline-source-map/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Thorsten Lorenz <thlorenz@gmx.de> (http://thlorenz.com)"
        }
      ],
      "group": "",
      "name": "convert-source-map",
      "version": "1.1.3",
      "description": "Converts a source-map from/to  different formats and allows adding/changing properties.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/convert-source-map@1.1.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/thlorenz/convert-source-map"
        },
        {
          "type": "vcs",
          "url": "git://github.com/thlorenz/convert-source-map.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/convert-source-map@1.1.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/insert-module-globals/node_modules/convert-source-map/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/insert-module-globals/node_modules/convert-source-map/package.json"
              }
            ],
            "concludedValue": "node_modules/insert-module-globals/node_modules/convert-source-map/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Thorsten Lorenz <thlorenz@gmx.de> (http://thlorenz.com)"
        }
      ],
      "group": "",
      "name": "combine-source-map",
      "version": "0.6.1",
      "description": "Add source maps of multiple files, offset them and then combine them into one source map",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/combine-source-map@0.6.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/thlorenz/combine-source-map"
        },
        {
          "type": "vcs",
          "url": "git://github.com/thlorenz/combine-source-map.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/combine-source-map@0.6.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/insert-module-globals/node_modules/combine-source-map/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/insert-module-globals/node_modules/combine-source-map/package.json"
              }
            ],
            "concludedValue": "node_modules/insert-module-globals/node_modules/combine-source-map/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Thorsten Lorenz <thlorenz@gmx.de> (http://thlorenz.com)"
        }
      ],
      "group": "",
      "name": "inline-source-map",
      "version": "0.3.1",
      "description": "Adds source mappings and base64 encodes them, so they can be inlined in your generated file.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/inline-source-map@0.3.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/thlorenz/inline-source-map"
        },
        {
          "type": "vcs",
          "url": "git://github.com/thlorenz/inline-source-map.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/inline-source-map@0.3.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/inline-source-map/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/inline-source-map/package.json"
              }
            ],
            "concludedValue": "node_modules/inline-source-map/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Nick Fitzgerald <nfitzgerald@mozilla.com>"
        }
      ],
      "group": "",
      "name": "source-map",
      "version": "0.3.0",
      "description": "Generates and consumes source maps",
      "scope": "optional",
      "purl": "pkg:npm/source-map@0.3.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mozilla/source-map"
        },
        {
          "type": "vcs",
          "url": "http://github.com/mozilla/source-map.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/source-map@0.3.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/inline-source-map/node_modules/source-map/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/inline-source-map/node_modules/source-map/package.json"
              }
            ],
            "concludedValue": "node_modules/inline-source-map/node_modules/source-map/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "inherits",
      "version": "2.0.3",
      "description": "Browser-friendly inheritance fully compatible with standard node.js inherits()",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/inherits@2.0.3",
      "type": "library",
      "bom-ref": "pkg:npm/inherits@2.0.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/inherits/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/inherits/package.json"
              }
            ],
            "concludedValue": "node_modules/inherits/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "inflight",
      "version": "1.0.5",
      "description": "Add callbacks to requests in flight to avoid async duplication",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/inflight@1.0.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/inflight"
        },
        {
          "type": "vcs",
          "url": "https://github.com/npm/inflight.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/inflight@1.0.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/inflight/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/inflight/package.json"
              }
            ],
            "concludedValue": "node_modules/inflight/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "indexof",
      "version": "0.0.1",
      "description": "Microsoft sucks",
      "scope": "optional",
      "purl": "pkg:npm/indexof@0.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/indexof@0.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/indexof/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/indexof/package.json"
              }
            ],
            "concludedValue": "node_modules/indexof/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "indent-string",
      "version": "2.1.0",
      "description": "Indent each line in a string",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/indent-string@2.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/indent-string@2.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/indent-string/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/indent-string/package.json"
              }
            ],
            "concludedValue": "node_modules/indent-string/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Feross Aboukhadijeh <feross@feross.org> (http://feross.org/)"
        }
      ],
      "group": "",
      "name": "ieee754",
      "version": "1.1.6",
      "description": "Read/write IEEE754 floating point numbers from/to a Buffer or array-like object",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/ieee754@1.1.6",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/feross/ieee754.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/ieee754@1.1.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/ieee754/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/ieee754/package.json"
              }
            ],
            "concludedValue": "node_modules/ieee754/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Alexander Shtuchkin <ashtuchkin@gmail.com>"
        }
      ],
      "group": "",
      "name": "iconv-lite",
      "version": "0.4.13",
      "description": "Convert character encodings in pure javascript.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/iconv-lite@0.4.13",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/ashtuchkin/iconv-lite"
        },
        {
          "type": "vcs",
          "url": "git://github.com/ashtuchkin/iconv-lite.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/iconv-lite@0.4.13",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/iconv-lite/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/iconv-lite/package.json"
              }
            ],
            "concludedValue": "node_modules/iconv-lite/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "https-browserify",
      "version": "0.0.1",
      "description": "https module compatability for browserify",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/https-browserify@0.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/https-browserify"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/https-browserify.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/https-browserify@0.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/https-browserify/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/https-browserify/package.json"
              }
            ],
            "concludedValue": "node_modules/https-browserify/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Joyent"
        },
        {
          "name": " Inc"
        }
      ],
      "group": "",
      "name": "http-signature",
      "version": "0.11.0",
      "description": "Reference implementation of Joyent's HTTP Signature scheme.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/http-signature@0.11.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/joyent/node-http-signature/"
        },
        {
          "type": "vcs",
          "url": "git://github.com/joyent/node-http-signature.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/http-signature@0.11.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/http-signature/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/http-signature/package.json"
              }
            ],
            "concludedValue": "node_modules/http-signature/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "http-browserify",
      "version": "1.7.0",
      "description": "http module compatability for browserify",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "name": "MIT/X11"
          }
        }
      ],
      "purl": "pkg:npm/http-browserify@1.7.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/substack/http-browserify.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/http-browserify@1.7.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/http-browserify/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/http-browserify/package.json"
              }
            ],
            "concludedValue": "node_modules/http-browserify/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Felix Boehm <me@feedic.com>"
        }
      ],
      "group": "",
      "name": "htmlparser2",
      "version": "3.8.3",
      "description": "Fast & forgiving HTML/XML/RSS parser",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/htmlparser2@3.8.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/fb55/htmlparser2.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/htmlparser2@3.8.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/htmlparser2/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/htmlparser2/package.json"
              }
            ],
            "concludedValue": "node_modules/htmlparser2/package.json"
          }
        ]
      },
      "tags": [
        "parse"
      ]
    },
    {
      "authors": [
        {
          "name": "Rebecca Turner <me@re-becca.org> (http://re-becca.org)"
        }
      ],
      "group": "",
      "name": "hosted-git-info",
      "version": "2.1.5",
      "description": "Provides metadata and conversions from repository urls for Github, Bitbucket and Gitlab",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/hosted-git-info@2.1.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/npm/hosted-git-info"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/npm/hosted-git-info.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/hosted-git-info@2.1.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/hosted-git-info/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/hosted-git-info/package.json"
              }
            ],
            "concludedValue": "node_modules/hosted-git-info/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "hoek",
      "version": "2.16.3",
      "description": "General purpose node utilities",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-3-Clause",
            "url": "https://opensource.org/licenses/BSD-3-Clause"
          }
        }
      ],
      "purl": "pkg:npm/hoek@2.16.3",
      "type": "library",
      "bom-ref": "pkg:npm/hoek@2.16.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/hoek/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/hoek/package.json"
              }
            ],
            "concludedValue": "node_modules/hoek/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Eran Hammer <eran@hammer.io> (http://hueniverse.com)"
        }
      ],
      "group": "",
      "name": "hawk",
      "version": "3.1.3",
      "description": "HTTP Hawk Authentication Scheme",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-3-Clause",
            "url": "https://opensource.org/licenses/BSD-3-Clause"
          }
        }
      ],
      "purl": "pkg:npm/hawk@3.1.3",
      "type": "library",
      "bom-ref": "pkg:npm/hawk@3.1.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/hawk/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/hawk/package.json"
              }
            ],
            "concludedValue": "node_modules/hawk/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Fedor Indutny <fedor@indutny.com>"
        }
      ],
      "group": "",
      "name": "hash.js",
      "version": "1.0.3",
      "description": "Various hash functions that could be run by both browser and node",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/hash.js@1.0.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/indutny/hash.js"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/hash.js@1.0.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/hash.js/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/hash.js/package.json"
              }
            ],
            "concludedValue": "node_modules/hash.js/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (http://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "has-ansi",
      "version": "0.1.0",
      "description": "Check if a string has ANSI escape codes",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/has-ansi@0.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/has-ansi@0.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/has-ansi/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/has-ansi/package.json"
              }
            ],
            "concludedValue": "node_modules/has-ansi/package.json"
          }
        ]
      },
      "tags": [
        "escape"
      ]
    },
    {
      "authors": [
        {
          "name": "Ahmad Nassri <ahmad@ahmadnassri.com> (https://www.ahmadnassri.com/)"
        }
      ],
      "group": "",
      "name": "har-validator",
      "version": "2.0.6",
      "description": "Extremely fast HTTP Archive (HAR) validator using JSON Schema",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/har-validator@2.0.6",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/ahmadnassri/har-validator"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/har-validator@2.0.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/har-validator/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/har-validator/package.json"
              }
            ],
            "concludedValue": "node_modules/har-validator/package.json"
          }
        ]
      },
      "tags": [
        "json"
      ]
    },
    {
      "authors": [
        {
          "name": "zhiyelee"
        }
      ],
      "group": "",
      "name": "graceful-readlink",
      "version": "1.0.1",
      "description": "graceful fs.readlink",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/graceful-readlink@1.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/zhiyelee/graceful-readlink"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/graceful-readlink@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/graceful-readlink/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/graceful-readlink/package.json"
              }
            ],
            "concludedValue": "node_modules/graceful-readlink/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "graceful-fs",
      "version": "4.1.8",
      "description": "A drop-in replacement for fs, making various improvements.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/graceful-fs@4.1.8",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/node-graceful-fs"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/graceful-fs@4.1.8",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/graceful-fs/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/graceful-fs/package.json"
              }
            ],
            "concludedValue": "node_modules/graceful-fs/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Chris Dickinson <chris@neversaw.us>"
        }
      ],
      "group": "",
      "name": "glsl-tokenizer",
      "version": "2.1.2",
      "description": "r/w stream of glsl tokens",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/glsl-tokenizer@2.1.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/gl-modules/glsl-tokenizer.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/glsl-tokenizer@2.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/glsl-tokenizer/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/glsl-tokenizer/package.json"
              }
            ],
            "concludedValue": "node_modules/glsl-tokenizer/package.json"
          }
        ]
      },
      "tags": [
        "stream"
      ]
    },
    {
      "authors": [
        {
          "name": "Raynos <raynos2@gmail.com>"
        }
      ],
      "group": "",
      "name": "global",
      "version": "4.3.1",
      "description": "Require global variables",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/global@4.3.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/Raynos/global"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/global@4.3.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/global/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/global/package.json"
              }
            ],
            "concludedValue": "node_modules/global/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Roman Shtylman <shtylman@gmail.com>"
        }
      ],
      "group": "",
      "name": "process",
      "version": "0.5.2",
      "description": "process information for node.js and browsers",
      "scope": "optional",
      "purl": "pkg:npm/process@0.5.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/shtylman/node-process.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/process@0.5.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/global/node_modules/process/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/global/node_modules/process/package.json"
              }
            ],
            "concludedValue": "node_modules/global/node_modules/process/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "glob",
      "version": "4.5.3",
      "description": "a little globber",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/glob@4.5.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/node-glob.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/glob@4.5.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/glob/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/glob/package.json"
              }
            ],
            "concludedValue": "node_modules/glob/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (http://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "get-stdin",
      "version": "4.0.1",
      "description": "Easier stdin",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/get-stdin@4.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/get-stdin@4.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/get-stdin/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/get-stdin/package.json"
              }
            ],
            "concludedValue": "node_modules/get-stdin/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mathias Buus (@mafintosh)"
        }
      ],
      "group": "",
      "name": "generate-object-property",
      "version": "1.2.0",
      "description": "Generate safe JS code that can used to reference a object property",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/generate-object-property@1.2.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mafintosh/generate-object-property"
        },
        {
          "type": "vcs",
          "url": "https://github.com/mafintosh/generate-object-property"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/generate-object-property@1.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/generate-object-property/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/generate-object-property/package.json"
              }
            ],
            "concludedValue": "node_modules/generate-object-property/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mathias Buus"
        }
      ],
      "group": "",
      "name": "generate-function",
      "version": "2.0.0",
      "description": "Module that helps you write generated functions in Node",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/generate-function@2.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mafintosh/generate-function"
        },
        {
          "type": "vcs",
          "url": "https://github.com/mafintosh/generate-function"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/generate-function@2.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/generate-function/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/generate-function/package.json"
              }
            ],
            "concludedValue": "node_modules/generate-function/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jonathan Ong <me@jongleberry.com> (http://jongleberry.com)"
        }
      ],
      "group": "",
      "name": "fs-readdir-recursive",
      "version": "0.1.0",
      "description": "Recursively read a directory",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/fs-readdir-recursive@0.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jonathanong/fs-readdir-recursive.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/fs-readdir-recursive@0.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/fs-readdir-recursive/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/fs-readdir-recursive/package.json"
              }
            ],
            "concludedValue": "node_modules/fs-readdir-recursive/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Felix Geisendörfer <felix@debuggable.com> (http://debuggable.com/)"
        }
      ],
      "group": "",
      "name": "form-data",
      "version": "1.0.1",
      "description": "A library to create readable \"multipart/form-data\" streams. Can be used to submit forms and file uploads to other web applications.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/form-data@1.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/form-data/form-data.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/form-data@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/form-data/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/form-data/package.json"
              }
            ],
            "concludedValue": "node_modules/form-data/package.json"
          }
        ]
      },
      "tags": [
        "web"
      ]
    },
    {
      "authors": [
        {
          "name": "Mikeal Rogers <mikeal.rogers@gmail.com> (http://www.futurealoof.com)"
        }
      ],
      "group": "",
      "name": "forever-agent",
      "version": "0.6.1",
      "description": "HTTP Agent that keeps socket connections alive between keep-alive requests. Formerly part of mikeal/request, now a standalone module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0",
            "url": "https://opensource.org/licenses/Apache-2.0"
          }
        }
      ],
      "purl": "pkg:npm/forever-agent@0.6.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mikeal/forever-agent"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/forever-agent@0.6.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/forever-agent/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/forever-agent/package.json"
              }
            ],
            "concludedValue": "node_modules/forever-agent/package.json"
          }
        ]
      },
      "tags": [
        "socket"
      ]
    },
    {
      "authors": [
        {
          "name": "Raynos <raynos2@gmail.com>"
        }
      ],
      "group": "",
      "name": "for-each",
      "version": "0.3.2",
      "description": "A better forEach",
      "scope": "optional",
      "purl": "pkg:npm/for-each@0.3.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/Raynos/for-each"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/for-each@0.3.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/for-each/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/for-each/package.json"
              }
            ],
            "concludedValue": "node_modules/for-each/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Hugh Kennedy <hughskennedy@gmail.com> (htttp://hughskennedy.com/)"
        }
      ],
      "group": "",
      "name": "first-match",
      "version": "0.0.1",
      "description": "Find the first element in an array that passes a callback test. Equivalent to underscore.find()",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/first-match@0.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/hughsk/first-match.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/first-match@0.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/first-match/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/first-match/package.json"
              }
            ],
            "concludedValue": "node_modules/first-match/package.json"
          }
        ]
      },
      "tags": [
        "test"
      ]
    },
    {
      "authors": [
        {
          "name": "Hugh Kennedy <hughskennedy@gmail.com> (http://hughsk.io/)"
        }
      ],
      "group": "",
      "name": "firefox-location",
      "version": "1.0.2",
      "description": "Approximates the current location of Mozilla Firefox on your system.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/firefox-location@1.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/hughsk/firefox-location"
        },
        {
          "type": "vcs",
          "url": "git://github.com/hughsk/firefox-location.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/firefox-location@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/firefox-location/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/firefox-location/package.json"
              }
            ],
            "concludedValue": "node_modules/firefox-location/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Hugh Kennedy <hughskennedy@gmail.com> (http://hughsk.io/)"
        }
      ],
      "group": "",
      "name": "firefox-launch",
      "version": "1.0.2",
      "description": "Light cross-platform launcher for Mozilla Firefox",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/firefox-launch@1.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/hughsk/firefox-launch"
        },
        {
          "type": "vcs",
          "url": "git://github.com/hughsk/firefox-launch.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/firefox-launch@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/firefox-launch/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/firefox-launch/package.json"
              }
            ],
            "concludedValue": "node_modules/firefox-launch/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "find-up",
      "version": "1.1.2",
      "description": "Find a file by walking up parent directories",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/find-up@1.1.2",
      "type": "library",
      "bom-ref": "pkg:npm/find-up@1.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/find-up/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/find-up/package.json"
              }
            ],
            "concludedValue": "node_modules/find-up/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Coglan <jcoglan@gmail.com> (http://jcoglan.com/)"
        }
      ],
      "group": "",
      "name": "faye-websocket",
      "version": "0.4.4",
      "description": "Standards-compliant WebSocket server and client",
      "scope": "optional",
      "purl": "pkg:npm/faye-websocket@0.4.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/faye/faye-websocket-node"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/faye-websocket@0.4.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/faye-websocket/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/faye-websocket/package.json"
              }
            ],
            "concludedValue": "node_modules/faye-websocket/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Stefan Thomas <justmoon@members.fsf.org> (http://www.justmoon.net)"
        }
      ],
      "group": "",
      "name": "extend",
      "version": "3.0.0",
      "description": "Port of jQuery.extend for node.js and the browser",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/extend@3.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/justmoon/node-extend.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/extend@3.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/extend/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/extend/package.json"
              }
            ],
            "concludedValue": "node_modules/extend/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "\"Cowboy\" Ben Alman (http://benalman.com/)"
        }
      ],
      "group": "",
      "name": "exit",
      "version": "0.1.2",
      "description": "A replacement for process.exit that ensures stdio are fully drained before exiting.",
      "scope": "optional",
      "purl": "pkg:npm/exit@0.1.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/cowboy/node-exit"
        },
        {
          "type": "vcs",
          "url": "git://github.com/cowboy/node-exit.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/exit@0.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/exit/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/exit/package.json"
              }
            ],
            "concludedValue": "node_modules/exit/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Calvin Metcalf <calvin.metcalf@gmail.com>"
        }
      ],
      "group": "",
      "name": "evp_bytestokey",
      "version": "1.0.0",
      "description": "he super secure key derivation algorithm from openssl",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/evp_bytestokey@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/crypto-browserify/EVP_BytesToKey"
        },
        {
          "type": "vcs",
          "url": "https://github.com/crypto-browserify/EVP_BytesToKey.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/evp_bytestokey@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/evp_bytestokey/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/evp_bytestokey/package.json"
              }
            ],
            "concludedValue": "node_modules/evp_bytestokey/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Irakli Gozalishvili <rfobic@gmail.com> (http://jeditoolkit.com)"
        }
      ],
      "group": "",
      "name": "events",
      "version": "1.0.2",
      "description": "Node's event emitter for all engines.",
      "scope": "optional",
      "purl": "pkg:npm/events@1.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/Gozala/events.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/events@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/events/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/events/package.json"
              }
            ],
            "concludedValue": "node_modules/events/package.json"
          }
        ]
      },
      "tags": [
        "event"
      ]
    },
    {
      "authors": [
        {
          "name": "Michael Ficarra"
        }
      ],
      "group": "",
      "name": "esvalid",
      "version": "1.1.0",
      "description": "confirm that a SpiderMonkey format AST represents an ECMAScript program",
      "scope": "optional",
      "licenses": [
        {
          "expression": "3-Clause BSD"
        }
      ],
      "purl": "pkg:npm/esvalid@1.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/michaelficarra/esvalid"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/esvalid@1.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/esvalid/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/esvalid/package.json"
              }
            ],
            "concludedValue": "node_modules/esvalid/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "esutils",
      "version": "1.1.6",
      "description": "utility box for ECMAScript language tools",
      "scope": "optional",
      "purl": "pkg:npm/esutils@1.1.6",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/Constellation/esutils"
        },
        {
          "type": "vcs",
          "url": "http://github.com/Constellation/esutils.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/esutils@1.1.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/esutils/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/esutils/package.json"
              }
            ],
            "concludedValue": "node_modules/esutils/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "estraverse",
      "version": "1.9.1",
      "description": "ECMAScript JS AST traversal functions",
      "scope": "optional",
      "purl": "pkg:npm/estraverse@1.9.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/estools/estraverse"
        },
        {
          "type": "vcs",
          "url": "http://github.com/estools/estraverse.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/estraverse@1.9.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/estraverse/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/estraverse/package.json"
              }
            ],
            "concludedValue": "node_modules/estraverse/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Ariya Hidayat <ariya.hidayat@gmail.com>"
        }
      ],
      "group": "",
      "name": "esprima-fb",
      "version": "10001.1.0-dev-harmony-fb",
      "description": "Facebook-specific fork of the esprima project",
      "scope": "optional",
      "purl": "pkg:npm/esprima-fb@10001.1.0-dev-harmony-fb",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/facebook/esprima/tree/fb-harmony"
        },
        {
          "type": "vcs",
          "url": "http://github.com/facebook/esprima.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/esprima-fb@10001.1.0-dev-harmony-fb",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/esprima-fb/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/esprima-fb/package.json"
              }
            ],
            "concludedValue": "node_modules/esprima-fb/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "escape-string-regexp",
      "version": "1.0.5",
      "description": "Escape RegExp special characters",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/escape-string-regexp@1.0.5",
      "type": "library",
      "bom-ref": "pkg:npm/escape-string-regexp@1.0.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/escape-string-regexp/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/escape-string-regexp/package.json"
              }
            ],
            "concludedValue": "node_modules/escape-string-regexp/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "error-ex",
      "version": "1.3.0",
      "description": "Easy error subclassing and stack customization",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/error-ex@1.3.0",
      "type": "library",
      "bom-ref": "pkg:npm/error-ex@1.3.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/error-ex/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/error-ex/package.json"
              }
            ],
            "concludedValue": "node_modules/error-ex/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Felix Boehm <me@feedic.com>"
        }
      ],
      "group": "",
      "name": "entities",
      "version": "1.0.0",
      "description": "Encode & decode XML/HTML entities with ease",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "name": "BSD-like"
          }
        }
      ],
      "purl": "pkg:npm/entities@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/fb55/node-entities.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/entities@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/entities/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/entities/package.json"
              }
            ],
            "concludedValue": "node_modules/entities/package.json"
          }
        ]
      },
      "tags": [
        "decode"
      ]
    },
    {
      "authors": [
        {
          "name": "Mathias Buus <mathiasbuus@gmail.com>"
        }
      ],
      "group": "",
      "name": "end-of-stream",
      "version": "1.1.0",
      "description": "Call a callback when a readable/writable/duplex stream has completed or failed.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/end-of-stream@1.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mafintosh/end-of-stream"
        },
        {
          "type": "vcs",
          "url": "git://github.com/mafintosh/end-of-stream.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/end-of-stream@1.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/end-of-stream/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/end-of-stream/package.json"
              }
            ],
            "concludedValue": "node_modules/end-of-stream/package.json"
          }
        ]
      },
      "tags": [
        "stream"
      ]
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "once",
      "version": "1.3.3",
      "description": "Run a function exactly one time",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/once@1.3.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/once"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/once@1.3.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/end-of-stream/node_modules/once/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/end-of-stream/node_modules/once/package.json"
              }
            ],
            "concludedValue": "node_modules/end-of-stream/node_modules/once/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Fedor Indutny <fedor@indutny.com>"
        }
      ],
      "group": "",
      "name": "elliptic",
      "version": "6.3.2",
      "description": "EC cryptography",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/elliptic@6.3.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/indutny/elliptic"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/elliptic@6.3.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/elliptic/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/elliptic/package.json"
              }
            ],
            "concludedValue": "node_modules/elliptic/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Conrad Pankoff <deoxxa@fknsrs.biz> (http://www.fknsrs.biz/)"
        }
      ],
      "group": "",
      "name": "duplexer2",
      "version": "0.0.2",
      "description": "Like duplexer (http://npm.im/duplexer) but using streams2",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "name": "BSD"
          }
        }
      ],
      "purl": "pkg:npm/duplexer2@0.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/deoxxa/duplexer2.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/duplexer2@0.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/duplexer2/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/duplexer2/package.json"
              }
            ],
            "concludedValue": "node_modules/duplexer2/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Raynos <raynos2@gmail.com>"
        }
      ],
      "group": "",
      "name": "duplexer",
      "version": "0.1.1",
      "description": "Creates a duplex stream",
      "scope": "optional",
      "purl": "pkg:npm/duplexer@0.1.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/Raynos/duplexer"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/duplexer@0.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/duplexer/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/duplexer/package.json"
              }
            ],
            "concludedValue": "node_modules/duplexer/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Felix Boehm <me@feedic.com>"
        }
      ],
      "group": "",
      "name": "domutils",
      "version": "1.5.1",
      "description": "utilities for working with htmlparser2's dom",
      "scope": "optional",
      "purl": "pkg:npm/domutils@1.5.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/FB55/domutils.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/domutils@1.5.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/domutils/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/domutils/package.json"
              }
            ],
            "concludedValue": "node_modules/domutils/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Felix Boehm <me@feedic.com>"
        }
      ],
      "group": "",
      "name": "domhandler",
      "version": "2.3.0",
      "description": "handler for htmlparser2 that turns pages into a dom",
      "scope": "optional",
      "purl": "pkg:npm/domhandler@2.3.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/fb55/DomHandler.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/domhandler@2.3.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/domhandler/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/domhandler/package.json"
              }
            ],
            "concludedValue": "node_modules/domhandler/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Felix Boehm <me@feedic.com>"
        }
      ],
      "group": "",
      "name": "domelementtype",
      "version": "1.2.0",
      "description": "all the types of nodes in htmlparser2's dom",
      "scope": "optional",
      "purl": "pkg:npm/domelementtype@1.2.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/FB55/domelementtype.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/domelementtype@1.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/domelementtype/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/domelementtype/package.json"
              }
            ],
            "concludedValue": "node_modules/domelementtype/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "2013+ Bevry Pty Ltd <us@bevry.me> (http://bevry.me)"
        }
      ],
      "group": "",
      "name": "domain-browser",
      "version": "1.1.7",
      "description": "Node's domain module for the web browser. This is merely an evented try...catch with the same API as node, nothing more.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/domain-browser@1.1.7",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/bevry/domain-browser"
        },
        {
          "type": "vcs",
          "url": "http://github.com/bevry/domain-browser.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/domain-browser@1.1.7",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/domain-browser/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/domain-browser/package.json"
              }
            ],
            "concludedValue": "node_modules/domain-browser/package.json"
          }
        ]
      },
      "tags": [
        "api",
        "web"
      ]
    },
    {
      "authors": [
        {
          "name": "Raynos <raynos2@gmail.com>"
        }
      ],
      "group": "",
      "name": "dom-walk",
      "version": "0.1.1",
      "description": "iteratively walk a DOM node",
      "scope": "optional",
      "purl": "pkg:npm/dom-walk@0.1.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/Raynos/dom-walk"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/dom-walk@0.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/dom-walk/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/dom-walk/package.json"
              }
            ],
            "concludedValue": "node_modules/dom-walk/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Felix Boehm <me@feedic.com>"
        }
      ],
      "group": "",
      "name": "dom-serializer",
      "version": "0.1.0",
      "description": "render dom nodes to string",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/dom-serializer@0.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/cheeriojs/dom-renderer.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/dom-serializer@0.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/dom-serializer/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/dom-serializer/package.json"
              }
            ],
            "concludedValue": "node_modules/dom-serializer/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Felix Boehm <me@feedic.com>"
        }
      ],
      "group": "",
      "name": "entities",
      "version": "1.1.1",
      "description": "Encode & decode XML/HTML entities with ease",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "name": "BSD-like"
          }
        }
      ],
      "purl": "pkg:npm/entities@1.1.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/fb55/node-entities.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/entities@1.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/dom-serializer/node_modules/entities/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/dom-serializer/node_modules/entities/package.json"
              }
            ],
            "concludedValue": "node_modules/dom-serializer/node_modules/entities/package.json"
          }
        ]
      },
      "tags": [
        "decode"
      ]
    },
    {
      "authors": [
        {
          "name": "Felix Boehm <me@feedic.com>"
        }
      ],
      "group": "",
      "name": "domelementtype",
      "version": "1.1.3",
      "description": "all the types of nodes in htmlparser2's dom",
      "scope": "optional",
      "purl": "pkg:npm/domelementtype@1.1.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/FB55/domelementtype.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/domelementtype@1.1.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/dom-serializer/node_modules/domelementtype/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/dom-serializer/node_modules/domelementtype/package.json"
              }
            ],
            "concludedValue": "node_modules/dom-serializer/node_modules/domelementtype/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Calvin Metcalf"
        }
      ],
      "group": "",
      "name": "diffie-hellman",
      "version": "5.0.2",
      "description": "pure js diffie-hellman",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/diffie-hellman@5.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/crypto-browserify/diffie-hellman"
        },
        {
          "type": "vcs",
          "url": "https://github.com/crypto-browserify/diffie-hellman.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/diffie-hellman@5.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/diffie-hellman/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/diffie-hellman/package.json"
              }
            ],
            "concludedValue": "node_modules/diffie-hellman/package.json"
          }
        ]
      },
      "tags": [
        "native"
      ]
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "detective",
      "version": "4.3.1",
      "description": "find all require() calls by walking the AST",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/detective@4.3.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/substack/node-detective.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/detective@4.3.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/detective/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/detective/package.json"
              }
            ],
            "concludedValue": "node_modules/detective/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Fedor Indutny <fedor@indutny.com>"
        }
      ],
      "group": "",
      "name": "des.js",
      "version": "1.0.0",
      "description": "DES implementation",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/des.js@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/indutny/des.js#readme"
        },
        {
          "type": "vcs",
          "url": "git+ssh://git@github.com/indutny/des.js.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/des.js@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/des.js/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/des.js/package.json"
              }
            ],
            "concludedValue": "node_modules/des.js/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "deps-sort",
      "version": "1.3.9",
      "description": "sort module-deps output for deterministic browserify bundles",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/deps-sort@1.3.9",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/deps-sort"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/deps-sort.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/deps-sort@1.3.9",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/deps-sort/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/deps-sort/package.json"
              }
            ],
            "concludedValue": "node_modules/deps-sort/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Felix Geisendörfer <felix@debuggable.com> (http://debuggable.com/)"
        }
      ],
      "group": "",
      "name": "delayed-stream",
      "version": "1.0.0",
      "description": "Buffers events from a stream until you are ready to handle them.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/delayed-stream@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/felixge/node-delayed-stream"
        },
        {
          "type": "vcs",
          "url": "git://github.com/felixge/node-delayed-stream.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/delayed-stream@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/delayed-stream/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/delayed-stream/package.json"
              }
            ],
            "concludedValue": "node_modules/delayed-stream/package.json"
          }
        ]
      },
      "tags": [
        "stream"
      ]
    },
    {
      "authors": [
        {
          "name": "Olov Lassus <olov.lassus@gmail.com>"
        }
      ],
      "group": "",
      "name": "defs",
      "version": "1.1.1",
      "description": "Static scope analysis and transpilation of ES6 block scoped const and let variables, to ES3.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/defs@1.1.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/olov/defs.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/defs@1.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/defs/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/defs/package.json"
              }
            ],
            "concludedValue": "node_modules/defs/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Ariya Hidayat <ariya.hidayat@gmail.com>"
        }
      ],
      "group": "",
      "name": "esprima-fb",
      "version": "15001.1001.0-dev-harmony-fb",
      "description": "Facebook-specific fork of the esprima project",
      "scope": "optional",
      "purl": "pkg:npm/esprima-fb@15001.1001.0-dev-harmony-fb",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/facebook/esprima/tree/fb-harmony"
        },
        {
          "type": "vcs",
          "url": "http://github.com/facebook/esprima.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/esprima-fb@15001.1001.0-dev-harmony-fb",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/defs/node_modules/esprima-fb/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/commoner/node_modules/esprima-fb/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/commoner/node_modules/esprima-fb/package.json"
              }
            ],
            "concludedValue": "node_modules/commoner/node_modules/esprima-fb/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "defined",
      "version": "0.0.0",
      "description": "return the first argument that is `!== undefined`",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/defined@0.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/defined"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/defined.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/defined@0.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/defined/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/defined/package.json"
              }
            ],
            "concludedValue": "node_modules/defined/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "deep-equal",
      "version": "0.2.2",
      "description": "node's assert.deepEqual algorithm",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/deep-equal@0.2.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/substack/node-deep-equal.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/deep-equal@0.2.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/deep-equal/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/deep-equal/package.json"
              }
            ],
            "concludedValue": "node_modules/deep-equal/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "decamelize",
      "version": "1.2.0",
      "description": "Convert a camelized string into a lowercased one with a custom separator: unicornRainbow → unicorn_rainbow",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/decamelize@1.2.0",
      "type": "library",
      "bom-ref": "pkg:npm/decamelize@1.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/decamelize/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/decamelize/package.json"
              }
            ],
            "concludedValue": "node_modules/decamelize/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "TJ Holowaychuk <tj@vision-media.ca>"
        }
      ],
      "group": "",
      "name": "debug",
      "version": "2.2.0",
      "description": "small debugging utility",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/debug@2.2.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/visionmedia/debug.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/debug@2.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/debug/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/debug/package.json"
              }
            ],
            "concludedValue": "node_modules/debug/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Raynos <raynos2@gmail.com>"
        }
      ],
      "group": "",
      "name": "date-now",
      "version": "0.1.4",
      "description": "A requirable version of Date.now()",
      "scope": "optional",
      "purl": "pkg:npm/date-now@0.1.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/Colingo/date-now"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/date-now@0.1.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/date-now/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/date-now/package.json"
              }
            ],
            "concludedValue": "node_modules/date-now/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Talmage <james@talmage.io> (github.com/jamestalmage)"
        }
      ],
      "group": "",
      "name": "currently-unhandled",
      "version": "0.4.1",
      "description": "Track the list of currently unhandled promise rejections.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/currently-unhandled@0.4.1",
      "type": "library",
      "bom-ref": "pkg:npm/currently-unhandled@0.4.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/currently-unhandled/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/currently-unhandled/package.json"
              }
            ],
            "concludedValue": "node_modules/currently-unhandled/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Robert Mustacchi <rm@fingolfin.org>"
        }
      ],
      "group": "",
      "name": "ctype",
      "version": "0.5.3",
      "description": "read and write binary structures and data types",
      "scope": "optional",
      "purl": "pkg:npm/ctype@0.5.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/rmustacc/node-ctype"
        },
        {
          "type": "vcs",
          "url": "https://github.com/rmustacc/node-ctype.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/ctype@0.5.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/ctype/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/ctype/package.json"
              }
            ],
            "concludedValue": "node_modules/ctype/package.json"
          }
        ]
      },
      "tags": [
        "binary"
      ]
    },
    {
      "authors": [
        {
          "name": "Dominic Tarr <dominic.tarr@gmail.com> (dominictarr.com)"
        }
      ],
      "group": "",
      "name": "crypto-browserify",
      "version": "3.11.0",
      "description": "implementation of crypto for the browser",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/crypto-browserify@3.11.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/crypto-browserify/crypto-browserify"
        },
        {
          "type": "vcs",
          "url": "git://github.com/crypto-browserify/crypto-browserify.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/crypto-browserify@3.11.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/crypto-browserify/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/crypto-browserify/package.json"
              }
            ],
            "concludedValue": "node_modules/crypto-browserify/package.json"
          }
        ]
      },
      "tags": [
        "crypto"
      ]
    },
    {
      "group": "",
      "name": "cryptiles",
      "version": "2.0.5",
      "description": "General purpose crypto utilities",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-3-Clause",
            "url": "https://opensource.org/licenses/BSD-3-Clause"
          }
        }
      ],
      "purl": "pkg:npm/cryptiles@2.0.5",
      "type": "library",
      "bom-ref": "pkg:npm/cryptiles@2.0.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/cryptiles/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/cryptiles/package.json"
              }
            ],
            "concludedValue": "node_modules/cryptiles/package.json"
          }
        ]
      },
      "tags": [
        "crypto"
      ]
    },
    {
      "group": "",
      "name": "create-hmac",
      "version": "1.1.4",
      "description": "node style hmacs in the browser",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/create-hmac@1.1.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/crypto-browserify/createHmac"
        },
        {
          "type": "vcs",
          "url": "https://github.com/crypto-browserify/createHmac.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/create-hmac@1.1.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/create-hmac/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/create-hmac/package.json"
              }
            ],
            "concludedValue": "node_modules/create-hmac/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "create-hash",
      "version": "1.1.2",
      "description": "create hashes for browserify",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/create-hash@1.1.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/crypto-browserify/createHash"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/create-hash@1.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/create-hash/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/create-hash/package.json"
              }
            ],
            "concludedValue": "node_modules/create-hash/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Calvin Metcalf"
        }
      ],
      "group": "",
      "name": "create-ecdh",
      "version": "4.0.0",
      "description": "createECDH but browserifiable",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/create-ecdh@4.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/crypto-browserify/createECDH"
        },
        {
          "type": "vcs",
          "url": "https://github.com/crypto-browserify/createECDH.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/create-ecdh@4.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/create-ecdh/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/create-ecdh/package.json"
              }
            ],
            "concludedValue": "node_modules/create-ecdh/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Chris Talkington (http://christalkington.com/)"
        }
      ],
      "group": "",
      "name": "crc32-stream",
      "version": "0.3.4",
      "description": "a streaming CRC32 checksumer",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/crc32-stream@0.3.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/archiverjs/node-crc32-stream"
        },
        {
          "type": "vcs",
          "url": "https://github.com/archiverjs/node-crc32-stream.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/crc32-stream@0.3.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/crc32-stream/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/crc32-stream/package.json"
              }
            ],
            "concludedValue": "node_modules/crc32-stream/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "core-util-is",
      "version": "1.0.2",
      "description": "The `util.is*` functions introduced in Node v0.12.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/core-util-is@1.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/core-util-is"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/core-util-is@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/core-util-is/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/core-util-is/package.json"
              }
            ],
            "concludedValue": "node_modules/core-util-is/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "core-js",
      "version": "0.4.5",
      "description": "Standard library",
      "scope": "optional",
      "purl": "pkg:npm/core-js@0.4.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/zloirock/core-js.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/core-js@0.4.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/core-js/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/core-js/package.json"
              }
            ],
            "concludedValue": "node_modules/core-js/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Thorsten Lorenz <thlorenz@gmx.de> (http://thlorenz.com)"
        }
      ],
      "group": "",
      "name": "convert-source-map",
      "version": "0.3.5",
      "description": "Converts a source-map from/to  different formats and allows adding/changing properties.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/convert-source-map@0.3.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/thlorenz/convert-source-map"
        },
        {
          "type": "vcs",
          "url": "git://github.com/thlorenz/convert-source-map.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/convert-source-map@0.3.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/convert-source-map/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/convert-source-map/package.json"
              }
            ],
            "concludedValue": "node_modules/convert-source-map/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Julian Gruber <julian@juliangruber.com> (http://juliangruber.com)"
        }
      ],
      "group": "",
      "name": "constants-browserify",
      "version": "0.0.1",
      "description": "node's constants module for the browser",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/constants-browserify@0.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/juliangruber/constants-browserify"
        },
        {
          "type": "vcs",
          "url": "git://github.com/juliangruber/constants-browserify.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/constants-browserify@0.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/constants-browserify/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/constants-browserify/package.json"
              }
            ],
            "concludedValue": "node_modules/constants-browserify/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Raynos <raynos2@gmail.com>"
        }
      ],
      "group": "",
      "name": "console-browserify",
      "version": "1.1.0",
      "description": "Emulate console for all the browsers",
      "scope": "optional",
      "purl": "pkg:npm/console-browserify@1.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/Raynos/console-browserify"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/console-browserify@1.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/console-browserify/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/console-browserify/package.json"
              }
            ],
            "concludedValue": "node_modules/console-browserify/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Max Ogden <max@maxogden.com>"
        }
      ],
      "group": "",
      "name": "concat-stream",
      "version": "1.4.10",
      "description": "writable stream that concatenates strings or binary data and calls a callback with the result",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/concat-stream@1.4.10",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/maxogden/concat-stream.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/concat-stream@1.4.10",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/concat-stream/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/concat-stream/package.json"
              }
            ],
            "concludedValue": "node_modules/concat-stream/package.json"
          }
        ]
      },
      "tags": [
        "binary",
        "stream"
      ]
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "concat-map",
      "version": "0.0.1",
      "description": "concatenative mapdashery",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/concat-map@0.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/substack/node-concat-map.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/concat-map@0.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/concat-map/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/concat-map/package.json"
              }
            ],
            "concludedValue": "node_modules/concat-map/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Chris Talkington (http://christalkington.com/)"
        }
      ],
      "group": "",
      "name": "compress-commons",
      "version": "0.2.9",
      "description": "a library that defines a common interface for working with archive formats within node",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/compress-commons@0.2.9",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/archiverjs/node-compress-commons"
        },
        {
          "type": "vcs",
          "url": "https://github.com/archiverjs/node-compress-commons.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/compress-commons@0.2.9",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/compress-commons/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/compress-commons/package.json"
              }
            ],
            "concludedValue": "node_modules/compress-commons/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Ben Newman <bn@cs.stanford.edu>"
        }
      ],
      "group": "",
      "name": "commoner",
      "version": "0.10.4",
      "description": "Flexible tool for translating any dialect of JavaScript into Node-readable CommonJS modules",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/commoner@0.10.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/reactjs/commoner"
        },
        {
          "type": "vcs",
          "url": "git://github.com/reactjs/commoner.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/commoner@0.10.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/commoner/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/commoner/package.json"
              }
            ],
            "concludedValue": "node_modules/commoner/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Nick Fitzgerald <nfitzgerald@mozilla.com>"
        }
      ],
      "group": "",
      "name": "source-map",
      "version": "0.5.6",
      "description": "Generates and consumes source maps",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-3-Clause",
            "url": "https://opensource.org/licenses/BSD-3-Clause"
          }
        }
      ],
      "purl": "pkg:npm/source-map@0.5.6",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mozilla/source-map"
        },
        {
          "type": "vcs",
          "url": "http://github.com/mozilla/source-map.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/source-map@0.5.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/commoner/node_modules/source-map/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/commoner/node_modules/source-map/package.json"
              }
            ],
            "concludedValue": "node_modules/commoner/node_modules/source-map/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Ben Newman <bn@cs.stanford.edu>"
        }
      ],
      "group": "",
      "name": "recast",
      "version": "0.10.43",
      "description": "JavaScript syntax tree transformer, nondestructive pretty-printer, and automatic source map generator",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/recast@0.10.43",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/benjamn/recast"
        },
        {
          "type": "vcs",
          "url": "git://github.com/benjamn/recast.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/recast@0.10.43",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/commoner/node_modules/recast/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/commoner/node_modules/recast/package.json"
              }
            ],
            "concludedValue": "node_modules/commoner/node_modules/recast/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "glob",
      "version": "5.0.15",
      "description": "a little globber",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/glob@5.0.15",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/node-glob.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/glob@5.0.15",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/commoner/node_modules/glob/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/commoner/node_modules/glob/package.json"
              }
            ],
            "concludedValue": "node_modules/commoner/node_modules/glob/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Ben Newman <bn@cs.stanford.edu>"
        }
      ],
      "group": "",
      "name": "ast-types",
      "version": "0.8.15",
      "description": "Esprima-compatible implementation of the Mozilla JS Parser API",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/ast-types@0.8.15",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/benjamn/ast-types"
        },
        {
          "type": "vcs",
          "url": "git://github.com/benjamn/ast-types.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/ast-types@0.8.15",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/commoner/node_modules/ast-types/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/commoner/node_modules/ast-types/package.json"
              }
            ],
            "concludedValue": "node_modules/commoner/node_modules/ast-types/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "commondir",
      "version": "0.0.1",
      "description": "Compute the closest common parent for file paths",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "name": "MIT/X11"
          }
        }
      ],
      "purl": "pkg:npm/commondir@0.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/substack/node-commondir.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/commondir@0.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/commondir/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/commondir/package.json"
              }
            ],
            "concludedValue": "node_modules/commondir/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "TJ Holowaychuk <tj@vision-media.ca>"
        }
      ],
      "group": "",
      "name": "commander",
      "version": "2.6.0",
      "description": "the complete solution for node.js command-line programs",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/commander@2.6.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/tj/commander.js.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/commander@2.6.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/commander/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/commander/package.json"
              }
            ],
            "concludedValue": "node_modules/commander/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Felix Geisendörfer <felix@debuggable.com> (http://debuggable.com/)"
        }
      ],
      "group": "",
      "name": "combined-stream",
      "version": "1.0.5",
      "description": "A stream that emits multiple other streams one after another.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/combined-stream@1.0.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/felixge/node-combined-stream"
        },
        {
          "type": "vcs",
          "url": "git://github.com/felixge/node-combined-stream.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/combined-stream@1.0.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/combined-stream/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/combined-stream/package.json"
              }
            ],
            "concludedValue": "node_modules/combined-stream/package.json"
          }
        ]
      },
      "tags": [
        "stream"
      ]
    },
    {
      "authors": [
        {
          "name": "Thorsten Lorenz <thlorenz@gmx.de> (http://thlorenz.com)"
        }
      ],
      "group": "",
      "name": "combine-source-map",
      "version": "0.3.0",
      "description": "Add source maps of multiple files, offset them and then combine them into one source map",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/combine-source-map@0.3.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/thlorenz/combine-source-map"
        },
        {
          "type": "vcs",
          "url": "git://github.com/thlorenz/combine-source-map.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/combine-source-map@0.3.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/combine-source-map/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/combine-source-map/package.json"
              }
            ],
            "concludedValue": "node_modules/combine-source-map/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "code-point-at",
      "version": "1.0.0",
      "description": "ES2015 String#codePointAt() ponyfill",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/code-point-at@1.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/code-point-at@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/code-point-at/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/code-point-at/package.json"
              }
            ],
            "concludedValue": "node_modules/code-point-at/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Ben Coe <ben@npmjs.com>"
        }
      ],
      "group": "",
      "name": "cliui",
      "version": "2.1.0",
      "description": "easily create complex multi-column command-line-interfaces",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/cliui@2.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/bcoe/cliui.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/cliui@2.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/cliui/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/cliui/package.json"
              }
            ],
            "concludedValue": "node_modules/cliui/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Chris O'Hara <cohara87@gmail.com>"
        }
      ],
      "group": "",
      "name": "cli",
      "version": "0.6.6",
      "description": "A tool for rapidly building command line apps",
      "scope": "optional",
      "purl": "pkg:npm/cli@0.6.6",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/chriso/cli"
        },
        {
          "type": "vcs",
          "url": "http://github.com/chriso/cli.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/cli@0.6.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/cli/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/cli/package.json"
              }
            ],
            "concludedValue": "node_modules/cli/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Calvin Metcalf <calvin.metcalf@gmail.com>"
        }
      ],
      "group": "",
      "name": "cipher-base",
      "version": "1.0.3",
      "description": "abstract base class for crypto-streams",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/cipher-base@1.0.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/crypto-browserify/cipher-base#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/crypto-browserify/cipher-base.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/cipher-base@1.0.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/cipher-base/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/cipher-base/package.json"
              }
            ],
            "concludedValue": "node_modules/cipher-base/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Hugh Kennedy <hughskennedy@gmail.com> (http://hughsk.io/)"
        }
      ],
      "group": "",
      "name": "chrome-location",
      "version": "1.2.1",
      "description": "Approximates the current location of Google Chrome on your system",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/chrome-location@1.2.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/hughsk/chrome-location"
        },
        {
          "type": "vcs",
          "url": "git://github.com/hughsk/chrome-location.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/chrome-location@1.2.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/chrome-location/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/chrome-location/package.json"
              }
            ],
            "concludedValue": "node_modules/chrome-location/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Hugh Kennedy <hughskennedy@gmail.com> (http://hughsk.io/)"
        }
      ],
      "group": "",
      "name": "chrome-launch",
      "version": "1.1.4",
      "description": "Light cross-platform launcher for Google Chrome",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/chrome-launch@1.1.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/hughsk/chrome-launch"
        },
        {
          "type": "vcs",
          "url": "git://github.com/hughsk/chrome-launch.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/chrome-launch@1.1.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/chrome-launch/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/chrome-launch/package.json"
              }
            ],
            "concludedValue": "node_modules/chrome-launch/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Paul Miller (http://paulmillr.com)"
        }
      ],
      "group": "",
      "name": "chokidar",
      "version": "0.12.6",
      "description": "A neat wrapper around node.js fs.watch / fs.watchFile / fsevents.",
      "scope": "optional",
      "purl": "pkg:npm/chokidar@0.12.6",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/paulmillr/chokidar"
        },
        {
          "type": "vcs",
          "url": "https://github.com/paulmillr/chokidar.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/chokidar@0.12.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/chokidar/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/chokidar/package.json"
              }
            ],
            "concludedValue": "node_modules/chokidar/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "chalk",
      "version": "0.5.1",
      "description": "Terminal string styling done right. Created because the `colors` module does some really horrible things.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/chalk@0.5.1",
      "type": "library",
      "bom-ref": "pkg:npm/chalk@0.5.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/chalk/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/chalk/package.json"
              }
            ],
            "concludedValue": "node_modules/chalk/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jon Schlinkert (https://github.com/jonschlinkert)"
        }
      ],
      "group": "",
      "name": "center-align",
      "version": "0.1.3",
      "description": "Center-align the text in a string.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/center-align@0.1.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jonschlinkert/center-align"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/center-align@0.1.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/center-align/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/center-align/package.json"
              }
            ],
            "concludedValue": "node_modules/center-align/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mikeal Rogers <mikeal.rogers@gmail.com>"
        }
      ],
      "group": "",
      "name": "caseless",
      "version": "0.11.0",
      "description": "Caseless object set/get/has, very useful when working with HTTP headers.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0",
            "url": "https://opensource.org/licenses/Apache-2.0"
          }
        }
      ],
      "purl": "pkg:npm/caseless@0.11.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mikeal/caseless"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/caseless@0.11.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/caseless/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/caseless/package.json"
              }
            ],
            "concludedValue": "node_modules/caseless/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (http://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "camelcase-keys",
      "version": "2.1.0",
      "description": "Convert object keys to camelCase",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/camelcase-keys@2.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/camelcase-keys@2.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/camelcase-keys/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/camelcase-keys/package.json"
              }
            ],
            "concludedValue": "node_modules/camelcase-keys/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (http://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "camelcase",
      "version": "2.1.1",
      "description": "Convert a dash/dot/underscore/space separated string to camelCase: foo-bar → fooBar",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/camelcase@2.1.1",
      "type": "library",
      "bom-ref": "pkg:npm/camelcase@2.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/camelcase/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/camelcase/package.json"
              }
            ],
            "concludedValue": "node_modules/camelcase/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "TJ Holowaychuk <tj@vision-media.ca>"
        }
      ],
      "group": "",
      "name": "callsite",
      "version": "1.0.0",
      "description": "access to v8's CallSites",
      "scope": "optional",
      "purl": "pkg:npm/callsite@1.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/callsite@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/callsite/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/callsite/package.json"
              }
            ],
            "concludedValue": "node_modules/callsite/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "builtins",
      "version": "0.0.7",
      "description": "List of node.js builtin modules",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/builtins@0.0.7",
      "type": "library",
      "bom-ref": "pkg:npm/builtins@0.0.7",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/builtins/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/builtins/package.json"
              }
            ],
            "concludedValue": "node_modules/builtins/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "builtin-modules",
      "version": "1.1.1",
      "description": "List of the Node.js builtin modules",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/builtin-modules@1.1.1",
      "type": "library",
      "bom-ref": "pkg:npm/builtin-modules@1.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/builtin-modules/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/builtin-modules/package.json"
              }
            ],
            "concludedValue": "node_modules/builtin-modules/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Daniel Cousens"
        }
      ],
      "group": "",
      "name": "buffer-xor",
      "version": "1.0.3",
      "description": "A simple module for bitwise-xor on buffers",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/buffer-xor@1.0.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/crypto-browserify/buffer-xor"
        },
        {
          "type": "vcs",
          "url": "https://github.com/crypto-browserify/buffer-xor.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/buffer-xor@1.0.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/buffer-xor/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/buffer-xor/package.json"
              }
            ],
            "concludedValue": "node_modules/buffer-xor/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Brian J. Brennan <brianloveswords@gmail.com> (http://bjb.io)"
        }
      ],
      "group": "",
      "name": "buffer-crc32",
      "version": "0.2.5",
      "description": "A pure javascript CRC32 algorithm that plays nice with binary data",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/buffer-crc32@0.2.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/brianloveswords/buffer-crc32"
        },
        {
          "type": "vcs",
          "url": "git://github.com/brianloveswords/buffer-crc32.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/buffer-crc32@0.2.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/buffer-crc32/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/buffer-crc32/package.json"
              }
            ],
            "concludedValue": "node_modules/buffer-crc32/package.json"
          }
        ]
      },
      "tags": [
        "binary"
      ]
    },
    {
      "authors": [
        {
          "name": "Feross Aboukhadijeh <feross@feross.org> (http://feross.org)"
        }
      ],
      "group": "",
      "name": "buffer",
      "version": "3.6.0",
      "description": "Node.js Buffer API, for the browser",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/buffer@3.6.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/feross/buffer"
        },
        {
          "type": "vcs",
          "url": "git://github.com/feross/buffer.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/buffer@3.6.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/buffer/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/buffer/package.json"
              }
            ],
            "concludedValue": "node_modules/buffer/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Devon Govett <devongovett@gmail.com>"
        }
      ],
      "group": "",
      "name": "browserify-zlib",
      "version": "0.1.4",
      "description": "Full zlib module for browserify",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/browserify-zlib@0.1.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/devongovett/browserify-zlib.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/browserify-zlib@0.1.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/browserify-zlib/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/browserify-zlib/package.json"
              }
            ],
            "concludedValue": "node_modules/browserify-zlib/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "browserify-sign",
      "version": "4.0.0",
      "description": "adds node crypto signing for browsers",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/browserify-sign@4.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/crypto-browserify/browserify-sign.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/browserify-sign@4.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/browserify-sign/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/browserify-sign/package.json"
              }
            ],
            "concludedValue": "node_modules/browserify-sign/package.json"
          }
        ]
      },
      "tags": [
        "crypto"
      ]
    },
    {
      "group": "",
      "name": "browserify-rsa",
      "version": "4.0.1",
      "description": "RSA for browserify",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/browserify-rsa@4.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/browserify-rsa@4.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/browserify-rsa/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/browserify-rsa/package.json"
              }
            ],
            "concludedValue": "node_modules/browserify-rsa/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Calvin Metcalf <calvin.metcalf@gmail.com>"
        }
      ],
      "group": "",
      "name": "browserify-des",
      "version": "1.0.0",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/browserify-des@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/crypto-browserify/browserify-des#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/crypto-browserify/browserify-des.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/browserify-des@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/browserify-des/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/browserify-des/package.json"
              }
            ],
            "concludedValue": "node_modules/browserify-des/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Calvin Metcalf <calvin.metcalf@gmail.com>"
        }
      ],
      "group": "",
      "name": "browserify-cipher",
      "version": "1.0.0",
      "description": "ciphers for the browser",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/browserify-cipher@1.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/browserify-cipher@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/browserify-cipher/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/browserify-cipher/package.json"
              }
            ],
            "concludedValue": "node_modules/browserify-cipher/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "browserify-aes",
      "version": "1.0.6",
      "description": "aes, for browserify",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/browserify-aes@1.0.6",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/crypto-browserify/browserify-aes"
        },
        {
          "type": "vcs",
          "url": "git://github.com/crypto-browserify/browserify-aes.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/browserify-aes@1.0.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/browserify-aes/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/browserify-aes/package.json"
              }
            ],
            "concludedValue": "node_modules/browserify-aes/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "browserify",
      "version": "8.1.3",
      "description": "browser-side require() the node way",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/browserify@8.1.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/substack/node-browserify.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/browserify@8.1.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/browserify/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/browserify/package.json"
              }
            ],
            "concludedValue": "node_modules/browserify/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Roman Shtylman <shtylman@gmail.com>"
        }
      ],
      "group": "",
      "name": "browser-resolve",
      "version": "1.11.2",
      "description": "resolve which handles browser field support in package.json",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/browser-resolve@1.11.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/shtylman/node-browser-resolve.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/browser-resolve@1.11.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/browser-resolve/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/browser-resolve/package.json"
              }
            ],
            "concludedValue": "node_modules/browser-resolve/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "browser-pack",
      "version": "3.2.0",
      "description": "pack node-style source files from a json stream into a browser bundle",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/browser-pack@3.2.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/browser-pack"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/browser-pack.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/browser-pack@3.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/browser-pack/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/browser-pack/package.json"
              }
            ],
            "concludedValue": "node_modules/browser-pack/package.json"
          }
        ]
      },
      "tags": [
        "json",
        "stream"
      ]
    },
    {
      "authors": [
        {
          "name": "Fedor Indutny <fedor@indutny.com>"
        }
      ],
      "group": "",
      "name": "brorand",
      "version": "1.0.6",
      "description": "Random number generator for browsers and node.js",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/brorand@1.0.6",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/indutny/brorand"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/brorand@1.0.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/brorand/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/brorand/package.json"
              }
            ],
            "concludedValue": "node_modules/brorand/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Olov Lassus <olov.lassus@gmail.com>"
        }
      ],
      "group": "",
      "name": "breakable",
      "version": "1.0.0",
      "description": "Break out of functions, recursive or not, in a more composable way than by using exceptions explicitly. Non-local return.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/breakable@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/olov/breakable.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/breakable@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/breakable/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/breakable/package.json"
              }
            ],
            "concludedValue": "node_modules/breakable/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Julian Gruber <mail@juliangruber.com> (http://juliangruber.com)"
        }
      ],
      "group": "",
      "name": "brace-expansion",
      "version": "1.1.6",
      "description": "Brace expansion as known from sh/bash",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/brace-expansion@1.1.6",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/juliangruber/brace-expansion"
        },
        {
          "type": "vcs",
          "url": "git://github.com/juliangruber/brace-expansion.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/brace-expansion@1.1.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/brace-expansion/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/brace-expansion/package.json"
              }
            ],
            "concludedValue": "node_modules/brace-expansion/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "boom",
      "version": "2.10.1",
      "description": "HTTP-friendly error objects",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-3-Clause",
            "url": "https://opensource.org/licenses/BSD-3-Clause"
          }
        }
      ],
      "purl": "pkg:npm/boom@2.10.1",
      "type": "library",
      "bom-ref": "pkg:npm/boom@2.10.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/boom/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/boom/package.json"
              }
            ],
            "concludedValue": "node_modules/boom/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Fedor Indutny <fedor@indutny.com>"
        }
      ],
      "group": "",
      "name": "bn.js",
      "version": "4.11.6",
      "description": "Big number implementation in pure javascript",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/bn.js@4.11.6",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/indutny/bn.js"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/bn.js@4.11.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/bn.js/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/bn.js/package.json"
              }
            ],
            "concludedValue": "node_modules/bn.js/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Petka Antonov <petka_antonov@hotmail.com> (http://github.com/petkaantonov/)"
        }
      ],
      "group": "",
      "name": "bluebird",
      "version": "2.11.0",
      "description": "Full featured Promises/A+ implementation with exceptionally good performance",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/bluebird@2.11.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/petkaantonov/bluebird"
        },
        {
          "type": "vcs",
          "url": "git://github.com/petkaantonov/bluebird.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/bluebird@2.11.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/bluebird/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/bluebird/package.json"
              }
            ],
            "concludedValue": "node_modules/bluebird/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "bl",
      "version": "0.9.5",
      "description": "Buffer List: collect buffers and access with a standard readable Buffer interface, streamable too!",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/bl@0.9.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/rvagg/bl"
        },
        {
          "type": "vcs",
          "url": "https://github.com/rvagg/bl.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/bl@0.9.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/bl/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/bl/package.json"
              }
            ],
            "concludedValue": "node_modules/bl/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "T. Jameson Little <t.jameson.little@gmail.com>"
        }
      ],
      "group": "",
      "name": "base64-js",
      "version": "0.0.8",
      "description": "Base64 encoding/decoding in pure JS",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/base64-js@0.0.8",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/beatgammit/base64-js.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/base64-js@0.0.8",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/base64-js/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/base64-js/package.json"
              }
            ],
            "concludedValue": "node_modules/base64-js/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Julian Gruber <mail@juliangruber.com> (http://juliangruber.com)"
        }
      ],
      "group": "",
      "name": "balanced-match",
      "version": "0.4.2",
      "description": "Match balanced character pairs, like \"{\" and \"}\"",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/balanced-match@0.4.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/juliangruber/balanced-match"
        },
        {
          "type": "vcs",
          "url": "git://github.com/juliangruber/balanced-match.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/balanced-match@0.4.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/balanced-match/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/balanced-match/package.json"
              }
            ],
            "concludedValue": "node_modules/balanced-match/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mikeal Rogers <mikeal.rogers@gmail.com> (http://www.futurealoof.com)"
        }
      ],
      "group": "",
      "name": "aws-sign2",
      "version": "0.6.0",
      "description": "AWS signing. Originally pulled from LearnBoost/knox, maintained as vendor in request, now a standalone module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0",
            "url": "https://opensource.org/licenses/Apache-2.0"
          }
        }
      ],
      "purl": "pkg:npm/aws-sign2@0.6.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mikeal/aws-sign"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/aws-sign2@0.6.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/aws-sign2/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/aws-sign2/package.json"
              }
            ],
            "concludedValue": "node_modules/aws-sign2/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Paul Miller (http://paulmillr.com/)"
        }
      ],
      "group": "",
      "name": "async-each",
      "version": "0.1.6",
      "description": "No-bullshit, ultra-simple, 35-lines-of-code async parallel forEach / map function for JavaScript.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/async-each@0.1.6",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/paulmillr/async-each/"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/async-each@0.1.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/async-each/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/async-each/package.json"
              }
            ],
            "concludedValue": "node_modules/async-each/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Caolan McMahon"
        }
      ],
      "group": "",
      "name": "async",
      "version": "2.0.1",
      "description": "Higher-order functions and common patterns for asynchronous code",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/async@2.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/caolan/async.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/async@2.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/async/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/async/package.json"
              }
            ],
            "concludedValue": "node_modules/async/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com> (http://allyoucanleet.com/)"
        }
      ],
      "group": "",
      "name": "lodash",
      "version": "4.16.2",
      "description": "Lodash modular utilities.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/lodash@4.16.2",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash@4.16.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/async/node_modules/lodash/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/async/node_modules/lodash/package.json"
              }
            ],
            "concludedValue": "node_modules/async/node_modules/lodash/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "astw",
      "version": "2.0.0",
      "description": "walk the ast with references to parent nodes",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/astw@2.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/astw"
        },
        {
          "type": "vcs",
          "url": "git://github.com/substack/astw.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/astw@2.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/astw/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/astw/package.json"
              }
            ],
            "concludedValue": "node_modules/astw/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Ben Newman <bn@cs.stanford.edu>"
        }
      ],
      "group": "",
      "name": "ast-types",
      "version": "0.6.16",
      "description": "Esprima-compatible implementation of the Mozilla JS Parser API",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/ast-types@0.6.16",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/benjamn/ast-types"
        },
        {
          "type": "vcs",
          "url": "git://github.com/benjamn/ast-types.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/ast-types@0.6.16",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/ast-types/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/ast-types/package.json"
              }
            ],
            "concludedValue": "node_modules/ast-types/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Olov Lassus <olov.lassus@gmail.com>"
        }
      ],
      "group": "",
      "name": "ast-traverse",
      "version": "0.1.1",
      "description": "simple but flexible AST traversal with pre and post visitors",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/ast-traverse@0.1.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/olov/ast-traverse.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/ast-traverse@0.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/ast-traverse/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/ast-traverse/package.json"
              }
            ],
            "concludedValue": "node_modules/ast-traverse/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mark Cavage <mcavage@gmail.com>"
        }
      ],
      "group": "",
      "name": "assert-plus",
      "version": "0.1.5",
      "description": "Extra assertions on top of node's assert module",
      "scope": "optional",
      "purl": "pkg:npm/assert-plus@0.1.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mcavage/node-assert-plus.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/assert-plus@0.1.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/assert-plus/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/assert-plus/package.json"
              }
            ],
            "concludedValue": "node_modules/assert-plus/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "assert",
      "version": "1.3.0",
      "description": "commonjs assert - node.js api compatible",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/assert@1.3.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/defunctzombie/commonjs-assert"
        },
        {
          "type": "vcs",
          "url": "git://github.com/defunctzombie/commonjs-assert.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/assert@1.3.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/assert/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/assert/package.json"
              }
            ],
            "concludedValue": "node_modules/assert/package.json"
          }
        ]
      },
      "tags": [
        "api"
      ]
    },
    {
      "authors": [
        {
          "name": "Fedor Indutny"
        }
      ],
      "group": "",
      "name": "asn1.js",
      "version": "4.8.1",
      "description": "ASN.1 encoder and decoder",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/asn1.js@4.8.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/indutny/asn1.js"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/asn1.js@4.8.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/asn1.js/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/asn1.js/package.json"
              }
            ],
            "concludedValue": "node_modules/asn1.js/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mark Cavage <mcavage@gmail.com>"
        }
      ],
      "group": "",
      "name": "asn1",
      "version": "0.1.11",
      "description": "Contains parsers and serializers for ASN.1 (currently BER only)",
      "scope": "optional",
      "purl": "pkg:npm/asn1@0.1.11",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/mcavage/node-asn1.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/asn1@0.1.11",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/asn1/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/asn1/package.json"
              }
            ],
            "concludedValue": "node_modules/asn1/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "array-find-index",
      "version": "1.0.1",
      "description": "ES2015 `Array#findIndex()` ponyfill",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/array-find-index@1.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/array-find-index@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/array-find-index/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/array-find-index/package.json"
              }
            ],
            "concludedValue": "node_modules/array-find-index/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Chris Talkington (http://christalkington.com/)"
        }
      ],
      "group": "",
      "name": "archiver",
      "version": "0.14.4",
      "description": "a streaming interface for archive generation",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/archiver@0.14.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/archiverjs/node-archiver"
        },
        {
          "type": "vcs",
          "url": "https://github.com/archiverjs/node-archiver.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/archiver@0.14.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/archiver/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/archiver/package.json"
              }
            ],
            "concludedValue": "node_modules/archiver/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "glob",
      "version": "4.3.5",
      "description": "a little globber",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/glob@4.3.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/node-glob.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/glob@4.3.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/archiver/node_modules/glob/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/archiver/node_modules/glob/package.json"
              }
            ],
            "concludedValue": "node_modules/archiver/node_modules/glob/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (http://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "ansi-styles",
      "version": "1.1.0",
      "description": "ANSI escape codes for styling strings in the terminal",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/ansi-styles@1.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/ansi-styles@1.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/ansi-styles/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/ansi-styles/package.json"
              }
            ],
            "concludedValue": "node_modules/ansi-styles/package.json"
          }
        ]
      },
      "tags": [
        "escape"
      ]
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (http://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "ansi-regex",
      "version": "0.2.1",
      "description": "Regular expression for matching ANSI escape codes",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/ansi-regex@0.2.1",
      "type": "library",
      "bom-ref": "pkg:npm/ansi-regex@0.2.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/ansi-regex/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/ansi-regex/package.json"
              }
            ],
            "concludedValue": "node_modules/ansi-regex/package.json"
          }
        ]
      },
      "tags": [
        "escape"
      ]
    },
    {
      "authors": [
        {
          "name": "James Burke <jrburke@gmail.com> (http://github.com/jrburke)"
        }
      ],
      "group": "",
      "name": "amdefine",
      "version": "1.0.0",
      "description": "Provide AMD's define() API for declaring modules in the AMD format",
      "scope": "optional",
      "licenses": [
        {
          "expression": "BSD-3-Clause AND MIT"
        }
      ],
      "purl": "pkg:npm/amdefine@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/jrburke/amdefine"
        },
        {
          "type": "vcs",
          "url": "https://github.com/jrburke/amdefine.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/amdefine@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/amdefine/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/amdefine/package.json"
              }
            ],
            "concludedValue": "node_modules/amdefine/package.json"
          }
        ]
      },
      "tags": [
        "api"
      ]
    },
    {
      "authors": [
        {
          "name": "Olov Lassus <olov.lassus@gmail.com>"
        }
      ],
      "group": "",
      "name": "alter",
      "version": "0.2.0",
      "description": "alters a string by replacing multiple range fragments in one fast pass",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/alter@0.2.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/olov/alter.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/alter@0.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/alter/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/alter/package.json"
              }
            ],
            "concludedValue": "node_modules/alter/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jon Schlinkert (https://github.com/jonschlinkert)"
        }
      ],
      "group": "",
      "name": "align-text",
      "version": "0.1.4",
      "description": "Align the text in a string.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/align-text@0.1.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jonschlinkert/align-text"
        },
        {
          "type": "vcs",
          "url": "git://github.com/jonschlinkert/align-text.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/align-text@0.1.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/align-text/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/align-text/package.json"
              }
            ],
            "concludedValue": "node_modules/align-text/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "acorn-6to5",
      "version": "0.11.1-18",
      "description": "Acorn fork used by 6to5",
      "scope": "optional",
      "purl": "pkg:npm/acorn-6to5@0.11.1-18",
      "type": "library",
      "bom-ref": "pkg:npm/acorn-6to5@0.11.1-18",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/acorn-6to5/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/acorn-6to5/package.json"
              }
            ],
            "concludedValue": "node_modules/acorn-6to5/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "acorn",
      "version": "1.2.2",
      "description": "ECMAScript parser",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/acorn@1.2.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/marijnh/acorn"
        },
        {
          "type": "vcs",
          "url": "https://github.com/marijnh/acorn.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/acorn@1.2.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/acorn/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/acorn/package.json"
              }
            ],
            "concludedValue": "node_modules/acorn/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Dominic Tarr <dominic.tarr@gmail.com> (http://bit.ly/dominictarr)"
        }
      ],
      "group": "",
      "name": "JSONStream",
      "version": "0.8.4",
      "description": "rawStream.pipe(JSONStream.parse()).pipe(streamOfObjects)",
      "scope": "optional",
      "purl": "pkg:npm/JSONStream@0.8.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/dominictarr/JSONStream"
        },
        {
          "type": "vcs",
          "url": "git://github.com/dominictarr/JSONStream.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/JSONStream@0.8.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/JSONStream/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/JSONStream/package.json"
              }
            ],
            "concludedValue": "node_modules/JSONStream/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "David Chambers <dc@davidchambers.me>"
        }
      ],
      "group": "",
      "name": "Base64",
      "version": "0.2.1",
      "description": "Base64 encoding and decoding",
      "scope": "optional",
      "purl": "pkg:npm/Base64@0.2.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/davidchambers/Base64.js.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/Base64@0.2.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/Base64/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/Base64/package.json"
              }
            ],
            "concludedValue": "node_modules/Base64/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sebastian McKenzie <sebmck@gmail.com>"
        }
      ],
      "group": "",
      "name": "6to5ify",
      "version": "3.1.2",
      "description": "6to5 browserify plugin",
      "scope": "optional",
      "purl": "pkg:npm/6to5ify@3.1.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/sebmck/6to5-browserify"
        },
        {
          "type": "vcs",
          "url": "https://github.com/sebmck/6to5-browserify.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/6to5ify@3.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/6to5ify/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/6to5ify/package.json"
              }
            ],
            "concludedValue": "node_modules/6to5ify/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sebastian McKenzie <sebmck@gmail.com>"
        }
      ],
      "group": "",
      "name": "6to5-core",
      "version": "2.13.7",
      "description": "Turn ES6 code into readable vanilla ES5 with source maps",
      "scope": "optional",
      "purl": "pkg:npm/6to5-core@2.13.7",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://6to5.org/"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/6to5-core@2.13.7",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/6to5-core/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/6to5-core/package.json"
              }
            ],
            "concludedValue": "node_modules/6to5-core/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sebastian McKenzie <sebmck@gmail.com>"
        }
      ],
      "group": "",
      "name": "6to5",
      "version": "2.13.7",
      "description": "Turn ES6 code into readable vanilla ES5 with source maps",
      "scope": "optional",
      "purl": "pkg:npm/6to5@2.13.7",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://6to5.org/"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/6to5@2.13.7",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/6to5/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/6to5/package.json"
              }
            ],
            "concludedValue": "node_modules/6to5/package.json"
          }
        ]
      }
    }
  ],
  "dependencies": [],
  "annotations": [
    {
      "bom-ref": "metadata-annotations",
      "subjects": [
        "pkg:npm/glsl-token-assignments@2.0.2"
      ],
      "annotator": {
        "component": {
          "group": "@cyclonedx",
          "name": "cdxgen",
          "version": "12.3.3",
          "purl": "pkg:npm/%40cyclonedx/cdxgen@12.3.3",
          "type": "application",
          "bom-ref": "pkg:npm/@cyclonedx/cdxgen@12.3.3",
          "publisher": "OWASP Foundation",
          "authors": [
            {
              "name": "OWASP Foundation"
            }
          ]
        }
      },
      "timestamp": "2026-07-27T21:35:52Z",
      "text": "This Software Bill-of-Materials (SBOM) document was created on Monday, July 27, 2026 with cdxgen. The data was captured during the pre-build lifecycle phase without building the application. The document describes an application named 'glsl-token-assignments' with version '2.0.2'."
    }
  ]
}