{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4117d374-b628-5208-927b-6a9d6b8c8a35",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@astrojs/rss",
      "purl": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.9",
      "type": "library",
      "bom-ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.9",
      "version": "3.6.5-tuxcare.9",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2024-47885",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:b30e53f5-0cdf-59a2-b8dc-edba18439702",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47885 is fixed in version 3.6.5-tuxcare.9 of @astrojs/rss."
      }
    },
    {
      "id": "CVE-2024-56140",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:d758e4cc-bb11-5429-9614-f66c7dece223",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56140 is fixed in version 3.6.5-tuxcare.9 of @astrojs/rss."
      }
    },
    {
      "id": "CVE-2024-56159",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:cccf7aeb-7420-5f2b-afe2-2a608a2ebf5c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56159 is fixed in version 3.6.5-tuxcare.9 of @astrojs/rss."
      }
    },
    {
      "id": "CVE-2025-55303",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:b6717a05-ea84-5f72-8936-9615408dffdd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55303 is fixed in version 3.6.5-tuxcare.9 of @astrojs/rss."
      }
    },
    {
      "id": "CVE-2025-61925",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:2a929115-c5e4-5f72-9aaf-a24e22e1fad8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61925 is fixed in version 3.6.5-tuxcare.9 of @astrojs/rss."
      }
    },
    {
      "id": "CVE-2025-64525",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:7165dbd0-788c-52fd-af23-df25a30b2555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64525 is fixed in version 3.6.5-tuxcare.9 of @astrojs/rss."
      }
    },
    {
      "id": "CVE-2025-64757",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:d6ecf3a7-2a35-5013-9867-94b9bce7f739",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64757 is fixed in version 3.6.5-tuxcare.9 of @astrojs/rss."
      }
    },
    {
      "id": "CVE-2025-64764",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:3ea68ff4-f4a4-5c1a-aae8-1582cdf0cf4f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64764 is fixed in version 3.6.5-tuxcare.9 of @astrojs/rss."
      }
    },
    {
      "id": "CVE-2025-64765",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:deba22b0-e70f-5e22-a80e-ca6b3f548e73",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64765 is fixed in version 3.6.5-tuxcare.9 of @astrojs/rss."
      }
    },
    {
      "id": "CVE-2025-65019",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:5969aea1-3605-5562-99f0-c06708274682",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-65019 is fixed in version 3.6.5-tuxcare.9 of @astrojs/rss."
      }
    },
    {
      "id": "CVE-2025-66202",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:d3cb7679-f680-532e-8b7a-9fe26913847c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66202 is fixed in version 3.6.5-tuxcare.9 of @astrojs/rss."
      }
    },
    {
      "id": "CVE-2026-33769",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:1dca18b3-3bc2-58dd-88e6-093320fa21c4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33769 is fixed in version 3.6.5-tuxcare.9 of @astrojs/rss."
      }
    },
    {
      "id": "CVE-2026-41067",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:37e584e9-7f66-5113-b5df-bee5adf896ad",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41067 is fixed in version 3.6.5-tuxcare.9 of @astrojs/rss."
      }
    },
    {
      "id": "CVE-2026-45028",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:1bfc2f56-4fe4-52f3-8f50-6667691ea7a7",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-45028 does not affect version 3.6.5-tuxcare.9 of @astrojs/rss. not_affected \u2014 Astro version 3.6.5 is NOT AFFECTED by CVE-2026-45028. The vulnerability concerns server islands encryption (AES-GCM ciphertext replay between props and slots), but server islands functionality does not exist in version 3.6.5. The feature was introduced in later versions (~May 2025, v5.x/6.x), and the vulnerability was fixed in v6.1.10 (April 2026). Exhaustive search across 327 source files con...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-50146",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:f21e972d-5397-595f-8f8e-7567690ddb29",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50146 is fixed in version 3.6.5-tuxcare.9 of @astrojs/rss."
      }
    },
    {
      "id": "CVE-2026-54298",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:bb56998f-d7d4-58ca-954b-f89e6a975c90",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54298 is fixed in version 3.6.5-tuxcare.9 of @astrojs/rss."
      }
    },
    {
      "id": "CVE-2026-54299",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:3f221a01-9e28-5597-91c8-64e007e5d770",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54299 is fixed in version 3.6.5-tuxcare.9 of @astrojs/rss."
      }
    },
    {
      "id": "CVE-2026-59728",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:01f821e2-ddae-5605-97f0-9530db5e9b09",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59728 is fixed in version 3.6.5-tuxcare.9 of @astrojs/rss."
      }
    },
    {
      "id": "CVE-2026-59729",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:7e026400-466b-5490-a011-b31e9631bf84",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59729 is fixed in version 3.6.5-tuxcare.9 of @astrojs/rss."
      }
    },
    {
      "id": "CVE-2026-73422",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:60cf457c-4dc6-5ccf-93ed-07482a6fee4a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-73422 is fixed in version 3.6.5-tuxcare.9 of @astrojs/rss."
      }
    },
    {
      "id": "CVE-2026-84376",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:9acf9896-3cd8-5f21-ba7e-8d16de0bd32e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-84376 is fixed in version 3.6.5-tuxcare.9 of @astrojs/rss."
      }
    },
    {
      "id": "GHSA-26w7-cxv4-gfx2",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:2ce01d9e-a24d-5ec6-8c1e-19ec22169be3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-26w7-cxv4-gfx2 is fixed in version 3.6.5-tuxcare.9 of @astrojs/rss."
      }
    },
    {
      "id": "GHSA-4g3v-8h47-v7g6",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:fd20cbc0-f14f-535a-83b0-80ebe693e615",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4g3v-8h47-v7g6 is fixed in version 3.6.5-tuxcare.9 of @astrojs/rss."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.9"
    }
  ]
}