{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d9ab96c6-b221-570e-91c6-f36a366b403f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/lodash.pick@4.4.0-tuxcare.1",
      "type": "library",
      "name": "lodash.pick",
      "version": "4.4.0-tuxcare.1",
      "purl": "pkg:npm/lodash.pick@4.4.0-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:9d35e48f-03bf-5eb4-8474-92ad35593152",
      "id": "CVE-2020-8203",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-8203 does not affect version 4.4.0-tuxcare.1 of lodash.pick. already_fixed \u2014 The target repository lodash.pick@4.4.0-tuxcare.1 already contains a complete fix for CVE-2020-8203 (Prototype Pollution). TuxCare applied the fix in commit 4ae6843 (JSELS-480), which adds explicit security checks blocking dangerous property identifiers (__proto__, constructor, prototype) before they can be used to modify Object.prototype."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.pick@4.4.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1497cb1e-c333-5303-a220-93cecd49ec4a",
      "id": "CVE-2021-23337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-23337 is fixed in version 4.4.0-tuxcare.1 of lodash.pick."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.pick@4.4.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35fa2a3d-794f-5451-8014-d4f7a7e27394",
      "id": "CVE-2024-41818",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-41818 is fixed in version 4.4.0-tuxcare.1 of lodash.pick."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.pick@4.4.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9df8df9-f284-5161-8473-4e169257439f",
      "id": "CVE-2026-25896",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25896 is fixed in version 4.4.0-tuxcare.1 of lodash.pick."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.pick@4.4.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50a9788e-fed6-5eb2-869a-80d812943ee5",
      "id": "CVE-2026-26278",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-26278 is fixed in version 4.4.0-tuxcare.1 of lodash.pick."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.pick@4.4.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:206ea3b1-49ca-5e09-8ff6-48ea8793f8f0",
      "id": "CVE-2026-27942",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27942 is fixed in version 4.4.0-tuxcare.1 of lodash.pick."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.pick@4.4.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:adbf5729-cc47-5fc4-96b5-cf4030dc8dfc",
      "id": "CVE-2026-33036",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33036 is fixed in version 4.4.0-tuxcare.1 of lodash.pick."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.pick@4.4.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0d09242-19a3-52b1-a1a6-70366e0c471e",
      "id": "CVE-2026-33349",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33349 is fixed in version 4.4.0-tuxcare.1 of lodash.pick."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.pick@4.4.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0f7dd9b-d9ec-5d2a-b8cc-732762920de6",
      "id": "CVE-2026-41650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41650 is fixed in version 4.4.0-tuxcare.1 of lodash.pick."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.pick@4.4.0-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/lodash.pick@4.4.0-tuxcare.1"
    }
  ]
}