{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d608ec02-fbfb-536c-a22f-74164739ee04",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/ms@1.0.0",
      "type": "library",
      "name": "ms",
      "version": "1.0.0",
      "purl": "pkg:npm/ms@1.0.0"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:e76e2cc6-599c-577c-b959-53c1693bfc98",
      "id": "CVE-2016-2515",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2016-2515 is a false positive for ms 1.0.0. false_positive \u2014 CVE-2016-2515 concerns the 'hawk' HTTP authentication library, but the target repository is the 'ms' time conversion utility - a completely different project. No relationship exists between the two packages."
      },
      "affects": [
        {
          "ref": "pkg:npm/ms@1.0.0"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6b17c5c-6d6d-5be8-a84c-209b9efd42cd",
      "id": "CVE-2018-3739",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2018-3739 is a false positive for ms 1.0.0. false_positive \u2014 CVE-2018-3739 is a wrong-project match. The advisory affects https-proxy-agent, but this repository is the ms package (a time conversion utility). The affected component's code is entirely absent from this repository."
      },
      "affects": [
        {
          "ref": "pkg:npm/ms@1.0.0"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0be720ac-4dd5-5f88-a81e-f824e609e67e",
      "id": "CVE-2021-33623",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-33623 is a false positive for ms 1.0.0. false_positive \u2014 CVE-2021-33623 concerns the 'trim-newlines' npm package (ReDoS vulnerability in .end() method), but this repository is the 'ms' package (millisecond conversion utility). This is a wrong-project match - the two packages are completely unrelated with no dependency relationship."
      },
      "affects": [
        {
          "ref": "pkg:npm/ms@1.0.0"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5712d268-c859-53ef-a162-8c3269dad000",
      "id": "CVE-2022-29167",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-29167 is a false positive for ms 1.0.0. false_positive \u2014 CVE-2022-29167 concerns the Hawk HTTP authentication library's Host header parsing (Hawk.utils.parseHost() ReDoS vulnerability). The target repository is the 'ms' (milliseconds) library - a time-string conversion utility unrelated to HTTP authentication or Host header parsing. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:npm/ms@1.0.0"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90f887a3-50a9-50ce-b166-da07d0434bab",
      "id": "CVE-2024-47178",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-47178 is a false positive for ms 1.0.0. false_positive \u2014 CVE-2024-47178 concerns 'basic-auth-connect' (an HTTP basic authentication middleware), but this repository is 'ms' (a time conversion utility). Wrong-project match - the affected component is completely absent from this repository."
      },
      "affects": [
        {
          "ref": "pkg:npm/ms@1.0.0"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd8beaa4-b101-5ec6-8f61-6365e7194fa6",
      "id": "GHSA-pc5p-h8pf-mvwp",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-pc5p-h8pf-mvwp is a false positive for ms 1.0.0. false_positive \u2014 GHSA-pc5p-h8pf-mvwp concerns https-proxy-agent, a TLS proxy agent package. The target repository is 'ms', a time conversion utility with no networking or proxy functionality. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:npm/ms@1.0.0"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5028cfaa-208a-5a19-94e4-c11e50e23a50",
      "id": "GHSA-qrg3-f6h6-vq8q",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-qrg3-f6h6-vq8q is a false positive for ms 1.0.0."
      },
      "affects": [
        {
          "ref": "pkg:npm/ms@1.0.0"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/ms@1.0.0"
    }
  ]
}