{
  "_comment": "Sample SBOM (Software Bill of Materials) for @nodatachat/protect@1.9.0 in CycloneDX 1.5 format. Truncated for kit; the full machine-generated SBOM is published with each npm release in the package's `sbom.json` artifact.",
  "bomFormat": "CycloneDX",
  "specVersion": "1.5",
  "version": 1,
  "metadata": {
    "timestamp": "2026-04-25T20:00:00Z",
    "tools": [{ "vendor": "Anchore", "name": "syft", "version": "1.0.0" }],
    "component": {
      "type": "application",
      "bom-ref": "pkg:npm/%40nodatachat/protect@1.9.0",
      "name": "@nodatachat/protect",
      "version": "1.9.0",
      "supplier": { "name": "NoData" },
      "licenses": [{ "license": { "id": "MIT" } }],
      "purl": "pkg:npm/%40nodatachat/protect@1.9.0"
    }
  },
  "components": [
    {
      "type": "library",
      "bom-ref": "pkg:npm/jszip@3.10.1",
      "name": "jszip",
      "version": "3.10.1",
      "purl": "pkg:npm/jszip@3.10.1",
      "licenses": [{ "license": { "id": "MIT" } }],
      "description": "Used for sign --dir Merkle tree manifest packing"
    },
    {
      "type": "library",
      "bom-ref": "pkg:npm/commander@11.1.0",
      "name": "commander",
      "version": "11.1.0",
      "purl": "pkg:npm/commander@11.1.0",
      "licenses": [{ "license": { "id": "MIT" } }],
      "description": "CLI argument parsing"
    },
    {
      "type": "library",
      "bom-ref": "pkg:npm/keytar@7.9.0",
      "name": "keytar",
      "version": "7.9.0",
      "purl": "pkg:npm/keytar@7.9.0",
      "licenses": [{ "license": { "id": "MIT" } }],
      "description": "OS keychain integration for device-bound key storage"
    },
    {
      "_comment": "...truncated; full SBOM has 47 entries..."
    }
  ],
  "vulnerabilities": [],
  "_attestation": {
    "sha512_of_package_tarball": "086fb29f1d7eaf2c4b9c3a8e5d1f6072c4a89b3e2f7d09e1a4b6c8d3f5a7b9c1086fb29f1d7eaf2c4b9c3a8e5d1f6072c4a89b3e2f7d09e1a4b6c8d3f5a7b9c1",
    "shasum_of_package_tarball": "a53c83b1d4e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b",
    "signed_by": "github.com/daviderez4 (npm provenance attestation)"
  }
}
