{
  "bomFormat": "CycloneDX",
  "specVersion": "1.7",
  "serialNumber": "urn:uuid:58dd077d-bf6a-4843-a988-4c61e3839449",
  "version": 1,
  "metadata": {
    "timestamp": "2026-07-29T22:59:20Z",
    "tools": {
      "components": [
        {
          "group": "@cyclonedx",
          "name": "cdxgen",
          "version": "12.3.3",
          "purl": "pkg:npm/%40cyclonedx/cdxgen@12.3.3",
          "type": "application",
          "bom-ref": "pkg:npm/@cyclonedx/cdxgen@12.3.3",
          "publisher": "OWASP Foundation",
          "authors": [
            {
              "name": "OWASP Foundation"
            }
          ]
        }
      ]
    },
    "authors": [
      {
        "name": "OWASP Foundation"
      }
    ],
    "lifecycles": [
      {
        "phase": "pre-build"
      }
    ],
    "component": {
      "name": "is",
      "group": "@sindresorhus",
      "version": "0.7.0",
      "description": "Type check values: `is.string('🦄') //=> true`",
      "purl": "pkg:npm/%40sindresorhus/is@0.7.0",
      "bom-ref": "pkg:npm/@sindresorhus/is@0.7.0",
      "author": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)",
      "properties": [
        {
          "name": "cdx:npm:scripts",
          "value": "lint, build, test, prepublish"
        },
        {
          "name": "cdx:npm:hasInstallScript",
          "value": "true"
        },
        {
          "name": "cdx:npm:risky_scripts",
          "value": "prepublish"
        }
      ],
      "type": "application",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ]
    },
    "properties": [
      {
        "name": "cdx:bom:componentTypes",
        "value": "npm"
      },
      {
        "name": "cdx:bom:componentNamespaces",
        "value": "@babel\\n@fimbul\\n@isaacs\\n@mapbox\\n@my-scope\\n@nodelib\\n@pkgjs\\n@rollup\\n@sindresorhus\\n@types\\n@vercel"
      },
      {
        "name": "cdx:bom:componentSrcFiles",
        "value": "node_modules/@babel/code-frame/package.json\\nnode_modules/@babel/helper-validator-identifier/package.json\\nnode_modules/@isaacs/cliui/node_modules/emoji-regex/package.json\\nnode_modules/@isaacs/cliui/node_modules/string-width/package.json\\nnode_modules/@isaacs/cliui/package.json\\nnode_modules/@isaacs/fs-minipass/package.json\\nnode_modules/@mapbox/node-pre-gyp/lib/util/nw-pre-gyp/package.json\\nnode_modules/@mapbox/node-pre-gyp/package.json\\nnode_modules/@nodelib/fs.scandir/package.json\\nnode_modules/@nodelib/fs.stat/package.json\\nnode_modules/@nodelib/fs.walk/package.json\\nnode_modules/@pkgjs/parseargs/package.json\\nnode_modules/@rollup/pluginutils/package.json\\nnode_modules/@sindresorhus/merge-streams/package.json\\nnode_modules/@types/estree/package.json\\nnode_modules/@types/jquery/package.json\\nnode_modules/@types/jsdom/package.json\\nnode_modules/@types/node/package.json\\nnode_modules/@types/tempy/package.json\\nnode_modules/@vercel/nft/package.json\\nnode_modules/abab/package.json\\nnode_modules/abbrev/package.json\\nnode_modules/acorn-globals/node_modules/acorn/package.json\\nnode_modules/acorn-globals/package.json\\nnode_modules/acorn-import-attributes/package.json\\nnode_modules/acorn-walk/package.json\\nnode_modules/acorn/package.json\\nnode_modules/agent-base/package.json\\nnode_modules/ajv/package.json\\nnode_modules/ansi-align/node_modules/ansi-regex/package.json\\nnode_modules/ansi-align/node_modules/is-fullwidth-code-point/package.json\\nnode_modules/ansi-align/node_modules/string-width/package.json\\nnode_modules/ansi-align/node_modules/strip-ansi/package.json\\nnode_modules/ansi-align/package.json\\nnode_modules/ansi-regex/package.json\\nnode_modules/ansi-styles/package.json\\nnode_modules/argparse/package.json\\nnode_modules/array-equal/package.json\\nnode_modules/array-find-index/package.json\\nnode_modules/array-union/package.json\\nnode_modules/array-uniq/package.json\\nnode_modules/arrgv/package.json\\nnode_modules/arrify/package.json\\nnode_modules/asn1/package.json\\nnode_modules/assert-plus/package.json\\nnode_modules/async-sema/package.json\\nnode_modules/asynckit/package.json\\nnode_modules/ava/package.json\\nnode_modules/aws-sign2/package.json\\nnode_modules/aws4/package.json\\nnode_modules/balanced-match/package.json\\nnode_modules/bcrypt-pbkdf/package.json\\nnode_modules/bindings/package.json\\nnode_modules/blueimp-md5/package.json\\nnode_modules/boxen/node_modules/ansi-regex/package.json\\nnode_modules/boxen/node_modules/ansi-styles/package.json\\nnode_modules/boxen/node_modules/camelcase/package.json\\nnode_modules/boxen/node_modules/chalk/package.json\\nnode_modules/boxen/node_modules/escape-string-regexp/package.json\\nnode_modules/boxen/node_modules/is-fullwidth-code-point/package.json\\nnode_modules/boxen/node_modules/string-width/package.json\\nnode_modules/boxen/node_modules/strip-ansi/package.json\\nnode_modules/boxen/package.json\\nnode_modules/brace-expansion/package.json\\nnode_modules/braces/package.json\\nnode_modules/builtin-modules/package.json\\nnode_modules/callsites/package.json\\nnode_modules/camelcase-keys/package.json\\nnode_modules/camelcase/package.json\\nnode_modules/capture-stack-trace/package.json\\nnode_modules/caseless/package.json\\nnode_modules/cbor/package.json\\nnode_modules/chalk/package.json\\nnode_modules/chownr/package.json\\nnode_modules/chunkd/package.json\\nnode_modules/ci-info/package.json\\nnode_modules/ci-parallel-vars/package.json\\nnode_modules/cli-boxes/package.json\\nnode_modules/cli-truncate/package.json\\nnode_modules/cliui/node_modules/ansi-regex/package.json\\nnode_modules/cliui/node_modules/ansi-styles/package.json\\nnode_modules/cliui/node_modules/color-convert/package.json\\nnode_modules/cliui/node_modules/color-name/package.json\\nnode_modules/cliui/node_modules/emoji-regex/package.json\\nnode_modules/cliui/node_modules/is-fullwidth-code-point/package.json\\nnode_modules/cliui/node_modules/string-width/package.json\\nnode_modules/cliui/node_modules/strip-ansi/package.json\\nnode_modules/cliui/node_modules/wrap-ansi/package.json\\nnode_modules/cliui/package.json\\nnode_modules/code-excerpt/package.json\\nnode_modules/color-convert/package.json\\nnode_modules/color-name/package.json\\nnode_modules/combined-stream/package.json\\nnode_modules/commander/package.json\\nnode_modules/common-path-prefix/package.json\\nnode_modules/concat-map/package.json\\nnode_modules/concordance/package.json\\nnode_modules/configstore/node_modules/signal-exit/package.json\\nnode_modules/configstore/node_modules/write-file-atomic/package.json\\nnode_modules/configstore/package.json\\nnode_modules/consola/package.json\\nnode_modules/content-type-parser/package.json\\nnode_modules/convert-to-spaces/package.json\\nnode_modules/core-util-is/package.json\\nnode_modules/create-error-class/package.json\\nnode_modules/cross-spawn/package.json\\nnode_modules/crypto-random-string/package.json\\nnode_modules/cssom/package.json\\nnode_modules/cssstyle/package.json\\nnode_modules/currently-unhandled/package.json\\nnode_modules/dashdash/package.json\\nnode_modules/date-time/package.json\\nnode_modules/debug/package.json\\nnode_modules/decamelize/package.json\\nnode_modules/deep-extend/package.json\\nnode_modules/deep-is/package.json\\nnode_modules/del-cli/package.json\\nnode_modules/del/node_modules/brace-expansion/package.json\\nnode_modules/del/node_modules/glob/package.json\\nnode_modules/del/node_modules/globby/node_modules/pify/package.json\\nnode_modules/del/node_modules/globby/package.json\\nnode_modules/del/node_modules/minimatch/package.json\\nnode_modules/del/node_modules/p-map/package.json\\nnode_modules/del/package.json\\nnode_modules/delayed-stream/package.json\\nnode_modules/detect-libc/package.json\\nnode_modules/diff/package.json\\nnode_modules/doctrine/node_modules/esutils/package.json\\nnode_modules/doctrine/package.json\\nnode_modules/dot-prop/package.json\\nnode_modules/duplexer3/package.json\\nnode_modules/eastasianwidth/package.json\\nnode_modules/ecc-jsbn/package.json\\nnode_modules/emittery/package.json\\nnode_modules/emoji-regex/package.json\\nnode_modules/error-ex/package.json\\nnode_modules/es-errors/package.json\\nnode_modules/escalade/package.json\\nnode_modules/escape-string-regexp/package.json\\nnode_modules/escodegen/package.json\\nnode_modules/esprima/package.json\\nnode_modules/estraverse/package.json\\nnode_modules/estree-walker/package.json\\nnode_modules/esutils/package.json\\nnode_modules/execa/node_modules/cross-spawn/package.json\\nnode_modules/execa/node_modules/lru-cache/package.json\\nnode_modules/execa/node_modules/shebang-command/package.json\\nnode_modules/execa/node_modules/shebang-regex/package.json\\nnode_modules/execa/node_modules/signal-exit/package.json\\nnode_modules/execa/node_modules/which/package.json\\nnode_modules/execa/node_modules/yallist/package.json\\nnode_modules/execa/package.json\\nnode_modules/extend/package.json\\nnode_modules/extsprintf/package.json\\nnode_modules/fast-deep-equal/package.json\\nnode_modules/fast-diff/package.json\\nnode_modules/fast-glob/package.json\\nnode_modules/fast-json-stable-stringify/package.json\\nnode_modules/fast-levenshtein/package.json\\nnode_modules/fastq/package.json\\nnode_modules/figures/package.json\\nnode_modules/file-uri-to-path/package.json\\nnode_modules/fill-range/package.json\\nnode_modules/find-up-simple/package.json\\nnode_modules/find-up/package.json\\nnode_modules/foreground-child/package.json\\nnode_modules/forever-agent/package.json\\nnode_modules/form-data/package.json\\nnode_modules/fs.realpath/package.json\\nnode_modules/function-bind/package.json\\nnode_modules/get-caller-file/package.json\\nnode_modules/get-east-asian-width/package.json\\nnode_modules/get-stdin/package.json\\nnode_modules/get-stream/package.json\\nnode_modules/getpass/package.json\\nnode_modules/glob-parent/package.json\\nnode_modules/glob/package.json\\nnode_modules/global-dirs/package.json\\nnode_modules/globby/package.json\\nnode_modules/got/package.json\\nnode_modules/graceful-fs/package.json\\nnode_modules/har-schema/package.json\\nnode_modules/har-validator/package.json\\nnode_modules/has-flag/package.json\\nnode_modules/hasown/package.json\\nnode_modules/hosted-git-info/package.json\\nnode_modules/html-encoding-sniffer/package.json\\nnode_modules/http-signature/package.json\\nnode_modules/https-proxy-agent/package.json\\nnode_modules/iconv-lite/package.json\\nnode_modules/ignore-by-default/package.json\\nnode_modules/ignore/package.json\\nnode_modules/import-lazy/package.json\\nnode_modules/imurmurhash/package.json\\nnode_modules/indent-string/package.json\\nnode_modules/inflight/package.json\\nnode_modules/inherits/package.json\\nnode_modules/ini/package.json\\nnode_modules/inversify/package.json\\nnode_modules/irregular-plurals/package.json\\nnode_modules/is-arrayish/package.json\\nnode_modules/is-ci/node_modules/ci-info/package.json\\nnode_modules/is-ci/package.json\\nnode_modules/is-core-module/package.json\\nnode_modules/is-extglob/package.json\\nnode_modules/is-finite/package.json\\nnode_modules/is-fullwidth-code-point/package.json\\nnode_modules/is-glob/package.json\\nnode_modules/is-installed-globally/package.json\\nnode_modules/is-npm/package.json\\nnode_modules/is-number/package.json\\nnode_modules/is-obj/package.json\\nnode_modules/is-path-cwd/package.json\\nnode_modules/is-path-in-cwd/package.json\\nnode_modules/is-path-inside/package.json\\nnode_modules/is-plain-object/package.json\\nnode_modules/is-promise/package.json\\nnode_modules/is-redirect/package.json\\nnode_modules/is-retry-allowed/package.json\\nnode_modules/is-stream/package.json\\nnode_modules/is-typedarray/package.json\\nnode_modules/is-unicode-supported/package.json\\nnode_modules/is-utf8/package.json\\nnode_modules/isarray/package.json\\nnode_modules/isexe/package.json\\nnode_modules/isstream/package.json\\nnode_modules/jackspeak/package.json\\nnode_modules/js-string-escape/package.json\\nnode_modules/js-tokens/package.json\\nnode_modules/js-yaml/package.json\\nnode_modules/jsbn/package.json\\nnode_modules/jsdom/node_modules/acorn/package.json\\nnode_modules/jsdom/package.json\\nnode_modules/json-schema-traverse/package.json\\nnode_modules/json-schema/package.json\\nnode_modules/json-stringify-safe/package.json\\nnode_modules/jsprim/package.json\\nnode_modules/latest-version/package.json\\nnode_modules/levn/package.json\\nnode_modules/load-json-file/package.json\\nnode_modules/lodash/package.json\\nnode_modules/loud-rejection/node_modules/signal-exit/package.json\\nnode_modules/loud-rejection/package.json\\nnode_modules/lowercase-keys/package.json\\nnode_modules/lru-cache/package.json\\nnode_modules/make-dir/package.json\\nnode_modules/map-obj/package.json\\nnode_modules/matcher/package.json\\nnode_modules/md5-hex/package.json\\nnode_modules/memoize/package.json\\nnode_modules/meow/package.json\\nnode_modules/merge2/package.json\\nnode_modules/micromatch/node_modules/picomatch/package.json\\nnode_modules/micromatch/package.json\\nnode_modules/mime-db/package.json\\nnode_modules/mime-types/package.json\\nnode_modules/mimic-function/package.json\\nnode_modules/minimatch/package.json\\nnode_modules/minimist/package.json\\nnode_modules/minipass/package.json\\nnode_modules/minizlib/package.json\\nnode_modules/mkdirp/package.json\\nnode_modules/ms/package.json\\nnode_modules/node-fetch/node_modules/webidl-conversions/package.json\\nnode_modules/node-fetch/node_modules/whatwg-url/package.json\\nnode_modules/node-fetch/package.json\\nnode_modules/node-gyp-build/package.json\\nnode_modules/nofilter/package.json\\nnode_modules/nopt/package.json\\nnode_modules/normalize-package-data/node_modules/semver/package.json\\nnode_modules/normalize-package-data/package.json\\nnode_modules/npm-run-path/node_modules/path-key/package.json\\nnode_modules/npm-run-path/package.json\\nnode_modules/nwmatcher/package.json\\nnode_modules/oauth-sign/package.json\\nnode_modules/object-assign/package.json\\nnode_modules/once/package.json\\nnode_modules/optionator/package.json\\nnode_modules/p-finally/package.json\\nnode_modules/p-map/package.json\\nnode_modules/package-config/package.json\\nnode_modules/package-json-from-dist/package.json\\nnode_modules/package-json/node_modules/semver/package.json\\nnode_modules/package-json/package.json\\nnode_modules/parse-json/package.json\\nnode_modules/parse-ms/package.json\\nnode_modules/parse5/package.json\\nnode_modules/path-exists/package.json\\nnode_modules/path-is-absolute/package.json\\nnode_modules/path-is-inside/package.json\\nnode_modules/path-key/package.json\\nnode_modules/path-parse/package.json\\nnode_modules/path-scurry/package.json\\nnode_modules/path-type/package.json\\nnode_modules/performance-now/package.json\\nnode_modules/picocolors/package.json\\nnode_modules/picomatch/package.json\\nnode_modules/pify/package.json\\nnode_modules/pinkie-promise/package.json\\nnode_modules/pinkie/package.json\\nnode_modules/plur/package.json\\nnode_modules/prelude-ls/package.json\\nnode_modules/prepend-http/package.json\\nnode_modules/pretty-ms/package.json\\nnode_modules/pseudomap/package.json\\nnode_modules/psl/package.json\\nnode_modules/punycode/package.json\\nnode_modules/qs/package.json\\nnode_modules/queue-microtask/package.json\\nnode_modules/rc/package.json\\nnode_modules/read-pkg-up/package.json\\nnode_modules/read-pkg/node_modules/load-json-file/package.json\\nnode_modules/read-pkg/node_modules/path-type/package.json\\nnode_modules/read-pkg/node_modules/pify/package.json\\nnode_modules/read-pkg/package.json\\nnode_modules/redent/node_modules/indent-string/package.json\\nnode_modules/redent/package.json\\nnode_modules/reflect-metadata/package.json\\nnode_modules/registry-auth-token/package.json\\nnode_modules/registry-url/package.json\\nnode_modules/repeating/package.json\\nnode_modules/request/package.json\\nnode_modules/require-directory/package.json\\nnode_modules/resolve-cwd/package.json\\nnode_modules/resolve-from/package.json\\nnode_modules/resolve/package.json\\nnode_modules/resolve/test/resolver/baz/package.json\\nnode_modules/resolve/test/resolver/browser_field/package.json\\nnode_modules/resolve/test/resolver/false_main/package.json\\nnode_modules/resolve/test/resolver/invalid_main/package.json\\nnode_modules/resolve/test/resolver/multirepo/package.json\\nnode_modules/resolve/test/resolver/multirepo/packages/package-a/package.json\\nnode_modules/resolve/test/resolver/multirepo/packages/package-b/package.json\\nnode_modules/resolve/test/resolver/nested_symlinks/mylib/package.json\\nnode_modules/reusify/package.json\\nnode_modules/rimraf/node_modules/brace-expansion/package.json\\nnode_modules/rimraf/node_modules/glob/package.json\\nnode_modules/rimraf/node_modules/minimatch/package.json\\nnode_modules/rimraf/package.json\\nnode_modules/run-parallel/package.json\\nnode_modules/safe-buffer/package.json\\nnode_modules/safer-buffer/package.json\\nnode_modules/sax/package.json\\nnode_modules/semver-diff/node_modules/semver/package.json\\nnode_modules/semver-diff/package.json\\nnode_modules/semver/package.json\\nnode_modules/serialize-error/package.json\\nnode_modules/shebang-command/package.json\\nnode_modules/shebang-regex/package.json\\nnode_modules/signal-exit/package.json\\nnode_modules/slash/package.json\\nnode_modules/slice-ansi/package.json\\nnode_modules/source-map/package.json\\nnode_modules/spdx-correct/package.json\\nnode_modules/spdx-exceptions/package.json\\nnode_modules/spdx-expression-parse/package.json\\nnode_modules/spdx-license-ids/package.json\\nnode_modules/sprintf-js/package.json\\nnode_modules/sshpk/package.json\\nnode_modules/stack-utils/node_modules/escape-string-regexp/package.json\\nnode_modules/stack-utils/package.json\\nnode_modules/string-width-cjs/node_modules/ansi-regex/package.json\\nnode_modules/string-width-cjs/node_modules/emoji-regex/package.json\\nnode_modules/string-width-cjs/node_modules/is-fullwidth-code-point/package.json\\nnode_modules/string-width-cjs/node_modules/strip-ansi/package.json\\nnode_modules/string-width-cjs/package.json\\nnode_modules/string-width/package.json\\nnode_modules/strip-ansi-cjs/node_modules/ansi-regex/package.json\\nnode_modules/strip-ansi-cjs/package.json\\nnode_modules/strip-ansi/package.json\\nnode_modules/strip-bom/package.json\\nnode_modules/strip-eof/package.json\\nnode_modules/strip-indent/package.json\\nnode_modules/strip-json-comments/package.json\\nnode_modules/supertap/package.json\\nnode_modules/supports-color/package.json\\nnode_modules/supports-preserve-symlinks-flag/package.json\\nnode_modules/symbol-tree/package.json\\nnode_modules/tar/package.json\\nnode_modules/temp-dir/package.json\\nnode_modules/tempy/node_modules/temp-dir/package.json\\nnode_modules/tempy/package.json\\nnode_modules/term-size/package.json\\nnode_modules/time-zone/package.json\\nnode_modules/timed-out/package.json\\nnode_modules/to-regex-range/package.json\\nnode_modules/tough-cookie/package.json\\nnode_modules/tr46/package.json\\nnode_modules/trim-newlines/package.json\\nnode_modules/tslib/package.json\\nnode_modules/tslint-consistent-codestyle/node_modules/@fimbul/bifrost/node_modules/@fimbul/ymir/package.json\\nnode_modules/tslint-consistent-codestyle/node_modules/@fimbul/bifrost/node_modules/tsutils/package.json\\nnode_modules/tslint-consistent-codestyle/node_modules/@fimbul/bifrost/package.json\\nnode_modules/tslint-consistent-codestyle/package.json\\nnode_modules/tslint-eslint-rules/node_modules/tsutils/package.json\\nnode_modules/tslint-eslint-rules/package.json\\nnode_modules/tslint-xo/node_modules/tslint-microsoft-contrib/package.json\\nnode_modules/tslint-xo/node_modules/tsutils/package.json\\nnode_modules/tslint-xo/node_modules/typescript/package.json\\nnode_modules/tslint-xo/package.json\\nnode_modules/tslint/node_modules/ansi-styles/package.json\\nnode_modules/tslint/node_modules/brace-expansion/package.json\\nnode_modules/tslint/node_modules/chalk/package.json\\nnode_modules/tslint/node_modules/escape-string-regexp/package.json\\nnode_modules/tslint/node_modules/glob/package.json\\nnode_modules/tslint/node_modules/minimatch/package.json\\nnode_modules/tslint/node_modules/semver/package.json\\nnode_modules/tslint/package.json\\nnode_modules/tsutils/package.json\\nnode_modules/tunnel-agent/package.json\\nnode_modules/tweetnacl/package.json\\nnode_modules/type-check/package.json\\nnode_modules/type-fest/package.json\\nnode_modules/typescript/package.json\\nnode_modules/unicorn-magic/package.json\\nnode_modules/unique-string/package.json\\nnode_modules/unzip-response/package.json\\nnode_modules/update-notifier/node_modules/ansi-styles/package.json\\nnode_modules/update-notifier/node_modules/chalk/package.json\\nnode_modules/update-notifier/node_modules/escape-string-regexp/package.json\\nnode_modules/update-notifier/package.json\\nnode_modules/uri-js/package.json\\nnode_modules/url-parse-lax/package.json\\nnode_modules/uuid/package.json\\nnode_modules/validate-npm-package-license/package.json\\nnode_modules/verror/package.json\\nnode_modules/webidl-conversions/package.json\\nnode_modules/well-known-symbols/package.json\\nnode_modules/whatwg-encoding/package.json\\nnode_modules/whatwg-url/node_modules/webidl-conversions/package.json\\nnode_modules/whatwg-url/package.json\\nnode_modules/which/package.json\\nnode_modules/widest-line/node_modules/ansi-regex/package.json\\nnode_modules/widest-line/node_modules/is-fullwidth-code-point/package.json\\nnode_modules/widest-line/node_modules/string-width/package.json\\nnode_modules/widest-line/node_modules/strip-ansi/package.json\\nnode_modules/widest-line/package.json\\nnode_modules/word-wrap/package.json\\nnode_modules/wrap-ansi-cjs/node_modules/ansi-regex/package.json\\nnode_modules/wrap-ansi-cjs/node_modules/ansi-styles/package.json\\nnode_modules/wrap-ansi-cjs/node_modules/color-convert/package.json\\nnode_modules/wrap-ansi-cjs/node_modules/color-name/package.json\\nnode_modules/wrap-ansi-cjs/node_modules/emoji-regex/package.json\\nnode_modules/wrap-ansi-cjs/node_modules/is-fullwidth-code-point/package.json\\nnode_modules/wrap-ansi-cjs/node_modules/string-width/package.json\\nnode_modules/wrap-ansi-cjs/node_modules/strip-ansi/package.json\\nnode_modules/wrap-ansi-cjs/package.json\\nnode_modules/wrap-ansi/node_modules/emoji-regex/package.json\\nnode_modules/wrap-ansi/node_modules/string-width/package.json\\nnode_modules/wrap-ansi/package.json\\nnode_modules/wrappy/package.json\\nnode_modules/write-file-atomic/package.json\\nnode_modules/xdg-basedir/package.json\\nnode_modules/xml-name-validator/package.json\\nnode_modules/y18n/package.json\\nnode_modules/yallist/package.json\\nnode_modules/yargs-parser/package.json\\nnode_modules/yargs/node_modules/ansi-regex/package.json\\nnode_modules/yargs/node_modules/emoji-regex/package.json\\nnode_modules/yargs/node_modules/is-fullwidth-code-point/package.json\\nnode_modules/yargs/node_modules/string-width/package.json\\nnode_modules/yargs/node_modules/strip-ansi/package.json\\nnode_modules/yargs/package.json"
      }
    ]
  },
  "components": [
    {
      "authors": [
        {
          "name": "Ben Coe <ben@npmjs.com>"
        }
      ],
      "group": "",
      "name": "yargs-parser",
      "version": "21.1.1",
      "description": "the mighty option parser used by yargs",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/yargs-parser@21.1.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/yargs/yargs-parser.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/yargs-parser@21.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/yargs-parser/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/yargs-parser/package.json"
              }
            ],
            "concludedValue": "node_modules/yargs-parser/package.json"
          }
        ]
      },
      "tags": [
        "parse"
      ]
    },
    {
      "group": "",
      "name": "yargs",
      "version": "17.7.2",
      "description": "yargs the modern, pirate-themed, successor to optimist.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/yargs@17.7.2",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://yargs.js.org/"
        },
        {
          "type": "vcs",
          "url": "https://github.com/yargs/yargs.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/yargs@17.7.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/yargs/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/yargs/package.json"
              }
            ],
            "concludedValue": "node_modules/yargs/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "strip-ansi",
      "version": "6.0.1",
      "description": "Strip ANSI escape codes from a string",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/strip-ansi@6.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/strip-ansi@6.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/yargs/node_modules/strip-ansi/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/wrap-ansi-cjs/node_modules/strip-ansi/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/strip-ansi-cjs/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/string-width-cjs/node_modules/strip-ansi/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/cliui/node_modules/strip-ansi/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/cliui/node_modules/strip-ansi/package.json"
              }
            ],
            "concludedValue": "node_modules/cliui/node_modules/strip-ansi/package.json"
          }
        ]
      },
      "tags": [
        "escape"
      ]
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "string-width",
      "version": "4.2.3",
      "description": "Get the visual width of a string - the number of columns required to display it",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/string-width@4.2.3",
      "type": "library",
      "bom-ref": "pkg:npm/string-width@4.2.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/yargs/node_modules/string-width/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/wrap-ansi-cjs/node_modules/string-width/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/string-width-cjs/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/cliui/node_modules/string-width/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/cliui/node_modules/string-width/package.json"
              }
            ],
            "concludedValue": "node_modules/cliui/node_modules/string-width/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "is-fullwidth-code-point",
      "version": "3.0.0",
      "description": "Check if the character represented by a given Unicode code point is fullwidth",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-fullwidth-code-point@3.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/is-fullwidth-code-point@3.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/yargs/node_modules/is-fullwidth-code-point/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/wrap-ansi-cjs/node_modules/is-fullwidth-code-point/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/string-width-cjs/node_modules/is-fullwidth-code-point/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/cliui/node_modules/is-fullwidth-code-point/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/cliui/node_modules/is-fullwidth-code-point/package.json"
              }
            ],
            "concludedValue": "node_modules/cliui/node_modules/is-fullwidth-code-point/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mathias Bynens (https://mathiasbynens.be/)"
        }
      ],
      "group": "",
      "name": "emoji-regex",
      "version": "8.0.0",
      "description": "A regular expression to match all Emoji-only symbols as per the Unicode Standard.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/emoji-regex@8.0.0",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://mths.be/emoji-regex"
        },
        {
          "type": "vcs",
          "url": "https://github.com/mathiasbynens/emoji-regex.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/emoji-regex@8.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/yargs/node_modules/emoji-regex/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/wrap-ansi-cjs/node_modules/emoji-regex/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/string-width-cjs/node_modules/emoji-regex/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/cliui/node_modules/emoji-regex/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/cliui/node_modules/emoji-regex/package.json"
              }
            ],
            "concludedValue": "node_modules/cliui/node_modules/emoji-regex/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "ansi-regex",
      "version": "5.0.1",
      "description": "Regular expression for matching ANSI escape codes",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/ansi-regex@5.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/ansi-regex@5.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/yargs/node_modules/ansi-regex/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/wrap-ansi-cjs/node_modules/ansi-regex/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/strip-ansi-cjs/node_modules/ansi-regex/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/string-width-cjs/node_modules/ansi-regex/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/cliui/node_modules/ansi-regex/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/cliui/node_modules/ansi-regex/package.json"
              }
            ],
            "concludedValue": "node_modules/cliui/node_modules/ansi-regex/package.json"
          }
        ]
      },
      "tags": [
        "escape"
      ]
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "yallist",
      "version": "5.0.0",
      "description": "Yet Another Linked List",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BlueOak-1.0.0",
            "url": "https://opensource.org/licenses/BlueOak-1.0.0"
          }
        }
      ],
      "purl": "pkg:npm/yallist@5.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git+https://github.com/isaacs/yallist.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/yallist@5.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/yallist/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/yallist/package.json"
              }
            ],
            "concludedValue": "node_modules/yallist/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Ben Coe <bencoe@gmail.com>"
        }
      ],
      "group": "",
      "name": "y18n",
      "version": "5.0.8",
      "description": "the bare-bones internationalization library used by yargs",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/y18n@5.0.8",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/yargs/y18n"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/y18n@5.0.8",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/y18n/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/y18n/package.json"
              }
            ],
            "concludedValue": "node_modules/y18n/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Domenic Denicola <d@domenic.me> (https://domenic.me/)"
        }
      ],
      "group": "",
      "name": "xml-name-validator",
      "version": "2.0.1",
      "description": "Validates whether a string matches the production for an XML name or qualified name",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "WTFPL",
            "url": "https://opensource.org/licenses/WTFPL"
          }
        }
      ],
      "purl": "pkg:npm/xml-name-validator@2.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/xml-name-validator@2.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/xml-name-validator/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/xml-name-validator/package.json"
              }
            ],
            "concludedValue": "node_modules/xml-name-validator/package.json"
          }
        ]
      },
      "tags": [
        "xml"
      ]
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "xdg-basedir",
      "version": "3.0.0",
      "description": "Get XDG Base Directory paths",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/xdg-basedir@3.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/xdg-basedir@3.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/xdg-basedir/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/xdg-basedir/package.json"
              }
            ],
            "concludedValue": "node_modules/xdg-basedir/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "GitHub Inc."
        }
      ],
      "group": "",
      "name": "write-file-atomic",
      "version": "6.0.0",
      "description": "Write files in an atomic fashion w/configurable ownership",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/write-file-atomic@6.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/npm/write-file-atomic"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/npm/write-file-atomic.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/write-file-atomic@6.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/write-file-atomic/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/write-file-atomic/package.json"
              }
            ],
            "concludedValue": "node_modules/write-file-atomic/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "wrappy",
      "version": "1.0.2",
      "description": "Callback wrapping utility",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/wrappy@1.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/npm/wrappy"
        },
        {
          "type": "vcs",
          "url": "https://github.com/npm/wrappy"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/wrappy@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/wrappy/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/wrappy/package.json"
              }
            ],
            "concludedValue": "node_modules/wrappy/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "wrap-ansi",
      "version": "7.0.0",
      "description": "Wordwrap a string with ANSI escape codes",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/wrap-ansi@7.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/wrap-ansi@7.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/wrap-ansi-cjs/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/cliui/node_modules/wrap-ansi/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/cliui/node_modules/wrap-ansi/package.json"
              }
            ],
            "concludedValue": "node_modules/cliui/node_modules/wrap-ansi/package.json"
          }
        ]
      },
      "tags": [
        "escape"
      ]
    },
    {
      "authors": [
        {
          "name": "DY <dfcreative@gmail.com>"
        }
      ],
      "group": "",
      "name": "color-name",
      "version": "1.1.4",
      "description": "A list of color names and its values",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/color-name@1.1.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/colorjs/color-name"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/color-name@1.1.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/wrap-ansi-cjs/node_modules/color-name/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/cliui/node_modules/color-name/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/cliui/node_modules/color-name/package.json"
              }
            ],
            "concludedValue": "node_modules/cliui/node_modules/color-name/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Heather Arthur <fayearthur@gmail.com>"
        }
      ],
      "group": "",
      "name": "color-convert",
      "version": "2.0.1",
      "description": "Plain color conversion functions",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/color-convert@2.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/color-convert@2.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/wrap-ansi-cjs/node_modules/color-convert/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/cliui/node_modules/color-convert/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/cliui/node_modules/color-convert/package.json"
              }
            ],
            "concludedValue": "node_modules/cliui/node_modules/color-convert/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "ansi-styles",
      "version": "4.3.0",
      "description": "ANSI escape codes for styling strings in the terminal",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/ansi-styles@4.3.0",
      "type": "library",
      "bom-ref": "pkg:npm/ansi-styles@4.3.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/wrap-ansi-cjs/node_modules/ansi-styles/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/cliui/node_modules/ansi-styles/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/cliui/node_modules/ansi-styles/package.json"
              }
            ],
            "concludedValue": "node_modules/cliui/node_modules/ansi-styles/package.json"
          }
        ]
      },
      "tags": [
        "escape"
      ]
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "wrap-ansi",
      "version": "8.1.0",
      "description": "Wordwrap a string with ANSI escape codes",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/wrap-ansi@8.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/wrap-ansi@8.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/wrap-ansi/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/wrap-ansi/package.json"
              }
            ],
            "concludedValue": "node_modules/wrap-ansi/package.json"
          }
        ]
      },
      "tags": [
        "escape"
      ]
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "string-width",
      "version": "5.1.2",
      "description": "Get the visual width of a string - the number of columns required to display it",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/string-width@5.1.2",
      "type": "library",
      "bom-ref": "pkg:npm/string-width@5.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/wrap-ansi/node_modules/string-width/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/@isaacs/cliui/node_modules/string-width/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@isaacs/cliui/node_modules/string-width/package.json"
              }
            ],
            "concludedValue": "node_modules/@isaacs/cliui/node_modules/string-width/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mathias Bynens (https://mathiasbynens.be/)"
        }
      ],
      "group": "",
      "name": "emoji-regex",
      "version": "9.2.2",
      "description": "A regular expression to match all Emoji-only symbols as per the Unicode Standard.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/emoji-regex@9.2.2",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://mths.be/emoji-regex"
        },
        {
          "type": "vcs",
          "url": "https://github.com/mathiasbynens/emoji-regex.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/emoji-regex@9.2.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/wrap-ansi/node_modules/emoji-regex/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/@isaacs/cliui/node_modules/emoji-regex/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@isaacs/cliui/node_modules/emoji-regex/package.json"
              }
            ],
            "concludedValue": "node_modules/@isaacs/cliui/node_modules/emoji-regex/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jon Schlinkert (https://github.com/jonschlinkert)"
        }
      ],
      "group": "",
      "name": "word-wrap",
      "version": "1.2.5",
      "description": "Wrap words to a specified length.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/word-wrap@1.2.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jonschlinkert/word-wrap"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/word-wrap@1.2.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/word-wrap/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/word-wrap/package.json"
              }
            ],
            "concludedValue": "node_modules/word-wrap/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "widest-line",
      "version": "2.0.1",
      "description": "Get the visual width of the widest line in a string - the number of columns required to display it",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/widest-line@2.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/widest-line@2.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/widest-line/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/widest-line/package.json"
              }
            ],
            "concludedValue": "node_modules/widest-line/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "strip-ansi",
      "version": "4.0.0",
      "description": "Strip ANSI escape codes",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/strip-ansi@4.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/strip-ansi@4.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/widest-line/node_modules/strip-ansi/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/boxen/node_modules/strip-ansi/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/ansi-align/node_modules/strip-ansi/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/ansi-align/node_modules/strip-ansi/package.json"
              }
            ],
            "concludedValue": "node_modules/ansi-align/node_modules/strip-ansi/package.json"
          }
        ]
      },
      "tags": [
        "escape"
      ]
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "string-width",
      "version": "2.1.1",
      "description": "Get the visual width of a string - the number of columns required to display it",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/string-width@2.1.1",
      "type": "library",
      "bom-ref": "pkg:npm/string-width@2.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/widest-line/node_modules/string-width/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/boxen/node_modules/string-width/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/ansi-align/node_modules/string-width/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/ansi-align/node_modules/string-width/package.json"
              }
            ],
            "concludedValue": "node_modules/ansi-align/node_modules/string-width/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "is-fullwidth-code-point",
      "version": "2.0.0",
      "description": "Check if the character represented by a given Unicode code point is fullwidth",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-fullwidth-code-point@2.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/is-fullwidth-code-point@2.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/widest-line/node_modules/is-fullwidth-code-point/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/boxen/node_modules/is-fullwidth-code-point/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/ansi-align/node_modules/is-fullwidth-code-point/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/ansi-align/node_modules/is-fullwidth-code-point/package.json"
              }
            ],
            "concludedValue": "node_modules/ansi-align/node_modules/is-fullwidth-code-point/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "ansi-regex",
      "version": "3.0.1",
      "description": "Regular expression for matching ANSI escape codes",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/ansi-regex@3.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/ansi-regex@3.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/widest-line/node_modules/ansi-regex/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/boxen/node_modules/ansi-regex/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/ansi-align/node_modules/ansi-regex/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/ansi-align/node_modules/ansi-regex/package.json"
              }
            ],
            "concludedValue": "node_modules/ansi-align/node_modules/ansi-regex/package.json"
          }
        ]
      },
      "tags": [
        "escape"
      ]
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me)"
        }
      ],
      "group": "",
      "name": "which",
      "version": "2.0.2",
      "description": "Like which(1) unix command. Find the first instance of an executable in the PATH.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/which@2.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/node-which.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/which@2.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/which/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/which/package.json"
              }
            ],
            "concludedValue": "node_modules/which/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sebastian Mayr <github@smayr.name>"
        }
      ],
      "group": "",
      "name": "whatwg-url",
      "version": "4.8.0",
      "description": "An implementation of the WHATWG URL Standard's URL API and parsing machinery",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/whatwg-url@4.8.0",
      "type": "library",
      "bom-ref": "pkg:npm/whatwg-url@4.8.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/whatwg-url/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/whatwg-url/package.json"
              }
            ],
            "concludedValue": "node_modules/whatwg-url/package.json"
          }
        ]
      },
      "tags": [
        "api"
      ]
    },
    {
      "authors": [
        {
          "name": "Domenic Denicola <d@domenic.me> (https://domenic.me/)"
        }
      ],
      "group": "",
      "name": "webidl-conversions",
      "version": "3.0.1",
      "description": "Implements the WebIDL algorithms for converting to and from JavaScript values",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-2-Clause",
            "url": "https://opensource.org/licenses/BSD-2-Clause"
          }
        }
      ],
      "purl": "pkg:npm/webidl-conversions@3.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/webidl-conversions@3.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/whatwg-url/node_modules/webidl-conversions/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/node-fetch/node_modules/webidl-conversions/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/node-fetch/node_modules/webidl-conversions/package.json"
              }
            ],
            "concludedValue": "node_modules/node-fetch/node_modules/webidl-conversions/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Domenic Denicola <d@domenic.me> (https://domenic.me/)"
        }
      ],
      "group": "",
      "name": "whatwg-encoding",
      "version": "1.0.5",
      "description": "Decode strings according to the WHATWG Encoding Standard",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/whatwg-encoding@1.0.5",
      "type": "library",
      "bom-ref": "pkg:npm/whatwg-encoding@1.0.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/whatwg-encoding/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/whatwg-encoding/package.json"
              }
            ],
            "concludedValue": "node_modules/whatwg-encoding/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mark Wubben (https://novemberborn.net/)"
        }
      ],
      "group": "",
      "name": "well-known-symbols",
      "version": "2.0.0",
      "description": "Check whether a symbol is well-known",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/well-known-symbols@2.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/novemberborn/well-known-symbols#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/novemberborn/well-known-symbols.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/well-known-symbols@2.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/well-known-symbols/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/well-known-symbols/package.json"
              }
            ],
            "concludedValue": "node_modules/well-known-symbols/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Domenic Denicola <d@domenic.me> (https://domenic.me/)"
        }
      ],
      "group": "",
      "name": "webidl-conversions",
      "version": "4.0.2",
      "description": "Implements the WebIDL algorithms for converting to and from JavaScript values",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-2-Clause",
            "url": "https://opensource.org/licenses/BSD-2-Clause"
          }
        }
      ],
      "purl": "pkg:npm/webidl-conversions@4.0.2",
      "type": "library",
      "bom-ref": "pkg:npm/webidl-conversions@4.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/webidl-conversions/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/webidl-conversions/package.json"
              }
            ],
            "concludedValue": "node_modules/webidl-conversions/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "verror",
      "version": "1.10.0",
      "description": "richer JavaScript errors",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/verror@1.10.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/davepacheco/node-verror.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/verror@1.10.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/verror/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/verror/package.json"
              }
            ],
            "concludedValue": "node_modules/verror/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Kyle E. Mitchell <kyle@kemitchell.com> (https://kemitchell.com)"
        }
      ],
      "group": "",
      "name": "validate-npm-package-license",
      "version": "3.0.4",
      "description": "Give me a string and I'll tell you if it's a valid npm package license string",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0",
            "url": "https://opensource.org/licenses/Apache-2.0"
          }
        }
      ],
      "purl": "pkg:npm/validate-npm-package-license@3.0.4",
      "type": "library",
      "bom-ref": "pkg:npm/validate-npm-package-license@3.0.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/validate-npm-package-license/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/validate-npm-package-license/package.json"
              }
            ],
            "concludedValue": "node_modules/validate-npm-package-license/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "uuid",
      "version": "3.4.0",
      "description": "RFC4122 (v1, v4, and v5) UUIDs",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/uuid@3.4.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/uuidjs/uuid.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/uuid@3.4.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/uuid/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/uuid/package.json"
              }
            ],
            "concludedValue": "node_modules/uuid/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "url-parse-lax",
      "version": "1.0.0",
      "description": "url.parse() with support for protocol-less URLs & IPs",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/url-parse-lax@1.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/url-parse-lax@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/url-parse-lax/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/url-parse-lax/package.json"
              }
            ],
            "concludedValue": "node_modules/url-parse-lax/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Gary Court <gary.court@gmail.com>"
        }
      ],
      "group": "",
      "name": "uri-js",
      "version": "4.4.1",
      "description": "An RFC 3986/3987 compliant, scheme extendable URI/IRI parsing/validating/resolving library for JavaScript.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-2-Clause",
            "url": "https://opensource.org/licenses/BSD-2-Clause"
          }
        }
      ],
      "purl": "pkg:npm/uri-js@4.4.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/garycourt/uri-js"
        },
        {
          "type": "vcs",
          "url": "http://github.com/garycourt/uri-js"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/uri-js@4.4.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/uri-js/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/uri-js/package.json"
              }
            ],
            "concludedValue": "node_modules/uri-js/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "update-notifier",
      "version": "2.5.0",
      "description": "Update notifications for your CLI app",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-2-Clause",
            "url": "https://opensource.org/licenses/BSD-2-Clause"
          }
        }
      ],
      "purl": "pkg:npm/update-notifier@2.5.0",
      "type": "library",
      "bom-ref": "pkg:npm/update-notifier@2.5.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/update-notifier/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/update-notifier/package.json"
              }
            ],
            "concludedValue": "node_modules/update-notifier/package.json"
          }
        ]
      },
      "tags": [
        "cli"
      ]
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "escape-string-regexp",
      "version": "1.0.5",
      "description": "Escape RegExp special characters",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/escape-string-regexp@1.0.5",
      "type": "library",
      "bom-ref": "pkg:npm/escape-string-regexp@1.0.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/update-notifier/node_modules/escape-string-regexp/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/tslint/node_modules/escape-string-regexp/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/boxen/node_modules/escape-string-regexp/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/boxen/node_modules/escape-string-regexp/package.json"
              }
            ],
            "concludedValue": "node_modules/boxen/node_modules/escape-string-regexp/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "chalk",
      "version": "2.4.2",
      "description": "Terminal string styling done right",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/chalk@2.4.2",
      "type": "library",
      "bom-ref": "pkg:npm/chalk@2.4.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/update-notifier/node_modules/chalk/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/tslint/node_modules/chalk/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/boxen/node_modules/chalk/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/boxen/node_modules/chalk/package.json"
              }
            ],
            "concludedValue": "node_modules/boxen/node_modules/chalk/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "ansi-styles",
      "version": "3.2.1",
      "description": "ANSI escape codes for styling strings in the terminal",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/ansi-styles@3.2.1",
      "type": "library",
      "bom-ref": "pkg:npm/ansi-styles@3.2.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/update-notifier/node_modules/ansi-styles/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/tslint/node_modules/ansi-styles/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/boxen/node_modules/ansi-styles/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/boxen/node_modules/ansi-styles/package.json"
              }
            ],
            "concludedValue": "node_modules/boxen/node_modules/ansi-styles/package.json"
          }
        ]
      },
      "tags": [
        "escape"
      ]
    },
    {
      "group": "",
      "name": "unzip-response",
      "version": "2.0.1",
      "description": "Unzip a HTTP response if needed",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/unzip-response@2.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/unzip-response@2.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/unzip-response/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/unzip-response/package.json"
              }
            ],
            "concludedValue": "node_modules/unzip-response/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "unique-string",
      "version": "1.0.0",
      "description": "Generate a unique random string",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/unique-string@1.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/unique-string@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/unique-string/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/unique-string/package.json"
              }
            ],
            "concludedValue": "node_modules/unique-string/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "unicorn-magic",
      "version": "0.3.0",
      "description": "Some useful utilities I often need",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/unicorn-magic@0.3.0",
      "type": "library",
      "bom-ref": "pkg:npm/unicorn-magic@0.3.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/unicorn-magic/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/unicorn-magic/package.json"
              }
            ],
            "concludedValue": "node_modules/unicorn-magic/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Microsoft Corp."
        }
      ],
      "group": "",
      "name": "typescript",
      "version": "5.9.3",
      "description": "TypeScript is a language for application scale JavaScript development",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0",
            "url": "https://opensource.org/licenses/Apache-2.0"
          }
        }
      ],
      "purl": "pkg:npm/typescript@5.9.3",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://www.typescriptlang.org/"
        },
        {
          "type": "vcs",
          "url": "https://github.com/microsoft/TypeScript.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/typescript@5.9.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/typescript/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/typescript/package.json"
              }
            ],
            "concludedValue": "node_modules/typescript/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "type-fest",
      "version": "0.13.1",
      "description": "A collection of essential TypeScript types",
      "scope": "optional",
      "licenses": [
        {
          "expression": "(MIT OR CC0-1.0)"
        }
      ],
      "purl": "pkg:npm/type-fest@0.13.1",
      "type": "library",
      "bom-ref": "pkg:npm/type-fest@0.13.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/type-fest/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/type-fest/package.json"
              }
            ],
            "concludedValue": "node_modules/type-fest/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "George Zahariev <z@georgezahariev.com>"
        }
      ],
      "group": "",
      "name": "type-check",
      "version": "0.3.2",
      "description": "type-check allows you to check the types of JavaScript values at runtime with a Haskell like type syntax.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/type-check@0.3.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/gkz/type-check"
        },
        {
          "type": "vcs",
          "url": "git://github.com/gkz/type-check.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/type-check@0.3.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/type-check/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/type-check/package.json"
              }
            ],
            "concludedValue": "node_modules/type-check/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "TweetNaCl-js contributors"
        }
      ],
      "group": "",
      "name": "tweetnacl",
      "version": "0.14.5",
      "description": "Port of TweetNaCl cryptographic library to JavaScript",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Unlicense",
            "url": "https://opensource.org/licenses/Unlicense"
          }
        }
      ],
      "purl": "pkg:npm/tweetnacl@0.14.5",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://tweetnacl.js.org"
        },
        {
          "type": "vcs",
          "url": "https://github.com/dchest/tweetnacl-js.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/tweetnacl@0.14.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tweetnacl/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tweetnacl/package.json"
              }
            ],
            "concludedValue": "node_modules/tweetnacl/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mikeal Rogers <mikeal.rogers@gmail.com> (http://www.futurealoof.com)"
        }
      ],
      "group": "",
      "name": "tunnel-agent",
      "version": "0.6.0",
      "description": "HTTP proxy tunneling agent. Formerly part of mikeal/request, now a standalone module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0",
            "url": "https://opensource.org/licenses/Apache-2.0"
          }
        }
      ],
      "purl": "pkg:npm/tunnel-agent@0.6.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mikeal/tunnel-agent"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/tunnel-agent@0.6.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tunnel-agent/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tunnel-agent/package.json"
              }
            ],
            "concludedValue": "node_modules/tunnel-agent/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Klaus Meinhardt"
        }
      ],
      "group": "",
      "name": "tsutils",
      "version": "2.29.0",
      "description": "utilities for working with typescript's AST",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/tsutils@2.29.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/ajafff/tsutils"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/tsutils@2.29.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tsutils/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tsutils/package.json"
              }
            ],
            "concludedValue": "node_modules/tsutils/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "tslint-xo",
      "version": "0.3.0",
      "description": "TSLint shareable config for XO",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/tslint-xo@0.3.0",
      "type": "library",
      "bom-ref": "pkg:npm/tslint-xo@0.3.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tslint-xo/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tslint-xo/package.json"
              }
            ],
            "concludedValue": "node_modules/tslint-xo/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Microsoft Corp."
        }
      ],
      "group": "",
      "name": "typescript",
      "version": "3.9.10",
      "description": "TypeScript is a language for application scale JavaScript development",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0",
            "url": "https://opensource.org/licenses/Apache-2.0"
          }
        }
      ],
      "purl": "pkg:npm/typescript@3.9.10",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://www.typescriptlang.org/"
        },
        {
          "type": "vcs",
          "url": "https://github.com/Microsoft/TypeScript.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/typescript@3.9.10",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tslint-xo/node_modules/typescript/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tslint-xo/node_modules/typescript/package.json"
              }
            ],
            "concludedValue": "node_modules/tslint-xo/node_modules/typescript/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Klaus Meinhardt"
        }
      ],
      "group": "",
      "name": "tsutils",
      "version": "2.28.0",
      "description": "utilities for working with typescript's AST",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/tsutils@2.28.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/ajafff/tsutils"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/tsutils@2.28.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tslint-xo/node_modules/tsutils/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tslint-xo/node_modules/tsutils/package.json"
              }
            ],
            "concludedValue": "node_modules/tslint-xo/node_modules/tsutils/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Hamlet D'Arcy"
        }
      ],
      "group": "",
      "name": "tslint-microsoft-contrib",
      "version": "5.2.1",
      "description": "TSLint Rules for Microsoft",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/tslint-microsoft-contrib@5.2.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/Microsoft/tslint-microsoft-contrib"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/tslint-microsoft-contrib@5.2.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tslint-xo/node_modules/tslint-microsoft-contrib/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tslint-xo/node_modules/tslint-microsoft-contrib/package.json"
              }
            ],
            "concludedValue": "node_modules/tslint-xo/node_modules/tslint-microsoft-contrib/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Vitor Buzinaro <buzinas@buzinas.com>"
        }
      ],
      "group": "",
      "name": "tslint-eslint-rules",
      "version": "4.1.1",
      "description": "Improve your TSLint with the missing ESLint Rules",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/tslint-eslint-rules@4.1.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/buzinas/tslint-eslint-rules.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/tslint-eslint-rules@4.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tslint-eslint-rules/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tslint-eslint-rules/package.json"
              }
            ],
            "concludedValue": "node_modules/tslint-eslint-rules/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Klaus Meinhardt"
        }
      ],
      "group": "",
      "name": "tsutils",
      "version": "1.9.1",
      "description": "utilities for working with typescript's AST",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/tsutils@1.9.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/ajafff/tsutils"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/tsutils@1.9.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tslint-eslint-rules/node_modules/tsutils/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tslint-eslint-rules/node_modules/tsutils/package.json"
              }
            ],
            "concludedValue": "node_modules/tslint-eslint-rules/node_modules/tsutils/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "tslint-consistent-codestyle",
      "version": "1.16.0",
      "description": "Additional rules to enforce constistent code style with tslint",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/tslint-consistent-codestyle@1.16.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/ajafff/tslint-consistent-codestyle"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/tslint-consistent-codestyle@1.16.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tslint-consistent-codestyle/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tslint-consistent-codestyle/package.json"
              }
            ],
            "concludedValue": "node_modules/tslint-consistent-codestyle/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Klaus Meinhardt"
        }
      ],
      "group": "@fimbul",
      "name": "bifrost",
      "version": "0.21.0",
      "description": "Compatibility layer for TSLint rules",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0",
            "url": "https://opensource.org/licenses/Apache-2.0"
          }
        }
      ],
      "purl": "pkg:npm/%40fimbul/bifrost@0.21.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/fimbullinter/wotan#readme"
        },
        {
          "type": "vcs",
          "url": "https://github.com/fimbullinter/wotan"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@fimbul/bifrost@0.21.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tslint-consistent-codestyle/node_modules/@fimbul/bifrost/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tslint-consistent-codestyle/node_modules/@fimbul/bifrost/package.json"
              }
            ],
            "concludedValue": "node_modules/tslint-consistent-codestyle/node_modules/@fimbul/bifrost/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Klaus Meinhardt"
        }
      ],
      "group": "",
      "name": "tsutils",
      "version": "3.21.0",
      "description": "utilities for working with typescript's AST",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/tsutils@3.21.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/ajafff/tsutils"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/tsutils@3.21.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tslint-consistent-codestyle/node_modules/@fimbul/bifrost/node_modules/tsutils/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tslint-consistent-codestyle/node_modules/@fimbul/bifrost/node_modules/tsutils/package.json"
              }
            ],
            "concludedValue": "node_modules/tslint-consistent-codestyle/node_modules/@fimbul/bifrost/node_modules/tsutils/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Klaus Meinhardt"
        }
      ],
      "group": "@fimbul",
      "name": "ymir",
      "version": "0.21.0",
      "description": "Core library for the Fimbullinter project",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0",
            "url": "https://opensource.org/licenses/Apache-2.0"
          }
        }
      ],
      "purl": "pkg:npm/%40fimbul/ymir@0.21.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/fimbullinter/wotan#readme"
        },
        {
          "type": "vcs",
          "url": "https://github.com/fimbullinter/wotan"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@fimbul/ymir@0.21.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tslint-consistent-codestyle/node_modules/@fimbul/bifrost/node_modules/@fimbul/ymir/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tslint-consistent-codestyle/node_modules/@fimbul/bifrost/node_modules/@fimbul/ymir/package.json"
              }
            ],
            "concludedValue": "node_modules/tslint-consistent-codestyle/node_modules/@fimbul/bifrost/node_modules/@fimbul/ymir/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "tslint",
      "version": "5.20.1",
      "description": "An extensible static analysis linter for the TypeScript language",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0",
            "url": "https://opensource.org/licenses/Apache-2.0"
          }
        }
      ],
      "purl": "pkg:npm/tslint@5.20.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://palantir.github.io/tslint"
        },
        {
          "type": "vcs",
          "url": "https://github.com/palantir/tslint.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/tslint@5.20.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tslint/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tslint/package.json"
              }
            ],
            "concludedValue": "node_modules/tslint/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "GitHub Inc."
        }
      ],
      "group": "",
      "name": "semver",
      "version": "5.7.2",
      "description": "The semantic version parser used by npm.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/semver@5.7.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/npm/node-semver.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/semver@5.7.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tslint/node_modules/semver/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/semver-diff/node_modules/semver/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/package-json/node_modules/semver/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/normalize-package-data/node_modules/semver/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/normalize-package-data/node_modules/semver/package.json"
              }
            ],
            "concludedValue": "node_modules/normalize-package-data/node_modules/semver/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me)"
        }
      ],
      "group": "",
      "name": "minimatch",
      "version": "3.1.5",
      "description": "a glob matcher in javascript",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/minimatch@3.1.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/minimatch.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/minimatch@3.1.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tslint/node_modules/minimatch/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/rimraf/node_modules/minimatch/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/del/node_modules/minimatch/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/del/node_modules/minimatch/package.json"
              }
            ],
            "concludedValue": "node_modules/del/node_modules/minimatch/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "glob",
      "version": "7.2.3",
      "description": "a little globber",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/glob@7.2.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/node-glob.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/glob@7.2.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tslint/node_modules/glob/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/rimraf/node_modules/glob/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/del/node_modules/glob/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/del/node_modules/glob/package.json"
              }
            ],
            "concludedValue": "node_modules/del/node_modules/glob/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Julian Gruber <mail@juliangruber.com> (http://juliangruber.com)"
        }
      ],
      "group": "",
      "name": "brace-expansion",
      "version": "1.1.14",
      "description": "Brace expansion as known from sh/bash",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/brace-expansion@1.1.14",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/juliangruber/brace-expansion"
        },
        {
          "type": "vcs",
          "url": "git://github.com/juliangruber/brace-expansion.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/brace-expansion@1.1.14",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tslint/node_modules/brace-expansion/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/rimraf/node_modules/brace-expansion/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/del/node_modules/brace-expansion/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/del/node_modules/brace-expansion/package.json"
              }
            ],
            "concludedValue": "node_modules/del/node_modules/brace-expansion/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Microsoft Corp."
        }
      ],
      "group": "",
      "name": "tslib",
      "version": "1.14.1",
      "description": "Runtime library for TypeScript helper functions",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "0BSD",
            "url": "https://opensource.org/licenses/0BSD"
          }
        }
      ],
      "purl": "pkg:npm/tslib@1.14.1",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://www.typescriptlang.org/"
        },
        {
          "type": "vcs",
          "url": "https://github.com/Microsoft/tslib.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/tslib@1.14.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tslib/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tslib/package.json"
              }
            ],
            "concludedValue": "node_modules/tslib/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "trim-newlines",
      "version": "1.0.0",
      "description": "Trim newlines from the start and/or end of a string",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/trim-newlines@1.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/trim-newlines@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/trim-newlines/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/trim-newlines/package.json"
              }
            ],
            "concludedValue": "node_modules/trim-newlines/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sebastian Mayr <npm@smayr.name>"
        }
      ],
      "group": "",
      "name": "tr46",
      "version": "0.0.3",
      "description": "An implementation of the Unicode TR46 spec",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/tr46@0.0.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/Sebmaster/tr46.js#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/Sebmaster/tr46.js.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/tr46@0.0.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tr46/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tr46/package.json"
              }
            ],
            "concludedValue": "node_modules/tr46/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jeremy Stashewsky <jstash@gmail.com>"
        }
      ],
      "group": "",
      "name": "tough-cookie",
      "version": "2.5.0",
      "description": "RFC6265 Cookies and Cookie Jar for node.js",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-3-Clause",
            "url": "https://opensource.org/licenses/BSD-3-Clause"
          }
        }
      ],
      "purl": "pkg:npm/tough-cookie@2.5.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/salesforce/tough-cookie"
        },
        {
          "type": "vcs",
          "url": "git://github.com/salesforce/tough-cookie.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/tough-cookie@2.5.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tough-cookie/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tough-cookie/package.json"
              }
            ],
            "concludedValue": "node_modules/tough-cookie/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jon Schlinkert (https://github.com/jonschlinkert)"
        }
      ],
      "group": "",
      "name": "to-regex-range",
      "version": "5.0.1",
      "description": "Pass two numbers, get a regex-compatible source string for matching ranges. Validated against more than 2.78 million test assertions.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/to-regex-range@5.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/micromatch/to-regex-range"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/to-regex-range@5.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/to-regex-range/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/to-regex-range/package.json"
              }
            ],
            "concludedValue": "node_modules/to-regex-range/package.json"
          }
        ]
      },
      "tags": [
        "test"
      ]
    },
    {
      "authors": [
        {
          "name": "Vsevolod Strukchinsky <floatdrop@gmail.com>"
        }
      ],
      "group": "",
      "name": "timed-out",
      "version": "4.0.1",
      "description": "Emit `ETIMEDOUT` or `ESOCKETTIMEDOUT` when ClientRequest is hanged",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/timed-out@4.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/timed-out@4.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/timed-out/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/timed-out/package.json"
              }
            ],
            "concludedValue": "node_modules/timed-out/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "time-zone",
      "version": "1.0.0",
      "description": "Pretty time zone: `+2` or `-9:30`",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/time-zone@1.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/time-zone@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/time-zone/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/time-zone/package.json"
              }
            ],
            "concludedValue": "node_modules/time-zone/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "term-size",
      "version": "1.2.0",
      "description": "Reliably get the terminal window size (columns & rows)",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/term-size@1.2.0",
      "type": "library",
      "bom-ref": "pkg:npm/term-size@1.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/term-size/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/term-size/package.json"
              }
            ],
            "concludedValue": "node_modules/term-size/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "tempy",
      "version": "0.2.1",
      "description": "Get a random temporary file or directory path",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/tempy@0.2.1",
      "type": "library",
      "bom-ref": "pkg:npm/tempy@0.2.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tempy/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tempy/package.json"
              }
            ],
            "concludedValue": "node_modules/tempy/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "temp-dir",
      "version": "1.0.0",
      "description": "Get the real path of the system temp directory",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/temp-dir@1.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/temp-dir@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tempy/node_modules/temp-dir/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tempy/node_modules/temp-dir/package.json"
              }
            ],
            "concludedValue": "node_modules/tempy/node_modules/temp-dir/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "temp-dir",
      "version": "3.0.0",
      "description": "Get the real path of the system temp directory",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/temp-dir@3.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/temp-dir@3.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/temp-dir/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/temp-dir/package.json"
              }
            ],
            "concludedValue": "node_modules/temp-dir/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter"
        }
      ],
      "group": "",
      "name": "tar",
      "version": "7.5.14",
      "description": "tar for node",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BlueOak-1.0.0",
            "url": "https://opensource.org/licenses/BlueOak-1.0.0"
          }
        }
      ],
      "purl": "pkg:npm/tar@7.5.14",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/node-tar.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/tar@7.5.14",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/tar/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/tar/package.json"
              }
            ],
            "concludedValue": "node_modules/tar/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Joris van der Wel <joris@jorisvanderwel.com>"
        }
      ],
      "group": "",
      "name": "symbol-tree",
      "version": "3.2.4",
      "description": "Turn any collection of objects into its own efficient tree or linked list using Symbol",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/symbol-tree@3.2.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jsdom/js-symbol-tree#symbol-tree"
        },
        {
          "type": "vcs",
          "url": "https://github.com/jsdom/js-symbol-tree.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/symbol-tree@3.2.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/symbol-tree/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/symbol-tree/package.json"
              }
            ],
            "concludedValue": "node_modules/symbol-tree/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jordan Harband <ljharb@gmail.com>"
        }
      ],
      "group": "",
      "name": "supports-preserve-symlinks-flag",
      "version": "1.0.0",
      "description": "Determine if the current node version supports the `--preserve-symlinks` flag.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/supports-preserve-symlinks-flag@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/inspect-js/node-supports-preserve-symlinks-flag#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/inspect-js/node-supports-preserve-symlinks-flag.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/supports-preserve-symlinks-flag@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/supports-preserve-symlinks-flag/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/supports-preserve-symlinks-flag/package.json"
              }
            ],
            "concludedValue": "node_modules/supports-preserve-symlinks-flag/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "supports-color",
      "version": "5.5.0",
      "description": "Detect whether a terminal supports color",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/supports-color@5.5.0",
      "type": "library",
      "bom-ref": "pkg:npm/supports-color@5.5.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/supports-color/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/supports-color/package.json"
              }
            ],
            "concludedValue": "node_modules/supports-color/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Vadim Demedes <vdemedes@gmail.com> (github.com/vadimdemedes)"
        }
      ],
      "group": "",
      "name": "supertap",
      "version": "3.0.1",
      "description": "Generate TAP output",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/supertap@3.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/supertap@3.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/supertap/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/supertap/package.json"
              }
            ],
            "concludedValue": "node_modules/supertap/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "strip-json-comments",
      "version": "2.0.1",
      "description": "Strip comments from JSON. Lets you use comments in your JSON files!",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/strip-json-comments@2.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/strip-json-comments@2.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/strip-json-comments/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/strip-json-comments/package.json"
              }
            ],
            "concludedValue": "node_modules/strip-json-comments/package.json"
          }
        ]
      },
      "tags": [
        "json"
      ]
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (http://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "strip-indent",
      "version": "1.0.1",
      "description": "Strip leading whitespace from every line in a string",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/strip-indent@1.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/strip-indent@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/strip-indent/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/strip-indent/package.json"
              }
            ],
            "concludedValue": "node_modules/strip-indent/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "strip-eof",
      "version": "1.0.0",
      "description": "Strip the End-Of-File (EOF) character from a string/buffer",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/strip-eof@1.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/strip-eof@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/strip-eof/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/strip-eof/package.json"
              }
            ],
            "concludedValue": "node_modules/strip-eof/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "strip-bom",
      "version": "2.0.0",
      "description": "Strip UTF-8 byte order mark (BOM) from a string/buffer",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/strip-bom@2.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/strip-bom@2.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/strip-bom/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/strip-bom/package.json"
              }
            ],
            "concludedValue": "node_modules/strip-bom/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "strip-ansi",
      "version": "7.2.0",
      "description": "Strip ANSI escape codes from a string",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/strip-ansi@7.2.0",
      "type": "library",
      "bom-ref": "pkg:npm/strip-ansi@7.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/strip-ansi/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/strip-ansi/package.json"
              }
            ],
            "concludedValue": "node_modules/strip-ansi/package.json"
          }
        ]
      },
      "tags": [
        "escape"
      ]
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "string-width",
      "version": "7.2.0",
      "description": "Get the visual width of a string - the number of columns required to display it",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/string-width@7.2.0",
      "type": "library",
      "bom-ref": "pkg:npm/string-width@7.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/string-width/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/string-width/package.json"
              }
            ],
            "concludedValue": "node_modules/string-width/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Talmage <james@talmage.io> (github.com/jamestalmage)"
        }
      ],
      "group": "",
      "name": "stack-utils",
      "version": "2.0.6",
      "description": "Captures and cleans stack traces",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/stack-utils@2.0.6",
      "type": "library",
      "bom-ref": "pkg:npm/stack-utils@2.0.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/stack-utils/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/stack-utils/package.json"
              }
            ],
            "concludedValue": "node_modules/stack-utils/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "escape-string-regexp",
      "version": "2.0.0",
      "description": "Escape RegExp special characters",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/escape-string-regexp@2.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/escape-string-regexp@2.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/stack-utils/node_modules/escape-string-regexp/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/stack-utils/node_modules/escape-string-regexp/package.json"
              }
            ],
            "concludedValue": "node_modules/stack-utils/node_modules/escape-string-regexp/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Joyent"
        },
        {
          "name": " Inc"
        }
      ],
      "group": "",
      "name": "sshpk",
      "version": "1.18.0",
      "description": "A library for finding and using SSH public keys",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/sshpk@1.18.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/arekinath/node-sshpk#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/joyent/node-sshpk.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/sshpk@1.18.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/sshpk/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/sshpk/package.json"
              }
            ],
            "concludedValue": "node_modules/sshpk/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Alexandru Marasteanu <hello@alexei.ro> (http://alexei.ro/)"
        }
      ],
      "group": "",
      "name": "sprintf-js",
      "version": "1.0.3",
      "description": "JavaScript sprintf implementation",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-3-Clause",
            "url": "https://opensource.org/licenses/BSD-3-Clause"
          }
        }
      ],
      "purl": "pkg:npm/sprintf-js@1.0.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/alexei/sprintf.js.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/sprintf-js@1.0.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/sprintf-js/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/sprintf-js/package.json"
              }
            ],
            "concludedValue": "node_modules/sprintf-js/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Shinnosuke Watanabe (https://github.com/shinnn)"
        }
      ],
      "group": "",
      "name": "spdx-license-ids",
      "version": "3.0.23",
      "description": "A list of SPDX license identifiers",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "CC0-1.0",
            "url": "https://opensource.org/licenses/CC0-1.0"
          }
        }
      ],
      "purl": "pkg:npm/spdx-license-ids@3.0.23",
      "type": "library",
      "bom-ref": "pkg:npm/spdx-license-ids@3.0.23",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/spdx-license-ids/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/spdx-license-ids/package.json"
              }
            ],
            "concludedValue": "node_modules/spdx-license-ids/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Kyle E. Mitchell <kyle@kemitchell.com> (https://kemitchell.com)"
        }
      ],
      "group": "",
      "name": "spdx-expression-parse",
      "version": "3.0.1",
      "description": "parse SPDX license expressions",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/spdx-expression-parse@3.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/spdx-expression-parse@3.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/spdx-expression-parse/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/spdx-expression-parse/package.json"
              }
            ],
            "concludedValue": "node_modules/spdx-expression-parse/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "The Linux Foundation"
        }
      ],
      "group": "",
      "name": "spdx-exceptions",
      "version": "2.5.0",
      "description": "list of SPDX standard license exceptions",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "CC-BY-3.0",
            "url": "https://opensource.org/licenses/CC-BY-3.0"
          }
        }
      ],
      "purl": "pkg:npm/spdx-exceptions@2.5.0",
      "type": "library",
      "bom-ref": "pkg:npm/spdx-exceptions@2.5.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/spdx-exceptions/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/spdx-exceptions/package.json"
              }
            ],
            "concludedValue": "node_modules/spdx-exceptions/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "spdx-correct",
      "version": "3.2.0",
      "description": "correct invalid SPDX expressions",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0",
            "url": "https://opensource.org/licenses/Apache-2.0"
          }
        }
      ],
      "purl": "pkg:npm/spdx-correct@3.2.0",
      "type": "library",
      "bom-ref": "pkg:npm/spdx-correct@3.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/spdx-correct/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/spdx-correct/package.json"
              }
            ],
            "concludedValue": "node_modules/spdx-correct/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Nick Fitzgerald <nfitzgerald@mozilla.com>"
        }
      ],
      "group": "",
      "name": "source-map",
      "version": "0.6.1",
      "description": "Generates and consumes source maps",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-3-Clause",
            "url": "https://opensource.org/licenses/BSD-3-Clause"
          }
        }
      ],
      "purl": "pkg:npm/source-map@0.6.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mozilla/source-map"
        },
        {
          "type": "vcs",
          "url": "http://github.com/mozilla/source-map.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/source-map@0.6.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/source-map/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/source-map/package.json"
              }
            ],
            "concludedValue": "node_modules/source-map/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "slice-ansi",
      "version": "5.0.0",
      "description": "Slice a string with ANSI escape codes",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/slice-ansi@5.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/slice-ansi@5.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/slice-ansi/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/slice-ansi/package.json"
              }
            ],
            "concludedValue": "node_modules/slice-ansi/package.json"
          }
        ]
      },
      "tags": [
        "escape"
      ]
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "slash",
      "version": "5.1.0",
      "description": "Convert Windows backslash paths to slash paths",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/slash@5.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/slash@5.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/slash/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/slash/package.json"
              }
            ],
            "concludedValue": "node_modules/slash/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Ben Coe <ben@npmjs.com>"
        }
      ],
      "group": "",
      "name": "signal-exit",
      "version": "4.1.0",
      "description": "when you want to fire an event no matter how a process exits.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/signal-exit@4.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/tapjs/signal-exit.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/signal-exit@4.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/signal-exit/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/signal-exit/package.json"
              }
            ],
            "concludedValue": "node_modules/signal-exit/package.json"
          }
        ]
      },
      "tags": [
        "event"
      ]
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "shebang-regex",
      "version": "3.0.0",
      "description": "Regular expression for matching a shebang line",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/shebang-regex@3.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/shebang-regex@3.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/shebang-regex/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/shebang-regex/package.json"
              }
            ],
            "concludedValue": "node_modules/shebang-regex/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Kevin Mårtensson <kevinmartensson@gmail.com> (github.com/kevva)"
        }
      ],
      "group": "",
      "name": "shebang-command",
      "version": "2.0.0",
      "description": "Get the command from a shebang",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/shebang-command@2.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/shebang-command@2.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/shebang-command/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/shebang-command/package.json"
              }
            ],
            "concludedValue": "node_modules/shebang-command/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "serialize-error",
      "version": "7.0.1",
      "description": "Serialize/deserialize an error into a plain object",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/serialize-error@7.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/serialize-error@7.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/serialize-error/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/serialize-error/package.json"
              }
            ],
            "concludedValue": "node_modules/serialize-error/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (http://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "semver-diff",
      "version": "2.1.0",
      "description": "Get the diff type of two semver versions: 0.0.1 0.0.2 → patch",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/semver-diff@2.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/semver-diff@2.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/semver-diff/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/semver-diff/package.json"
              }
            ],
            "concludedValue": "node_modules/semver-diff/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "GitHub Inc."
        }
      ],
      "group": "",
      "name": "semver",
      "version": "7.7.4",
      "description": "The semantic version parser used by npm.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/semver@7.7.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git+https://github.com/npm/node-semver.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/semver@7.7.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/semver/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/semver/package.json"
              }
            ],
            "concludedValue": "node_modules/semver/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "sax",
      "version": "1.6.0",
      "description": "An evented streaming XML parser in JavaScript",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BlueOak-1.0.0",
            "url": "https://opensource.org/licenses/BlueOak-1.0.0"
          }
        }
      ],
      "purl": "pkg:npm/sax@1.6.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git+ssh://git@github.com/isaacs/sax-js.git"
        }
      ],
      "type": "framework",
      "bom-ref": "pkg:npm/sax@1.6.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/sax/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/sax/package.json"
              }
            ],
            "concludedValue": "node_modules/sax/package.json"
          }
        ]
      },
      "tags": [
        "framework",
        "xml"
      ]
    },
    {
      "authors": [
        {
          "name": "Nikita Skovoroda <chalkerx@gmail.com> (https://github.com/ChALkeR)"
        }
      ],
      "group": "",
      "name": "safer-buffer",
      "version": "2.1.2",
      "description": "Modern Buffer API polyfill without footguns",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/safer-buffer@2.1.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git+https://github.com/ChALkeR/safer-buffer.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/safer-buffer@2.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/safer-buffer/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/safer-buffer/package.json"
              }
            ],
            "concludedValue": "node_modules/safer-buffer/package.json"
          }
        ]
      },
      "tags": [
        "api"
      ]
    },
    {
      "authors": [
        {
          "name": "Feross Aboukhadijeh <feross@feross.org> (https://feross.org)"
        }
      ],
      "group": "",
      "name": "safe-buffer",
      "version": "5.2.1",
      "description": "Safer Node.js Buffer API",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/safe-buffer@5.2.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/feross/safe-buffer"
        },
        {
          "type": "vcs",
          "url": "git://github.com/feross/safe-buffer.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/safe-buffer@5.2.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/safe-buffer/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/safe-buffer/package.json"
              }
            ],
            "concludedValue": "node_modules/safe-buffer/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Feross Aboukhadijeh <feross@feross.org> (https://feross.org)"
        }
      ],
      "group": "",
      "name": "run-parallel",
      "version": "1.2.0",
      "description": "Run an array of functions in parallel",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/run-parallel@1.2.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/feross/run-parallel"
        },
        {
          "type": "vcs",
          "url": "git://github.com/feross/run-parallel.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/run-parallel@1.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/run-parallel/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/run-parallel/package.json"
              }
            ],
            "concludedValue": "node_modules/run-parallel/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "rimraf",
      "version": "2.7.1",
      "description": "A deep deletion module for node (like `rm -rf`)",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/rimraf@2.7.1",
      "type": "library",
      "bom-ref": "pkg:npm/rimraf@2.7.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/rimraf/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/rimraf/package.json"
              }
            ],
            "concludedValue": "node_modules/rimraf/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Matteo Collina <hello@matteocollina.com>"
        }
      ],
      "group": "",
      "name": "reusify",
      "version": "1.1.0",
      "description": "Reuse objects and functions with style",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/reusify@1.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mcollina/reusify#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/mcollina/reusify.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/reusify@1.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/reusify/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/reusify/package.json"
              }
            ],
            "concludedValue": "node_modules/reusify/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "resolve-from",
      "version": "5.0.0",
      "description": "Resolve the path of a module like `require.resolve()` but from a given path",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/resolve-from@5.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/resolve-from@5.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/resolve-from/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/resolve-from/package.json"
              }
            ],
            "concludedValue": "node_modules/resolve-from/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "resolve-cwd",
      "version": "3.0.0",
      "description": "Resolve the path of a module like `require.resolve()` but from the current working directory",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/resolve-cwd@3.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/resolve-cwd@3.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/resolve-cwd/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/resolve-cwd/package.json"
              }
            ],
            "concludedValue": "node_modules/resolve-cwd/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "resolve",
      "version": "1.22.12",
      "description": "resolve like require.resolve() on behalf of files asynchronously and synchronously",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/resolve@1.22.12",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "ssh://github.com/browserify/resolve.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/resolve@1.22.12",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/resolve/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/resolve/package.json"
              }
            ],
            "concludedValue": "node_modules/resolve/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "mylib",
      "version": "0.0.0",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/mylib@0.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/mylib@0.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/resolve/test/resolver/nested_symlinks/mylib/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/resolve/test/resolver/nested_symlinks/mylib/package.json"
              }
            ],
            "concludedValue": "node_modules/resolve/test/resolver/nested_symlinks/mylib/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "ljharb-monorepo-symlink-test",
      "version": "0.0.0",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/ljharb-monorepo-symlink-test@0.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/ljharb-monorepo-symlink-test@0.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/resolve/test/resolver/multirepo/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/resolve/test/resolver/multirepo/package.json"
              }
            ],
            "concludedValue": "node_modules/resolve/test/resolver/multirepo/package.json"
          }
        ]
      }
    },
    {
      "group": "@my-scope",
      "name": "package-b",
      "version": "0.0.0",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40my-scope/package-b@0.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/@my-scope/package-b@0.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/resolve/test/resolver/multirepo/packages/package-b/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/resolve/test/resolver/multirepo/packages/package-b/package.json"
              }
            ],
            "concludedValue": "node_modules/resolve/test/resolver/multirepo/packages/package-b/package.json"
          }
        ]
      }
    },
    {
      "group": "@my-scope",
      "name": "package-a",
      "version": "0.0.0",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40my-scope/package-a@0.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/@my-scope/package-a@0.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/resolve/test/resolver/multirepo/packages/package-a/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/resolve/test/resolver/multirepo/packages/package-a/package.json"
              }
            ],
            "concludedValue": "node_modules/resolve/test/resolver/multirepo/packages/package-a/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "invalid_main",
      "version": "",
      "scope": "optional",
      "purl": "pkg:npm/invalid_main",
      "type": "library",
      "bom-ref": "pkg:npm/invalid_main",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/resolve/test/resolver/invalid_main/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/resolve/test/resolver/invalid_main/package.json"
              }
            ],
            "concludedValue": "node_modules/resolve/test/resolver/invalid_main/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "false_main",
      "version": "",
      "scope": "optional",
      "purl": "pkg:npm/false_main",
      "type": "library",
      "bom-ref": "pkg:npm/false_main",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/resolve/test/resolver/false_main/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/resolve/test/resolver/false_main/package.json"
              }
            ],
            "concludedValue": "node_modules/resolve/test/resolver/false_main/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "browser_field",
      "version": "",
      "scope": "optional",
      "purl": "pkg:npm/browser_field",
      "type": "library",
      "bom-ref": "pkg:npm/browser_field",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/resolve/test/resolver/browser_field/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/resolve/test/resolver/browser_field/package.json"
              }
            ],
            "concludedValue": "node_modules/resolve/test/resolver/browser_field/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "baz",
      "version": "",
      "scope": "optional",
      "purl": "pkg:npm/baz",
      "type": "library",
      "bom-ref": "pkg:npm/baz",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/resolve/test/resolver/baz/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/resolve/test/resolver/baz/package.json"
              }
            ],
            "concludedValue": "node_modules/resolve/test/resolver/baz/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Troy Goode <troygoode@gmail.com> (http://github.com/troygoode/)"
        }
      ],
      "group": "",
      "name": "require-directory",
      "version": "2.1.1",
      "description": "Recursively iterates over specified directory, require()'ing each file, and returning a nested hash structure containing those modules.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/require-directory@2.1.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/troygoode/node-require-directory/"
        },
        {
          "type": "vcs",
          "url": "git://github.com/troygoode/node-require-directory.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/require-directory@2.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/require-directory/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/require-directory/package.json"
              }
            ],
            "concludedValue": "node_modules/require-directory/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mikeal Rogers <mikeal.rogers@gmail.com>"
        }
      ],
      "group": "",
      "name": "request",
      "version": "2.88.2",
      "description": "Simplified HTTP request client.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0",
            "url": "https://opensource.org/licenses/Apache-2.0"
          }
        }
      ],
      "purl": "pkg:npm/request@2.88.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/request/request.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/request@2.88.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/request/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/request/package.json"
              }
            ],
            "concludedValue": "node_modules/request/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "repeating",
      "version": "2.0.1",
      "description": "Repeat a string - fast",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/repeating@2.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/repeating@2.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/repeating/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/repeating/package.json"
              }
            ],
            "concludedValue": "node_modules/repeating/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "registry-url",
      "version": "3.1.0",
      "description": "Get the set npm registry URL",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/registry-url@3.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/registry-url@3.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/registry-url/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/registry-url/package.json"
              }
            ],
            "concludedValue": "node_modules/registry-url/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Espen Hovlandsdal <espen@hovlandsdal.com>"
        }
      ],
      "group": "",
      "name": "registry-auth-token",
      "version": "3.4.0",
      "description": "Get the auth token set for an npm registry (if any)",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/registry-auth-token@3.4.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/rexxars/registry-auth-token#readme"
        },
        {
          "type": "vcs",
          "url": "git+ssh://git@github.com/rexxars/registry-auth-token.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/registry-auth-token@3.4.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/registry-auth-token/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/registry-auth-token/package.json"
              }
            ],
            "concludedValue": "node_modules/registry-auth-token/package.json"
          }
        ]
      },
      "tags": [
        "auth",
        "token"
      ]
    },
    {
      "authors": [
        {
          "name": "Ron Buckton <ron.buckton@microsoft.com> (http://github.com/rbuckton)"
        }
      ],
      "group": "",
      "name": "reflect-metadata",
      "version": "0.1.14",
      "description": "Polyfill for Metadata Reflection API",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0",
            "url": "https://opensource.org/licenses/Apache-2.0"
          }
        }
      ],
      "purl": "pkg:npm/reflect-metadata@0.1.14",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://rbuckton.github.io/reflect-metadata"
        },
        {
          "type": "vcs",
          "url": "https://github.com/rbuckton/reflect-metadata.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/reflect-metadata@0.1.14",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/reflect-metadata/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/reflect-metadata/package.json"
              }
            ],
            "concludedValue": "node_modules/reflect-metadata/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "redent",
      "version": "1.0.0",
      "description": "Strip redundant indentation and indent the string",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/redent@1.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/redent@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/redent/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/redent/package.json"
              }
            ],
            "concludedValue": "node_modules/redent/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "indent-string",
      "version": "2.1.0",
      "description": "Indent each line in a string",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/indent-string@2.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/indent-string@2.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/redent/node_modules/indent-string/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/redent/node_modules/indent-string/package.json"
              }
            ],
            "concludedValue": "node_modules/redent/node_modules/indent-string/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "read-pkg-up",
      "version": "1.0.1",
      "description": "Read the closest package.json file",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/read-pkg-up@1.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/read-pkg-up@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/read-pkg-up/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/read-pkg-up/package.json"
              }
            ],
            "concludedValue": "node_modules/read-pkg-up/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "read-pkg",
      "version": "1.1.0",
      "description": "Read a package.json file",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/read-pkg@1.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/read-pkg@1.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/read-pkg/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/read-pkg/package.json"
              }
            ],
            "concludedValue": "node_modules/read-pkg/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "pify",
      "version": "2.3.0",
      "description": "Promisify a callback-style function",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/pify@2.3.0",
      "type": "library",
      "bom-ref": "pkg:npm/pify@2.3.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/read-pkg/node_modules/pify/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/del/node_modules/globby/node_modules/pify/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/del/node_modules/globby/node_modules/pify/package.json"
              }
            ],
            "concludedValue": "node_modules/del/node_modules/globby/node_modules/pify/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "path-type",
      "version": "1.1.0",
      "description": "Check if a path is a file, directory, or symlink",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/path-type@1.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/path-type@1.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/read-pkg/node_modules/path-type/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/read-pkg/node_modules/path-type/package.json"
              }
            ],
            "concludedValue": "node_modules/read-pkg/node_modules/path-type/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "load-json-file",
      "version": "1.1.0",
      "description": "Read and parse a JSON file",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/load-json-file@1.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/load-json-file@1.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/read-pkg/node_modules/load-json-file/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/read-pkg/node_modules/load-json-file/package.json"
              }
            ],
            "concludedValue": "node_modules/read-pkg/node_modules/load-json-file/package.json"
          }
        ]
      },
      "tags": [
        "json",
        "parse"
      ]
    },
    {
      "authors": [
        {
          "name": "Dominic Tarr <dominic.tarr@gmail.com> (dominictarr.com)"
        }
      ],
      "group": "",
      "name": "rc",
      "version": "1.2.8",
      "description": "hardwired configuration loader",
      "scope": "optional",
      "licenses": [
        {
          "expression": "(BSD-2-Clause OR MIT OR Apache-2.0)"
        }
      ],
      "purl": "pkg:npm/rc@1.2.8",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/dominictarr/rc.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/rc@1.2.8",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/rc/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/rc/package.json"
              }
            ],
            "concludedValue": "node_modules/rc/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Feross Aboukhadijeh <feross@feross.org> (https://feross.org)"
        }
      ],
      "group": "",
      "name": "queue-microtask",
      "version": "1.2.3",
      "description": "fast, tiny `queueMicrotask` shim for modern engines",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/queue-microtask@1.2.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/feross/queue-microtask"
        },
        {
          "type": "vcs",
          "url": "git://github.com/feross/queue-microtask.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/queue-microtask@1.2.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/queue-microtask/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/queue-microtask/package.json"
              }
            ],
            "concludedValue": "node_modules/queue-microtask/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "qs",
      "version": "6.5.5",
      "description": "A querystring parser that supports nesting and arrays, with a depth limit",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-3-Clause",
            "url": "https://opensource.org/licenses/BSD-3-Clause"
          }
        }
      ],
      "purl": "pkg:npm/qs@6.5.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/ljharb/qs"
        },
        {
          "type": "vcs",
          "url": "https://github.com/ljharb/qs.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/qs@6.5.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/qs/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/qs/package.json"
              }
            ],
            "concludedValue": "node_modules/qs/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mathias Bynens (https://mathiasbynens.be/)"
        }
      ],
      "group": "",
      "name": "punycode",
      "version": "2.3.1",
      "description": "A robust Punycode converter that fully complies to RFC 3492 and RFC 5891, and works on nearly all JavaScript platforms.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/punycode@2.3.1",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://mths.be/punycode"
        },
        {
          "type": "vcs",
          "url": "https://github.com/mathiasbynens/punycode.js.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/punycode@2.3.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/punycode/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/punycode/package.json"
              }
            ],
            "concludedValue": "node_modules/punycode/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Lupo Montero <lupomontero@gmail.com> (https://lupomontero.com/)"
        }
      ],
      "group": "",
      "name": "psl",
      "version": "1.15.0",
      "description": "Domain name parser based on the Public Suffix List",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/psl@1.15.0",
      "type": "library",
      "bom-ref": "pkg:npm/psl@1.15.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/psl/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/psl/package.json"
              }
            ],
            "concludedValue": "node_modules/psl/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "pseudomap",
      "version": "1.0.2",
      "description": "A thing that is a lot like ES6 `Map`, but without iterators, for use in environments where `for..of` syntax and `Map` are not available.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/pseudomap@1.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/pseudomap#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/isaacs/pseudomap.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/pseudomap@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/pseudomap/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/pseudomap/package.json"
              }
            ],
            "concludedValue": "node_modules/pseudomap/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "pretty-ms",
      "version": "9.3.0",
      "description": "Convert milliseconds to a human readable string: `1337000000` → `15d 11h 23m 20s`",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/pretty-ms@9.3.0",
      "type": "library",
      "bom-ref": "pkg:npm/pretty-ms@9.3.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/pretty-ms/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/pretty-ms/package.json"
              }
            ],
            "concludedValue": "node_modules/pretty-ms/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "prepend-http",
      "version": "1.0.4",
      "description": "Prepend `http://` to humanized URLs like todomvc.com and localhost",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/prepend-http@1.0.4",
      "type": "library",
      "bom-ref": "pkg:npm/prepend-http@1.0.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/prepend-http/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/prepend-http/package.json"
              }
            ],
            "concludedValue": "node_modules/prepend-http/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "George Zahariev <z@georgezahariev.com>"
        }
      ],
      "group": "",
      "name": "prelude-ls",
      "version": "1.1.2",
      "description": "prelude.ls is a functionally oriented utility library. It is powerful and flexible. Almost all of its functions are curried. It is written in, and is the recommended base library for, LiveScript.",
      "scope": "optional",
      "purl": "pkg:npm/prelude-ls@1.1.2",
      "externalReferences": [
        {
          "type": "website",
          "url": "http://preludels.com"
        },
        {
          "type": "vcs",
          "url": "git://github.com/gkz/prelude-ls.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/prelude-ls@1.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/prelude-ls/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/prelude-ls/package.json"
              }
            ],
            "concludedValue": "node_modules/prelude-ls/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "plur",
      "version": "5.1.0",
      "description": "Pluralize a word",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/plur@5.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/plur@5.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/plur/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/plur/package.json"
              }
            ],
            "concludedValue": "node_modules/plur/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Vsevolod Strukchinsky <floatdrop@gmail.com> (github.com/floatdrop)"
        }
      ],
      "group": "",
      "name": "pinkie-promise",
      "version": "2.0.1",
      "description": "ES2015 Promise ponyfill",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/pinkie-promise@2.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/pinkie-promise@2.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/pinkie-promise/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/pinkie-promise/package.json"
              }
            ],
            "concludedValue": "node_modules/pinkie-promise/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Vsevolod Strukchinsky <floatdrop@gmail.com> (github.com/floatdrop)"
        }
      ],
      "group": "",
      "name": "pinkie",
      "version": "2.0.4",
      "description": "Itty bitty little widdle twinkie pinkie ES2015 Promise implementation",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/pinkie@2.0.4",
      "type": "library",
      "bom-ref": "pkg:npm/pinkie@2.0.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/pinkie/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/pinkie/package.json"
              }
            ],
            "concludedValue": "node_modules/pinkie/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "pify",
      "version": "3.0.0",
      "description": "Promisify a callback-style function",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/pify@3.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/pify@3.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/pify/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/pify/package.json"
              }
            ],
            "concludedValue": "node_modules/pify/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jon Schlinkert (https://github.com/jonschlinkert)"
        }
      ],
      "group": "",
      "name": "picomatch",
      "version": "4.0.4",
      "description": "Blazing fast and accurate glob matcher written in JavaScript, with no dependencies and full support for standard and extended Bash glob features, including braces, extglobs, POSIX brackets, and regular expressions.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/picomatch@4.0.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/micromatch/picomatch"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/picomatch@4.0.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/picomatch/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/picomatch/package.json"
              }
            ],
            "concludedValue": "node_modules/picomatch/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Alexey Raspopov"
        }
      ],
      "group": "",
      "name": "picocolors",
      "version": "1.1.1",
      "description": "The tiniest and the fastest library for terminal output formatting with ANSI colors",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/picocolors@1.1.1",
      "type": "library",
      "bom-ref": "pkg:npm/picocolors@1.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/picocolors/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/picocolors/package.json"
              }
            ],
            "concludedValue": "node_modules/picocolors/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Braveg1rl <braveg1rl@outlook.com>"
        }
      ],
      "group": "",
      "name": "performance-now",
      "version": "2.1.0",
      "description": "Implements performance.now (based on process.hrtime).",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/performance-now@2.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/braveg1rl/performance-now"
        },
        {
          "type": "vcs",
          "url": "git://github.com/braveg1rl/performance-now.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/performance-now@2.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/performance-now/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/performance-now/package.json"
              }
            ],
            "concludedValue": "node_modules/performance-now/package.json"
          }
        ]
      },
      "tags": [
        "performance"
      ]
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "path-type",
      "version": "6.0.0",
      "description": "Check if a path is a file, directory, or symlink",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/path-type@6.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/path-type@6.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/path-type/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/path-type/package.json"
              }
            ],
            "concludedValue": "node_modules/path-type/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (https://blog.izs.me)"
        }
      ],
      "group": "",
      "name": "path-scurry",
      "version": "1.11.1",
      "description": "walk paths fast and efficiently",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BlueOak-1.0.0",
            "url": "https://opensource.org/licenses/BlueOak-1.0.0"
          }
        }
      ],
      "purl": "pkg:npm/path-scurry@1.11.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git+https://github.com/isaacs/path-scurry"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/path-scurry@1.11.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/path-scurry/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/path-scurry/package.json"
              }
            ],
            "concludedValue": "node_modules/path-scurry/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Javier Blanco <http://jbgutierrez.info>"
        }
      ],
      "group": "",
      "name": "path-parse",
      "version": "1.0.7",
      "description": "Node.js path.parse() ponyfill",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/path-parse@1.0.7",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jbgutierrez/path-parse#readme"
        },
        {
          "type": "vcs",
          "url": "https://github.com/jbgutierrez/path-parse.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/path-parse@1.0.7",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/path-parse/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/path-parse/package.json"
              }
            ],
            "concludedValue": "node_modules/path-parse/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "path-key",
      "version": "3.1.1",
      "description": "Get the PATH environment variable key cross-platform",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/path-key@3.1.1",
      "type": "library",
      "bom-ref": "pkg:npm/path-key@3.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/path-key/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/path-key/package.json"
              }
            ],
            "concludedValue": "node_modules/path-key/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Domenic Denicola <d@domenic.me> (https://domenic.me)"
        }
      ],
      "group": "",
      "name": "path-is-inside",
      "version": "1.0.2",
      "description": "Tests whether one path is inside another path",
      "scope": "optional",
      "licenses": [
        {
          "expression": "(WTFPL OR MIT)"
        }
      ],
      "purl": "pkg:npm/path-is-inside@1.0.2",
      "type": "library",
      "bom-ref": "pkg:npm/path-is-inside@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/path-is-inside/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/path-is-inside/package.json"
              }
            ],
            "concludedValue": "node_modules/path-is-inside/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "path-is-absolute",
      "version": "1.0.1",
      "description": "Node.js 0.12 path.isAbsolute() ponyfill",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/path-is-absolute@1.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/path-is-absolute@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/path-is-absolute/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/path-is-absolute/package.json"
              }
            ],
            "concludedValue": "node_modules/path-is-absolute/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "path-exists",
      "version": "2.1.0",
      "description": "Check if a path exists",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/path-exists@2.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/path-exists@2.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/path-exists/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/path-exists/package.json"
              }
            ],
            "concludedValue": "node_modules/path-exists/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Ivan Nikulin <ifaaan@gmail.com> (https://github.com/inikulin)"
        }
      ],
      "group": "",
      "name": "parse5",
      "version": "1.5.1",
      "description": "WHATWG HTML5 specification-compliant, fast and ready for production HTML parsing/serialization toolset for Node and io.js.",
      "scope": "optional",
      "purl": "pkg:npm/parse5@1.5.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://inikulin.github.io/parse5/"
        },
        {
          "type": "vcs",
          "url": "git://github.com/inikulin/parse5.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/parse5@1.5.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/parse5/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/parse5/package.json"
              }
            ],
            "concludedValue": "node_modules/parse5/package.json"
          }
        ]
      },
      "tags": [
        "html"
      ]
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "parse-ms",
      "version": "4.0.0",
      "description": "Parse milliseconds into an object",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/parse-ms@4.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/parse-ms@4.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/parse-ms/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/parse-ms/package.json"
              }
            ],
            "concludedValue": "node_modules/parse-ms/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "parse-json",
      "version": "2.2.0",
      "description": "Parse JSON with more helpful errors",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/parse-json@2.2.0",
      "type": "library",
      "bom-ref": "pkg:npm/parse-json@2.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/parse-json/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/parse-json/package.json"
              }
            ],
            "concludedValue": "node_modules/parse-json/package.json"
          }
        ]
      },
      "tags": [
        "json"
      ]
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (https://izs.me)"
        }
      ],
      "group": "",
      "name": "package-json-from-dist",
      "version": "1.0.1",
      "description": "Load the local package.json from either src or dist folder",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BlueOak-1.0.0",
            "url": "https://opensource.org/licenses/BlueOak-1.0.0"
          }
        }
      ],
      "purl": "pkg:npm/package-json-from-dist@1.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git+https://github.com/isaacs/package-json-from-dist.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/package-json-from-dist@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/package-json-from-dist/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/package-json-from-dist/package.json"
              }
            ],
            "concludedValue": "node_modules/package-json-from-dist/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "package-json",
      "version": "4.0.1",
      "description": "Get metadata of a package from the npm registry",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/package-json@4.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/package-json@4.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/package-json/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/package-json/package.json"
              }
            ],
            "concludedValue": "node_modules/package-json/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "package-config",
      "version": "5.0.0",
      "description": "Get namespaced config from the closest package.json",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/package-config@5.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/package-config@5.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/package-config/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/package-config/package.json"
              }
            ],
            "concludedValue": "node_modules/package-config/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "p-map",
      "version": "7.0.4",
      "description": "Map over promises concurrently",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/p-map@7.0.4",
      "type": "library",
      "bom-ref": "pkg:npm/p-map@7.0.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/p-map/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/p-map/package.json"
              }
            ],
            "concludedValue": "node_modules/p-map/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "p-finally",
      "version": "1.0.0",
      "description": "`Promise#finally()` ponyfill - Invoked when the promise is settled regardless of outcome",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/p-finally@1.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/p-finally@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/p-finally/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/p-finally/package.json"
              }
            ],
            "concludedValue": "node_modules/p-finally/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "George Zahariev <z@georgezahariev.com>"
        }
      ],
      "group": "",
      "name": "optionator",
      "version": "0.8.3",
      "description": "option parsing and help generation",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/optionator@0.8.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/gkz/optionator"
        },
        {
          "type": "vcs",
          "url": "git://github.com/gkz/optionator.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/optionator@0.8.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/optionator/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/optionator/package.json"
              }
            ],
            "concludedValue": "node_modules/optionator/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "once",
      "version": "1.4.0",
      "description": "Run a function exactly one time",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/once@1.4.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/once"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/once@1.4.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/once/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/once/package.json"
              }
            ],
            "concludedValue": "node_modules/once/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "object-assign",
      "version": "4.1.1",
      "description": "ES2015 `Object.assign()` ponyfill",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/object-assign@4.1.1",
      "type": "library",
      "bom-ref": "pkg:npm/object-assign@4.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/object-assign/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/object-assign/package.json"
              }
            ],
            "concludedValue": "node_modules/object-assign/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mikeal Rogers <mikeal.rogers@gmail.com> (http://www.futurealoof.com)"
        }
      ],
      "group": "",
      "name": "oauth-sign",
      "version": "0.9.0",
      "description": "OAuth 1 signing. Formerly a vendor lib in mikeal/request, now a standalone module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0",
            "url": "https://opensource.org/licenses/Apache-2.0"
          }
        }
      ],
      "purl": "pkg:npm/oauth-sign@0.9.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mikeal/oauth-sign"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/oauth-sign@0.9.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/oauth-sign/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/oauth-sign/package.json"
              }
            ],
            "concludedValue": "node_modules/oauth-sign/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Diego Perini <diego.perini@gmail.com>"
        }
      ],
      "group": "",
      "name": "nwmatcher",
      "version": "1.4.4",
      "description": "A CSS3-compliant JavaScript selector engine.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/nwmatcher@1.4.4",
      "externalReferences": [
        {
          "type": "website",
          "url": "http://javascript.nwbox.com/NWMatcher/"
        },
        {
          "type": "vcs",
          "url": "git://github.com/dperini/nwmatcher.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/nwmatcher@1.4.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/nwmatcher/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/nwmatcher/package.json"
              }
            ],
            "concludedValue": "node_modules/nwmatcher/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "npm-run-path",
      "version": "2.0.2",
      "description": "Get your PATH prepended with locally installed binaries",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/npm-run-path@2.0.2",
      "type": "library",
      "bom-ref": "pkg:npm/npm-run-path@2.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm-run-path/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm-run-path/package.json"
              }
            ],
            "concludedValue": "node_modules/npm-run-path/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "path-key",
      "version": "2.0.1",
      "description": "Get the PATH environment variable key cross-platform",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/path-key@2.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/path-key@2.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/npm-run-path/node_modules/path-key/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/npm-run-path/node_modules/path-key/package.json"
              }
            ],
            "concludedValue": "node_modules/npm-run-path/node_modules/path-key/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Meryn Stol <merynstol@gmail.com>"
        }
      ],
      "group": "",
      "name": "normalize-package-data",
      "version": "2.5.0",
      "description": "Normalizes data that can be found in package.json files.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-2-Clause",
            "url": "https://opensource.org/licenses/BSD-2-Clause"
          }
        }
      ],
      "purl": "pkg:npm/normalize-package-data@2.5.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/npm/normalize-package-data.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/normalize-package-data@2.5.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/normalize-package-data/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/normalize-package-data/package.json"
              }
            ],
            "concludedValue": "node_modules/normalize-package-data/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "GitHub Inc."
        }
      ],
      "group": "",
      "name": "nopt",
      "version": "8.1.0",
      "description": "Option parsing for Node, supporting types, shorthands, etc. Used by npm.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/nopt@8.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git+https://github.com/npm/nopt.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/nopt@8.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/nopt/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/nopt/package.json"
              }
            ],
            "concludedValue": "node_modules/nopt/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Joe Hildebrand <joe-github@cursive.net>"
        }
      ],
      "group": "",
      "name": "nofilter",
      "version": "3.1.0",
      "description": "Read and write a growable buffer as a stream",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/nofilter@3.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/hildjj/nofilter#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/hildjj/nofilter.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/nofilter@3.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/nofilter/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/nofilter/package.json"
              }
            ],
            "concludedValue": "node_modules/nofilter/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mathias Buus (@mafintosh)"
        }
      ],
      "group": "",
      "name": "node-gyp-build",
      "version": "4.8.4",
      "description": "Build tool and bindings loader for node-gyp that supports prebuilds",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/node-gyp-build@4.8.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/prebuild/node-gyp-build"
        },
        {
          "type": "vcs",
          "url": "https://github.com/prebuild/node-gyp-build.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/node-gyp-build@4.8.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/node-gyp-build/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/node-gyp-build/package.json"
              }
            ],
            "concludedValue": "node_modules/node-gyp-build/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "David Frank"
        }
      ],
      "group": "",
      "name": "node-fetch",
      "version": "2.7.0",
      "description": "A light-weight module that brings window.fetch to node.js",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/node-fetch@2.7.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/bitinn/node-fetch"
        },
        {
          "type": "vcs",
          "url": "https://github.com/bitinn/node-fetch.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/node-fetch@2.7.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/node-fetch/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/node-fetch/package.json"
              }
            ],
            "concludedValue": "node_modules/node-fetch/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sebastian Mayr <github@smayr.name>"
        }
      ],
      "group": "",
      "name": "whatwg-url",
      "version": "5.0.0",
      "description": "An implementation of the WHATWG URL Standard's URL API and parsing machinery",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/whatwg-url@5.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/whatwg-url@5.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/node-fetch/node_modules/whatwg-url/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/node-fetch/node_modules/whatwg-url/package.json"
              }
            ],
            "concludedValue": "node_modules/node-fetch/node_modules/whatwg-url/package.json"
          }
        ]
      },
      "tags": [
        "api"
      ]
    },
    {
      "group": "",
      "name": "ms",
      "version": "2.1.3",
      "description": "Tiny millisecond conversion utility",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/ms@2.1.3",
      "type": "library",
      "bom-ref": "pkg:npm/ms@2.1.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/ms/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/ms/package.json"
              }
            ],
            "concludedValue": "node_modules/ms/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "mkdirp",
      "version": "0.5.6",
      "description": "Recursively mkdir, like `mkdir -p`",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/mkdirp@0.5.6",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/substack/node-mkdirp.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/mkdirp@0.5.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/mkdirp/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/mkdirp/package.json"
              }
            ],
            "concludedValue": "node_modules/mkdirp/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "minizlib",
      "version": "3.1.0",
      "description": "A small fast zlib stream built on [minipass](http://npm.im/minipass) and Node.js's zlib binding.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/minizlib@3.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git+https://github.com/isaacs/minizlib.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/minizlib@3.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/minizlib/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/minizlib/package.json"
              }
            ],
            "concludedValue": "node_modules/minizlib/package.json"
          }
        ]
      },
      "tags": [
        "stream"
      ]
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "minipass",
      "version": "7.1.3",
      "description": "minimal implementation of a PassThrough stream",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BlueOak-1.0.0",
            "url": "https://opensource.org/licenses/BlueOak-1.0.0"
          }
        }
      ],
      "purl": "pkg:npm/minipass@7.1.3",
      "type": "library",
      "bom-ref": "pkg:npm/minipass@7.1.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/minipass/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/minipass/package.json"
              }
            ],
            "concludedValue": "node_modules/minipass/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "minimist",
      "version": "1.2.8",
      "description": "parse argument options",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/minimist@1.2.8",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/minimistjs/minimist"
        },
        {
          "type": "vcs",
          "url": "git://github.com/minimistjs/minimist.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/minimist@1.2.8",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/minimist/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/minimist/package.json"
              }
            ],
            "concludedValue": "node_modules/minimist/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me)"
        }
      ],
      "group": "",
      "name": "minimatch",
      "version": "9.0.9",
      "description": "a glob matcher in javascript",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/minimatch@9.0.9",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/minimatch.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/minimatch@9.0.9",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/minimatch/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/minimatch/package.json"
              }
            ],
            "concludedValue": "node_modules/minimatch/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "mimic-function",
      "version": "5.0.1",
      "description": "Make a function mimic another one",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/mimic-function@5.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/mimic-function@5.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/mimic-function/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/mimic-function/package.json"
              }
            ],
            "concludedValue": "node_modules/mimic-function/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "mime-types",
      "version": "2.1.35",
      "description": "The ultimate javascript content-type utility.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/mime-types@2.1.35",
      "type": "library",
      "bom-ref": "pkg:npm/mime-types@2.1.35",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/mime-types/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/mime-types/package.json"
              }
            ],
            "concludedValue": "node_modules/mime-types/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "mime-db",
      "version": "1.52.0",
      "description": "Media Type Database",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/mime-db@1.52.0",
      "type": "library",
      "bom-ref": "pkg:npm/mime-db@1.52.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/mime-db/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/mime-db/package.json"
              }
            ],
            "concludedValue": "node_modules/mime-db/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jon Schlinkert (https://github.com/jonschlinkert)"
        }
      ],
      "group": "",
      "name": "micromatch",
      "version": "4.0.8",
      "description": "Glob matching for javascript/node.js. A replacement and faster alternative to minimatch and multimatch.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/micromatch@4.0.8",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/micromatch/micromatch"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/micromatch@4.0.8",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/micromatch/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/micromatch/package.json"
              }
            ],
            "concludedValue": "node_modules/micromatch/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jon Schlinkert (https://github.com/jonschlinkert)"
        }
      ],
      "group": "",
      "name": "picomatch",
      "version": "2.3.2",
      "description": "Blazing fast and accurate glob matcher written in JavaScript, with no dependencies and full support for standard and extended Bash glob features, including braces, extglobs, POSIX brackets, and regular expressions.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/picomatch@2.3.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/micromatch/picomatch"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/picomatch@2.3.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/micromatch/node_modules/picomatch/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/micromatch/node_modules/picomatch/package.json"
              }
            ],
            "concludedValue": "node_modules/micromatch/node_modules/picomatch/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "merge2",
      "version": "1.4.1",
      "description": "Merge multiple streams into one stream in sequence or parallel.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/merge2@1.4.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/teambition/merge2"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/merge2@1.4.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/merge2/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/merge2/package.json"
              }
            ],
            "concludedValue": "node_modules/merge2/package.json"
          }
        ]
      },
      "tags": [
        "stream"
      ]
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "meow",
      "version": "3.7.0",
      "description": "CLI app helper",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/meow@3.7.0",
      "type": "library",
      "bom-ref": "pkg:npm/meow@3.7.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/meow/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/meow/package.json"
              }
            ],
            "concludedValue": "node_modules/meow/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "memoize",
      "version": "10.2.0",
      "description": "Memoize functions - An optimization used to speed up consecutive function calls by caching the result of calls with identical input",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/memoize@10.2.0",
      "type": "library",
      "bom-ref": "pkg:npm/memoize@10.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/memoize/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/memoize/package.json"
              }
            ],
            "concludedValue": "node_modules/memoize/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "md5-hex",
      "version": "3.0.1",
      "description": "Create a MD5 hash with hex encoding",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/md5-hex@3.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/md5-hex@3.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/md5-hex/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/md5-hex/package.json"
              }
            ],
            "concludedValue": "node_modules/md5-hex/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "matcher",
      "version": "5.0.0",
      "description": "Simple wildcard matching",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/matcher@5.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/matcher@5.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/matcher/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/matcher/package.json"
              }
            ],
            "concludedValue": "node_modules/matcher/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "map-obj",
      "version": "1.0.1",
      "description": "Map object keys and values into a new object",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/map-obj@1.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/map-obj@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/map-obj/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/map-obj/package.json"
              }
            ],
            "concludedValue": "node_modules/map-obj/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "make-dir",
      "version": "1.3.0",
      "description": "Make a directory and its parents if needed - Think `mkdir -p`",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/make-dir@1.3.0",
      "type": "library",
      "bom-ref": "pkg:npm/make-dir@1.3.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/make-dir/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/make-dir/package.json"
              }
            ],
            "concludedValue": "node_modules/make-dir/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me>"
        }
      ],
      "group": "",
      "name": "lru-cache",
      "version": "10.4.3",
      "description": "A cache object that deletes the least-recently-used items.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/lru-cache@10.4.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/node-lru-cache.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lru-cache@10.4.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/lru-cache/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/lru-cache/package.json"
              }
            ],
            "concludedValue": "node_modules/lru-cache/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "lowercase-keys",
      "version": "1.0.1",
      "description": "Lowercase the keys of an object",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/lowercase-keys@1.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/lowercase-keys@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/lowercase-keys/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/lowercase-keys/package.json"
              }
            ],
            "concludedValue": "node_modules/lowercase-keys/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "loud-rejection",
      "version": "1.6.0",
      "description": "Make unhandled promise rejections fail loudly instead of the default silent fail",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/loud-rejection@1.6.0",
      "type": "library",
      "bom-ref": "pkg:npm/loud-rejection@1.6.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/loud-rejection/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/loud-rejection/package.json"
              }
            ],
            "concludedValue": "node_modules/loud-rejection/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Ben Coe <ben@npmjs.com>"
        }
      ],
      "group": "",
      "name": "signal-exit",
      "version": "3.0.7",
      "description": "when you want to fire an event no matter how a process exits.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/signal-exit@3.0.7",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/tapjs/signal-exit"
        },
        {
          "type": "vcs",
          "url": "https://github.com/tapjs/signal-exit.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/signal-exit@3.0.7",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/loud-rejection/node_modules/signal-exit/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/execa/node_modules/signal-exit/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/configstore/node_modules/signal-exit/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/configstore/node_modules/signal-exit/package.json"
              }
            ],
            "concludedValue": "node_modules/configstore/node_modules/signal-exit/package.json"
          }
        ]
      },
      "tags": [
        "event"
      ]
    },
    {
      "authors": [
        {
          "name": "John-David Dalton <john.david.dalton@gmail.com>"
        }
      ],
      "group": "",
      "name": "lodash",
      "version": "4.18.1",
      "description": "Lodash modular utilities.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/lodash@4.18.1",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://lodash.com/"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/lodash@4.18.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/lodash/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/lodash/package.json"
              }
            ],
            "concludedValue": "node_modules/lodash/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "load-json-file",
      "version": "7.0.1",
      "description": "Read and parse a JSON file",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/load-json-file@7.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/load-json-file@7.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/load-json-file/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/load-json-file/package.json"
              }
            ],
            "concludedValue": "node_modules/load-json-file/package.json"
          }
        ]
      },
      "tags": [
        "json",
        "parse"
      ]
    },
    {
      "authors": [
        {
          "name": "George Zahariev <z@georgezahariev.com>"
        }
      ],
      "group": "",
      "name": "levn",
      "version": "0.3.0",
      "description": "Light ECMAScript (JavaScript) Value Notation - human written, concise, typed, flexible",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/levn@0.3.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/gkz/levn"
        },
        {
          "type": "vcs",
          "url": "git://github.com/gkz/levn.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/levn@0.3.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/levn/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/levn/package.json"
              }
            ],
            "concludedValue": "node_modules/levn/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "latest-version",
      "version": "3.1.0",
      "description": "Get the latest version of an npm package",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/latest-version@3.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/latest-version@3.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/latest-version/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/latest-version/package.json"
              }
            ],
            "concludedValue": "node_modules/latest-version/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "jsprim",
      "version": "1.4.2",
      "description": "utilities for primitive JavaScript types",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/jsprim@1.4.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/joyent/node-jsprim.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/jsprim@1.4.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/jsprim/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/jsprim/package.json"
              }
            ],
            "concludedValue": "node_modules/jsprim/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me)"
        }
      ],
      "group": "",
      "name": "json-stringify-safe",
      "version": "5.0.1",
      "description": "Like JSON.stringify, but doesn't blow up on circular refs.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/json-stringify-safe@5.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/json-stringify-safe"
        },
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/json-stringify-safe"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/json-stringify-safe@5.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/json-stringify-safe/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/json-stringify-safe/package.json"
              }
            ],
            "concludedValue": "node_modules/json-stringify-safe/package.json"
          }
        ]
      },
      "tags": [
        "json"
      ]
    },
    {
      "authors": [
        {
          "name": "Evgeny Poberezkin"
        }
      ],
      "group": "",
      "name": "json-schema-traverse",
      "version": "0.4.1",
      "description": "Traverse JSON Schema passing each schema object to callback",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/json-schema-traverse@0.4.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/epoberezkin/json-schema-traverse#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/epoberezkin/json-schema-traverse.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/json-schema-traverse@0.4.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/json-schema-traverse/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/json-schema-traverse/package.json"
              }
            ],
            "concludedValue": "node_modules/json-schema-traverse/package.json"
          }
        ]
      },
      "tags": [
        "json"
      ]
    },
    {
      "authors": [
        {
          "name": "Kris Zyp"
        }
      ],
      "group": "",
      "name": "json-schema",
      "version": "0.4.0",
      "description": "JSON Schema validation and specifications",
      "scope": "optional",
      "licenses": [
        {
          "expression": "(AFL-2.1 OR BSD-3-Clause)"
        }
      ],
      "purl": "pkg:npm/json-schema@0.4.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/kriszyp/json-schema"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/json-schema@0.4.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/json-schema/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/json-schema/package.json"
              }
            ],
            "concludedValue": "node_modules/json-schema/package.json"
          }
        ]
      },
      "tags": [
        "validation"
      ]
    },
    {
      "group": "",
      "name": "jsdom",
      "version": "9.12.0",
      "description": "A JavaScript implementation of the DOM and HTML standards",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/jsdom@9.12.0",
      "type": "library",
      "bom-ref": "pkg:npm/jsdom@9.12.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/jsdom/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/jsdom/package.json"
              }
            ],
            "concludedValue": "node_modules/jsdom/package.json"
          }
        ]
      },
      "tags": [
        "html"
      ]
    },
    {
      "group": "",
      "name": "acorn",
      "version": "4.0.13",
      "description": "ECMAScript parser",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/acorn@4.0.13",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/ternjs/acorn"
        },
        {
          "type": "vcs",
          "url": "https://github.com/ternjs/acorn.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/acorn@4.0.13",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/jsdom/node_modules/acorn/package.json"
        },
        {
          "name": "SrcFile",
          "value": "node_modules/acorn-globals/node_modules/acorn/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/acorn-globals/node_modules/acorn/package.json"
              }
            ],
            "concludedValue": "node_modules/acorn-globals/node_modules/acorn/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Tom Wu"
        }
      ],
      "group": "",
      "name": "jsbn",
      "version": "0.1.1",
      "description": "The jsbn library is a fast, portable implementation of large-number math in pure JavaScript, enabling public-key crypto and other applications on desktop and mobile browsers.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/jsbn@0.1.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/andyperlitch/jsbn.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/jsbn@0.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/jsbn/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/jsbn/package.json"
              }
            ],
            "concludedValue": "node_modules/jsbn/package.json"
          }
        ]
      },
      "tags": [
        "crypto"
      ]
    },
    {
      "authors": [
        {
          "name": "Vladimir Zapparov <dervus.grim@gmail.com>"
        }
      ],
      "group": "",
      "name": "js-yaml",
      "version": "3.14.2",
      "description": "YAML 1.2 parser and serializer",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/js-yaml@3.14.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/nodeca/js-yaml"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/js-yaml@3.14.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/js-yaml/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/js-yaml/package.json"
              }
            ],
            "concludedValue": "node_modules/js-yaml/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Simon Lydell"
        }
      ],
      "group": "",
      "name": "js-tokens",
      "version": "4.0.0",
      "description": "A regex that tokenizes JavaScript.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/js-tokens@4.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/js-tokens@4.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/js-tokens/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/js-tokens/package.json"
              }
            ],
            "concludedValue": "node_modules/js-tokens/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jo Liss <joliss42@gmail.com>"
        }
      ],
      "group": "",
      "name": "js-string-escape",
      "version": "1.0.1",
      "description": "Escape strings for use as JavaScript string literals",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/js-string-escape@1.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/joliss/js-string-escape"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/js-string-escape@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/js-string-escape/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/js-string-escape/package.json"
              }
            ],
            "concludedValue": "node_modules/js-string-escape/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me>"
        }
      ],
      "group": "",
      "name": "jackspeak",
      "version": "3.4.3",
      "description": "A very strict and proper argument parser.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BlueOak-1.0.0",
            "url": "https://opensource.org/licenses/BlueOak-1.0.0"
          }
        }
      ],
      "purl": "pkg:npm/jackspeak@3.4.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git+https://github.com/isaacs/jackspeak.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/jackspeak@3.4.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/jackspeak/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/jackspeak/package.json"
              }
            ],
            "concludedValue": "node_modules/jackspeak/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Rod Vagg <rod@vagg.org>"
        }
      ],
      "group": "",
      "name": "isstream",
      "version": "0.1.2",
      "description": "Determine if an object is a Stream",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/isstream@0.1.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/rvagg/isstream"
        },
        {
          "type": "vcs",
          "url": "https://github.com/rvagg/isstream.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/isstream@0.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/isstream/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/isstream/package.json"
              }
            ],
            "concludedValue": "node_modules/isstream/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "isexe",
      "version": "2.0.0",
      "description": "Minimal module to check if a file is executable.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/isexe@2.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/isexe#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/isaacs/isexe.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/isexe@2.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/isexe/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/isexe/package.json"
              }
            ],
            "concludedValue": "node_modules/isexe/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Julian Gruber <mail@juliangruber.com> (http://juliangruber.com)"
        }
      ],
      "group": "",
      "name": "isarray",
      "version": "0.0.1",
      "description": "Array#isArray for older browsers",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/isarray@0.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/juliangruber/isarray"
        },
        {
          "type": "vcs",
          "url": "git://github.com/juliangruber/isarray.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/isarray@0.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/isarray/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/isarray/package.json"
              }
            ],
            "concludedValue": "node_modules/isarray/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "wayfind"
        }
      ],
      "group": "",
      "name": "is-utf8",
      "version": "0.2.1",
      "description": "Detect if a buffer is utf8 encoded.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-utf8@0.2.1",
      "type": "library",
      "bom-ref": "pkg:npm/is-utf8@0.2.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-utf8/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-utf8/package.json"
              }
            ],
            "concludedValue": "node_modules/is-utf8/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "is-unicode-supported",
      "version": "2.1.0",
      "description": "Detect whether the terminal supports Unicode",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-unicode-supported@2.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/is-unicode-supported@2.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-unicode-supported/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-unicode-supported/package.json"
              }
            ],
            "concludedValue": "node_modules/is-unicode-supported/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Hugh Kennedy <hughskennedy@gmail.com> (http://hughsk.io/)"
        }
      ],
      "group": "",
      "name": "is-typedarray",
      "version": "1.0.0",
      "description": "Detect whether or not an object is a Typed Array",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-typedarray@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/hughsk/is-typedarray"
        },
        {
          "type": "vcs",
          "url": "git://github.com/hughsk/is-typedarray.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/is-typedarray@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-typedarray/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-typedarray/package.json"
              }
            ],
            "concludedValue": "node_modules/is-typedarray/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "is-stream",
      "version": "1.1.0",
      "description": "Check if something is a Node.js stream",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-stream@1.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/is-stream@1.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-stream/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-stream/package.json"
              }
            ],
            "concludedValue": "node_modules/is-stream/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Vsevolod Strukchinsky <floatdrop@gmail.com> (github.com/floatdrop)"
        }
      ],
      "group": "",
      "name": "is-retry-allowed",
      "version": "1.2.0",
      "description": "Is retry allowed for Error?",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-retry-allowed@1.2.0",
      "type": "library",
      "bom-ref": "pkg:npm/is-retry-allowed@1.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-retry-allowed/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-retry-allowed/package.json"
              }
            ],
            "concludedValue": "node_modules/is-retry-allowed/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "is-redirect",
      "version": "1.0.0",
      "description": "Check if a number is a redirect HTTP status code",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-redirect@1.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/is-redirect@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-redirect/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-redirect/package.json"
              }
            ],
            "concludedValue": "node_modules/is-redirect/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "ForbesLindesay"
        }
      ],
      "group": "",
      "name": "is-promise",
      "version": "4.0.0",
      "description": "Test whether an object looks like a promises-a+ promise",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-promise@4.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/then/is-promise.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/is-promise@4.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-promise/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-promise/package.json"
              }
            ],
            "concludedValue": "node_modules/is-promise/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jon Schlinkert (https://github.com/jonschlinkert)"
        }
      ],
      "group": "",
      "name": "is-plain-object",
      "version": "5.0.0",
      "description": "Returns true if an object was created by the `Object` constructor, or Object.create(null).",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-plain-object@5.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jonschlinkert/is-plain-object"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/is-plain-object@5.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-plain-object/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-plain-object/package.json"
              }
            ],
            "concludedValue": "node_modules/is-plain-object/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "is-path-inside",
      "version": "1.0.1",
      "description": "Check if a path is inside another path",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-path-inside@1.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/is-path-inside@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-path-inside/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-path-inside/package.json"
              }
            ],
            "concludedValue": "node_modules/is-path-inside/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (http://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "is-path-in-cwd",
      "version": "1.0.1",
      "description": "Check if a path is in the current working directory",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-path-in-cwd@1.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/is-path-in-cwd@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-path-in-cwd/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-path-in-cwd/package.json"
              }
            ],
            "concludedValue": "node_modules/is-path-in-cwd/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (http://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "is-path-cwd",
      "version": "1.0.0",
      "description": "Check if a path is CWD",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-path-cwd@1.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/is-path-cwd@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-path-cwd/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-path-cwd/package.json"
              }
            ],
            "concludedValue": "node_modules/is-path-cwd/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "is-obj",
      "version": "1.0.1",
      "description": "Check if a value is an object",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-obj@1.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/is-obj@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-obj/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-obj/package.json"
              }
            ],
            "concludedValue": "node_modules/is-obj/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jon Schlinkert (https://github.com/jonschlinkert)"
        }
      ],
      "group": "",
      "name": "is-number",
      "version": "7.0.0",
      "description": "Returns true if a number or string value is a finite number. Useful for regex matches, parsing, user input, etc.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-number@7.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jonschlinkert/is-number"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/is-number@7.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-number/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-number/package.json"
              }
            ],
            "concludedValue": "node_modules/is-number/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (http://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "is-npm",
      "version": "1.0.0",
      "description": "Check if your code is running as an npm script",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-npm@1.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/is-npm@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-npm/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-npm/package.json"
              }
            ],
            "concludedValue": "node_modules/is-npm/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "is-installed-globally",
      "version": "0.1.0",
      "description": "Check if your package was installed globally",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-installed-globally@0.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/is-installed-globally@0.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-installed-globally/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-installed-globally/package.json"
              }
            ],
            "concludedValue": "node_modules/is-installed-globally/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jon Schlinkert (https://github.com/jonschlinkert)"
        }
      ],
      "group": "",
      "name": "is-glob",
      "version": "4.0.3",
      "description": "Returns `true` if the given string looks like a glob pattern or an extglob pattern. This makes it easy to create code that only uses external modules like node-glob when necessary, resulting in much faster code execution and initialization time, and a better user experience.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-glob@4.0.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/micromatch/is-glob"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/is-glob@4.0.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-glob/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-glob/package.json"
              }
            ],
            "concludedValue": "node_modules/is-glob/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "is-fullwidth-code-point",
      "version": "4.0.0",
      "description": "Check if the character represented by a given Unicode code point is fullwidth",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-fullwidth-code-point@4.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/is-fullwidth-code-point@4.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-fullwidth-code-point/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-fullwidth-code-point/package.json"
              }
            ],
            "concludedValue": "node_modules/is-fullwidth-code-point/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "is-finite",
      "version": "1.1.0",
      "description": "ES2015 Number.isFinite() ponyfill",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-finite@1.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/is-finite@1.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-finite/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-finite/package.json"
              }
            ],
            "concludedValue": "node_modules/is-finite/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jon Schlinkert (https://github.com/jonschlinkert)"
        }
      ],
      "group": "",
      "name": "is-extglob",
      "version": "2.1.1",
      "description": "Returns true if a string has an extglob.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-extglob@2.1.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jonschlinkert/is-extglob"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/is-extglob@2.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-extglob/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-extglob/package.json"
              }
            ],
            "concludedValue": "node_modules/is-extglob/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jordan Harband <ljharb@gmail.com>"
        }
      ],
      "group": "",
      "name": "is-core-module",
      "version": "2.16.2",
      "description": "Is this specifier a node.js core module?",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-core-module@2.16.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/inspect-js/is-core-module"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/inspect-js/is-core-module.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/is-core-module@2.16.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-core-module/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-core-module/package.json"
              }
            ],
            "concludedValue": "node_modules/is-core-module/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Thomas Watson Steen <w@tson.dk> (https://twitter.com/wa7son)"
        }
      ],
      "group": "",
      "name": "is-ci",
      "version": "1.2.1",
      "description": "Detect if the current environment is a CI server",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-ci@1.2.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/watson/is-ci"
        },
        {
          "type": "vcs",
          "url": "https://github.com/watson/is-ci.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/is-ci@1.2.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-ci/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-ci/package.json"
              }
            ],
            "concludedValue": "node_modules/is-ci/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Thomas Watson Steen <w@tson.dk> (https://twitter.com/wa7son)"
        }
      ],
      "group": "",
      "name": "ci-info",
      "version": "1.6.0",
      "description": "Get details about the current Continuous Integration environment",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/ci-info@1.6.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/watson/ci-info"
        },
        {
          "type": "vcs",
          "url": "https://github.com/watson/ci-info.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/ci-info@1.6.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-ci/node_modules/ci-info/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-ci/node_modules/ci-info/package.json"
              }
            ],
            "concludedValue": "node_modules/is-ci/node_modules/ci-info/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Qix (http://github.com/qix-)"
        }
      ],
      "group": "",
      "name": "is-arrayish",
      "version": "0.2.1",
      "description": "Determines if an object can be used as an array",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/is-arrayish@0.2.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/qix-/node-is-arrayish.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/is-arrayish@0.2.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/is-arrayish/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/is-arrayish/package.json"
              }
            ],
            "concludedValue": "node_modules/is-arrayish/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "irregular-plurals",
      "version": "3.5.0",
      "description": "Map of nouns to their irregular plural form",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/irregular-plurals@3.5.0",
      "type": "library",
      "bom-ref": "pkg:npm/irregular-plurals@3.5.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/irregular-plurals/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/irregular-plurals/package.json"
              }
            ],
            "concludedValue": "node_modules/irregular-plurals/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Remo H. Jansen"
        }
      ],
      "group": "",
      "name": "inversify",
      "version": "5.1.1",
      "description": "A powerful and lightweight inversion of control container for JavaScript and Node.js apps powered by TypeScript.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/inversify@5.1.1",
      "externalReferences": [
        {
          "type": "website",
          "url": "http://inversify.io"
        },
        {
          "type": "vcs",
          "url": "https://github.com/inversify/InversifyJS.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/inversify@5.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/inversify/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/inversify/package.json"
              }
            ],
            "concludedValue": "node_modules/inversify/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "ini",
      "version": "1.3.8",
      "description": "An ini encoder/decoder for node",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/ini@1.3.8",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/ini.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/ini@1.3.8",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/ini/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/ini/package.json"
              }
            ],
            "concludedValue": "node_modules/ini/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "inherits",
      "version": "2.0.4",
      "description": "Browser-friendly inheritance fully compatible with standard node.js inherits()",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/inherits@2.0.4",
      "type": "library",
      "bom-ref": "pkg:npm/inherits@2.0.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/inherits/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/inherits/package.json"
              }
            ],
            "concludedValue": "node_modules/inherits/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "inflight",
      "version": "1.0.6",
      "description": "Add callbacks to requests in flight to avoid async duplication",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/inflight@1.0.6",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/inflight"
        },
        {
          "type": "vcs",
          "url": "https://github.com/npm/inflight.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/inflight@1.0.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/inflight/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/inflight/package.json"
              }
            ],
            "concludedValue": "node_modules/inflight/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "indent-string",
      "version": "5.0.0",
      "description": "Indent each line in a string",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/indent-string@5.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/indent-string@5.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/indent-string/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/indent-string/package.json"
              }
            ],
            "concludedValue": "node_modules/indent-string/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jens Taylor <jensyt@gmail.com> (https://github.com/homebrewing)"
        }
      ],
      "group": "",
      "name": "imurmurhash",
      "version": "0.1.4",
      "description": "An incremental implementation of MurmurHash3",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/imurmurhash@0.1.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jensyt/imurmurhash-js"
        },
        {
          "type": "vcs",
          "url": "https://github.com/jensyt/imurmurhash-js"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/imurmurhash@0.1.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/imurmurhash/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/imurmurhash/package.json"
              }
            ],
            "concludedValue": "node_modules/imurmurhash/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "import-lazy",
      "version": "2.1.0",
      "description": "Import modules lazily",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/import-lazy@2.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/import-lazy@2.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/import-lazy/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/import-lazy/package.json"
              }
            ],
            "concludedValue": "node_modules/import-lazy/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mark Wubben (https://novemberborn.net/)"
        }
      ],
      "group": "",
      "name": "ignore-by-default",
      "version": "2.1.0",
      "description": "A list of directories you should ignore by default",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/ignore-by-default@2.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/novemberborn/ignore-by-default#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/novemberborn/ignore-by-default.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/ignore-by-default@2.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/ignore-by-default/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/ignore-by-default/package.json"
              }
            ],
            "concludedValue": "node_modules/ignore-by-default/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "kael"
        }
      ],
      "group": "",
      "name": "ignore",
      "version": "7.0.5",
      "description": "Ignore is a manager and filter for .gitignore rules, the one used by eslint, gitbook and many others.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/ignore@7.0.5",
      "type": "library",
      "bom-ref": "pkg:npm/ignore@7.0.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/ignore/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/ignore/package.json"
              }
            ],
            "concludedValue": "node_modules/ignore/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Alexander Shtuchkin <ashtuchkin@gmail.com>"
        }
      ],
      "group": "",
      "name": "iconv-lite",
      "version": "0.4.24",
      "description": "Convert character encodings in pure javascript.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/iconv-lite@0.4.24",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/ashtuchkin/iconv-lite"
        },
        {
          "type": "vcs",
          "url": "git://github.com/ashtuchkin/iconv-lite.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/iconv-lite@0.4.24",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/iconv-lite/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/iconv-lite/package.json"
              }
            ],
            "concludedValue": "node_modules/iconv-lite/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Nathan Rajlich <nathan@tootallnate.net> (http://n8.io/)"
        }
      ],
      "group": "",
      "name": "https-proxy-agent",
      "version": "7.0.6",
      "description": "An HTTP(s) proxy `http.Agent` implementation for HTTPS",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/https-proxy-agent@7.0.6",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/TooTallNate/proxy-agents.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/https-proxy-agent@7.0.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/https-proxy-agent/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/https-proxy-agent/package.json"
              }
            ],
            "concludedValue": "node_modules/https-proxy-agent/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Joyent"
        },
        {
          "name": " Inc"
        }
      ],
      "group": "",
      "name": "http-signature",
      "version": "1.2.0",
      "description": "Reference implementation of Joyent's HTTP Signature scheme.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/http-signature@1.2.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/joyent/node-http-signature/"
        },
        {
          "type": "vcs",
          "url": "git://github.com/joyent/node-http-signature.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/http-signature@1.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/http-signature/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/http-signature/package.json"
              }
            ],
            "concludedValue": "node_modules/http-signature/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Domenic Denicola <d@domenic.me> (https://domenic.me/)"
        }
      ],
      "group": "",
      "name": "html-encoding-sniffer",
      "version": "1.0.2",
      "description": "Sniff the encoding from a HTML byte stream",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/html-encoding-sniffer@1.0.2",
      "type": "library",
      "bom-ref": "pkg:npm/html-encoding-sniffer@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/html-encoding-sniffer/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/html-encoding-sniffer/package.json"
              }
            ],
            "concludedValue": "node_modules/html-encoding-sniffer/package.json"
          }
        ]
      },
      "tags": [
        "html"
      ]
    },
    {
      "authors": [
        {
          "name": "Rebecca Turner <me@re-becca.org> (http://re-becca.org)"
        }
      ],
      "group": "",
      "name": "hosted-git-info",
      "version": "2.8.9",
      "description": "Provides metadata and conversions from repository urls for Github, Bitbucket and Gitlab",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/hosted-git-info@2.8.9",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/npm/hosted-git-info"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/npm/hosted-git-info.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/hosted-git-info@2.8.9",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/hosted-git-info/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/hosted-git-info/package.json"
              }
            ],
            "concludedValue": "node_modules/hosted-git-info/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jordan Harband <ljharb@gmail.com>"
        }
      ],
      "group": "",
      "name": "hasown",
      "version": "2.0.3",
      "description": "A robust, ES3 compatible, \"has own property\" predicate.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/hasown@2.0.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/inspect-js/hasOwn#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/inspect-js/hasOwn.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/hasown@2.0.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/hasown/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/hasown/package.json"
              }
            ],
            "concludedValue": "node_modules/hasown/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "has-flag",
      "version": "3.0.0",
      "description": "Check if argv has a specific flag",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/has-flag@3.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/has-flag@3.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/has-flag/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/has-flag/package.json"
              }
            ],
            "concludedValue": "node_modules/has-flag/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Ahmad Nassri <ahmad@ahmadnassri.com> (https://www.ahmadnassri.com/)"
        }
      ],
      "group": "",
      "name": "har-validator",
      "version": "5.1.5",
      "description": "Extremely fast HTTP Archive (HAR) validator using JSON Schema",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/har-validator@5.1.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/ahmadnassri/node-har-validator"
        },
        {
          "type": "vcs",
          "url": "https://github.com/ahmadnassri/node-har-validator.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/har-validator@5.1.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/har-validator/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/har-validator/package.json"
              }
            ],
            "concludedValue": "node_modules/har-validator/package.json"
          }
        ]
      },
      "tags": [
        "json"
      ]
    },
    {
      "authors": [
        {
          "name": "Ahmad Nassri <ahmad@ahmadnassri.com> (https://www.ahmadnassri.com/)"
        }
      ],
      "group": "",
      "name": "har-schema",
      "version": "2.0.0",
      "description": "JSON Schema for HTTP Archive (HAR)",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/har-schema@2.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/ahmadnassri/har-schema"
        },
        {
          "type": "vcs",
          "url": "https://github.com/ahmadnassri/har-schema.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/har-schema@2.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/har-schema/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/har-schema/package.json"
              }
            ],
            "concludedValue": "node_modules/har-schema/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "graceful-fs",
      "version": "4.2.11",
      "description": "A drop-in replacement for fs, making various improvements.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/graceful-fs@4.2.11",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/isaacs/node-graceful-fs"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/graceful-fs@4.2.11",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/graceful-fs/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/graceful-fs/package.json"
              }
            ],
            "concludedValue": "node_modules/graceful-fs/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "got",
      "version": "6.7.1",
      "description": "Simplified HTTP requests",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/got@6.7.1",
      "type": "library",
      "bom-ref": "pkg:npm/got@6.7.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/got/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/got/package.json"
              }
            ],
            "concludedValue": "node_modules/got/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "globby",
      "version": "14.1.0",
      "description": "User-friendly glob matching",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/globby@14.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/globby@14.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/globby/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/globby/package.json"
              }
            ],
            "concludedValue": "node_modules/globby/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "global-dirs",
      "version": "0.1.1",
      "description": "Get the directory of globally installed packages and binaries",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/global-dirs@0.1.1",
      "type": "library",
      "bom-ref": "pkg:npm/global-dirs@0.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/global-dirs/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/global-dirs/package.json"
              }
            ],
            "concludedValue": "node_modules/global-dirs/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Gulp Team <team@gulpjs.com> (https://gulpjs.com/)"
        }
      ],
      "group": "",
      "name": "glob-parent",
      "version": "5.1.2",
      "description": "Extract the non-magic parent path from a glob string.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/glob-parent@5.1.2",
      "type": "library",
      "bom-ref": "pkg:npm/glob-parent@5.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/glob-parent/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/glob-parent/package.json"
              }
            ],
            "concludedValue": "node_modules/glob-parent/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (https://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "glob",
      "version": "10.5.0",
      "description": "the most correct and second fastest glob implementation in JavaScript",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/glob@10.5.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/node-glob.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/glob@10.5.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/glob/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/glob/package.json"
              }
            ],
            "concludedValue": "node_modules/glob/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Alex Wilson <alex.wilson@joyent.com>"
        }
      ],
      "group": "",
      "name": "getpass",
      "version": "0.1.7",
      "description": "getpass for node.js",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/getpass@0.1.7",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/arekinath/node-getpass.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/getpass@0.1.7",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/getpass/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/getpass/package.json"
              }
            ],
            "concludedValue": "node_modules/getpass/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "get-stream",
      "version": "3.0.0",
      "description": "Get a stream as a string, buffer, or array",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/get-stream@3.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/get-stream@3.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/get-stream/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/get-stream/package.json"
              }
            ],
            "concludedValue": "node_modules/get-stream/package.json"
          }
        ]
      },
      "tags": [
        "stream"
      ]
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (http://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "get-stdin",
      "version": "4.0.1",
      "description": "Easier stdin",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/get-stdin@4.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/get-stdin@4.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/get-stdin/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/get-stdin/package.json"
              }
            ],
            "concludedValue": "node_modules/get-stdin/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "get-east-asian-width",
      "version": "1.5.0",
      "description": "Determine the East Asian Width of a Unicode character",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/get-east-asian-width@1.5.0",
      "type": "library",
      "bom-ref": "pkg:npm/get-east-asian-width@1.5.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/get-east-asian-width/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/get-east-asian-width/package.json"
              }
            ],
            "concludedValue": "node_modules/get-east-asian-width/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Stefan Penner"
        }
      ],
      "group": "",
      "name": "get-caller-file",
      "version": "2.0.5",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/get-caller-file@2.0.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/stefanpenner/get-caller-file#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/stefanpenner/get-caller-file.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/get-caller-file@2.0.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/get-caller-file/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/get-caller-file/package.json"
              }
            ],
            "concludedValue": "node_modules/get-caller-file/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Raynos <raynos2@gmail.com>"
        }
      ],
      "group": "",
      "name": "function-bind",
      "version": "1.1.2",
      "description": "Implementation of Function.prototype.bind",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/function-bind@1.1.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/Raynos/function-bind"
        },
        {
          "type": "vcs",
          "url": "https://github.com/Raynos/function-bind.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/function-bind@1.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/function-bind/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/function-bind/package.json"
              }
            ],
            "concludedValue": "node_modules/function-bind/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "fs.realpath",
      "version": "1.0.0",
      "description": "Use node's fs.realpath, but fall back to the JS implementation if the native one fails",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/fs.realpath@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git+https://github.com/isaacs/fs.realpath.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/fs.realpath@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/fs.realpath/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/fs.realpath/package.json"
              }
            ],
            "concludedValue": "node_modules/fs.realpath/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Felix Geisendörfer <felix@debuggable.com> (http://debuggable.com/)"
        }
      ],
      "group": "",
      "name": "form-data",
      "version": "2.3.3",
      "description": "A library to create readable \"multipart/form-data\" streams. Can be used to submit forms and file uploads to other web applications.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/form-data@2.3.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/form-data/form-data.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/form-data@2.3.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/form-data/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/form-data/package.json"
              }
            ],
            "concludedValue": "node_modules/form-data/package.json"
          }
        ]
      },
      "tags": [
        "web"
      ]
    },
    {
      "authors": [
        {
          "name": "Mikeal Rogers <mikeal.rogers@gmail.com> (http://www.futurealoof.com)"
        }
      ],
      "group": "",
      "name": "forever-agent",
      "version": "0.6.1",
      "description": "HTTP Agent that keeps socket connections alive between keep-alive requests. Formerly part of mikeal/request, now a standalone module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0",
            "url": "https://opensource.org/licenses/Apache-2.0"
          }
        }
      ],
      "purl": "pkg:npm/forever-agent@0.6.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mikeal/forever-agent"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/forever-agent@0.6.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/forever-agent/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/forever-agent/package.json"
              }
            ],
            "concludedValue": "node_modules/forever-agent/package.json"
          }
        ]
      },
      "tags": [
        "socket"
      ]
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "foreground-child",
      "version": "3.3.1",
      "description": "Run a child as if it's the foreground process. Give it stdio. Exit when it exits.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/foreground-child@3.3.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git+https://github.com/tapjs/foreground-child.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/foreground-child@3.3.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/foreground-child/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/foreground-child/package.json"
              }
            ],
            "concludedValue": "node_modules/foreground-child/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "find-up-simple",
      "version": "1.0.1",
      "description": "Find a file or directory by walking up parent directories — Zero dependencies",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/find-up-simple@1.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/find-up-simple@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/find-up-simple/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/find-up-simple/package.json"
              }
            ],
            "concludedValue": "node_modules/find-up-simple/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "find-up",
      "version": "1.1.2",
      "description": "Find a file by walking up parent directories",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/find-up@1.1.2",
      "type": "library",
      "bom-ref": "pkg:npm/find-up@1.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/find-up/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/find-up/package.json"
              }
            ],
            "concludedValue": "node_modules/find-up/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jon Schlinkert (https://github.com/jonschlinkert)"
        }
      ],
      "group": "",
      "name": "fill-range",
      "version": "7.1.1",
      "description": "Fill in a range of numbers or letters, optionally passing an increment or `step` to use, or create a regex-compatible range with `options.toRegex`",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/fill-range@7.1.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jonschlinkert/fill-range"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/fill-range@7.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/fill-range/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/fill-range/package.json"
              }
            ],
            "concludedValue": "node_modules/fill-range/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Nathan Rajlich <nathan@tootallnate.net> (http://n8.io/)"
        }
      ],
      "group": "",
      "name": "file-uri-to-path",
      "version": "1.0.0",
      "description": "Convert a file: URI to a file path",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/file-uri-to-path@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/TooTallNate/file-uri-to-path"
        },
        {
          "type": "vcs",
          "url": "git://github.com/TooTallNate/file-uri-to-path.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/file-uri-to-path@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/file-uri-to-path/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/file-uri-to-path/package.json"
              }
            ],
            "concludedValue": "node_modules/file-uri-to-path/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "figures",
      "version": "6.1.0",
      "description": "Unicode symbols with fallbacks for older terminals",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/figures@6.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/figures@6.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/figures/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/figures/package.json"
              }
            ],
            "concludedValue": "node_modules/figures/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Matteo Collina <hello@matteocollina.com>"
        }
      ],
      "group": "",
      "name": "fastq",
      "version": "1.20.1",
      "description": "Fast, in memory work queue",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/fastq@1.20.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mcollina/fastq#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/mcollina/fastq.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/fastq@1.20.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/fastq/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/fastq/package.json"
              }
            ],
            "concludedValue": "node_modules/fastq/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Ramesh Nair <ram@hiddentao.com> (http://www.hiddentao.com/)"
        }
      ],
      "group": "",
      "name": "fast-levenshtein",
      "version": "2.0.6",
      "description": "Efficient implementation of Levenshtein algorithm  with locale-specific collator support.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/fast-levenshtein@2.0.6",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/hiddentao/fast-levenshtein.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/fast-levenshtein@2.0.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/fast-levenshtein/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/fast-levenshtein/package.json"
              }
            ],
            "concludedValue": "node_modules/fast-levenshtein/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "fast-json-stable-stringify",
      "version": "2.1.0",
      "description": "deterministic `JSON.stringify()` - a faster version of substack's json-stable-strigify without jsonify",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/fast-json-stable-stringify@2.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/epoberezkin/fast-json-stable-stringify"
        },
        {
          "type": "vcs",
          "url": "git://github.com/epoberezkin/fast-json-stable-stringify.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/fast-json-stable-stringify@2.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/fast-json-stable-stringify/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/fast-json-stable-stringify/package.json"
              }
            ],
            "concludedValue": "node_modules/fast-json-stable-stringify/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Denis Malinochkin (https://mrmlnc.com)"
        }
      ],
      "group": "",
      "name": "fast-glob",
      "version": "3.3.3",
      "description": "It's a very fast and efficient glob library for Node.js",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/fast-glob@3.3.3",
      "type": "library",
      "bom-ref": "pkg:npm/fast-glob@3.3.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/fast-glob/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/fast-glob/package.json"
              }
            ],
            "concludedValue": "node_modules/fast-glob/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jason Chen <jhchen7@gmail.com>"
        }
      ],
      "group": "",
      "name": "fast-diff",
      "version": "1.3.0",
      "description": "Fast Javascript text diff",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0",
            "url": "https://opensource.org/licenses/Apache-2.0"
          }
        }
      ],
      "purl": "pkg:npm/fast-diff@1.3.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jhchen/fast-diff"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/fast-diff@1.3.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/fast-diff/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/fast-diff/package.json"
              }
            ],
            "concludedValue": "node_modules/fast-diff/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Evgeny Poberezkin"
        }
      ],
      "group": "",
      "name": "fast-deep-equal",
      "version": "3.1.3",
      "description": "Fast deep equal",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/fast-deep-equal@3.1.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/epoberezkin/fast-deep-equal#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/epoberezkin/fast-deep-equal.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/fast-deep-equal@3.1.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/fast-deep-equal/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/fast-deep-equal/package.json"
              }
            ],
            "concludedValue": "node_modules/fast-deep-equal/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "extsprintf",
      "version": "1.3.0",
      "description": "extended POSIX-style sprintf",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/extsprintf@1.3.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/davepacheco/node-extsprintf.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/extsprintf@1.3.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/extsprintf/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/extsprintf/package.json"
              }
            ],
            "concludedValue": "node_modules/extsprintf/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Stefan Thomas <justmoon@members.fsf.org> (http://www.justmoon.net)"
        }
      ],
      "group": "",
      "name": "extend",
      "version": "3.0.2",
      "description": "Port of jQuery.extend for node.js and the browser",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/extend@3.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/justmoon/node-extend.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/extend@3.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/extend/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/extend/package.json"
              }
            ],
            "concludedValue": "node_modules/extend/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "execa",
      "version": "0.7.0",
      "description": "A better `child_process`",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/execa@0.7.0",
      "type": "library",
      "bom-ref": "pkg:npm/execa@0.7.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/execa/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/execa/package.json"
              }
            ],
            "concludedValue": "node_modules/execa/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "yallist",
      "version": "2.1.2",
      "description": "Yet Another Linked List",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/yallist@2.1.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git+https://github.com/isaacs/yallist.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/yallist@2.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/execa/node_modules/yallist/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/execa/node_modules/yallist/package.json"
              }
            ],
            "concludedValue": "node_modules/execa/node_modules/yallist/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me)"
        }
      ],
      "group": "",
      "name": "which",
      "version": "1.3.1",
      "description": "Like which(1) unix command. Find the first instance of an executable in the PATH.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/which@1.3.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/node-which.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/which@1.3.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/execa/node_modules/which/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/execa/node_modules/which/package.json"
              }
            ],
            "concludedValue": "node_modules/execa/node_modules/which/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "shebang-regex",
      "version": "1.0.0",
      "description": "Regular expression for matching a shebang",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/shebang-regex@1.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/shebang-regex@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/execa/node_modules/shebang-regex/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/execa/node_modules/shebang-regex/package.json"
              }
            ],
            "concludedValue": "node_modules/execa/node_modules/shebang-regex/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Kevin Martensson <kevinmartensson@gmail.com> (github.com/kevva)"
        }
      ],
      "group": "",
      "name": "shebang-command",
      "version": "1.2.0",
      "description": "Get the command from a shebang",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/shebang-command@1.2.0",
      "type": "library",
      "bom-ref": "pkg:npm/shebang-command@1.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/execa/node_modules/shebang-command/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/execa/node_modules/shebang-command/package.json"
              }
            ],
            "concludedValue": "node_modules/execa/node_modules/shebang-command/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me>"
        }
      ],
      "group": "",
      "name": "lru-cache",
      "version": "4.1.5",
      "description": "A cache object that deletes the least-recently-used items.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/lru-cache@4.1.5",
      "type": "library",
      "bom-ref": "pkg:npm/lru-cache@4.1.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/execa/node_modules/lru-cache/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/execa/node_modules/lru-cache/package.json"
              }
            ],
            "concludedValue": "node_modules/execa/node_modules/lru-cache/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "IndigoUnited <hello@indigounited.com> (http://indigounited.com)"
        }
      ],
      "group": "",
      "name": "cross-spawn",
      "version": "5.1.0",
      "description": "Cross platform child_process#spawn and child_process#spawnSync",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/cross-spawn@5.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/IndigoUnited/node-cross-spawn.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/cross-spawn@5.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/execa/node_modules/cross-spawn/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/execa/node_modules/cross-spawn/package.json"
              }
            ],
            "concludedValue": "node_modules/execa/node_modules/cross-spawn/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "esutils",
      "version": "2.0.3",
      "description": "utility box for ECMAScript language tools",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-2-Clause",
            "url": "https://opensource.org/licenses/BSD-2-Clause"
          }
        }
      ],
      "purl": "pkg:npm/esutils@2.0.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/estools/esutils"
        },
        {
          "type": "vcs",
          "url": "http://github.com/estools/esutils.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/esutils@2.0.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/esutils/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/esutils/package.json"
              }
            ],
            "concludedValue": "node_modules/esutils/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Rich Harris"
        }
      ],
      "group": "",
      "name": "estree-walker",
      "version": "2.0.2",
      "description": "Traverse an ESTree-compliant AST",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/estree-walker@2.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/Rich-Harris/estree-walker"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/estree-walker@2.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/estree-walker/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/estree-walker/package.json"
              }
            ],
            "concludedValue": "node_modules/estree-walker/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "estraverse",
      "version": "4.3.0",
      "description": "ECMAScript JS AST traversal functions",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-2-Clause",
            "url": "https://opensource.org/licenses/BSD-2-Clause"
          }
        }
      ],
      "purl": "pkg:npm/estraverse@4.3.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/estools/estraverse"
        },
        {
          "type": "vcs",
          "url": "http://github.com/estools/estraverse.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/estraverse@4.3.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/estraverse/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/estraverse/package.json"
              }
            ],
            "concludedValue": "node_modules/estraverse/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Ariya Hidayat <ariya.hidayat@gmail.com>"
        }
      ],
      "group": "",
      "name": "esprima",
      "version": "4.0.1",
      "description": "ECMAScript parsing infrastructure for multipurpose analysis",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-2-Clause",
            "url": "https://opensource.org/licenses/BSD-2-Clause"
          }
        }
      ],
      "purl": "pkg:npm/esprima@4.0.1",
      "externalReferences": [
        {
          "type": "website",
          "url": "http://esprima.org"
        },
        {
          "type": "vcs",
          "url": "https://github.com/jquery/esprima.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/esprima@4.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/esprima/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/esprima/package.json"
              }
            ],
            "concludedValue": "node_modules/esprima/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "escodegen",
      "version": "1.14.3",
      "description": "ECMAScript code generator",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-2-Clause",
            "url": "https://opensource.org/licenses/BSD-2-Clause"
          }
        }
      ],
      "purl": "pkg:npm/escodegen@1.14.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/estools/escodegen"
        },
        {
          "type": "vcs",
          "url": "http://github.com/estools/escodegen.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/escodegen@1.14.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/escodegen/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/escodegen/package.json"
              }
            ],
            "concludedValue": "node_modules/escodegen/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "escape-string-regexp",
      "version": "5.0.0",
      "description": "Escape RegExp special characters",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/escape-string-regexp@5.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/escape-string-regexp@5.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/escape-string-regexp/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/escape-string-regexp/package.json"
              }
            ],
            "concludedValue": "node_modules/escape-string-regexp/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Luke Edwards <luke.edwards05@gmail.com> (https://lukeed.com)"
        }
      ],
      "group": "",
      "name": "escalade",
      "version": "3.2.0",
      "description": "A tiny (183B to 210B) and fast utility to ascend parent directories",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/escalade@3.2.0",
      "type": "library",
      "bom-ref": "pkg:npm/escalade@3.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/escalade/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/escalade/package.json"
              }
            ],
            "concludedValue": "node_modules/escalade/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jordan Harband <ljharb@gmail.com>"
        }
      ],
      "group": "",
      "name": "es-errors",
      "version": "1.3.0",
      "description": "A simple cache for a few of the JS Error constructors.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/es-errors@1.3.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/ljharb/es-errors#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/ljharb/es-errors.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/es-errors@1.3.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/es-errors/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/es-errors/package.json"
              }
            ],
            "concludedValue": "node_modules/es-errors/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "error-ex",
      "version": "1.3.4",
      "description": "Easy error subclassing and stack customization",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/error-ex@1.3.4",
      "type": "library",
      "bom-ref": "pkg:npm/error-ex@1.3.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/error-ex/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/error-ex/package.json"
              }
            ],
            "concludedValue": "node_modules/error-ex/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mathias Bynens (https://mathiasbynens.be/)"
        }
      ],
      "group": "",
      "name": "emoji-regex",
      "version": "10.6.0",
      "description": "A regular expression to match all Emoji-only symbols as per the Unicode Standard.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/emoji-regex@10.6.0",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://mths.be/emoji-regex"
        },
        {
          "type": "vcs",
          "url": "https://github.com/mathiasbynens/emoji-regex.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/emoji-regex@10.6.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/emoji-regex/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/emoji-regex/package.json"
              }
            ],
            "concludedValue": "node_modules/emoji-regex/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "emittery",
      "version": "1.2.1",
      "description": "Simple and modern async event emitter",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/emittery@1.2.1",
      "type": "library",
      "bom-ref": "pkg:npm/emittery@1.2.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/emittery/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/emittery/package.json"
              }
            ],
            "concludedValue": "node_modules/emittery/package.json"
          }
        ]
      },
      "tags": [
        "event"
      ]
    },
    {
      "authors": [
        {
          "name": "Jeremie Miller <jeremie@jabber.org> (http://jeremie.com/)"
        }
      ],
      "group": "",
      "name": "ecc-jsbn",
      "version": "0.1.2",
      "description": "ECC JS code based on JSBN",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/ecc-jsbn@0.1.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/quartzjer/ecc-jsbn"
        },
        {
          "type": "vcs",
          "url": "https://github.com/quartzjer/ecc-jsbn.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/ecc-jsbn@0.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/ecc-jsbn/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/ecc-jsbn/package.json"
              }
            ],
            "concludedValue": "node_modules/ecc-jsbn/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Masaki Komagata"
        }
      ],
      "group": "",
      "name": "eastasianwidth",
      "version": "0.2.0",
      "description": "Get East Asian Width from a character.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/eastasianwidth@0.2.0",
      "type": "library",
      "bom-ref": "pkg:npm/eastasianwidth@0.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/eastasianwidth/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/eastasianwidth/package.json"
              }
            ],
            "concludedValue": "node_modules/eastasianwidth/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "duplexer3",
      "version": "0.1.5",
      "description": "Like duplexer but using streams3",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-3-Clause",
            "url": "https://opensource.org/licenses/BSD-3-Clause"
          }
        }
      ],
      "purl": "pkg:npm/duplexer3@0.1.5",
      "type": "library",
      "bom-ref": "pkg:npm/duplexer3@0.1.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/duplexer3/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/duplexer3/package.json"
              }
            ],
            "concludedValue": "node_modules/duplexer3/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "dot-prop",
      "version": "4.2.1",
      "description": "Get, set, or delete a property from a nested object using a dot path",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/dot-prop@4.2.1",
      "type": "library",
      "bom-ref": "pkg:npm/dot-prop@4.2.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/dot-prop/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/dot-prop/package.json"
              }
            ],
            "concludedValue": "node_modules/dot-prop/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "doctrine",
      "version": "0.7.2",
      "description": "JSDoc parser",
      "scope": "optional",
      "purl": "pkg:npm/doctrine@0.7.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/eslint/doctrine"
        },
        {
          "type": "vcs",
          "url": "http://github.com/eslint/doctrine.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/doctrine@0.7.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/doctrine/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/doctrine/package.json"
              }
            ],
            "concludedValue": "node_modules/doctrine/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "esutils",
      "version": "1.1.6",
      "description": "utility box for ECMAScript language tools",
      "scope": "optional",
      "purl": "pkg:npm/esutils@1.1.6",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/Constellation/esutils"
        },
        {
          "type": "vcs",
          "url": "http://github.com/Constellation/esutils.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/esutils@1.1.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/doctrine/node_modules/esutils/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/doctrine/node_modules/esutils/package.json"
              }
            ],
            "concludedValue": "node_modules/doctrine/node_modules/esutils/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "diff",
      "version": "4.0.4",
      "description": "A javascript text diff implementation.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-3-Clause",
            "url": "https://opensource.org/licenses/BSD-3-Clause"
          }
        }
      ],
      "purl": "pkg:npm/diff@4.0.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/kpdecker/jsdiff.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/diff@4.0.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/diff/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/diff/package.json"
              }
            ],
            "concludedValue": "node_modules/diff/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Lovell Fuller <npm@lovell.info>"
        }
      ],
      "group": "",
      "name": "detect-libc",
      "version": "2.1.2",
      "description": "Node.js module to detect the C standard library (libc) implementation family and version",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0",
            "url": "https://opensource.org/licenses/Apache-2.0"
          }
        }
      ],
      "purl": "pkg:npm/detect-libc@2.1.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/lovell/detect-libc.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/detect-libc@2.1.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/detect-libc/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/detect-libc/package.json"
              }
            ],
            "concludedValue": "node_modules/detect-libc/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Felix Geisendörfer <felix@debuggable.com> (http://debuggable.com/)"
        }
      ],
      "group": "",
      "name": "delayed-stream",
      "version": "1.0.0",
      "description": "Buffers events from a stream until you are ready to handle them.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/delayed-stream@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/felixge/node-delayed-stream"
        },
        {
          "type": "vcs",
          "url": "git://github.com/felixge/node-delayed-stream.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/delayed-stream@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/delayed-stream/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/delayed-stream/package.json"
              }
            ],
            "concludedValue": "node_modules/delayed-stream/package.json"
          }
        ]
      },
      "tags": [
        "stream"
      ]
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "del-cli",
      "version": "1.1.0",
      "description": "Delete files and directories - Cross-platform",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/del-cli@1.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/del-cli@1.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/del-cli/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/del-cli/package.json"
              }
            ],
            "concludedValue": "node_modules/del-cli/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "del",
      "version": "3.0.0",
      "description": "Delete files and folders",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/del@3.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/del@3.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/del/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/del/package.json"
              }
            ],
            "concludedValue": "node_modules/del/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "p-map",
      "version": "1.2.0",
      "description": "Map over promises concurrently",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/p-map@1.2.0",
      "type": "library",
      "bom-ref": "pkg:npm/p-map@1.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/del/node_modules/p-map/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/del/node_modules/p-map/package.json"
              }
            ],
            "concludedValue": "node_modules/del/node_modules/p-map/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "globby",
      "version": "6.1.0",
      "description": "Extends `glob` with support for multiple patterns and exposes a Promise API",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/globby@6.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/globby@6.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/del/node_modules/globby/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/del/node_modules/globby/package.json"
              }
            ],
            "concludedValue": "node_modules/del/node_modules/globby/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Thorsten Lorenz <thlorenz@gmx.de> (http://thlorenz.com)"
        }
      ],
      "group": "",
      "name": "deep-is",
      "version": "0.1.4",
      "description": "node's assert.deepEqual algorithm except for NaN being equal to NaN",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/deep-is@0.1.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "http://github.com/thlorenz/deep-is.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/deep-is@0.1.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/deep-is/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/deep-is/package.json"
              }
            ],
            "concludedValue": "node_modules/deep-is/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Viacheslav Lotsmanov <lotsmanov89@gmail.com>"
        }
      ],
      "group": "",
      "name": "deep-extend",
      "version": "0.6.0",
      "description": "Recursive object extending",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/deep-extend@0.6.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/unclechu/node-deep-extend"
        },
        {
          "type": "vcs",
          "url": "git://github.com/unclechu/node-deep-extend.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/deep-extend@0.6.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/deep-extend/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/deep-extend/package.json"
              }
            ],
            "concludedValue": "node_modules/deep-extend/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "decamelize",
      "version": "1.2.0",
      "description": "Convert a camelized string into a lowercased one with a custom separator: unicornRainbow → unicorn_rainbow",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/decamelize@1.2.0",
      "type": "library",
      "bom-ref": "pkg:npm/decamelize@1.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/decamelize/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/decamelize/package.json"
              }
            ],
            "concludedValue": "node_modules/decamelize/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Josh Junon (https://github.com/qix-)"
        }
      ],
      "group": "",
      "name": "debug",
      "version": "4.4.3",
      "description": "Lightweight debugging utility for Node.js and the browser",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/debug@4.4.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/debug-js/debug.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/debug@4.4.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/debug/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/debug/package.json"
              }
            ],
            "concludedValue": "node_modules/debug/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "date-time",
      "version": "3.1.0",
      "description": "Pretty datetime: `2014-01-09 06:46:01`",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/date-time@3.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/date-time@3.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/date-time/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/date-time/package.json"
              }
            ],
            "concludedValue": "node_modules/date-time/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Trent Mick <trentm@gmail.com> (http://trentm.com)"
        }
      ],
      "group": "",
      "name": "dashdash",
      "version": "1.14.1",
      "description": "A light, featureful and explicit option parsing library.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/dashdash@1.14.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/trentm/node-dashdash.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/dashdash@1.14.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/dashdash/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/dashdash/package.json"
              }
            ],
            "concludedValue": "node_modules/dashdash/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Talmage <james@talmage.io> (github.com/jamestalmage)"
        }
      ],
      "group": "",
      "name": "currently-unhandled",
      "version": "0.4.1",
      "description": "Track the list of currently unhandled promise rejections.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/currently-unhandled@0.4.1",
      "type": "library",
      "bom-ref": "pkg:npm/currently-unhandled@0.4.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/currently-unhandled/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/currently-unhandled/package.json"
              }
            ],
            "concludedValue": "node_modules/currently-unhandled/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "cssstyle",
      "version": "0.2.37",
      "description": "CSSStyleDeclaration Object Model implementation",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/cssstyle@0.2.37",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/chad3814/CSSStyleDeclaration"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/cssstyle@0.2.37",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/cssstyle/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/cssstyle/package.json"
              }
            ],
            "concludedValue": "node_modules/cssstyle/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Nikita Vasilyev <me@elv1s.ru>"
        }
      ],
      "group": "",
      "name": "cssom",
      "version": "0.3.8",
      "description": "CSS Object Model implementation and CSS parser",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/cssom@0.3.8",
      "type": "library",
      "bom-ref": "pkg:npm/cssom@0.3.8",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/cssom/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/cssom/package.json"
              }
            ],
            "concludedValue": "node_modules/cssom/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "crypto-random-string",
      "version": "1.0.0",
      "description": "Generate a cryptographically strong random string",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/crypto-random-string@1.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/crypto-random-string@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/crypto-random-string/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/crypto-random-string/package.json"
              }
            ],
            "concludedValue": "node_modules/crypto-random-string/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "André Cruz <andre@moxy.studio>"
        }
      ],
      "group": "",
      "name": "cross-spawn",
      "version": "7.0.6",
      "description": "Cross platform child_process#spawn and child_process#spawnSync",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/cross-spawn@7.0.6",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/moxystudio/node-cross-spawn"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/cross-spawn@7.0.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/cross-spawn/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/cross-spawn/package.json"
              }
            ],
            "concludedValue": "node_modules/cross-spawn/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Vsevolod Strukchinsky <floatdrop@gmail.com> (github.com/floatdrop)"
        }
      ],
      "group": "",
      "name": "create-error-class",
      "version": "3.0.2",
      "description": "Create Error classes",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/create-error-class@3.0.2",
      "type": "library",
      "bom-ref": "pkg:npm/create-error-class@3.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/create-error-class/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/create-error-class/package.json"
              }
            ],
            "concludedValue": "node_modules/create-error-class/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "core-util-is",
      "version": "1.0.2",
      "description": "The `util.is*` functions introduced in Node v0.12.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/core-util-is@1.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/core-util-is"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/core-util-is@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/core-util-is/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/core-util-is/package.json"
              }
            ],
            "concludedValue": "node_modules/core-util-is/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Vadim Demedes <vdemedes@gmail.com>"
        }
      ],
      "group": "",
      "name": "convert-to-spaces",
      "version": "2.0.1",
      "description": "Convert tabs to spaces in a string",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/convert-to-spaces@2.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/convert-to-spaces@2.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/convert-to-spaces/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/convert-to-spaces/package.json"
              }
            ],
            "concludedValue": "node_modules/convert-to-spaces/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Domenic Denicola <d@domenic.me> (https://domenic.me/)"
        }
      ],
      "group": "",
      "name": "content-type-parser",
      "version": "1.0.2",
      "description": "Parse the value of the Content-Type header",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/content-type-parser@1.0.2",
      "type": "library",
      "bom-ref": "pkg:npm/content-type-parser@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/content-type-parser/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/content-type-parser/package.json"
              }
            ],
            "concludedValue": "node_modules/content-type-parser/package.json"
          }
        ]
      },
      "tags": [
        "parse"
      ]
    },
    {
      "group": "",
      "name": "consola",
      "version": "3.4.2",
      "description": "Elegant Console Wrapper",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/consola@3.4.2",
      "type": "library",
      "bom-ref": "pkg:npm/consola@3.4.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/consola/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/consola/package.json"
              }
            ],
            "concludedValue": "node_modules/consola/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "configstore",
      "version": "3.1.5",
      "description": "Easily load and save config without having to think about where and how",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-2-Clause",
            "url": "https://opensource.org/licenses/BSD-2-Clause"
          }
        }
      ],
      "purl": "pkg:npm/configstore@3.1.5",
      "type": "library",
      "bom-ref": "pkg:npm/configstore@3.1.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/configstore/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/configstore/package.json"
              }
            ],
            "concludedValue": "node_modules/configstore/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Rebecca Turner <me@re-becca.org> (http://re-becca.org)"
        }
      ],
      "group": "",
      "name": "write-file-atomic",
      "version": "2.4.3",
      "description": "Write files in an atomic fashion w/configurable ownership",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/write-file-atomic@2.4.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/iarna/write-file-atomic"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/write-file-atomic@2.4.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/configstore/node_modules/write-file-atomic/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/configstore/node_modules/write-file-atomic/package.json"
              }
            ],
            "concludedValue": "node_modules/configstore/node_modules/write-file-atomic/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mark Wubben (https://novemberborn.net/)"
        }
      ],
      "group": "",
      "name": "concordance",
      "version": "5.0.4",
      "description": "Compare, format, diff and serialize any JavaScript value",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/concordance@5.0.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/concordancejs/concordance#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/concordancejs/concordance.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/concordance@5.0.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/concordance/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/concordance/package.json"
              }
            ],
            "concludedValue": "node_modules/concordance/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "James Halliday <mail@substack.net> (http://substack.net)"
        }
      ],
      "group": "",
      "name": "concat-map",
      "version": "0.0.1",
      "description": "concatenative mapdashery",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/concat-map@0.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/substack/node-concat-map.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/concat-map@0.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/concat-map/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/concat-map/package.json"
              }
            ],
            "concludedValue": "node_modules/concat-map/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mark Wubben (https://novemberborn.net/)"
        }
      ],
      "group": "",
      "name": "common-path-prefix",
      "version": "3.0.0",
      "description": "Computes the longest prefix string that is common to each path, excluding the base component",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/common-path-prefix@3.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/novemberborn/common-path-prefix#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/novemberborn/common-path-prefix.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/common-path-prefix@3.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/common-path-prefix/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/common-path-prefix/package.json"
              }
            ],
            "concludedValue": "node_modules/common-path-prefix/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "TJ Holowaychuk <tj@vision-media.ca>"
        }
      ],
      "group": "",
      "name": "commander",
      "version": "2.20.3",
      "description": "the complete solution for node.js command-line programs",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/commander@2.20.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/tj/commander.js.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/commander@2.20.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/commander/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/commander/package.json"
              }
            ],
            "concludedValue": "node_modules/commander/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Felix Geisendörfer <felix@debuggable.com> (http://debuggable.com/)"
        }
      ],
      "group": "",
      "name": "combined-stream",
      "version": "1.0.8",
      "description": "A stream that emits multiple other streams one after another.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/combined-stream@1.0.8",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/felixge/node-combined-stream"
        },
        {
          "type": "vcs",
          "url": "git://github.com/felixge/node-combined-stream.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/combined-stream@1.0.8",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/combined-stream/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/combined-stream/package.json"
              }
            ],
            "concludedValue": "node_modules/combined-stream/package.json"
          }
        ]
      },
      "tags": [
        "stream"
      ]
    },
    {
      "authors": [
        {
          "name": "DY <dfcreative@gmail.com>"
        }
      ],
      "group": "",
      "name": "color-name",
      "version": "1.1.3",
      "description": "A list of color names and its values",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/color-name@1.1.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/dfcreative/color-name"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/color-name@1.1.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/color-name/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/color-name/package.json"
              }
            ],
            "concludedValue": "node_modules/color-name/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Heather Arthur <fayearthur@gmail.com>"
        }
      ],
      "group": "",
      "name": "color-convert",
      "version": "1.9.3",
      "description": "Plain color conversion functions",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/color-convert@1.9.3",
      "type": "library",
      "bom-ref": "pkg:npm/color-convert@1.9.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/color-convert/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/color-convert/package.json"
              }
            ],
            "concludedValue": "node_modules/color-convert/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "vdemedes <vdemedes@gmail.com> (github.com/vadimdemedes)"
        }
      ],
      "group": "",
      "name": "code-excerpt",
      "version": "4.0.0",
      "description": "Extract code excerpts",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/code-excerpt@4.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/code-excerpt@4.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/code-excerpt/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/code-excerpt/package.json"
              }
            ],
            "concludedValue": "node_modules/code-excerpt/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Ben Coe <ben@npmjs.com>"
        }
      ],
      "group": "",
      "name": "cliui",
      "version": "8.0.1",
      "description": "easily create complex multi-column command-line-interfaces",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/cliui@8.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/cliui@8.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/cliui/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/cliui/package.json"
              }
            ],
            "concludedValue": "node_modules/cliui/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "cli-truncate",
      "version": "4.0.0",
      "description": "Truncate a string to a specific width in the terminal",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/cli-truncate@4.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/cli-truncate@4.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/cli-truncate/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/cli-truncate/package.json"
              }
            ],
            "concludedValue": "node_modules/cli-truncate/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "cli-boxes",
      "version": "1.0.0",
      "description": "Boxes for use in the terminal",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/cli-boxes@1.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/cli-boxes@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/cli-boxes/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/cli-boxes/package.json"
              }
            ],
            "concludedValue": "node_modules/cli-boxes/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jamie Kyle <me@thejameskyle.com>"
        }
      ],
      "group": "",
      "name": "ci-parallel-vars",
      "version": "1.0.1",
      "description": "Get CI environment variables for parallelizing builds",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/ci-parallel-vars@1.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/ci-parallel-vars@1.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/ci-parallel-vars/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/ci-parallel-vars/package.json"
              }
            ],
            "concludedValue": "node_modules/ci-parallel-vars/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Thomas Watson Steen <w@tson.dk> (https://twitter.com/wa7son)"
        }
      ],
      "group": "",
      "name": "ci-info",
      "version": "4.4.0",
      "description": "Get details about the current Continuous Integration environment",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/ci-info@4.4.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/watson/ci-info"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/ci-info@4.4.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/ci-info/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/ci-info/package.json"
              }
            ],
            "concludedValue": "node_modules/ci-info/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jamie Kyle <me@thejameskyle.com>"
        }
      ],
      "group": "",
      "name": "chunkd",
      "version": "2.0.1",
      "description": "Get a chunk of an array based on the total number of chunks and current index",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/chunkd@2.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/chunkd@2.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/chunkd/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/chunkd/package.json"
              }
            ],
            "concludedValue": "node_modules/chunkd/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
        }
      ],
      "group": "",
      "name": "chownr",
      "version": "3.0.0",
      "description": "like `chown -R`",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BlueOak-1.0.0",
            "url": "https://opensource.org/licenses/BlueOak-1.0.0"
          }
        }
      ],
      "purl": "pkg:npm/chownr@3.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/isaacs/chownr.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/chownr@3.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/chownr/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/chownr/package.json"
              }
            ],
            "concludedValue": "node_modules/chownr/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "chalk",
      "version": "5.6.2",
      "description": "Terminal string styling done right",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/chalk@5.6.2",
      "type": "library",
      "bom-ref": "pkg:npm/chalk@5.6.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/chalk/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/chalk/package.json"
              }
            ],
            "concludedValue": "node_modules/chalk/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Joe Hildebrand <joe-github@cursive.net>"
        }
      ],
      "group": "",
      "name": "cbor",
      "version": "10.0.12",
      "description": "Encode and parse data in the Concise Binary Object Representation (CBOR) data format (RFC8949).",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/cbor@10.0.12",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/hildjj/node-cbor/tree/main/packages/cbor"
        },
        {
          "type": "vcs",
          "url": "git+ssh://git@github.com/hildjj/node-cbor.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/cbor@10.0.12",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/cbor/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/cbor/package.json"
              }
            ],
            "concludedValue": "node_modules/cbor/package.json"
          }
        ]
      },
      "tags": [
        "binary",
        "parse"
      ]
    },
    {
      "authors": [
        {
          "name": "Mikeal Rogers <mikeal.rogers@gmail.com>"
        }
      ],
      "group": "",
      "name": "caseless",
      "version": "0.12.0",
      "description": "Caseless object set/get/has, very useful when working with HTTP headers.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0",
            "url": "https://opensource.org/licenses/Apache-2.0"
          }
        }
      ],
      "purl": "pkg:npm/caseless@0.12.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mikeal/caseless"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/caseless@0.12.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/caseless/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/caseless/package.json"
              }
            ],
            "concludedValue": "node_modules/caseless/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Vsevolod Strukchinsky <floatdrop@gmail.com> (https://github.com/floatdrop)"
        }
      ],
      "group": "",
      "name": "capture-stack-trace",
      "version": "1.0.2",
      "description": "Error.captureStackTrace ponyfill",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/capture-stack-trace@1.0.2",
      "type": "library",
      "bom-ref": "pkg:npm/capture-stack-trace@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/capture-stack-trace/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/capture-stack-trace/package.json"
              }
            ],
            "concludedValue": "node_modules/capture-stack-trace/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (http://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "camelcase-keys",
      "version": "2.1.0",
      "description": "Convert object keys to camelCase",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/camelcase-keys@2.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/camelcase-keys@2.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/camelcase-keys/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/camelcase-keys/package.json"
              }
            ],
            "concludedValue": "node_modules/camelcase-keys/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (http://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "camelcase",
      "version": "2.1.1",
      "description": "Convert a dash/dot/underscore/space separated string to camelCase: foo-bar → fooBar",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/camelcase@2.1.1",
      "type": "library",
      "bom-ref": "pkg:npm/camelcase@2.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/camelcase/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/camelcase/package.json"
              }
            ],
            "concludedValue": "node_modules/camelcase/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "callsites",
      "version": "4.2.0",
      "description": "Get callsites from the V8 stack trace API",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/callsites@4.2.0",
      "type": "library",
      "bom-ref": "pkg:npm/callsites@4.2.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/callsites/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/callsites/package.json"
              }
            ],
            "concludedValue": "node_modules/callsites/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "builtin-modules",
      "version": "1.1.1",
      "description": "List of the Node.js builtin modules",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/builtin-modules@1.1.1",
      "type": "library",
      "bom-ref": "pkg:npm/builtin-modules@1.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/builtin-modules/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/builtin-modules/package.json"
              }
            ],
            "concludedValue": "node_modules/builtin-modules/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jon Schlinkert (https://github.com/jonschlinkert)"
        }
      ],
      "group": "",
      "name": "braces",
      "version": "3.0.3",
      "description": "Bash-like brace expansion, implemented in JavaScript. Safer than other brace expansion libs, with complete support for the Bash 4.3 braces specification, without sacrificing speed.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/braces@3.0.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/micromatch/braces"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/braces@3.0.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/braces/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/braces/package.json"
              }
            ],
            "concludedValue": "node_modules/braces/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Julian Gruber <mail@juliangruber.com> (http://juliangruber.com)"
        }
      ],
      "group": "",
      "name": "brace-expansion",
      "version": "2.1.0",
      "description": "Brace expansion as known from sh/bash",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/brace-expansion@2.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/juliangruber/brace-expansion"
        },
        {
          "type": "vcs",
          "url": "git://github.com/juliangruber/brace-expansion.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/brace-expansion@2.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/brace-expansion/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/brace-expansion/package.json"
              }
            ],
            "concludedValue": "node_modules/brace-expansion/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "boxen",
      "version": "1.3.0",
      "description": "Create boxes in the terminal",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/boxen@1.3.0",
      "type": "library",
      "bom-ref": "pkg:npm/boxen@1.3.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/boxen/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/boxen/package.json"
              }
            ],
            "concludedValue": "node_modules/boxen/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "camelcase",
      "version": "4.1.0",
      "description": "Convert a dash/dot/underscore/space separated string to camelCase: foo-bar → fooBar",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/camelcase@4.1.0",
      "type": "library",
      "bom-ref": "pkg:npm/camelcase@4.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/boxen/node_modules/camelcase/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/boxen/node_modules/camelcase/package.json"
              }
            ],
            "concludedValue": "node_modules/boxen/node_modules/camelcase/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sebastian Tschan (https://blueimp.net)"
        }
      ],
      "group": "",
      "name": "blueimp-md5",
      "version": "2.19.0",
      "description": "JavaScript MD5 implementation. Compatible with server-side environments like Node.js, module loaders like RequireJS, Browserify or webpack and all web browsers.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/blueimp-md5@2.19.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/blueimp/JavaScript-MD5"
        },
        {
          "type": "vcs",
          "url": "git://github.com/blueimp/JavaScript-MD5.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/blueimp-md5@2.19.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/blueimp-md5/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/blueimp-md5/package.json"
              }
            ],
            "concludedValue": "node_modules/blueimp-md5/package.json"
          }
        ]
      },
      "tags": [
        "web"
      ]
    },
    {
      "authors": [
        {
          "name": "Nathan Rajlich <nathan@tootallnate.net> (http://tootallnate.net)"
        }
      ],
      "group": "",
      "name": "bindings",
      "version": "1.5.0",
      "description": "Helper module for loading your native module's .node file",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/bindings@1.5.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/TooTallNate/node-bindings"
        },
        {
          "type": "vcs",
          "url": "git://github.com/TooTallNate/node-bindings.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/bindings@1.5.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/bindings/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/bindings/package.json"
              }
            ],
            "concludedValue": "node_modules/bindings/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "bcrypt-pbkdf",
      "version": "1.0.2",
      "description": "Port of the OpenBSD bcrypt_pbkdf function to pure JS",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-3-Clause",
            "url": "https://opensource.org/licenses/BSD-3-Clause"
          }
        }
      ],
      "purl": "pkg:npm/bcrypt-pbkdf@1.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/joyent/node-bcrypt-pbkdf.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/bcrypt-pbkdf@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/bcrypt-pbkdf/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/bcrypt-pbkdf/package.json"
              }
            ],
            "concludedValue": "node_modules/bcrypt-pbkdf/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Julian Gruber <mail@juliangruber.com> (http://juliangruber.com)"
        }
      ],
      "group": "",
      "name": "balanced-match",
      "version": "1.0.2",
      "description": "Match balanced character pairs, like \"{\" and \"}\"",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/balanced-match@1.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/juliangruber/balanced-match"
        },
        {
          "type": "vcs",
          "url": "git://github.com/juliangruber/balanced-match.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/balanced-match@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/balanced-match/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/balanced-match/package.json"
              }
            ],
            "concludedValue": "node_modules/balanced-match/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Michael Hart <michael.hart.au@gmail.com> (https://github.com/mhart)"
        }
      ],
      "group": "",
      "name": "aws4",
      "version": "1.13.2",
      "description": "Signs and prepares requests using AWS Signature Version 4",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/aws4@1.13.2",
      "type": "library",
      "bom-ref": "pkg:npm/aws4@1.13.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/aws4/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/aws4/package.json"
              }
            ],
            "concludedValue": "node_modules/aws4/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mikeal Rogers <mikeal.rogers@gmail.com> (http://www.futurealoof.com)"
        }
      ],
      "group": "",
      "name": "aws-sign2",
      "version": "0.7.0",
      "description": "AWS signing. Originally pulled from LearnBoost/knox, maintained as vendor in request, now a standalone module.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0",
            "url": "https://opensource.org/licenses/Apache-2.0"
          }
        }
      ],
      "purl": "pkg:npm/aws-sign2@0.7.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mikeal/aws-sign"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/aws-sign2@0.7.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/aws-sign2/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/aws-sign2/package.json"
              }
            ],
            "concludedValue": "node_modules/aws-sign2/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "ava",
      "version": "6.4.1",
      "description": "Node.js test runner that lets you develop with confidence.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/ava@6.4.1",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://avajs.dev"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/avajs/ava.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/ava@6.4.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/ava/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/ava/package.json"
              }
            ],
            "concludedValue": "node_modules/ava/package.json"
          }
        ]
      },
      "tags": [
        "test"
      ]
    },
    {
      "authors": [
        {
          "name": "Alex Indigo <iam@alexindigo.com>"
        }
      ],
      "group": "",
      "name": "asynckit",
      "version": "0.4.0",
      "description": "Minimal async jobs utility library, with streams support",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/asynckit@0.4.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/alexindigo/asynckit#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/alexindigo/asynckit.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/asynckit@0.4.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/asynckit/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/asynckit/package.json"
              }
            ],
            "concludedValue": "node_modules/asynckit/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Olli Vanhoja"
        }
      ],
      "group": "",
      "name": "async-sema",
      "version": "3.1.1",
      "description": "Semaphore using `async` and `await`",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/async-sema@3.1.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/vercel/async-sema"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/vercel/async-sema.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/async-sema@3.1.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/async-sema/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/async-sema/package.json"
              }
            ],
            "concludedValue": "node_modules/async-sema/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Mark Cavage <mcavage@gmail.com>"
        }
      ],
      "group": "",
      "name": "assert-plus",
      "version": "1.0.0",
      "description": "Extra assertions on top of node's assert module",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/assert-plus@1.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/mcavage/node-assert-plus.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/assert-plus@1.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/assert-plus/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/assert-plus/package.json"
              }
            ],
            "concludedValue": "node_modules/assert-plus/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Joyent (joyent.com)"
        }
      ],
      "group": "",
      "name": "asn1",
      "version": "0.2.6",
      "description": "Contains parsers and serializers for ASN.1 (currently BER only)",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/asn1@0.2.6",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/joyent/node-asn1.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/asn1@0.2.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/asn1/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/asn1/package.json"
              }
            ],
            "concludedValue": "node_modules/asn1/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "arrify",
      "version": "3.0.0",
      "description": "Convert a value to an array",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/arrify@3.0.0",
      "type": "library",
      "bom-ref": "pkg:npm/arrify@3.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/arrify/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/arrify/package.json"
              }
            ],
            "concludedValue": "node_modules/arrify/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "astur <astur@yandex.ru> (http://kozlov.am/)"
        }
      ],
      "group": "",
      "name": "arrgv",
      "version": "1.0.2",
      "description": "Parsing string to array of args like node on bash do.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/arrgv@1.0.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/astur/arrgv.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/arrgv@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/arrgv/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/arrgv/package.json"
              }
            ],
            "concludedValue": "node_modules/arrgv/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "array-uniq",
      "version": "1.0.3",
      "description": "Create an array without duplicates",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/array-uniq@1.0.3",
      "type": "library",
      "bom-ref": "pkg:npm/array-uniq@1.0.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/array-uniq/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/array-uniq/package.json"
              }
            ],
            "concludedValue": "node_modules/array-uniq/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "array-union",
      "version": "1.0.2",
      "description": "Create an array of unique values, in order, from the input arrays",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/array-union@1.0.2",
      "type": "library",
      "bom-ref": "pkg:npm/array-union@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/array-union/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/array-union/package.json"
              }
            ],
            "concludedValue": "node_modules/array-union/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "array-find-index",
      "version": "1.0.2",
      "description": "ES2015 `Array#findIndex()` ponyfill",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/array-find-index@1.0.2",
      "type": "library",
      "bom-ref": "pkg:npm/array-find-index@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/array-find-index/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/array-find-index/package.json"
              }
            ],
            "concludedValue": "node_modules/array-find-index/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jonathan Ong <me@jongleberry.com> (http://jongleberry.com)"
        }
      ],
      "group": "",
      "name": "array-equal",
      "version": "1.0.2",
      "description": "Check if two arrays are equal",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/array-equal@1.0.2",
      "type": "library",
      "bom-ref": "pkg:npm/array-equal@1.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/array-equal/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/array-equal/package.json"
              }
            ],
            "concludedValue": "node_modules/array-equal/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "argparse",
      "version": "1.0.10",
      "description": "Very powerful CLI arguments parser. Native port of argparse - python's options parsing library",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/argparse@1.0.10",
      "type": "library",
      "bom-ref": "pkg:npm/argparse@1.0.10",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/argparse/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/argparse/package.json"
              }
            ],
            "concludedValue": "node_modules/argparse/package.json"
          }
        ]
      },
      "tags": [
        "cli"
      ]
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "ansi-styles",
      "version": "6.2.3",
      "description": "ANSI escape codes for styling strings in the terminal",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/ansi-styles@6.2.3",
      "type": "library",
      "bom-ref": "pkg:npm/ansi-styles@6.2.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/ansi-styles/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/ansi-styles/package.json"
              }
            ],
            "concludedValue": "node_modules/ansi-styles/package.json"
          }
        ]
      },
      "tags": [
        "escape"
      ]
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "",
      "name": "ansi-regex",
      "version": "6.2.2",
      "description": "Regular expression for matching ANSI escape codes",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/ansi-regex@6.2.2",
      "type": "library",
      "bom-ref": "pkg:npm/ansi-regex@6.2.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/ansi-regex/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/ansi-regex/package.json"
              }
            ],
            "concludedValue": "node_modules/ansi-regex/package.json"
          }
        ]
      },
      "tags": [
        "escape"
      ]
    },
    {
      "authors": [
        {
          "name": "nexdrew"
        }
      ],
      "group": "",
      "name": "ansi-align",
      "version": "2.0.0",
      "description": "align-text with ANSI support for CLIs",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/ansi-align@2.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/nexdrew/ansi-align#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/nexdrew/ansi-align.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/ansi-align@2.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/ansi-align/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/ansi-align/package.json"
              }
            ],
            "concludedValue": "node_modules/ansi-align/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Evgeny Poberezkin"
        }
      ],
      "group": "",
      "name": "ajv",
      "version": "6.15.0",
      "description": "Another JSON Schema Validator",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/ajv@6.15.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/ajv-validator/ajv"
        },
        {
          "type": "vcs",
          "url": "https://github.com/ajv-validator/ajv.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/ajv@6.15.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/ajv/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/ajv/package.json"
              }
            ],
            "concludedValue": "node_modules/ajv/package.json"
          }
        ]
      },
      "tags": [
        "json"
      ]
    },
    {
      "authors": [
        {
          "name": "Nathan Rajlich <nathan@tootallnate.net> (http://n8.io/)"
        }
      ],
      "group": "",
      "name": "agent-base",
      "version": "7.1.4",
      "description": "Turn a function into an `http.Agent` instance",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/agent-base@7.1.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/TooTallNate/proxy-agents.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/agent-base@7.1.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/agent-base/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/agent-base/package.json"
              }
            ],
            "concludedValue": "node_modules/agent-base/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "acorn-walk",
      "version": "8.3.5",
      "description": "ECMAScript (ESTree) AST walker",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/acorn-walk@8.3.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/acornjs/acorn"
        },
        {
          "type": "vcs",
          "url": "https://github.com/acornjs/acorn.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/acorn-walk@8.3.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/acorn-walk/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/acorn-walk/package.json"
              }
            ],
            "concludedValue": "node_modules/acorn-walk/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sven Sauleau <sven@sauleau.com>"
        }
      ],
      "group": "",
      "name": "acorn-import-attributes",
      "version": "1.9.5",
      "description": "Support for import attributes in acorn",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/acorn-import-attributes@1.9.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/xtuc/acorn-import-attributes"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/acorn-import-attributes@1.9.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/acorn-import-attributes/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/acorn-import-attributes/package.json"
              }
            ],
            "concludedValue": "node_modules/acorn-import-attributes/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "ForbesLindesay"
        }
      ],
      "group": "",
      "name": "acorn-globals",
      "version": "3.1.0",
      "description": "Detect global variables in JavaScript using acorn",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/acorn-globals@3.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/ForbesLindesay/acorn-globals.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/acorn-globals@3.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/acorn-globals/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/acorn-globals/package.json"
              }
            ],
            "concludedValue": "node_modules/acorn-globals/package.json"
          }
        ]
      }
    },
    {
      "group": "",
      "name": "acorn",
      "version": "8.16.0",
      "description": "ECMAScript parser",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/acorn@8.16.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/acornjs/acorn"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/acornjs/acorn.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/acorn@8.16.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/acorn/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/acorn/package.json"
              }
            ],
            "concludedValue": "node_modules/acorn/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "GitHub Inc."
        }
      ],
      "group": "",
      "name": "abbrev",
      "version": "3.0.1",
      "description": "Like ruby's abbrev module, but in js",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/abbrev@3.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git+https://github.com/npm/abbrev-js.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/abbrev@3.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/abbrev/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/abbrev/package.json"
              }
            ],
            "concludedValue": "node_modules/abbrev/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Jeff Carpenter <gcarpenterv@gmail.com>"
        }
      ],
      "group": "",
      "name": "abab",
      "version": "1.0.4",
      "description": "WHATWG spec-compliant implementations of window.atob and window.btoa.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/abab@1.0.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/jsdom/abab#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/jsdom/abab.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/abab@1.0.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/abab/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/abab/package.json"
              }
            ],
            "concludedValue": "node_modules/abab/package.json"
          }
        ]
      }
    },
    {
      "group": "@vercel",
      "name": "nft",
      "version": "0.29.4",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40vercel/nft@0.29.4",
      "type": "library",
      "bom-ref": "pkg:npm/@vercel/nft@0.29.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@vercel/nft/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@vercel/nft/package.json"
              }
            ],
            "concludedValue": "node_modules/@vercel/nft/package.json"
          }
        ]
      }
    },
    {
      "group": "@types",
      "name": "tempy",
      "version": "0.1.0",
      "description": "TypeScript definitions for tempy",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40types/tempy@0.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://www.github.com/DefinitelyTyped/DefinitelyTyped.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@types/tempy@0.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@types/tempy/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@types/tempy/package.json"
              }
            ],
            "concludedValue": "node_modules/@types/tempy/package.json"
          }
        ]
      }
    },
    {
      "group": "@types",
      "name": "node",
      "version": "8.10.66",
      "description": "TypeScript definitions for Node.js",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40types/node@8.10.66",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/DefinitelyTyped/DefinitelyTyped.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@types/node@8.10.66",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@types/node/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@types/node/package.json"
              }
            ],
            "concludedValue": "node_modules/@types/node/package.json"
          }
        ]
      }
    },
    {
      "group": "@types",
      "name": "jsdom",
      "version": "2.0.34",
      "description": "TypeScript definitions for jsdom",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40types/jsdom@2.0.34",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/jsdom"
        },
        {
          "type": "vcs",
          "url": "https://github.com/DefinitelyTyped/DefinitelyTyped.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@types/jsdom@2.0.34",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@types/jsdom/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@types/jsdom/package.json"
              }
            ],
            "concludedValue": "node_modules/@types/jsdom/package.json"
          }
        ]
      }
    },
    {
      "group": "@types",
      "name": "jquery",
      "version": "4.0.0",
      "description": "TypeScript definitions for jquery",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40types/jquery@4.0.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/jquery"
        },
        {
          "type": "vcs",
          "url": "https://github.com/DefinitelyTyped/DefinitelyTyped.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@types/jquery@4.0.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@types/jquery/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@types/jquery/package.json"
              }
            ],
            "concludedValue": "node_modules/@types/jquery/package.json"
          }
        ]
      }
    },
    {
      "group": "@types",
      "name": "estree",
      "version": "1.0.8",
      "description": "TypeScript definitions for estree",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40types/estree@1.0.8",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/estree"
        },
        {
          "type": "vcs",
          "url": "https://github.com/DefinitelyTyped/DefinitelyTyped.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@types/estree@1.0.8",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@types/estree/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@types/estree/package.json"
              }
            ],
            "concludedValue": "node_modules/@types/estree/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)"
        }
      ],
      "group": "@sindresorhus",
      "name": "merge-streams",
      "version": "2.3.0",
      "description": "Merge multiple streams into a unified stream",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40sindresorhus/merge-streams@2.3.0",
      "type": "library",
      "bom-ref": "pkg:npm/@sindresorhus/merge-streams@2.3.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@sindresorhus/merge-streams/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@sindresorhus/merge-streams/package.json"
              }
            ],
            "concludedValue": "node_modules/@sindresorhus/merge-streams/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Rich Harris <richard.a.harris@gmail.com>"
        }
      ],
      "group": "@rollup",
      "name": "pluginutils",
      "version": "5.3.0",
      "description": "A set of utility functions commonly used by Rollup plugins",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40rollup/pluginutils@5.3.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/rollup/plugins/tree/master/packages/pluginutils#readme"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@rollup/pluginutils@5.3.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@rollup/pluginutils/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@rollup/pluginutils/package.json"
              }
            ],
            "concludedValue": "node_modules/@rollup/pluginutils/package.json"
          }
        ]
      }
    },
    {
      "group": "@pkgjs",
      "name": "parseargs",
      "version": "0.11.0",
      "description": "Polyfill of future proposal for `util.parseArgs()`",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40pkgjs/parseargs@0.11.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/pkgjs/parseargs#readme"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@pkgjs/parseargs@0.11.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@pkgjs/parseargs/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@pkgjs/parseargs/package.json"
              }
            ],
            "concludedValue": "node_modules/@pkgjs/parseargs/package.json"
          }
        ]
      }
    },
    {
      "group": "@nodelib",
      "name": "fs.walk",
      "version": "1.2.8",
      "description": "A library for efficiently walking a directory recursively",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40nodelib/fs.walk@1.2.8",
      "type": "library",
      "bom-ref": "pkg:npm/@nodelib/fs.walk@1.2.8",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@nodelib/fs.walk/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@nodelib/fs.walk/package.json"
              }
            ],
            "concludedValue": "node_modules/@nodelib/fs.walk/package.json"
          }
        ]
      }
    },
    {
      "group": "@nodelib",
      "name": "fs.stat",
      "version": "2.0.5",
      "description": "Get the status of a file with some features",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40nodelib/fs.stat@2.0.5",
      "type": "library",
      "bom-ref": "pkg:npm/@nodelib/fs.stat@2.0.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@nodelib/fs.stat/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@nodelib/fs.stat/package.json"
              }
            ],
            "concludedValue": "node_modules/@nodelib/fs.stat/package.json"
          }
        ]
      }
    },
    {
      "group": "@nodelib",
      "name": "fs.scandir",
      "version": "2.1.5",
      "description": "List files and directories inside the specified directory",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40nodelib/fs.scandir@2.1.5",
      "type": "library",
      "bom-ref": "pkg:npm/@nodelib/fs.scandir@2.1.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@nodelib/fs.scandir/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@nodelib/fs.scandir/package.json"
              }
            ],
            "concludedValue": "node_modules/@nodelib/fs.scandir/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Dane Springmeyer <dane@mapbox.com>"
        }
      ],
      "group": "@mapbox",
      "name": "node-pre-gyp",
      "version": "2.0.3",
      "description": "Node.js native addon binary install tool",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "BSD-3-Clause",
            "url": "https://opensource.org/licenses/BSD-3-Clause"
          }
        }
      ],
      "purl": "pkg:npm/%40mapbox/node-pre-gyp@2.0.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git://github.com/mapbox/node-pre-gyp.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@mapbox/node-pre-gyp@2.0.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@mapbox/node-pre-gyp/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@mapbox/node-pre-gyp/package.json"
              }
            ],
            "concludedValue": "node_modules/@mapbox/node-pre-gyp/package.json"
          }
        ]
      },
      "tags": [
        "binary"
      ]
    },
    {
      "group": "",
      "name": "nw-pre-gyp-module-test",
      "version": "0.0.1",
      "description": "Node-webkit-based module test.",
      "scope": "optional",
      "purl": "pkg:npm/nw-pre-gyp-module-test@0.0.1",
      "type": "library",
      "bom-ref": "pkg:npm/nw-pre-gyp-module-test@0.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@mapbox/node-pre-gyp/lib/util/nw-pre-gyp/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@mapbox/node-pre-gyp/lib/util/nw-pre-gyp/package.json"
              }
            ],
            "concludedValue": "node_modules/@mapbox/node-pre-gyp/lib/util/nw-pre-gyp/package.json"
          }
        ]
      },
      "tags": [
        "test"
      ]
    },
    {
      "authors": [
        {
          "name": "Isaac Z. Schlueter"
        }
      ],
      "group": "@isaacs",
      "name": "fs-minipass",
      "version": "4.0.1",
      "description": "fs read and write streams based on minipass",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/%40isaacs/fs-minipass@4.0.1",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/npm/fs-minipass.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@isaacs/fs-minipass@4.0.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@isaacs/fs-minipass/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@isaacs/fs-minipass/package.json"
              }
            ],
            "concludedValue": "node_modules/@isaacs/fs-minipass/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Ben Coe <ben@npmjs.com>"
        }
      ],
      "group": "@isaacs",
      "name": "cliui",
      "version": "8.0.2",
      "description": "easily create complex multi-column command-line-interfaces",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "ISC",
            "url": "https://opensource.org/licenses/ISC"
          }
        }
      ],
      "purl": "pkg:npm/%40isaacs/cliui@8.0.2",
      "type": "library",
      "bom-ref": "pkg:npm/@isaacs/cliui@8.0.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@isaacs/cliui/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@isaacs/cliui/package.json"
              }
            ],
            "concludedValue": "node_modules/@isaacs/cliui/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "The Babel Team (https://babel.dev/team)"
        }
      ],
      "group": "@babel",
      "name": "helper-validator-identifier",
      "version": "7.28.5",
      "description": "Validate identifier/keywords name",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40babel/helper-validator-identifier@7.28.5",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/babel/babel.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@babel/helper-validator-identifier@7.28.5",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@babel/helper-validator-identifier/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@babel/helper-validator-identifier/package.json"
              }
            ],
            "concludedValue": "node_modules/@babel/helper-validator-identifier/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "The Babel Team (https://babel.dev/team)"
        }
      ],
      "group": "@babel",
      "name": "code-frame",
      "version": "7.29.0",
      "description": "Generate errors that contain a code frame that point to source locations.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT"
          }
        }
      ],
      "purl": "pkg:npm/%40babel/code-frame@7.29.0",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://babel.dev/docs/en/next/babel-code-frame"
        },
        {
          "type": "vcs",
          "url": "https://github.com/babel/babel.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@babel/code-frame@7.29.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@babel/code-frame/package.json"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@babel/code-frame/package.json"
              }
            ],
            "concludedValue": "node_modules/@babel/code-frame/package.json"
          }
        ]
      }
    }
  ],
  "dependencies": [],
  "annotations": [
    {
      "bom-ref": "metadata-annotations",
      "subjects": [
        "pkg:npm/@sindresorhus/is@0.7.0"
      ],
      "annotator": {
        "component": {
          "group": "@cyclonedx",
          "name": "cdxgen",
          "version": "12.3.3",
          "purl": "pkg:npm/%40cyclonedx/cdxgen@12.3.3",
          "type": "application",
          "bom-ref": "pkg:npm/@cyclonedx/cdxgen@12.3.3",
          "publisher": "OWASP Foundation",
          "authors": [
            {
              "name": "OWASP Foundation"
            }
          ]
        }
      },
      "timestamp": "2026-07-29T22:59:20Z",
      "text": "This Software Bill-of-Materials (SBOM) document was created on Wednesday, July 29, 2026 with cdxgen. The data was captured during the pre-build lifecycle phase without building the application. The document describes an application named 'is' with version '0.7.0'. The package type in this SBOM is npm with 11 purl namespaces described under components. The components were identified from 463 source files."
    }
  ]
}