{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:433f3af0-6821-5365-9c83-87c80aed9364",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@astrojs/telemetry",
      "purl": "pkg:npm/%40astrojs/telemetry@3.6.5-tuxcare.8",
      "type": "library",
      "bom-ref": "pkg:npm/%40astrojs/telemetry@3.6.5-tuxcare.8",
      "version": "3.6.5-tuxcare.8",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2024-47885",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:8009fece-9ac9-5c61-8a2d-f1b9f69e4dec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47885 is fixed in version 3.6.5-tuxcare.8 of @astrojs/telemetry."
      }
    },
    {
      "id": "CVE-2024-56140",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:7cfa83ec-458d-58cd-ad1e-6534408d6530",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56140 is fixed in version 3.6.5-tuxcare.8 of @astrojs/telemetry."
      }
    },
    {
      "id": "CVE-2024-56159",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:deb6343c-7a64-53bd-b0d6-f79df135a146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56159 is fixed in version 3.6.5-tuxcare.8 of @astrojs/telemetry."
      }
    },
    {
      "id": "CVE-2025-55303",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:041dea06-36bb-5144-b824-c4e836d373d5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55303 is fixed in version 3.6.5-tuxcare.8 of @astrojs/telemetry."
      }
    },
    {
      "id": "CVE-2025-61925",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:bc42bc4b-18d7-540f-9cf9-720afbe0d157",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61925 is fixed in version 3.6.5-tuxcare.8 of @astrojs/telemetry."
      }
    },
    {
      "id": "CVE-2025-64525",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:b4023531-299c-557c-8433-de0727cdcf1c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64525 is fixed in version 3.6.5-tuxcare.8 of @astrojs/telemetry."
      }
    },
    {
      "id": "CVE-2025-64757",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:1578cec8-0930-5b4d-82a8-fc95e794f2a2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64757 is fixed in version 3.6.5-tuxcare.8 of @astrojs/telemetry."
      }
    },
    {
      "id": "CVE-2025-64764",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:96019e94-f069-5cf4-abc2-80541ccb3dc5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64764 is fixed in version 3.6.5-tuxcare.8 of @astrojs/telemetry."
      }
    },
    {
      "id": "CVE-2025-64765",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:3b01920a-3d1e-5224-9503-d55be3e436e1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64765 is fixed in version 3.6.5-tuxcare.8 of @astrojs/telemetry."
      }
    },
    {
      "id": "CVE-2025-65019",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:89439707-824f-5a65-9665-6b8b930fa54d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-65019 is fixed in version 3.6.5-tuxcare.8 of @astrojs/telemetry."
      }
    },
    {
      "id": "CVE-2025-66202",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:de07a255-f8c4-5524-bf4c-7834f060af01",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66202 is fixed in version 3.6.5-tuxcare.8 of @astrojs/telemetry."
      }
    },
    {
      "id": "CVE-2026-33769",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:32fe2fd9-7b4e-5242-8116-eeabdd87eea3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33769 is fixed in version 3.6.5-tuxcare.8 of @astrojs/telemetry."
      }
    },
    {
      "id": "CVE-2026-41067",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:f37d0f76-374c-594c-9d44-10f641723fc0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41067 is fixed in version 3.6.5-tuxcare.8 of @astrojs/telemetry."
      }
    },
    {
      "id": "CVE-2026-45028",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:281c67cc-8bdf-502b-8121-fbdd746c078d",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-45028 does not affect version 3.6.5-tuxcare.8 of @astrojs/telemetry. not_affected \u2014 Astro version 3.6.5 is NOT AFFECTED by CVE-2026-45028. The vulnerability concerns server islands encryption (AES-GCM ciphertext replay between props and slots), but server islands functionality does not exist in version 3.6.5. The feature was introduced in later versions (~May 2025, v5.x/6.x), and the vulnerability was fixed in v6.1.10 (April 2026). Exhaustive search across 327 source files con...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-50146",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:aa6f9b0b-4144-5ffd-896b-16c54c7e5aa3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50146 is fixed in version 3.6.5-tuxcare.8 of @astrojs/telemetry."
      }
    },
    {
      "id": "CVE-2026-54298",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:f2a60f97-7d0a-54dc-b15f-668b0c2e9fd4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54298 is fixed in version 3.6.5-tuxcare.8 of @astrojs/telemetry."
      }
    },
    {
      "id": "CVE-2026-54299",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:c07c08a8-69ca-5145-922d-cb5107311be9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54299 is fixed in version 3.6.5-tuxcare.8 of @astrojs/telemetry."
      }
    },
    {
      "id": "CVE-2026-59728",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:d5f6822c-2ef4-5b37-b54e-c1b85935f580",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59728 is fixed in version 3.6.5-tuxcare.8 of @astrojs/telemetry."
      }
    },
    {
      "id": "CVE-2026-59729",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:f9ac2c00-6437-59ca-b65c-d284670440ce",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59729 is fixed in version 3.6.5-tuxcare.8 of @astrojs/telemetry."
      }
    },
    {
      "id": "CVE-2026-73422",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:a8983cc8-e7d3-58ab-9572-876da5aaebea",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-73422 is fixed in version 3.6.5-tuxcare.8 of @astrojs/telemetry."
      }
    },
    {
      "id": "CVE-2026-84376",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:d6843bad-c581-5283-b1a2-fa7777fe677f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-84376 affects version 3.6.5-tuxcare.8 of @astrojs/telemetry."
      }
    },
    {
      "id": "GHSA-26w7-cxv4-gfx2",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:5b01624e-8ee2-5d1a-a3b1-be2b949bb96e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-26w7-cxv4-gfx2 affects version 3.6.5-tuxcare.8 of @astrojs/telemetry."
      }
    },
    {
      "id": "GHSA-4g3v-8h47-v7g6",
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@3.6.5-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:44c1c57f-85f2-5698-91de-76a9e75336bc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4g3v-8h47-v7g6 is fixed in version 3.6.5-tuxcare.8 of @astrojs/telemetry."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40astrojs/telemetry@3.6.5-tuxcare.8"
    }
  ]
}