{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4aa0b8e0-e00e-5d25-b0c7-e6c554198465",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "pip",
      "purl": "pkg:pypi/pip@9.0.0.post3+tuxcare",
      "type": "library",
      "bom-ref": "pkg:pypi/pip@9.0.0.post3+tuxcare",
      "version": "9.0.0.post3+tuxcare",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2019-20916",
      "affects": [
        {
          "ref": "pkg:pypi/pip@9.0.0.post3+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:7db5b888-50df-5f2a-9cda-c645f2712a33",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-20916 is fixed in version 9.0.0.post3+tuxcare of pip."
      }
    },
    {
      "id": "CVE-2021-3572",
      "affects": [
        {
          "ref": "pkg:pypi/pip@9.0.0.post3+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:3944903d-1c0d-5c47-ab8d-d79d1869d2bc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-3572 is fixed in version 9.0.0.post3+tuxcare of pip."
      }
    },
    {
      "id": "CVE-2023-5752",
      "affects": [
        {
          "ref": "pkg:pypi/pip@9.0.0.post3+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:66d7add6-a213-5189-b6c5-94b1458483b1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-5752 is fixed in version 9.0.0.post3+tuxcare of pip."
      }
    },
    {
      "id": "CVE-2025-8869",
      "affects": [
        {
          "ref": "pkg:pypi/pip@9.0.0.post3+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:924947bd-2d1b-5946-9b89-fcae21ecc65d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-8869 is fixed in version 9.0.0.post3+tuxcare of pip."
      }
    },
    {
      "id": "CVE-2026-13346",
      "affects": [
        {
          "ref": "pkg:pypi/pip@9.0.0.post3+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:908f5350-8a0c-5569-9bba-dc84457c5899",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-13346 is fixed in version 9.0.0.post3+tuxcare of pip."
      }
    },
    {
      "id": "CVE-2026-1703",
      "affects": [
        {
          "ref": "pkg:pypi/pip@9.0.0.post3+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:e02e7aa8-d17c-5628-b491-365267ae6306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1703 affects version 9.0.0.post3+tuxcare of pip."
      }
    },
    {
      "id": "CVE-2026-3219",
      "affects": [
        {
          "ref": "pkg:pypi/pip@9.0.0.post3+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:76e83ec1-0d08-5911-9b46-20cc30eda859",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-3219 is fixed in version 9.0.0.post3+tuxcare of pip."
      }
    },
    {
      "id": "CVE-2026-6357",
      "affects": [
        {
          "ref": "pkg:pypi/pip@9.0.0.post3+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:c24c485f-9f10-5d18-80e1-cbf994898e9e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-6357 is fixed in version 9.0.0.post3+tuxcare of pip."
      }
    },
    {
      "id": "CVE-2026-8643",
      "affects": [
        {
          "ref": "pkg:pypi/pip@9.0.0.post3+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:031a4c72-a2ec-5862-bf19-191c5cab0356",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-8643 is fixed in version 9.0.0.post3+tuxcare of pip."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/pip@9.0.0.post3+tuxcare"
    }
  ]
}