From c58ffe428c231ef09197bf95389ac62d3f18ce95 Mon Sep 17 00:00:00 2001 From: John Kjell Date: Mon, 10 Jun 2024 17:08:18 -0500 Subject: [PATCH 1/5] Add new docs and schema for new SBOM attestor. Also includes schema update to git attestor Signed-off-by: John Kjell --- docs/attestors/git.json | 4 +- docs/attestors/git.md | 3 ++ docs/attestors/sbom.json | 17 ++++++++ docs/attestors/sbom.md | 24 +++++++++++ go.mod | 41 +++++++++--------- go.sum | 89 +++++++++++++++++++++------------------- 6 files changed, 114 insertions(+), 64 deletions(-) create mode 100644 docs/attestors/sbom.json create mode 100644 docs/attestors/sbom.md diff --git a/docs/attestors/git.json b/docs/attestors/git.json index ae8acfc4..13f0da77 100644 --- a/docs/attestors/git.json +++ b/docs/attestors/git.json @@ -63,6 +63,9 @@ "$ref": "#/$defs/Tag" }, "type": "array" + }, + "branch": { + "type": "string" } }, "additionalProperties": false, @@ -129,4 +132,3 @@ } } } - \ No newline at end of file diff --git a/docs/attestors/git.md b/docs/attestors/git.md index 2904b85c..6c0d3f7e 100644 --- a/docs/attestors/git.md +++ b/docs/attestors/git.md @@ -75,6 +75,9 @@ The attestor returns the SHA1 ([Secure Hash Algorithm 1](https://en.wikipedia.or "$ref": "#/$defs/Tag" }, "type": "array" + }, + "branch": { + "type": "string" } }, "additionalProperties": false, diff --git a/docs/attestors/sbom.json b/docs/attestors/sbom.json new file mode 100644 index 00000000..e17e6a1a --- /dev/null +++ b/docs/attestors/sbom.json @@ -0,0 +1,17 @@ +{ + "$schema": "https://json-schema.org/draft/2020-12/schema", + "$id": "https://github.com/in-toto/go-witness/attestation/sbom/sbom-attestor", + "$ref": "#/$defs/SBOMAttestor", + "$defs": { + "SBOMAttestor": { + "properties": { + "SBOMDocument": true + }, + "additionalProperties": false, + "type": "object", + "required": [ + "SBOMDocument" + ] + } + } +} diff --git a/docs/attestors/sbom.md b/docs/attestors/sbom.md new file mode 100644 index 00000000..b65fba49 --- /dev/null +++ b/docs/attestors/sbom.md @@ -0,0 +1,24 @@ +# SBOM Attestor + +The SBOM attestor records the contents of any [products](./product.md) that are valid [CycloneDX](https://cyclonedx.org/specification/overview/) or [SPDX](https://spdx.dev/learn/overview/) json files. The SBOM file is parsed and the contents are recorded in the attestation. + +## Schema +```json +{ + "$schema": "https://json-schema.org/draft/2020-12/schema", + "$id": "https://github.com/in-toto/go-witness/attestation/sbom/sbom-attestor", + "$ref": "#/$defs/SBOMAttestor", + "$defs": { + "SBOMAttestor": { + "properties": { + "SBOMDocument": true + }, + "additionalProperties": false, + "type": "object", + "required": [ + "SBOMDocument" + ] + } + } +} +``` diff --git a/go.mod b/go.mod index 5950ff36..3ae471c5 100644 --- a/go.mod +++ b/go.mod @@ -5,7 +5,7 @@ go 1.22.0 toolchain go1.22.2 require ( - github.com/in-toto/go-witness v0.4.0 + github.com/in-toto/go-witness v0.4.1-0.20240608134736-6f2f501dd2bd github.com/invopop/jsonschema v0.12.0 github.com/olekukonko/tablewriter v0.0.5 github.com/sigstore/fulcio v1.4.5 @@ -25,7 +25,7 @@ require ( github.com/skratchdot/open-golang v0.0.0-20200116055534-eef842397966 // indirect github.com/spiffe/go-spiffe/v2 v2.1.7 // indirect github.com/zclconf/go-cty v1.14.2 // indirect - golang.org/x/oauth2 v0.19.0 // indirect + golang.org/x/oauth2 v0.20.0 // indirect ) require ( @@ -41,19 +41,19 @@ require ( github.com/agnivade/levenshtein v1.1.1 // indirect github.com/apparentlymart/go-textseg/v15 v15.0.0 // indirect github.com/aws/aws-sdk-go v1.50.38 // indirect - github.com/aws/aws-sdk-go-v2 v1.26.1 // indirect - github.com/aws/aws-sdk-go-v2/config v1.27.13 // indirect - github.com/aws/aws-sdk-go-v2/credentials v1.17.13 // indirect - github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.16.1 // indirect - github.com/aws/aws-sdk-go-v2/internal/configsources v1.3.5 // indirect - github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.6.5 // indirect + github.com/aws/aws-sdk-go-v2 v1.27.0 // indirect + github.com/aws/aws-sdk-go-v2/config v1.27.16 // indirect + github.com/aws/aws-sdk-go-v2/credentials v1.17.16 // indirect + github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.16.3 // indirect + github.com/aws/aws-sdk-go-v2/internal/configsources v1.3.7 // indirect + github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.6.7 // indirect github.com/aws/aws-sdk-go-v2/internal/ini v1.8.0 // indirect github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.11.2 // indirect - github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.11.7 // indirect - github.com/aws/aws-sdk-go-v2/service/kms v1.31.1 // indirect - github.com/aws/aws-sdk-go-v2/service/sso v1.20.6 // indirect - github.com/aws/aws-sdk-go-v2/service/ssooidc v1.24.0 // indirect - github.com/aws/aws-sdk-go-v2/service/sts v1.28.7 // indirect + github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.11.9 // indirect + github.com/aws/aws-sdk-go-v2/service/kms v1.31.3 // indirect + github.com/aws/aws-sdk-go-v2/service/sso v1.20.9 // indirect + github.com/aws/aws-sdk-go-v2/service/ssooidc v1.24.3 // indirect + github.com/aws/aws-sdk-go-v2/service/sts v1.28.10 // indirect github.com/aws/smithy-go v1.20.2 // indirect github.com/bahlo/generic-list-go v0.2.0 // indirect github.com/beorn7/perks v1.0.1 // indirect @@ -69,6 +69,7 @@ require ( github.com/emirpasic/gods v1.18.1 // indirect github.com/felixge/httpsnoop v1.0.4 // indirect github.com/fsnotify/fsnotify v1.7.0 // indirect + github.com/gabriel-vasile/mimetype v1.4.4 // indirect github.com/go-git/gcfg v1.5.1-0.20230307220236-3a3c6141e376 // indirect github.com/go-git/go-billy/v5 v5.5.0 // indirect github.com/go-git/go-git/v5 v5.11.0 // indirect @@ -81,7 +82,7 @@ require ( github.com/gogo/protobuf v1.3.2 // indirect github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da // indirect github.com/golang/protobuf v1.5.4 // indirect - github.com/google/go-containerregistry v0.19.0 // indirect + github.com/google/go-containerregistry v0.19.1 // indirect github.com/google/gofuzz v1.2.0 // indirect github.com/google/s2a-go v0.1.7 // indirect github.com/google/uuid v1.6.0 // indirect @@ -121,7 +122,7 @@ require ( github.com/sagikazarmark/slog-shim v0.1.0 // indirect github.com/secure-systems-lab/go-securesystemslib v0.8.0 // indirect github.com/sergi/go-diff v1.3.1 // indirect - github.com/sigstore/sigstore v1.8.3 // indirect + github.com/sigstore/sigstore v1.8.4 // indirect github.com/skeema/knownhosts v1.2.1 // indirect github.com/sourcegraph/conc v0.3.0 // indirect github.com/spf13/afero v1.11.0 // indirect @@ -144,14 +145,14 @@ require ( go.opentelemetry.io/otel/sdk v1.24.0 // indirect go.opentelemetry.io/otel/trace v1.24.0 // indirect go.uber.org/multierr v1.11.0 // indirect - golang.org/x/crypto v0.22.0 // indirect + golang.org/x/crypto v0.23.0 // indirect golang.org/x/exp v0.0.0-20240325151524-a685a6edb6d8 // indirect golang.org/x/mod v0.16.0 // indirect - golang.org/x/net v0.24.0 // indirect + golang.org/x/net v0.25.0 // indirect golang.org/x/sync v0.7.0 // indirect - golang.org/x/sys v0.19.0 // indirect - golang.org/x/term v0.19.0 // indirect - golang.org/x/text v0.14.0 // indirect + golang.org/x/sys v0.20.0 // indirect + golang.org/x/term v0.20.0 // indirect + golang.org/x/text v0.15.0 // indirect golang.org/x/time v0.5.0 // indirect golang.org/x/tools v0.19.0 // indirect google.golang.org/api v0.177.0 // indirect diff --git a/go.sum b/go.sum index 5dc71f95..280a4d86 100644 --- a/go.sum +++ b/go.sum @@ -36,32 +36,32 @@ github.com/armon/go-socks5 v0.0.0-20160902184237-e75332964ef5 h1:0CwZNZbxp69SHPd github.com/armon/go-socks5 v0.0.0-20160902184237-e75332964ef5/go.mod h1:wHh0iHkYZB8zMSxRWpUBQtwG5a7fFgvEO+odwuTv2gs= github.com/aws/aws-sdk-go v1.50.38 h1:h8wxaLin7sFGK4sKassc1VpNcDbgAAEQJ5PHjqLAvXQ= github.com/aws/aws-sdk-go v1.50.38/go.mod h1:LF8svs817+Nz+DmiMQKTO3ubZ/6IaTpq3TjupRn3Eqk= -github.com/aws/aws-sdk-go-v2 v1.26.1 h1:5554eUqIYVWpU0YmeeYZ0wU64H2VLBs8TlhRB2L+EkA= -github.com/aws/aws-sdk-go-v2 v1.26.1/go.mod h1:ffIFB97e2yNsv4aTSGkqtHnppsIJzw7G7BReUZ3jCXM= -github.com/aws/aws-sdk-go-v2/config v1.27.13 h1:WbKW8hOzrWoOA/+35S5okqO/2Ap8hkkFUzoW8Hzq24A= -github.com/aws/aws-sdk-go-v2/config v1.27.13/go.mod h1:XLiyiTMnguytjRER7u5RIkhIqS8Nyz41SwAWb4xEjxs= -github.com/aws/aws-sdk-go-v2/credentials v1.17.13 h1:XDCJDzk/u5cN7Aple7D/MiAhx1Rjo/0nueJ0La8mRuE= -github.com/aws/aws-sdk-go-v2/credentials v1.17.13/go.mod h1:FMNcjQrmuBYvOTZDtOLCIu0esmxjF7RuA/89iSXWzQI= -github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.16.1 h1:FVJ0r5XTHSmIHJV6KuDmdYhEpvlHpiSd38RQWhut5J4= -github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.16.1/go.mod h1:zusuAeqezXzAB24LGuzuekqMAEgWkVYukBec3kr3jUg= -github.com/aws/aws-sdk-go-v2/internal/configsources v1.3.5 h1:aw39xVGeRWlWx9EzGVnhOR4yOjQDHPQ6o6NmBlscyQg= -github.com/aws/aws-sdk-go-v2/internal/configsources v1.3.5/go.mod h1:FSaRudD0dXiMPK2UjknVwwTYyZMRsHv3TtkabsZih5I= -github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.6.5 h1:PG1F3OD1szkuQPzDw3CIQsRIrtTlUC3lP84taWzHlq0= -github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.6.5/go.mod h1:jU1li6RFryMz+so64PpKtudI+QzbKoIEivqdf6LNpOc= +github.com/aws/aws-sdk-go-v2 v1.27.0 h1:7bZWKoXhzI+mMR/HjdMx8ZCC5+6fY0lS5tr0bbgiLlo= +github.com/aws/aws-sdk-go-v2 v1.27.0/go.mod h1:ffIFB97e2yNsv4aTSGkqtHnppsIJzw7G7BReUZ3jCXM= +github.com/aws/aws-sdk-go-v2/config v1.27.16 h1:knpCuH7laFVGYTNd99Ns5t+8PuRjDn4HnnZK48csipM= +github.com/aws/aws-sdk-go-v2/config v1.27.16/go.mod h1:vutqgRhDUktwSge3hrC3nkuirzkJ4E/mLj5GvI0BQas= +github.com/aws/aws-sdk-go-v2/credentials v1.17.16 h1:7d2QxY83uYl0l58ceyiSpxg9bSbStqBC6BeEeHEchwo= +github.com/aws/aws-sdk-go-v2/credentials v1.17.16/go.mod h1:Ae6li/6Yc6eMzysRL2BXlPYvnrLLBg3D11/AmOjw50k= +github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.16.3 h1:dQLK4TjtnlRGb0czOht2CevZ5l6RSyRWAnKeGd7VAFE= +github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.16.3/go.mod h1:TL79f2P6+8Q7dTsILpiVST+AL9lkF6PPGI167Ny0Cjw= +github.com/aws/aws-sdk-go-v2/internal/configsources v1.3.7 h1:lf/8VTF2cM+N4SLzaYJERKEWAXq8MOMpZfU6wEPWsPk= +github.com/aws/aws-sdk-go-v2/internal/configsources v1.3.7/go.mod h1:4SjkU7QiqK2M9oozyMzfZ/23LmUY+h3oFqhdeP5OMiI= +github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.6.7 h1:4OYVp0705xu8yjdyoWix0r9wPIRXnIzzOoUpQVHIJ/g= +github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.6.7/go.mod h1:vd7ESTEvI76T2Na050gODNmNU7+OyKrIKroYTu4ABiI= github.com/aws/aws-sdk-go-v2/internal/ini v1.8.0 h1:hT8rVHwugYE2lEfdFE0QWVo81lF7jMrYJVDWI+f+VxU= github.com/aws/aws-sdk-go-v2/internal/ini v1.8.0/go.mod h1:8tu/lYfQfFe6IGnaOdrpVgEL2IrrDOf6/m9RQum4NkY= github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.11.2 h1:Ji0DY1xUsUr3I8cHps0G+XM3WWU16lP6yG8qu1GAZAs= github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.11.2/go.mod h1:5CsjAbs3NlGQyZNFACh+zztPDI7fU6eW9QsxjfnuBKg= -github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.11.7 h1:ogRAwT1/gxJBcSWDMZlgyFUM962F51A5CRhDLbxLdmo= -github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.11.7/go.mod h1:YCsIZhXfRPLFFCl5xxY+1T9RKzOKjCut+28JSX2DnAk= -github.com/aws/aws-sdk-go-v2/service/kms v1.31.1 h1:5wtyAwuUiJiM3DHYeGZmP5iMonM7DFBWAEaaVPHYZA0= -github.com/aws/aws-sdk-go-v2/service/kms v1.31.1/go.mod h1:2snWQJQUKsbN66vAawJuOGX7dr37pfOq9hb0tZDGIqQ= -github.com/aws/aws-sdk-go-v2/service/sso v1.20.6 h1:o5cTaeunSpfXiLTIBx5xo2enQmiChtu1IBbzXnfU9Hs= -github.com/aws/aws-sdk-go-v2/service/sso v1.20.6/go.mod h1:qGzynb/msuZIE8I75DVRCUXw3o3ZyBmUvMwQ2t/BrGM= -github.com/aws/aws-sdk-go-v2/service/ssooidc v1.24.0 h1:Qe0r0lVURDDeBQJ4yP+BOrJkvkiCo/3FH/t+wY11dmw= -github.com/aws/aws-sdk-go-v2/service/ssooidc v1.24.0/go.mod h1:mUYPBhaF2lGiukDEjJX2BLRRKTmoUSitGDUgM4tRxak= -github.com/aws/aws-sdk-go-v2/service/sts v1.28.7 h1:et3Ta53gotFR4ERLXXHIHl/Uuk1qYpP5uU7cvNql8ns= -github.com/aws/aws-sdk-go-v2/service/sts v1.28.7/go.mod h1:FZf1/nKNEkHdGGJP/cI2MoIMquumuRK6ol3QQJNDxmw= +github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.11.9 h1:Wx0rlZoEJR7JwlSZcHnEa7CNjrSIyVxMFWGAaXy4fJY= +github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.11.9/go.mod h1:aVMHdE0aHO3v+f/iw01fmXV/5DbfQ3Bi9nN7nd9bE9Y= +github.com/aws/aws-sdk-go-v2/service/kms v1.31.3 h1:wLBgq6nDNYdd0A5CvscVAKV5SVlHKOHVPedpgtigATg= +github.com/aws/aws-sdk-go-v2/service/kms v1.31.3/go.mod h1:8lETO9lelSG2B6KMXFh2OwPPqGV6WQM3RqLAEjP1xaU= +github.com/aws/aws-sdk-go-v2/service/sso v1.20.9 h1:aD7AGQhvPuAxlSUfo0CWU7s6FpkbyykMhGYMvlqTjVs= +github.com/aws/aws-sdk-go-v2/service/sso v1.20.9/go.mod h1:c1qtZUWtygI6ZdvKppzCSXsDOq5I4luJPZ0Ud3juFCA= +github.com/aws/aws-sdk-go-v2/service/ssooidc v1.24.3 h1:Pav5q3cA260Zqez42T9UhIlsd9QeypszRPwC9LdSSsQ= +github.com/aws/aws-sdk-go-v2/service/ssooidc v1.24.3/go.mod h1:9lmoVDVLz/yUZwLaQ676TK02fhCu4+PgRSmMaKR1ozk= +github.com/aws/aws-sdk-go-v2/service/sts v1.28.10 h1:69tpbPED7jKPyzMcrwSvhWcJ9bPnZsZs18NT40JwM0g= +github.com/aws/aws-sdk-go-v2/service/sts v1.28.10/go.mod h1:0Aqn1MnEuitqfsCNyKsdKLhDUOr4txD/g19EfiUqgws= github.com/aws/smithy-go v1.20.2 h1:tbp628ireGtzcHDDmLT/6ADHidqnwgF57XOXZe6tp4Q= github.com/aws/smithy-go v1.20.2/go.mod h1:krry+ya/rV9RDcV/Q16kpu6ypI4K2czasz0NC3qS14E= github.com/bahlo/generic-list-go v0.2.0 h1:5sz/EEAK+ls5wF+NeqDpk5+iNdMDXrh3z3nPnH1Wvgk= @@ -128,6 +128,8 @@ github.com/frankban/quicktest v1.14.6 h1:7Xjx+VpznH+oBnejlPUj8oUpdxnVs4f8XU8WnHk github.com/frankban/quicktest v1.14.6/go.mod h1:4ptaffx2x8+WTWXmUCuVU6aPUX1/Mz7zb5vbUoiM6w0= github.com/fsnotify/fsnotify v1.7.0 h1:8JEhPFa5W2WU7YfeZzPNqzMP6Lwt7L2715Ggo0nosvA= github.com/fsnotify/fsnotify v1.7.0/go.mod h1:40Bi/Hjc2AVfZrqy+aj+yEI+/bRxZnMJyTJwOpGvigM= +github.com/gabriel-vasile/mimetype v1.4.4 h1:QjV6pZ7/XZ7ryI2KuyeEDE8wnh7fHP9YnQy+R0LnH8I= +github.com/gabriel-vasile/mimetype v1.4.4/go.mod h1:JwLei5XPtWdGiMFB5Pjle1oEeoSeEuJfJE+TtfvdB/s= github.com/gliderlabs/ssh v0.3.5 h1:OcaySEmAQJgyYcArR+gGGTHCyE7nvhEMTlYY+Dp8CpY= github.com/gliderlabs/ssh v0.3.5/go.mod h1:8XB4KraRrX39qHhT6yxPsHedjA08I/uBVwj4xC+/+z4= github.com/go-git/gcfg v1.5.1-0.20230307220236-3a3c6141e376 h1:+zs/tPmkDkHx3U66DAb0lQFJrpS6731Oaa12ikc+DiI= @@ -149,8 +151,8 @@ github.com/go-logr/logr v1.4.1 h1:pKouT5E8xu9zeFC39JXRDukb6JFQPXM5p5I91188VAQ= github.com/go-logr/logr v1.4.1/go.mod h1:9T104GzyrTigFIr8wt5mBrctHMim0Nb2HLGrmQ40KvY= github.com/go-logr/stdr v1.2.2 h1:hSWxHoqTgW2S2qGc0LTAI563KZ5YKYRhT3MFKZMbjag= github.com/go-logr/stdr v1.2.2/go.mod h1:mMo/vtBO5dYbehREoey6XUKy/eSumjCCveDpRre4VKE= -github.com/go-rod/rod v0.114.7 h1:h4pimzSOUnw7Eo41zdJA788XsawzHjJMyzCE3BrBww0= -github.com/go-rod/rod v0.114.7/go.mod h1:aiedSEFg5DwG/fnNbUOTPMTTWX3MRj6vIs/a684Mthw= +github.com/go-rod/rod v0.116.0 h1:ypRryjTys3EnqHskJ/TdgodFMvXV0EHvmy4bSkKZgHM= +github.com/go-rod/rod v0.116.0/go.mod h1:aiedSEFg5DwG/fnNbUOTPMTTWX3MRj6vIs/a684Mthw= github.com/go-test/deep v1.1.0 h1:WOcxcdHcvdgThNXjw0t76K42FXTU7HpNQWHpA2HHNlg= github.com/go-test/deep v1.1.0/go.mod h1:5C2ZWiW0ErCdrYzpqxLbTX7MG14M9iiw8DgHncVwcsE= github.com/gobwas/glob v0.2.3 h1:A4xDbljILXROh+kObIiy5kIaPYD8e96x1tgBhUI5J+Y= @@ -190,8 +192,8 @@ github.com/google/go-cmp v0.5.3/go.mod h1:v8dTdLbMG2kIc/vJvl+f65V22dbkXbowE6jgT/ github.com/google/go-cmp v0.5.9/go.mod h1:17dUlkBOakJ0+DkrSSNjCkIjxS6bF9zb3elmeNGIjoY= github.com/google/go-cmp v0.6.0 h1:ofyhxvXcZhMsU5ulbFiLKl/XBFqE1GSq7atu8tAmTRI= github.com/google/go-cmp v0.6.0/go.mod h1:17dUlkBOakJ0+DkrSSNjCkIjxS6bF9zb3elmeNGIjoY= -github.com/google/go-containerregistry v0.19.0 h1:uIsMRBV7m/HDkDxE/nXMnv1q+lOOSPlQ/ywc5JbB8Ic= -github.com/google/go-containerregistry v0.19.0/go.mod h1:u0qB2l7mvtWVR5kNcbFIhFY1hLbf8eeGapA+vbFDCtQ= +github.com/google/go-containerregistry v0.19.1 h1:yMQ62Al6/V0Z7CqIrrS1iYoA5/oQCm88DeNujc7C1KY= +github.com/google/go-containerregistry v0.19.1/go.mod h1:YCMFNQeeXeLF+dnhhWkqDItx/JSkH01j1Kis4PsjzFI= github.com/google/gofuzz v1.0.0/go.mod h1:dBl0BpW6vV/+mYPU4Po3pmUjxk6FQPldtuIdl/M65Eg= github.com/google/gofuzz v1.2.0 h1:xRy4A+RhZaiKjJ1bPfwQ8sedCA+YS2YcCHW6ec7JMi0= github.com/google/gofuzz v1.2.0/go.mod h1:dBl0BpW6vV/+mYPU4Po3pmUjxk6FQPldtuIdl/M65Eg= @@ -214,8 +216,8 @@ github.com/in-toto/archivista v0.4.0 h1:5g79iqmyXblnnwuD+768lrEbeoE0V5H7URYJFnr0 github.com/in-toto/archivista v0.4.0/go.mod h1:HgqAu7az0Ql0Jf844Paf0Ji5PdUMKxO5JIBh4hOjMs8= github.com/in-toto/attestation v1.0.2 h1:ICqV41bfaDC3ixVUzAtFxFu+Dy56EPcjiIrJQe+4LVM= github.com/in-toto/attestation v1.0.2/go.mod h1:3uRayZSKuCHDDZOxLm5UfYulqqd1L1NdzYvxX/jyZEM= -github.com/in-toto/go-witness v0.4.0 h1:6DZakoe2DxBFuvat9xQW6SmPVrT7T5KiO2ft619OwyI= -github.com/in-toto/go-witness v0.4.0/go.mod h1:7Ed461YDgTrfzkdf81Hq9GgRgiaJ8bHbjY9Vx6RDtkc= +github.com/in-toto/go-witness v0.4.1-0.20240608134736-6f2f501dd2bd h1:sPGd1tzOrrEjxHXqbtatexyNKu1tcrllppdKkOlpV1c= +github.com/in-toto/go-witness v0.4.1-0.20240608134736-6f2f501dd2bd/go.mod h1:G3tdf4O1bjP9F0BdZ3jfpGhZ4P+8b+O8Adcdw5FNE6M= github.com/inconshreveable/mousetrap v1.1.0 h1:wN+x4NVGpMsO7ErUn/mUI3vEoE6Jt13X2s0bqwp9tc8= github.com/inconshreveable/mousetrap v1.1.0/go.mod h1:vpF70FUmC8bwa3OWnCshd2FqLfsEA9PFc4w1p2J65bw= github.com/invopop/jsonschema v0.12.0 h1:6ovsNSuvn9wEQVOyc72aycBMVQFKz7cPdMJn10CvzRI= @@ -237,8 +239,8 @@ github.com/kevinburke/ssh_config v1.2.0 h1:x584FjTGwHzMwvHx18PXxbBVzfnxogHaAReU4 github.com/kevinburke/ssh_config v1.2.0/go.mod h1:CT57kijsi8u/K/BOFA39wgDQJ9CxiF4nAY/ojJ6r6mM= github.com/kisielk/errcheck v1.5.0/go.mod h1:pFxgyoBC7bSaBwPgfKdkLd5X25qrDl4LWUI2bnpBCr8= github.com/kisielk/gotool v1.0.0/go.mod h1:XhKaO+MFFWcvkIS/tQcRk01m1F5IRFswLeQ+oQHNcck= -github.com/klauspost/compress v1.17.4 h1:Ej5ixsIri7BrIjBkRZLTo6ghwrEtHFk7ijlczPW4fZ4= -github.com/klauspost/compress v1.17.4/go.mod h1:/dCuZOvVtNoHsyb+cuJD3itjs3NbnF6KH9zAO4BDxPM= +github.com/klauspost/compress v1.17.6 h1:60eq2E/jlfwQXtvZEeBUYADs+BwKBWURIY+Gj2eRGjI= +github.com/klauspost/compress v1.17.6/go.mod h1:/dCuZOvVtNoHsyb+cuJD3itjs3NbnF6KH9zAO4BDxPM= github.com/kr/pretty v0.1.0/go.mod h1:dAy3ld7l9f0ibDNOQOHHMYYIIbhfbHSm3C4ZsoJORNo= github.com/kr/pretty v0.3.1 h1:flRD4NNwYAUpkphVc1HcthR4KEIFJ65n8Mw5qdRn3LE= github.com/kr/pretty v0.3.1/go.mod h1:hoEshYVHaxMs3cyo3Yncou5ZscifuDolrwPKZanG3xk= @@ -313,8 +315,8 @@ github.com/sergi/go-diff v1.3.1 h1:xkr+Oxo4BOQKmkn/B9eMK0g5Kg/983T9DqqPHwYqD+8= github.com/sergi/go-diff v1.3.1/go.mod h1:aMJSSKb2lpPvRNec0+w3fl7LP9IOFzdc9Pa4NFbPK1I= github.com/sigstore/fulcio v1.4.5 h1:WWNnrOknD0DbruuZWCbN+86WRROpEl3Xts+WT2Ek1yc= github.com/sigstore/fulcio v1.4.5/go.mod h1:oz3Qwlma8dWcSS/IENR/6SjbW4ipN0cxpRVfgdsjMU8= -github.com/sigstore/sigstore v1.8.3 h1:G7LVXqL+ekgYtYdksBks9B38dPoIsbscjQJX/MGWkA4= -github.com/sigstore/sigstore v1.8.3/go.mod h1:mqbTEariiGA94cn6G3xnDiV6BD8eSLdL/eA7bvJ0fVs= +github.com/sigstore/sigstore v1.8.4 h1:g4ICNpiENFnWxjmBzBDWUn62rNFeny/P77HUC8da32w= +github.com/sigstore/sigstore v1.8.4/go.mod h1:1jIKtkTFEeISen7en+ZPWdDHazqhxco/+v9CNjc7oNg= github.com/sirupsen/logrus v1.7.0/go.mod h1:yWOB1SBYBC5VeMP7gHvWumXLIWorT60ONWic61uBYv0= github.com/sirupsen/logrus v1.9.3 h1:dueUQJ1C2q9oE3F7wvmSGAaVtTmUizReu6fjN8uqzbQ= github.com/sirupsen/logrus v1.9.3/go.mod h1:naHLuLoDiP4jHNo9R0sCBMtWGeIprob74mVsIT4qYEQ= @@ -421,8 +423,8 @@ golang.org/x/crypto v0.0.0-20220622213112-05595931fe9d/go.mod h1:IxCIyHEi3zRg3s0 golang.org/x/crypto v0.3.1-0.20221117191849-2c476679df9a/go.mod h1:hebNnKkNXi2UzZN1eVRvBB7co0a+JxK6XbPiWVs/3J4= golang.org/x/crypto v0.7.0/go.mod h1:pYwdfH91IfpZVANVyUOhSIPZaFoJGxTFbZhFTx+dXZU= golang.org/x/crypto v0.19.0/go.mod h1:Iy9bg/ha4yyC70EfRS8jz+B6ybOBKMaSxLj6P6oBDfU= -golang.org/x/crypto v0.22.0 h1:g1v0xeRhjcugydODzvb3mEM9SQ0HGp9s/nh3COQ/C30= -golang.org/x/crypto v0.22.0/go.mod h1:vr6Su+7cTlO45qkww3VDJlzDn0ctJvRgYbC2NvXHt+M= +golang.org/x/crypto v0.23.0 h1:dIJU/v2J8Mdglj/8rJ6UUOM3Zc9zLZxVZwwxMooUSAI= +golang.org/x/crypto v0.23.0/go.mod h1:CKFgDieR+mRhux2Lsu27y0fO304Db0wZe70UKqHu0v8= golang.org/x/exp v0.0.0-20190121172915-509febef88a4/go.mod h1:CJ0aWSM057203Lf6IL+f9T1iT9GByDxfZKAQTCR3kQA= golang.org/x/exp v0.0.0-20240325151524-a685a6edb6d8 h1:aAcj0Da7eBAtrTp03QXWvm88pSyOt+UgdZw2BFZ+lEw= golang.org/x/exp v0.0.0-20240325151524-a685a6edb6d8/go.mod h1:CQ1k9gNrJ50XIzaKCRR2hssIjF07kZFEiieALBM/ARQ= @@ -453,11 +455,11 @@ golang.org/x/net v0.2.0/go.mod h1:KqCZLdyyvdV855qA2rE3GC2aiw5xGR5TEjj8smXukLY= golang.org/x/net v0.6.0/go.mod h1:2Tu9+aMcznHK/AK1HMvgo6xiTLG5rD5rZLDS+rp2Bjs= golang.org/x/net v0.8.0/go.mod h1:QVkue5JL9kW//ek3r6jTKnTFis1tRmNAW2P1shuFdJc= golang.org/x/net v0.10.0/go.mod h1:0qNGK6F8kojg2nk9dLZ2mShWaEBan6FAoqfSigmmuDg= -golang.org/x/net v0.24.0 h1:1PcaxkF854Fu3+lvBIx5SYn9wRlBzzcnHZSiaFFAb0w= -golang.org/x/net v0.24.0/go.mod h1:2Q7sJY5mzlzWjKtYUEXSlBWCdyaioyXzRB2RtU8KVE8= +golang.org/x/net v0.25.0 h1:d/OCCoBEUq33pjydKrGQhw7IlUPI2Oylr+8qLx49kac= +golang.org/x/net v0.25.0/go.mod h1:JkAGAh7GEvH74S6FOH42FLoXpXbE/aqXSrIQjXgsiwM= golang.org/x/oauth2 v0.0.0-20180821212333-d2e6202438be/go.mod h1:N/0e6XlmueqKjAGxoOufVs8QHGRruUQn6yWY3a++T0U= -golang.org/x/oauth2 v0.19.0 h1:9+E/EZBCbTLNrbN35fHv/a/d/mOBatymz1zbtQrXpIg= -golang.org/x/oauth2 v0.19.0/go.mod h1:vYi7skDa1x015PmRRYZ7+s1cWyPgrPiSYRe4rnsexc8= +golang.org/x/oauth2 v0.20.0 h1:4mQdhULixXKP1rwYBW0vAijoXnkTG0BLCDRzfe1idMo= +golang.org/x/oauth2 v0.20.0/go.mod h1:XYTD2NtWslqkgxebSiOHnXEap4TF09sJSc7H1sXbhtI= golang.org/x/sync v0.0.0-20180314180146-1d60e4601c6f/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= golang.org/x/sync v0.0.0-20181108010431-42b317875d0f/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= golang.org/x/sync v0.0.0-20190423024810-112230192c58/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= @@ -485,8 +487,8 @@ golang.org/x/sys v0.5.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= golang.org/x/sys v0.6.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= golang.org/x/sys v0.8.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= golang.org/x/sys v0.17.0/go.mod h1:/VUhepiaJMQUp4+oa/7Zr1D23ma6VTLIYjOOTFZPUcA= -golang.org/x/sys v0.19.0 h1:q5f1RH2jigJ1MoAWp2KTp3gm5zAGFUTarQZ5U386+4o= -golang.org/x/sys v0.19.0/go.mod h1:/VUhepiaJMQUp4+oa/7Zr1D23ma6VTLIYjOOTFZPUcA= +golang.org/x/sys v0.20.0 h1:Od9JTbYCk261bKm4M/mw7AklTlFYIa0bIp9BgSm1S8Y= +golang.org/x/sys v0.20.0/go.mod h1:/VUhepiaJMQUp4+oa/7Zr1D23ma6VTLIYjOOTFZPUcA= golang.org/x/term v0.0.0-20201126162022-7de9c90e9dd1/go.mod h1:bj7SfCRtBDWHUb9snDiAeCFNEtKQo2Wmx5Cou7ajbmo= golang.org/x/term v0.0.0-20210927222741-03fcf44c2211/go.mod h1:jbD1KX2456YbFQfuXm/mYQcufACuNUgVhRMnK/tPxf8= golang.org/x/term v0.2.0/go.mod h1:TVmDHMZPmdnySmBfhjOoOdhjzdE1h4u1VwSiw2l1Nuc= @@ -494,8 +496,8 @@ golang.org/x/term v0.5.0/go.mod h1:jMB1sMXY+tzblOD4FWmEbocvup2/aLOaQEp7JmGp78k= golang.org/x/term v0.6.0/go.mod h1:m6U89DPEgQRMq3DNkDClhWw02AUbt2daBVO4cn4Hv9U= golang.org/x/term v0.8.0/go.mod h1:xPskH00ivmX89bAKVGSKKtLOWNx2+17Eiy94tnKShWo= golang.org/x/term v0.17.0/go.mod h1:lLRBjIVuehSbZlaOtGMbcMncT+aqLLLmKrsjNrUguwk= -golang.org/x/term v0.19.0 h1:+ThwsDv+tYfnJFhF4L8jITxu1tdTWRTZpdsWgEgjL6Q= -golang.org/x/term v0.19.0/go.mod h1:2CuTdWZ7KHSQwUzKva0cbMg6q2DMI3Mmxp+gKJbskEk= +golang.org/x/term v0.20.0 h1:VnkxpohqXaOBYJtBmEppKUG6mXpi+4O6purfc2+sMhw= +golang.org/x/term v0.20.0/go.mod h1:8UkIAJTvZgivsXaD6/pH6U9ecQzZ45awqEOzuCvwpFY= golang.org/x/text v0.3.0/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ= golang.org/x/text v0.3.2/go.mod h1:bEr9sfX3Q8Zfm5fL9x+3itogRgK3+ptLWKqgva+5dAk= golang.org/x/text v0.3.3/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ= @@ -506,8 +508,9 @@ golang.org/x/text v0.4.0/go.mod h1:mrYo+phRRbMaCq/xk9113O4dZlRixOauAjOtrjsXDZ8= golang.org/x/text v0.7.0/go.mod h1:mrYo+phRRbMaCq/xk9113O4dZlRixOauAjOtrjsXDZ8= golang.org/x/text v0.8.0/go.mod h1:e1OnstbJyHTd6l/uOt8jFFHp6TRDWZR/bV3emEE/zU8= golang.org/x/text v0.9.0/go.mod h1:e1OnstbJyHTd6l/uOt8jFFHp6TRDWZR/bV3emEE/zU8= -golang.org/x/text v0.14.0 h1:ScX5w1eTa3QqT8oi6+ziP7dTV1S2+ALU0bI+0zXKWiQ= golang.org/x/text v0.14.0/go.mod h1:18ZOQIKpY8NJVqYksKHtTdi31H5itFRjB5/qKTNYzSU= +golang.org/x/text v0.15.0 h1:h1V/4gjBv8v9cjcR6+AR5+/cIYK5N/WAgiv4xlsEtAk= +golang.org/x/text v0.15.0/go.mod h1:18ZOQIKpY8NJVqYksKHtTdi31H5itFRjB5/qKTNYzSU= golang.org/x/time v0.5.0 h1:o7cqy6amK/52YcAKIPlM3a+Fpj35zvRj2TP+e1xFSfk= golang.org/x/time v0.5.0/go.mod h1:3BpzKBy/shNhVucY/MWOyx10tF3SFh9QdLuxbVysPQM= golang.org/x/tools v0.0.0-20180917221912-90fa682c2a6e/go.mod h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ= From 0c15286a502098a7746e6cc586b78ae5cf35caa4 Mon Sep 17 00:00:00 2001 From: John Kjell Date: Wed, 12 Jun 2024 14:55:59 -0500 Subject: [PATCH 2/5] Update docs and fix multiple signatures Signed-off-by: John Kjell --- cmd/run.go | 1 - docs/attestors/omnitrail.json | 145 +++++++++++++++++++++++++++++++++ docs/attestors/omnitrail.md | 148 ++++++++++++++++++++++++++++++++++ docs/commands.md | 1 + go.mod | 4 +- go.sum | 8 ++ 6 files changed, 305 insertions(+), 2 deletions(-) create mode 100644 docs/attestors/omnitrail.json create mode 100644 docs/attestors/omnitrail.md diff --git a/cmd/run.go b/cmd/run.go index 3d557682..9f2091ed 100644 --- a/cmd/run.go +++ b/cmd/run.go @@ -133,7 +133,6 @@ func runRun(ctx context.Context, ro options.RunOptions, args []string, signers . witness.RunWithAttestors(attestors), witness.RunWithAttestationOpts(attestation.WithWorkingDir(ro.WorkingDir), attestation.WithHashes(roHashes)), witness.RunWithTimestampers(timestampers...), - witness.RunWithSigners(signers...), ) if err != nil { return err diff --git a/docs/attestors/omnitrail.json b/docs/attestors/omnitrail.json new file mode 100644 index 00000000..e0a0f538 --- /dev/null +++ b/docs/attestors/omnitrail.json @@ -0,0 +1,145 @@ +{ + "$schema": "https://json-schema.org/draft/2020-12/schema", + "$ref": "#/$defs/Attestor", + "$defs": { + "Attestor": { + "properties": { + "Envelope": { + "$ref": "#/$defs/Envelope" + } + }, + "additionalProperties": false, + "type": "object", + "required": [ + "Envelope" + ] + }, + "Element": { + "properties": { + "type": { + "type": "string" + }, + "sha1": { + "type": "string" + }, + "sha256": { + "type": "string" + }, + "gitoid:sha1": { + "type": "string" + }, + "gitoid:sha256": { + "type": "string" + }, + "posix": { + "$ref": "#/$defs/Posix" + } + }, + "additionalProperties": false, + "type": "object", + "required": [ + "type" + ] + }, + "Envelope": { + "properties": { + "header": { + "$ref": "#/$defs/Header" + }, + "mapping": { + "additionalProperties": { + "$ref": "#/$defs/Element" + }, + "type": "object" + } + }, + "additionalProperties": false, + "type": "object", + "required": [ + "header", + "mapping" + ] + }, + "Feature": { + "properties": { + "algorithms": { + "items": { + "type": "string" + }, + "type": "array" + } + }, + "additionalProperties": false, + "type": "object" + }, + "Header": { + "properties": { + "features": { + "additionalProperties": { + "$ref": "#/$defs/Feature" + }, + "type": "object" + } + }, + "additionalProperties": false, + "type": "object", + "required": [ + "features" + ] + }, + "Posix": { + "properties": { + "atime": { + "type": "string" + }, + "ctime": { + "type": "string" + }, + "creation_time": { + "type": "string" + }, + "extended_attributes": { + "type": "string" + }, + "file_device_id": { + "type": "string" + }, + "file_flags": { + "type": "string" + }, + "file_inode": { + "type": "string" + }, + "file_system_id": { + "type": "string" + }, + "file_type": { + "type": "string" + }, + "hard_link_count": { + "type": "string" + }, + "mtime": { + "type": "string" + }, + "metadata_ctime": { + "type": "string" + }, + "owner_gid": { + "type": "string" + }, + "owner_uid": { + "type": "string" + }, + "permissions": { + "type": "string" + }, + "size": { + "type": "string" + } + }, + "additionalProperties": false, + "type": "object" + } + } +} diff --git a/docs/attestors/omnitrail.md b/docs/attestors/omnitrail.md new file mode 100644 index 00000000..5f703efc --- /dev/null +++ b/docs/attestors/omnitrail.md @@ -0,0 +1,148 @@ +## Schema +```json +{ + "$schema": "https://json-schema.org/draft/2020-12/schema", + "$ref": "#/$defs/Attestor", + "$defs": { + "Attestor": { + "properties": { + "Envelope": { + "$ref": "#/$defs/Envelope" + } + }, + "additionalProperties": false, + "type": "object", + "required": [ + "Envelope" + ] + }, + "Element": { + "properties": { + "type": { + "type": "string" + }, + "sha1": { + "type": "string" + }, + "sha256": { + "type": "string" + }, + "gitoid:sha1": { + "type": "string" + }, + "gitoid:sha256": { + "type": "string" + }, + "posix": { + "$ref": "#/$defs/Posix" + } + }, + "additionalProperties": false, + "type": "object", + "required": [ + "type" + ] + }, + "Envelope": { + "properties": { + "header": { + "$ref": "#/$defs/Header" + }, + "mapping": { + "additionalProperties": { + "$ref": "#/$defs/Element" + }, + "type": "object" + } + }, + "additionalProperties": false, + "type": "object", + "required": [ + "header", + "mapping" + ] + }, + "Feature": { + "properties": { + "algorithms": { + "items": { + "type": "string" + }, + "type": "array" + } + }, + "additionalProperties": false, + "type": "object" + }, + "Header": { + "properties": { + "features": { + "additionalProperties": { + "$ref": "#/$defs/Feature" + }, + "type": "object" + } + }, + "additionalProperties": false, + "type": "object", + "required": [ + "features" + ] + }, + "Posix": { + "properties": { + "atime": { + "type": "string" + }, + "ctime": { + "type": "string" + }, + "creation_time": { + "type": "string" + }, + "extended_attributes": { + "type": "string" + }, + "file_device_id": { + "type": "string" + }, + "file_flags": { + "type": "string" + }, + "file_inode": { + "type": "string" + }, + "file_system_id": { + "type": "string" + }, + "file_type": { + "type": "string" + }, + "hard_link_count": { + "type": "string" + }, + "mtime": { + "type": "string" + }, + "metadata_ctime": { + "type": "string" + }, + "owner_gid": { + "type": "string" + }, + "owner_uid": { + "type": "string" + }, + "permissions": { + "type": "string" + }, + "size": { + "type": "string" + } + }, + "additionalProperties": false, + "type": "object" + } + } +} +``` diff --git a/docs/commands.md b/docs/commands.md index 05f0b370..14078fd2 100644 --- a/docs/commands.md +++ b/docs/commands.md @@ -46,6 +46,7 @@ witness run [cmd] [flags] --attestor-maven-pom-path string The path to the Project Object Model (POM) XML file used for task being attested (default "pom.xml"). (default "pom.xml") --attestor-product-exclude-glob string Pattern to use when recording products. Files that match this pattern will be excluded as subjects on the attestation. --attestor-product-include-glob string Pattern to use when recording products. Files that match this pattern will be included as subjects on the attestation. (default "*") + --attestor-sbom-export Export the SBOM predicate in its own attestation --attestor-slsa-export Export the SLSA provenance predicate in its own attestation --enable-archivista Use Archivista to store or retrieve attestations --hashes strings Hashes selected for digest calculation. Defaults to SHA256 (default [sha256]) diff --git a/go.mod b/go.mod index 3ae471c5..28fdc1f0 100644 --- a/go.mod +++ b/go.mod @@ -5,7 +5,7 @@ go 1.22.0 toolchain go1.22.2 require ( - github.com/in-toto/go-witness v0.4.1-0.20240608134736-6f2f501dd2bd + github.com/in-toto/go-witness v0.4.1-0.20240612191953-430d30c0e675 github.com/invopop/jsonschema v0.12.0 github.com/olekukonko/tablewriter v0.0.5 github.com/sigstore/fulcio v1.4.5 @@ -68,6 +68,7 @@ require ( github.com/edwarnicke/gitoid v0.0.0-20220710194850-1be5bfda1f9d // indirect github.com/emirpasic/gods v1.18.1 // indirect github.com/felixge/httpsnoop v1.0.4 // indirect + github.com/fkautz/omnitrail-go v0.0.0-20230808061951-37d34c23539d // indirect github.com/fsnotify/fsnotify v1.7.0 // indirect github.com/gabriel-vasile/mimetype v1.4.4 // indirect github.com/go-git/gcfg v1.5.1-0.20230307220236-3a3c6141e376 // indirect @@ -107,6 +108,7 @@ require ( github.com/mitchellh/mapstructure v1.5.0 // indirect github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect github.com/modern-go/reflect2 v1.0.2 // indirect + github.com/omnibor/omnibor-go v0.0.0-20230521145532-a77de61a16cd // indirect github.com/open-policy-agent/opa v0.61.0 // indirect github.com/owenrumney/go-sarif v1.1.1 // indirect github.com/pelletier/go-toml/v2 v2.2.2 // indirect diff --git a/go.sum b/go.sum index 280a4d86..7f51c4bf 100644 --- a/go.sum +++ b/go.sum @@ -120,6 +120,8 @@ github.com/envoyproxy/go-control-plane v0.9.4/go.mod h1:6rpuAdCZL397s3pYoYcLgu1m github.com/envoyproxy/protoc-gen-validate v0.1.0/go.mod h1:iSmxcyjqTsJpI2R4NaDN7+kN2VEUnK/pcBlmesArF7c= github.com/felixge/httpsnoop v1.0.4 h1:NFTV2Zj1bL4mc9sqWACXbQFVBBg2W3GPvqp8/ESS2Wg= github.com/felixge/httpsnoop v1.0.4/go.mod h1:m8KPJKqk1gH5J9DgRY2ASl2lWCfGKXixSwevea8zH2U= +github.com/fkautz/omnitrail-go v0.0.0-20230808061951-37d34c23539d h1:p4DOjnN5IAuUhtksK+RuwR2q3VclzeI1+zh+AfNFFjw= +github.com/fkautz/omnitrail-go v0.0.0-20230808061951-37d34c23539d/go.mod h1:To+426All36lUwebm2u5Qptl3daW1Nnk+LHrkTFhiWQ= github.com/fortytw2/leaktest v1.3.0 h1:u8491cBMTQ8ft8aeV+adlcytMZylmA5nnwwkRZjI8vw= github.com/fortytw2/leaktest v1.3.0/go.mod h1:jDsjWgpAGjm2CA7WthBh/CdZYEPF31XHquHwclZch5g= github.com/foxcpp/go-mockdns v1.0.0 h1:7jBqxd3WDWwi/6WhDvacvH1XsN3rOLXyHM1uhvIx6FI= @@ -218,6 +220,10 @@ github.com/in-toto/attestation v1.0.2 h1:ICqV41bfaDC3ixVUzAtFxFu+Dy56EPcjiIrJQe+ github.com/in-toto/attestation v1.0.2/go.mod h1:3uRayZSKuCHDDZOxLm5UfYulqqd1L1NdzYvxX/jyZEM= github.com/in-toto/go-witness v0.4.1-0.20240608134736-6f2f501dd2bd h1:sPGd1tzOrrEjxHXqbtatexyNKu1tcrllppdKkOlpV1c= github.com/in-toto/go-witness v0.4.1-0.20240608134736-6f2f501dd2bd/go.mod h1:G3tdf4O1bjP9F0BdZ3jfpGhZ4P+8b+O8Adcdw5FNE6M= +github.com/in-toto/go-witness v0.4.1-0.20240612145707-93c2d04134ec h1:NLX7Mtim7ZyEog9sn7n4IOx+3hFHGj/j3e5bawsh/jE= +github.com/in-toto/go-witness v0.4.1-0.20240612145707-93c2d04134ec/go.mod h1:6naOxeUWknoYAxGysHav9y8EIff0kGEeFxHqZMchfho= +github.com/in-toto/go-witness v0.4.1-0.20240612191953-430d30c0e675 h1:+BYfIJclVcZEqjh+8kChaCMn8V9/lH/tOJ8yIXdHYy8= +github.com/in-toto/go-witness v0.4.1-0.20240612191953-430d30c0e675/go.mod h1:6naOxeUWknoYAxGysHav9y8EIff0kGEeFxHqZMchfho= github.com/inconshreveable/mousetrap v1.1.0 h1:wN+x4NVGpMsO7ErUn/mUI3vEoE6Jt13X2s0bqwp9tc8= github.com/inconshreveable/mousetrap v1.1.0/go.mod h1:vpF70FUmC8bwa3OWnCshd2FqLfsEA9PFc4w1p2J65bw= github.com/invopop/jsonschema v0.12.0 h1:6ovsNSuvn9wEQVOyc72aycBMVQFKz7cPdMJn10CvzRI= @@ -271,6 +277,8 @@ github.com/modern-go/reflect2 v1.0.2 h1:xBagoLtFs94CBntxluKeaWgTMpvLxC4ur3nMaC9G github.com/modern-go/reflect2 v1.0.2/go.mod h1:yWuevngMOJpCy52FWWMvUC8ws7m/LJsjYzDa0/r8luk= github.com/olekukonko/tablewriter v0.0.5 h1:P2Ga83D34wi1o9J6Wh1mRuqd4mF/x/lgBS7N7AbDhec= github.com/olekukonko/tablewriter v0.0.5/go.mod h1:hPp6KlRPjbx+hW8ykQs1w3UBbZlj6HuIJcUGPhkA7kY= +github.com/omnibor/omnibor-go v0.0.0-20230521145532-a77de61a16cd h1:25EpGVgctk6V3DUa1gqFHvjVbmdWqM+jBZAed7p/krQ= +github.com/omnibor/omnibor-go v0.0.0-20230521145532-a77de61a16cd/go.mod h1:ArlQivzDQvZnFe8itjlA3ndPTXd9iWOgqzF31OyIEFQ= github.com/onsi/gomega v1.31.0 h1:54UJxxj6cPInHS3a35wm6BK/F9nHYueZ1NVujHDrnXE= github.com/onsi/gomega v1.31.0/go.mod h1:DW9aCi7U6Yi40wNVAvT6kzFnEVEI5n3DloYBiKiT6zk= github.com/open-policy-agent/opa v0.61.0 h1:nhncQ2CAYtQTV/SMBhDDPsCpCQsUW+zO/1j+T5V7oZg= From 616eab955ce6991fb49a58c8becbef8271ac74ec Mon Sep 17 00:00:00 2001 From: John Kjell Date: Thu, 13 Jun 2024 10:45:14 -0500 Subject: [PATCH 3/5] Update to go-witness v0.5.0 and support testing on Darwin/Mac (no tracing support) Signed-off-by: John Kjell --- go.mod | 53 ++++++++++---------- go.sum | 118 +++++++++++++++++++++------------------------ test/test-mac.yaml | 31 ++++++++++++ test/test.sh | 22 ++++++--- 4 files changed, 128 insertions(+), 96 deletions(-) create mode 100644 test/test-mac.yaml diff --git a/go.mod b/go.mod index 28fdc1f0..7a613cac 100644 --- a/go.mod +++ b/go.mod @@ -5,7 +5,7 @@ go 1.22.0 toolchain go1.22.2 require ( - github.com/in-toto/go-witness v0.4.1-0.20240612191953-430d30c0e675 + github.com/in-toto/go-witness v0.5.0 github.com/invopop/jsonschema v0.12.0 github.com/olekukonko/tablewriter v0.0.5 github.com/sigstore/fulcio v1.4.5 @@ -24,7 +24,7 @@ require ( github.com/segmentio/ksuid v1.0.4 // indirect github.com/skratchdot/open-golang v0.0.0-20200116055534-eef842397966 // indirect github.com/spiffe/go-spiffe/v2 v2.1.7 // indirect - github.com/zclconf/go-cty v1.14.2 // indirect + github.com/zclconf/go-cty v1.14.4 // indirect golang.org/x/oauth2 v0.20.0 // indirect ) @@ -41,24 +41,24 @@ require ( github.com/agnivade/levenshtein v1.1.1 // indirect github.com/apparentlymart/go-textseg/v15 v15.0.0 // indirect github.com/aws/aws-sdk-go v1.50.38 // indirect - github.com/aws/aws-sdk-go-v2 v1.27.0 // indirect - github.com/aws/aws-sdk-go-v2/config v1.27.16 // indirect - github.com/aws/aws-sdk-go-v2/credentials v1.17.16 // indirect - github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.16.3 // indirect - github.com/aws/aws-sdk-go-v2/internal/configsources v1.3.7 // indirect - github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.6.7 // indirect + github.com/aws/aws-sdk-go-v2 v1.27.2 // indirect + github.com/aws/aws-sdk-go-v2/config v1.27.18 // indirect + github.com/aws/aws-sdk-go-v2/credentials v1.17.18 // indirect + github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.16.5 // indirect + github.com/aws/aws-sdk-go-v2/internal/configsources v1.3.9 // indirect + github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.6.9 // indirect github.com/aws/aws-sdk-go-v2/internal/ini v1.8.0 // indirect github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.11.2 // indirect - github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.11.9 // indirect + github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.11.11 // indirect github.com/aws/aws-sdk-go-v2/service/kms v1.31.3 // indirect - github.com/aws/aws-sdk-go-v2/service/sso v1.20.9 // indirect - github.com/aws/aws-sdk-go-v2/service/ssooidc v1.24.3 // indirect - github.com/aws/aws-sdk-go-v2/service/sts v1.28.10 // indirect + github.com/aws/aws-sdk-go-v2/service/sso v1.20.11 // indirect + github.com/aws/aws-sdk-go-v2/service/ssooidc v1.24.5 // indirect + github.com/aws/aws-sdk-go-v2/service/sts v1.28.12 // indirect github.com/aws/smithy-go v1.20.2 // indirect github.com/bahlo/generic-list-go v0.2.0 // indirect github.com/beorn7/perks v1.0.1 // indirect github.com/buger/jsonparser v1.1.1 // indirect - github.com/cespare/xxhash/v2 v2.2.0 // indirect + github.com/cespare/xxhash/v2 v2.3.0 // indirect github.com/cloudflare/circl v1.3.7 // indirect github.com/cpuguy83/go-md2man/v2 v2.0.3 // indirect github.com/cyphar/filepath-securejoin v0.2.4 // indirect @@ -92,7 +92,7 @@ require ( github.com/gorilla/mux v1.8.1 // indirect github.com/grpc-ecosystem/grpc-gateway/v2 v2.19.1 // indirect github.com/hashicorp/hcl v1.0.1-vault-3 // indirect - github.com/in-toto/archivista v0.4.0 // indirect + github.com/in-toto/archivista v0.5.1 // indirect github.com/in-toto/attestation v1.0.2 // indirect github.com/inconshreveable/mousetrap v1.1.0 // indirect github.com/jbenet/go-context v0.0.0-20150711004518-d14ea06fba99 // indirect @@ -109,15 +109,15 @@ require ( github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect github.com/modern-go/reflect2 v1.0.2 // indirect github.com/omnibor/omnibor-go v0.0.0-20230521145532-a77de61a16cd // indirect - github.com/open-policy-agent/opa v0.61.0 // indirect + github.com/open-policy-agent/opa v0.64.0 // indirect github.com/owenrumney/go-sarif v1.1.1 // indirect github.com/pelletier/go-toml/v2 v2.2.2 // indirect github.com/pjbgf/sha1cd v0.3.0 // indirect github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect github.com/prometheus/client_golang v1.19.0 // indirect - github.com/prometheus/client_model v0.6.0 // indirect - github.com/prometheus/common v0.51.1 // indirect - github.com/prometheus/procfs v0.12.0 // indirect + github.com/prometheus/client_model v0.6.1 // indirect + github.com/prometheus/common v0.53.0 // indirect + github.com/prometheus/procfs v0.14.0 // indirect github.com/rcrowley/go-metrics v0.0.0-20201227073835-cf1acfcdf475 // indirect github.com/russross/blackfriday/v2 v2.1.0 // indirect github.com/sagikazarmark/locafero v0.4.0 // indirect @@ -142,21 +142,21 @@ require ( go.opencensus.io v0.24.0 // indirect go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.49.0 // indirect go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.49.0 // indirect - go.opentelemetry.io/otel v1.24.0 // indirect - go.opentelemetry.io/otel/metric v1.24.0 // indirect - go.opentelemetry.io/otel/sdk v1.24.0 // indirect - go.opentelemetry.io/otel/trace v1.24.0 // indirect + go.opentelemetry.io/otel v1.26.0 // indirect + go.opentelemetry.io/otel/metric v1.26.0 // indirect + go.opentelemetry.io/otel/sdk v1.26.0 // indirect + go.opentelemetry.io/otel/trace v1.26.0 // indirect go.uber.org/multierr v1.11.0 // indirect golang.org/x/crypto v0.23.0 // indirect - golang.org/x/exp v0.0.0-20240325151524-a685a6edb6d8 // indirect - golang.org/x/mod v0.16.0 // indirect + golang.org/x/exp v0.0.0-20240416160154-fe59bbe5cc7f // indirect + golang.org/x/mod v0.17.0 // indirect golang.org/x/net v0.25.0 // indirect golang.org/x/sync v0.7.0 // indirect golang.org/x/sys v0.20.0 // indirect golang.org/x/term v0.20.0 // indirect golang.org/x/text v0.15.0 // indirect golang.org/x/time v0.5.0 // indirect - golang.org/x/tools v0.19.0 // indirect + golang.org/x/tools v0.21.0 // indirect google.golang.org/api v0.177.0 // indirect google.golang.org/genproto v0.0.0-20240401170217-c3f982113cda // indirect google.golang.org/genproto/googleapis/api v0.0.0-20240429193739-8cf5692501f6 // indirect @@ -166,12 +166,11 @@ require ( gopkg.in/go-jose/go-jose.v2 v2.6.3 // indirect gopkg.in/inf.v0 v0.9.1 // indirect gopkg.in/ini.v1 v1.67.0 // indirect - gopkg.in/square/go-jose.v2 v2.6.0 // indirect gopkg.in/warnings.v0 v0.1.2 // indirect gopkg.in/yaml.v2 v2.4.0 // indirect gopkg.in/yaml.v3 v3.0.1 // indirect k8s.io/klog/v2 v2.120.1 // indirect - k8s.io/utils v0.0.0-20240102154912-e7106e64919e // indirect + k8s.io/utils v0.0.0-20240423183400-0849a56e8f22 // indirect sigs.k8s.io/json v0.0.0-20221116044647-bc3834ca7abd // indirect sigs.k8s.io/structured-merge-diff/v4 v4.4.1 // indirect sigs.k8s.io/yaml v1.4.0 // indirect diff --git a/go.sum b/go.sum index 7f51c4bf..8d743ea3 100644 --- a/go.sum +++ b/go.sum @@ -36,32 +36,32 @@ github.com/armon/go-socks5 v0.0.0-20160902184237-e75332964ef5 h1:0CwZNZbxp69SHPd github.com/armon/go-socks5 v0.0.0-20160902184237-e75332964ef5/go.mod h1:wHh0iHkYZB8zMSxRWpUBQtwG5a7fFgvEO+odwuTv2gs= github.com/aws/aws-sdk-go v1.50.38 h1:h8wxaLin7sFGK4sKassc1VpNcDbgAAEQJ5PHjqLAvXQ= github.com/aws/aws-sdk-go v1.50.38/go.mod h1:LF8svs817+Nz+DmiMQKTO3ubZ/6IaTpq3TjupRn3Eqk= -github.com/aws/aws-sdk-go-v2 v1.27.0 h1:7bZWKoXhzI+mMR/HjdMx8ZCC5+6fY0lS5tr0bbgiLlo= -github.com/aws/aws-sdk-go-v2 v1.27.0/go.mod h1:ffIFB97e2yNsv4aTSGkqtHnppsIJzw7G7BReUZ3jCXM= -github.com/aws/aws-sdk-go-v2/config v1.27.16 h1:knpCuH7laFVGYTNd99Ns5t+8PuRjDn4HnnZK48csipM= -github.com/aws/aws-sdk-go-v2/config v1.27.16/go.mod h1:vutqgRhDUktwSge3hrC3nkuirzkJ4E/mLj5GvI0BQas= -github.com/aws/aws-sdk-go-v2/credentials v1.17.16 h1:7d2QxY83uYl0l58ceyiSpxg9bSbStqBC6BeEeHEchwo= -github.com/aws/aws-sdk-go-v2/credentials v1.17.16/go.mod h1:Ae6li/6Yc6eMzysRL2BXlPYvnrLLBg3D11/AmOjw50k= -github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.16.3 h1:dQLK4TjtnlRGb0czOht2CevZ5l6RSyRWAnKeGd7VAFE= -github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.16.3/go.mod h1:TL79f2P6+8Q7dTsILpiVST+AL9lkF6PPGI167Ny0Cjw= -github.com/aws/aws-sdk-go-v2/internal/configsources v1.3.7 h1:lf/8VTF2cM+N4SLzaYJERKEWAXq8MOMpZfU6wEPWsPk= -github.com/aws/aws-sdk-go-v2/internal/configsources v1.3.7/go.mod h1:4SjkU7QiqK2M9oozyMzfZ/23LmUY+h3oFqhdeP5OMiI= -github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.6.7 h1:4OYVp0705xu8yjdyoWix0r9wPIRXnIzzOoUpQVHIJ/g= -github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.6.7/go.mod h1:vd7ESTEvI76T2Na050gODNmNU7+OyKrIKroYTu4ABiI= +github.com/aws/aws-sdk-go-v2 v1.27.2 h1:pLsTXqX93rimAOZG2FIYraDQstZaaGVVN4tNw65v0h8= +github.com/aws/aws-sdk-go-v2 v1.27.2/go.mod h1:ffIFB97e2yNsv4aTSGkqtHnppsIJzw7G7BReUZ3jCXM= +github.com/aws/aws-sdk-go-v2/config v1.27.18 h1:wFvAnwOKKe7QAyIxziwSKjmer9JBMH1vzIL6W+fYuKk= +github.com/aws/aws-sdk-go-v2/config v1.27.18/go.mod h1:0xz6cgdX55+kmppvPm2IaKzIXOheGJhAufacPJaXZ7c= +github.com/aws/aws-sdk-go-v2/credentials v1.17.18 h1:D/ALDWqK4JdY3OFgA2thcPO1c9aYTT5STS/CvnkqY1c= +github.com/aws/aws-sdk-go-v2/credentials v1.17.18/go.mod h1:JuitCWq+F5QGUrmMPsk945rop6bB57jdscu+Glozdnc= +github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.16.5 h1:dDgptDO9dxeFkXy+tEgVkzSClHZje/6JkPW5aZyEvrQ= +github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.16.5/go.mod h1:gjvE2KBUgUQhcv89jqxrIxH9GaKs1JbZzWejj/DaHGA= +github.com/aws/aws-sdk-go-v2/internal/configsources v1.3.9 h1:cy8ahBJuhtM8GTTSyOkfy6WVPV1IE+SS5/wfXUYuulw= +github.com/aws/aws-sdk-go-v2/internal/configsources v1.3.9/go.mod h1:CZBXGLaJnEZI6EVNcPd7a6B5IC5cA/GkRWtu9fp3S6Y= +github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.6.9 h1:A4SYk07ef04+vxZToz9LWvAXl9LW0NClpPpMsi31cz0= +github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.6.9/go.mod h1:5jJcHuwDagxN+ErjQ3PU3ocf6Ylc/p9x+BLO/+X4iXw= github.com/aws/aws-sdk-go-v2/internal/ini v1.8.0 h1:hT8rVHwugYE2lEfdFE0QWVo81lF7jMrYJVDWI+f+VxU= github.com/aws/aws-sdk-go-v2/internal/ini v1.8.0/go.mod h1:8tu/lYfQfFe6IGnaOdrpVgEL2IrrDOf6/m9RQum4NkY= github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.11.2 h1:Ji0DY1xUsUr3I8cHps0G+XM3WWU16lP6yG8qu1GAZAs= github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.11.2/go.mod h1:5CsjAbs3NlGQyZNFACh+zztPDI7fU6eW9QsxjfnuBKg= -github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.11.9 h1:Wx0rlZoEJR7JwlSZcHnEa7CNjrSIyVxMFWGAaXy4fJY= -github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.11.9/go.mod h1:aVMHdE0aHO3v+f/iw01fmXV/5DbfQ3Bi9nN7nd9bE9Y= +github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.11.11 h1:o4T+fKxA3gTMcluBNZZXE9DNaMkJuUL1O3mffCUjoJo= +github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.11.11/go.mod h1:84oZdJ+VjuJKs9v1UTC9NaodRZRseOXCTgku+vQJWR8= github.com/aws/aws-sdk-go-v2/service/kms v1.31.3 h1:wLBgq6nDNYdd0A5CvscVAKV5SVlHKOHVPedpgtigATg= github.com/aws/aws-sdk-go-v2/service/kms v1.31.3/go.mod h1:8lETO9lelSG2B6KMXFh2OwPPqGV6WQM3RqLAEjP1xaU= -github.com/aws/aws-sdk-go-v2/service/sso v1.20.9 h1:aD7AGQhvPuAxlSUfo0CWU7s6FpkbyykMhGYMvlqTjVs= -github.com/aws/aws-sdk-go-v2/service/sso v1.20.9/go.mod h1:c1qtZUWtygI6ZdvKppzCSXsDOq5I4luJPZ0Ud3juFCA= -github.com/aws/aws-sdk-go-v2/service/ssooidc v1.24.3 h1:Pav5q3cA260Zqez42T9UhIlsd9QeypszRPwC9LdSSsQ= -github.com/aws/aws-sdk-go-v2/service/ssooidc v1.24.3/go.mod h1:9lmoVDVLz/yUZwLaQ676TK02fhCu4+PgRSmMaKR1ozk= -github.com/aws/aws-sdk-go-v2/service/sts v1.28.10 h1:69tpbPED7jKPyzMcrwSvhWcJ9bPnZsZs18NT40JwM0g= -github.com/aws/aws-sdk-go-v2/service/sts v1.28.10/go.mod h1:0Aqn1MnEuitqfsCNyKsdKLhDUOr4txD/g19EfiUqgws= +github.com/aws/aws-sdk-go-v2/service/sso v1.20.11 h1:gEYM2GSpr4YNWc6hCd5nod4+d4kd9vWIAWrmGuLdlMw= +github.com/aws/aws-sdk-go-v2/service/sso v1.20.11/go.mod h1:gVvwPdPNYehHSP9Rs7q27U1EU+3Or2ZpXvzAYJNh63w= +github.com/aws/aws-sdk-go-v2/service/ssooidc v1.24.5 h1:iXjh3uaH3vsVcnyZX7MqCoCfcyxIrVE9iOQruRaWPrQ= +github.com/aws/aws-sdk-go-v2/service/ssooidc v1.24.5/go.mod h1:5ZXesEuy/QcO0WUnt+4sDkxhdXRHTu2yG0uCSH8B6os= +github.com/aws/aws-sdk-go-v2/service/sts v1.28.12 h1:M/1u4HBpwLuMtjlxuI2y6HoVLzF5e2mfxHCg7ZVMYmk= +github.com/aws/aws-sdk-go-v2/service/sts v1.28.12/go.mod h1:kcfd+eTdEi/40FIbLq4Hif3XMXnl5b/+t/KTfLt9xIk= github.com/aws/smithy-go v1.20.2 h1:tbp628ireGtzcHDDmLT/6ADHidqnwgF57XOXZe6tp4Q= github.com/aws/smithy-go v1.20.2/go.mod h1:krry+ya/rV9RDcV/Q16kpu6ypI4K2czasz0NC3qS14E= github.com/bahlo/generic-list-go v0.2.0 h1:5sz/EEAK+ls5wF+NeqDpk5+iNdMDXrh3z3nPnH1Wvgk= @@ -78,8 +78,8 @@ github.com/cenkalti/backoff/v4 v4.2.1/go.mod h1:Y3VNntkOUPxTVeUxJ/G5vcM//AlwfmyY github.com/census-instrumentation/opencensus-proto v0.2.1/go.mod h1:f6KPmirojxKA12rnyqOA5BBL4O983OfeGPqjHWSTneU= github.com/cespare/xxhash v1.1.0 h1:a6HrQnmkObjyL+Gs60czilIUGqrzKutQD6XZog3p+ko= github.com/cespare/xxhash v1.1.0/go.mod h1:XrSqR1VqqWfGrhpAt58auRo0WTKS1nRRg3ghfAqPWnc= -github.com/cespare/xxhash/v2 v2.2.0 h1:DC2CZ1Ep5Y4k3ZQ899DldepgrayRUGE6BBZ/cd9Cj44= -github.com/cespare/xxhash/v2 v2.2.0/go.mod h1:VGX0DQ3Q6kWi7AoAeZDth3/j3BFtOZR5XLFGgcrjCOs= +github.com/cespare/xxhash/v2 v2.3.0 h1:UL815xU9SqsFlibzuggzjXhog7bL6oX9BbNZnL2UFvs= +github.com/cespare/xxhash/v2 v2.3.0/go.mod h1:VGX0DQ3Q6kWi7AoAeZDth3/j3BFtOZR5XLFGgcrjCOs= github.com/client9/misspell v0.3.4/go.mod h1:qj6jICC3Q7zFZvVWo7KLAzC3yx5G7kyvSDkc90ppPyw= github.com/cloudflare/circl v1.3.3/go.mod h1:5XYMA4rFBvNIrhs50XuiBJ15vF2pZn4nnUKZrLbUZFA= github.com/cloudflare/circl v1.3.7 h1:qlCDlTPz2n9fu58M0Nh1J/JzcFpfgkFHHX3O35r5vcU= @@ -124,8 +124,8 @@ github.com/fkautz/omnitrail-go v0.0.0-20230808061951-37d34c23539d h1:p4DOjnN5IAu github.com/fkautz/omnitrail-go v0.0.0-20230808061951-37d34c23539d/go.mod h1:To+426All36lUwebm2u5Qptl3daW1Nnk+LHrkTFhiWQ= github.com/fortytw2/leaktest v1.3.0 h1:u8491cBMTQ8ft8aeV+adlcytMZylmA5nnwwkRZjI8vw= github.com/fortytw2/leaktest v1.3.0/go.mod h1:jDsjWgpAGjm2CA7WthBh/CdZYEPF31XHquHwclZch5g= -github.com/foxcpp/go-mockdns v1.0.0 h1:7jBqxd3WDWwi/6WhDvacvH1XsN3rOLXyHM1uhvIx6FI= -github.com/foxcpp/go-mockdns v1.0.0/go.mod h1:lgRN6+KxQBawyIghpnl5CezHFGS9VLzvtVlwxvzXTQ4= +github.com/foxcpp/go-mockdns v1.1.0 h1:jI0rD8M0wuYAxL7r/ynTrCQQq0BVqfB99Vgk7DlmewI= +github.com/foxcpp/go-mockdns v1.1.0/go.mod h1:IhLeSFGed3mJIAXPH2aiRQB+kqz7oqu8ld2qVbOu7Wk= github.com/frankban/quicktest v1.14.6 h1:7Xjx+VpznH+oBnejlPUj8oUpdxnVs4f8XU8WnHkI4W8= github.com/frankban/quicktest v1.14.6/go.mod h1:4ptaffx2x8+WTWXmUCuVU6aPUX1/Mz7zb5vbUoiM6w0= github.com/fsnotify/fsnotify v1.7.0 h1:8JEhPFa5W2WU7YfeZzPNqzMP6Lwt7L2715Ggo0nosvA= @@ -214,16 +214,12 @@ github.com/grpc-ecosystem/grpc-gateway/v2 v2.19.1 h1:/c3QmbOGMGTOumP2iT/rCwB7b0Q github.com/grpc-ecosystem/grpc-gateway/v2 v2.19.1/go.mod h1:5SN9VR2LTsRFsrEC6FHgRbTWrTHu6tqPeKxEQv15giM= github.com/hashicorp/hcl v1.0.1-vault-3 h1:V95v5KSTu6DB5huDSKiq4uAfILEuNigK/+qPET6H/Mg= github.com/hashicorp/hcl v1.0.1-vault-3/go.mod h1:XYhtn6ijBSAj6n4YqAaf7RBPS4I06AItNorpy+MoQNM= -github.com/in-toto/archivista v0.4.0 h1:5g79iqmyXblnnwuD+768lrEbeoE0V5H7URYJFnr0p4I= -github.com/in-toto/archivista v0.4.0/go.mod h1:HgqAu7az0Ql0Jf844Paf0Ji5PdUMKxO5JIBh4hOjMs8= +github.com/in-toto/archivista v0.5.1 h1:mAPt1lW9VAMnEGiS38OGvej4t2AZ4Irfh8+y5koqSmo= +github.com/in-toto/archivista v0.5.1/go.mod h1:wzOSEgvDdV27CZUWm6H72sQ+vzAWjQLX1qhBJIJUSYI= github.com/in-toto/attestation v1.0.2 h1:ICqV41bfaDC3ixVUzAtFxFu+Dy56EPcjiIrJQe+4LVM= github.com/in-toto/attestation v1.0.2/go.mod h1:3uRayZSKuCHDDZOxLm5UfYulqqd1L1NdzYvxX/jyZEM= -github.com/in-toto/go-witness v0.4.1-0.20240608134736-6f2f501dd2bd h1:sPGd1tzOrrEjxHXqbtatexyNKu1tcrllppdKkOlpV1c= -github.com/in-toto/go-witness v0.4.1-0.20240608134736-6f2f501dd2bd/go.mod h1:G3tdf4O1bjP9F0BdZ3jfpGhZ4P+8b+O8Adcdw5FNE6M= -github.com/in-toto/go-witness v0.4.1-0.20240612145707-93c2d04134ec h1:NLX7Mtim7ZyEog9sn7n4IOx+3hFHGj/j3e5bawsh/jE= -github.com/in-toto/go-witness v0.4.1-0.20240612145707-93c2d04134ec/go.mod h1:6naOxeUWknoYAxGysHav9y8EIff0kGEeFxHqZMchfho= -github.com/in-toto/go-witness v0.4.1-0.20240612191953-430d30c0e675 h1:+BYfIJclVcZEqjh+8kChaCMn8V9/lH/tOJ8yIXdHYy8= -github.com/in-toto/go-witness v0.4.1-0.20240612191953-430d30c0e675/go.mod h1:6naOxeUWknoYAxGysHav9y8EIff0kGEeFxHqZMchfho= +github.com/in-toto/go-witness v0.5.0 h1:ViES51SWrgOByFdZTny+ZRFPClJcFQ8WId/YlxdPG7Q= +github.com/in-toto/go-witness v0.5.0/go.mod h1:RN10WG5hFnK9OSHFlQD4mql54uCrtWdZ08/bl1vPuMI= github.com/inconshreveable/mousetrap v1.1.0 h1:wN+x4NVGpMsO7ErUn/mUI3vEoE6Jt13X2s0bqwp9tc8= github.com/inconshreveable/mousetrap v1.1.0/go.mod h1:vpF70FUmC8bwa3OWnCshd2FqLfsEA9PFc4w1p2J65bw= github.com/invopop/jsonschema v0.12.0 h1:6ovsNSuvn9wEQVOyc72aycBMVQFKz7cPdMJn10CvzRI= @@ -245,8 +241,8 @@ github.com/kevinburke/ssh_config v1.2.0 h1:x584FjTGwHzMwvHx18PXxbBVzfnxogHaAReU4 github.com/kevinburke/ssh_config v1.2.0/go.mod h1:CT57kijsi8u/K/BOFA39wgDQJ9CxiF4nAY/ojJ6r6mM= github.com/kisielk/errcheck v1.5.0/go.mod h1:pFxgyoBC7bSaBwPgfKdkLd5X25qrDl4LWUI2bnpBCr8= github.com/kisielk/gotool v1.0.0/go.mod h1:XhKaO+MFFWcvkIS/tQcRk01m1F5IRFswLeQ+oQHNcck= -github.com/klauspost/compress v1.17.6 h1:60eq2E/jlfwQXtvZEeBUYADs+BwKBWURIY+Gj2eRGjI= -github.com/klauspost/compress v1.17.6/go.mod h1:/dCuZOvVtNoHsyb+cuJD3itjs3NbnF6KH9zAO4BDxPM= +github.com/klauspost/compress v1.17.8 h1:YcnTYrq7MikUT7k0Yb5eceMmALQPYBW/Xltxn0NAMnU= +github.com/klauspost/compress v1.17.8/go.mod h1:Di0epgTjJY877eYKx5yC51cX2A2Vl2ibi7bDH9ttBbw= github.com/kr/pretty v0.1.0/go.mod h1:dAy3ld7l9f0ibDNOQOHHMYYIIbhfbHSm3C4ZsoJORNo= github.com/kr/pretty v0.3.1 h1:flRD4NNwYAUpkphVc1HcthR4KEIFJ65n8Mw5qdRn3LE= github.com/kr/pretty v0.3.1/go.mod h1:hoEshYVHaxMs3cyo3Yncou5ZscifuDolrwPKZanG3xk= @@ -281,8 +277,8 @@ github.com/omnibor/omnibor-go v0.0.0-20230521145532-a77de61a16cd h1:25EpGVgctk6V github.com/omnibor/omnibor-go v0.0.0-20230521145532-a77de61a16cd/go.mod h1:ArlQivzDQvZnFe8itjlA3ndPTXd9iWOgqzF31OyIEFQ= github.com/onsi/gomega v1.31.0 h1:54UJxxj6cPInHS3a35wm6BK/F9nHYueZ1NVujHDrnXE= github.com/onsi/gomega v1.31.0/go.mod h1:DW9aCi7U6Yi40wNVAvT6kzFnEVEI5n3DloYBiKiT6zk= -github.com/open-policy-agent/opa v0.61.0 h1:nhncQ2CAYtQTV/SMBhDDPsCpCQsUW+zO/1j+T5V7oZg= -github.com/open-policy-agent/opa v0.61.0/go.mod h1:7OUuzJnsS9yHf8lw0ApfcbrnaRG1EkN3J2fuuqi4G/E= +github.com/open-policy-agent/opa v0.64.0 h1:2g0JTt78zxhFaoBmZViY4UXvtOlzBjhhrnyrIxkm+tI= +github.com/open-policy-agent/opa v0.64.0/go.mod h1:j4VeLorVpKipnkQ2TDjWshEuV3cvP/rHzQhYaraUXZY= github.com/opencontainers/go-digest v1.0.0 h1:apOUWs51W5PlhuyGyz9FCeeBIOUDA/6nW8Oi/yOhh5U= github.com/opencontainers/go-digest v1.0.0/go.mod h1:0JzlMkj0TRzQZfJkVvzbP0HBR3IKzErnv2BNG4W4MAM= github.com/owenrumney/go-sarif v1.1.1 h1:QNObu6YX1igyFKhdzd7vgzmw7XsWN3/6NMGuDzBgXmE= @@ -299,12 +295,12 @@ github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2/go.mod h1:iKH github.com/prometheus/client_golang v1.19.0 h1:ygXvpU1AoN1MhdzckN+PyD9QJOSD4x7kmXYlnfbA6JU= github.com/prometheus/client_golang v1.19.0/go.mod h1:ZRM9uEAypZakd+q/x7+gmsvXdURP+DABIEIjnmDdp+k= github.com/prometheus/client_model v0.0.0-20190812154241-14fe0d1b01d4/go.mod h1:xMI15A0UPsDsEKsMN9yxemIoYk6Tm2C1GtYGdfGttqA= -github.com/prometheus/client_model v0.6.0 h1:k1v3CzpSRUTrKMppY35TLwPvxHqBu0bYgxZzqGIgaos= -github.com/prometheus/client_model v0.6.0/go.mod h1:NTQHnmxFpouOD0DpvP4XujX3CdOAGQPoaGhyTchlyt8= -github.com/prometheus/common v0.51.1 h1:eIjN50Bwglz6a/c3hAgSMcofL3nD+nFQkV6Dd4DsQCw= -github.com/prometheus/common v0.51.1/go.mod h1:lrWtQx+iDfn2mbH5GUzlH9TSHyfZpHkSiG1W7y3sF2Q= -github.com/prometheus/procfs v0.12.0 h1:jluTpSng7V9hY0O2R9DzzJHYb2xULk9VTR1V1R/k6Bo= -github.com/prometheus/procfs v0.12.0/go.mod h1:pcuDEFsWDnvcgNzo4EEweacyhjeA9Zk3cnaOZAZEfOo= +github.com/prometheus/client_model v0.6.1 h1:ZKSh/rekM+n3CeS952MLRAdFwIKqeY8b62p8ais2e9E= +github.com/prometheus/client_model v0.6.1/go.mod h1:OrxVMOVHjw3lKMa8+x6HeMGkHMQyHDk9E3jmP2AmGiY= +github.com/prometheus/common v0.53.0 h1:U2pL9w9nmJwJDa4qqLQ3ZaePJ6ZTwt7cMD3AG3+aLCE= +github.com/prometheus/common v0.53.0/go.mod h1:BrxBKv3FWBIGXw89Mg1AeBq7FSyRzXWI3l3e7W3RN5U= +github.com/prometheus/procfs v0.14.0 h1:Lw4VdGGoKEZilJsayHf0B+9YgLGREba2C6xr+Fdfq6s= +github.com/prometheus/procfs v0.14.0/go.mod h1:XL+Iwz8k8ZabyZfMFHPiilCniixqQarAy5Mu67pHlNQ= github.com/rcrowley/go-metrics v0.0.0-20201227073835-cf1acfcdf475 h1:N/ElC8H3+5XpJzTSTfLsJV/mx9Q9g7kxmchpfZyxgzM= github.com/rcrowley/go-metrics v0.0.0-20201227073835-cf1acfcdf475/go.mod h1:bCqnVzQkZxMG4s8nGwiZ5l3QUCyqpo9Y+/ZMZ9VjZe4= github.com/rogpeppe/go-internal v1.11.0 h1:cWPaGQEPrBb5/AsnsZesgZZ9yb1OQ+GOISoDNXVBh4M= @@ -393,8 +389,8 @@ github.com/yuin/goldmark v1.1.27/go.mod h1:3hX8gzYuyVAZsxl0MRgGTJEmQBFcNTphYh9de github.com/yuin/goldmark v1.2.1/go.mod h1:3hX8gzYuyVAZsxl0MRgGTJEmQBFcNTphYh9decYSb74= github.com/yuin/goldmark v1.4.13/go.mod h1:6yULJ656Px+3vBD8DxQVa3kxgyrAnzto9xy5taEt/CY= github.com/zclconf/go-cty v1.10.0/go.mod h1:vVKLxnk3puL4qRAv72AO+W99LUD4da90g3uUAzyuvAk= -github.com/zclconf/go-cty v1.14.2 h1:kTG7lqmBou0Zkx35r6HJHUQTvaRPr5bIAf3AoHS0izI= -github.com/zclconf/go-cty v1.14.2/go.mod h1:VvMs5i0vgZdhYawQNq5kePSpLAoz8u1xvZgrPIxfnZE= +github.com/zclconf/go-cty v1.14.4 h1:uXXczd9QDGsgu0i/QFR/hzI5NYCHLf6NQw/atrbnhq8= +github.com/zclconf/go-cty v1.14.4/go.mod h1:VvMs5i0vgZdhYawQNq5kePSpLAoz8u1xvZgrPIxfnZE= github.com/zeebo/errs v1.3.0 h1:hmiaKqgYZzcVgRL1Vkc1Mn2914BbzB0IBxs+ebeutGs= github.com/zeebo/errs v1.3.0/go.mod h1:sgbWHsvVuTPHcqJJGQ1WhI5KbWlHYz+2+2C/LSEtCw4= go.opencensus.io v0.24.0 h1:y73uSU6J157QMP2kn2r30vwW1A2W2WFwSCGnAVxeaD0= @@ -403,18 +399,18 @@ go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.4 go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.49.0/go.mod h1:Mjt1i1INqiaoZOMGR1RIUJN+i3ChKoFRqzrRQhlkbs0= go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.49.0 h1:jq9TW8u3so/bN+JPT166wjOI6/vQPF6Xe7nMNIltagk= go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.49.0/go.mod h1:p8pYQP+m5XfbZm9fxtSKAbM6oIllS7s2AfxrChvc7iw= -go.opentelemetry.io/otel v1.24.0 h1:0LAOdjNmQeSTzGBzduGe/rU4tZhMwL5rWgtp9Ku5Jfo= -go.opentelemetry.io/otel v1.24.0/go.mod h1:W7b9Ozg4nkF5tWI5zsXkaKKDjdVjpD4oAt9Qi/MArHo= +go.opentelemetry.io/otel v1.26.0 h1:LQwgL5s/1W7YiiRwxf03QGnWLb2HW4pLiAhaA5cZXBs= +go.opentelemetry.io/otel v1.26.0/go.mod h1:UmLkJHUAidDval2EICqBMbnAd0/m2vmpf/dAM+fvFs4= go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.22.0 h1:9M3+rhx7kZCIQQhQRYaZCdNu1V73tm4TvXs2ntl98C4= go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.22.0/go.mod h1:noq80iT8rrHP1SfybmPiRGc9dc5M8RPmGvtwo7Oo7tc= go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.21.0 h1:tIqheXEFWAZ7O8A7m+J0aPTmpJN3YQ7qetUAdkkkKpk= go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.21.0/go.mod h1:nUeKExfxAQVbiVFn32YXpXZZHZ61Cc3s3Rn1pDBGAb0= -go.opentelemetry.io/otel/metric v1.24.0 h1:6EhoGWWK28x1fbpA4tYTOWBkPefTDQnb8WSGXlc88kI= -go.opentelemetry.io/otel/metric v1.24.0/go.mod h1:VYhLe1rFfxuTXLgj4CBiyz+9WYBA8pNGJgDcSFRKBco= -go.opentelemetry.io/otel/sdk v1.24.0 h1:YMPPDNymmQN3ZgczicBY3B6sf9n62Dlj9pWD3ucgoDw= -go.opentelemetry.io/otel/sdk v1.24.0/go.mod h1:KVrIYw6tEubO9E96HQpcmpTKDVn9gdv35HoYiQWGDFg= -go.opentelemetry.io/otel/trace v1.24.0 h1:CsKnnL4dUAr/0llH9FKuc698G04IrpWV0MQA/Y1YELI= -go.opentelemetry.io/otel/trace v1.24.0/go.mod h1:HPc3Xr/cOApsBI154IU0OI0HJexz+aw5uPdbs3UCjNU= +go.opentelemetry.io/otel/metric v1.26.0 h1:7S39CLuY5Jgg9CrnA9HHiEjGMF/X2VHvoXGgSllRz30= +go.opentelemetry.io/otel/metric v1.26.0/go.mod h1:SY+rHOI4cEawI9a7N1A4nIg/nTQXe1ccCNWYOJUrpX4= +go.opentelemetry.io/otel/sdk v1.26.0 h1:Y7bumHf5tAiDlRYFmGqetNcLaVUZmh4iYfmGxtmz7F8= +go.opentelemetry.io/otel/sdk v1.26.0/go.mod h1:0p8MXpqLeJ0pzcszQQN4F0S5FVjBLgypeGSngLsmirs= +go.opentelemetry.io/otel/trace v1.26.0 h1:1ieeAUb4y0TE26jUFrCIXKpTuVK7uJGN9/Z/2LP5sQA= +go.opentelemetry.io/otel/trace v1.26.0/go.mod h1:4iDxvGDQuUkHve82hJJ8UqrwswHYsZuWCBllGV2U2y0= go.opentelemetry.io/proto/otlp v1.0.0 h1:T0TX0tmXU8a3CbNXzEKGeU5mIVOdf0oykP+u2lIVU/I= go.opentelemetry.io/proto/otlp v1.0.0/go.mod h1:Sy6pihPLfYHkr3NkUbEhGHFhINUSI/v80hjKIs5JXpM= go.step.sm/crypto v0.44.8 h1:jDSHL6FdB1UTA0d56ECNx9XtLVkewzeg38Vy3HWB3N8= @@ -434,8 +430,8 @@ golang.org/x/crypto v0.19.0/go.mod h1:Iy9bg/ha4yyC70EfRS8jz+B6ybOBKMaSxLj6P6oBDf golang.org/x/crypto v0.23.0 h1:dIJU/v2J8Mdglj/8rJ6UUOM3Zc9zLZxVZwwxMooUSAI= golang.org/x/crypto v0.23.0/go.mod h1:CKFgDieR+mRhux2Lsu27y0fO304Db0wZe70UKqHu0v8= golang.org/x/exp v0.0.0-20190121172915-509febef88a4/go.mod h1:CJ0aWSM057203Lf6IL+f9T1iT9GByDxfZKAQTCR3kQA= -golang.org/x/exp v0.0.0-20240325151524-a685a6edb6d8 h1:aAcj0Da7eBAtrTp03QXWvm88pSyOt+UgdZw2BFZ+lEw= -golang.org/x/exp v0.0.0-20240325151524-a685a6edb6d8/go.mod h1:CQ1k9gNrJ50XIzaKCRR2hssIjF07kZFEiieALBM/ARQ= +golang.org/x/exp v0.0.0-20240416160154-fe59bbe5cc7f h1:99ci1mjWVBWwJiEKYY6jWa4d2nTQVIEhZIptnrVb1XY= +golang.org/x/exp v0.0.0-20240416160154-fe59bbe5cc7f/go.mod h1:/lliqkxwWAhPjf5oSOIJup2XcqJaw8RGS6k3TGEc7GI= golang.org/x/lint v0.0.0-20181026193005-c67002cb31c3/go.mod h1:UVdnD1Gm6xHRNCYTkRU2/jEulfH38KcIWyp/GAMgvoE= golang.org/x/lint v0.0.0-20190227174305-5b3e6a55c961/go.mod h1:wehouNa3lNwaWXcvxsM5YxQ5yQlVC4a0KAMCusXpPoU= golang.org/x/lint v0.0.0-20190313153728-d0100b6bd8b3/go.mod h1:6SW0HCj/g11FgYtHlgUYUwCkIfeOF89ocIRzGO/8vkc= @@ -443,8 +439,8 @@ golang.org/x/mod v0.2.0/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA= golang.org/x/mod v0.3.0/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA= golang.org/x/mod v0.6.0-dev.0.20220419223038-86c51ed26bb4/go.mod h1:jJ57K6gSWd91VN4djpZkiMVwK6gcyfeH4XE8wZrZaV4= golang.org/x/mod v0.8.0/go.mod h1:iBbtSCu2XBx23ZKBPSOrRkjjQPZFPuis4dIYUhu/chs= -golang.org/x/mod v0.16.0 h1:QX4fJ0Rr5cPQCF7O9lh9Se4pmwfwskqZfq5moyldzic= -golang.org/x/mod v0.16.0/go.mod h1:hTbmBsO62+eylJbnUtE2MGJUyE7QWk4xUqPFrRgJ+7c= +golang.org/x/mod v0.17.0 h1:zY54UmvipHiNd+pm+m0x9KhZ9hl1/7QNMyxXbc6ICqA= +golang.org/x/mod v0.17.0/go.mod h1:hTbmBsO62+eylJbnUtE2MGJUyE7QWk4xUqPFrRgJ+7c= golang.org/x/net v0.0.0-20180724234803-3673e40ba225/go.mod h1:mL1N/T3taQHkDXs73rZJwtUhF3w3ftmwwsq0BUmARs4= golang.org/x/net v0.0.0-20180826012351-8a410e7b638d/go.mod h1:mL1N/T3taQHkDXs73rZJwtUhF3w3ftmwwsq0BUmARs4= golang.org/x/net v0.0.0-20190213061140-3a22650c66bd/go.mod h1:mL1N/T3taQHkDXs73rZJwtUhF3w3ftmwwsq0BUmARs4= @@ -531,8 +527,8 @@ golang.org/x/tools v0.0.0-20200619180055-7c47624df98f/go.mod h1:EkVYQZoAsY45+roY golang.org/x/tools v0.0.0-20210106214847-113979e3529a/go.mod h1:emZCQorbCU4vsT4fOWvOPXz4eW1wZW4PmDk9uLelYpA= golang.org/x/tools v0.1.12/go.mod h1:hNGJHUnrk76NpqgfD5Aqm5Crs+Hm0VOH/i9J2+nxYbc= golang.org/x/tools v0.6.0/go.mod h1:Xwgl3UAJ/d3gWutnCtw505GrjyAbvKui8lOU390QaIU= -golang.org/x/tools v0.19.0 h1:tfGCXNR1OsFG+sVdLAitlpjAvD/I6dHDKnYrpEZUHkw= -golang.org/x/tools v0.19.0/go.mod h1:qoJWxmGSIBmAeriMx19ogtrEPrGtDbPK634QFIcLAhc= +golang.org/x/tools v0.21.0 h1:qc0xYgIbsSDt9EyWz05J5wfa7LOVW0YTLOXrqdLAWIw= +golang.org/x/tools v0.21.0/go.mod h1:aiJjzUbINMkxbQROHiO6hDPo2LHcIPhhQsa9DLh0yGk= golang.org/x/xerrors v0.0.0-20190717185122-a985d3407aa7/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= golang.org/x/xerrors v0.0.0-20191011141410-1b5146add898/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= golang.org/x/xerrors v0.0.0-20191204190536-9bdfabe68543/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= @@ -580,8 +576,6 @@ gopkg.in/inf.v0 v0.9.1 h1:73M5CoZyi3ZLMOyDlQh031Cx6N9NDJ2Vvfl76EDAgDc= gopkg.in/inf.v0 v0.9.1/go.mod h1:cWUDdTG/fYaXco+Dcufb5Vnc6Gp2YChqWtbxRZE0mXw= gopkg.in/ini.v1 v1.67.0 h1:Dgnx+6+nfE+IfzjUEISNeydPJh9AXNNsWbGP9KzCsOA= gopkg.in/ini.v1 v1.67.0/go.mod h1:pNLf8WUiyNEtQjuu5G5vTm06TEv9tsIgeAvK8hOrP4k= -gopkg.in/square/go-jose.v2 v2.6.0 h1:NGk74WTnPKBNUhNzQX7PYcTLUjoq7mzKk2OKbvwk2iI= -gopkg.in/square/go-jose.v2 v2.6.0/go.mod h1:M9dMgbHiYLoDGQrXy7OpJDJWiKiU//h+vD76mk0e1AI= gopkg.in/warnings.v0 v0.1.2 h1:wFXVbFY8DY5/xOe1ECiWdKCzZlxgshcYVNkBHstARME= gopkg.in/warnings.v0 v0.1.2/go.mod h1:jksf8JmL6Qr/oQM2OXTHunEvvTAsrWBLb6OOjuVWRNI= gopkg.in/yaml.v2 v2.2.2/go.mod h1:hI93XBmqTisBFMUTm0b8Fm+jr3Dg1NNxqwp+5A1VGuI= @@ -597,8 +591,8 @@ k8s.io/apimachinery v0.30.1 h1:ZQStsEfo4n65yAdlGTfP/uSHMQSoYzU/oeEbkmF7P2U= k8s.io/apimachinery v0.30.1/go.mod h1:iexa2somDaxdnj7bha06bhb43Zpa6eWH8N8dbqVjTUc= k8s.io/klog/v2 v2.120.1 h1:QXU6cPEOIslTGvZaXvFWiP9VKyeet3sawzTOvdXb4Vw= k8s.io/klog/v2 v2.120.1/go.mod h1:3Jpz1GvMt720eyJH1ckRHK1EDfpxISzJ7I9OYgaDtPE= -k8s.io/utils v0.0.0-20240102154912-e7106e64919e h1:eQ/4ljkx21sObifjzXwlPKpdGLrCfRziVtos3ofG/sQ= -k8s.io/utils v0.0.0-20240102154912-e7106e64919e/go.mod h1:OLgZIPagt7ERELqWJFomSt595RzquPNLL48iOWgYOg0= +k8s.io/utils v0.0.0-20240423183400-0849a56e8f22 h1:ao5hUqGhsqdm+bYbjH/pRkCs0unBGe9UyDahzs9zQzQ= +k8s.io/utils v0.0.0-20240423183400-0849a56e8f22/go.mod h1:OLgZIPagt7ERELqWJFomSt595RzquPNLL48iOWgYOg0= sigs.k8s.io/json v0.0.0-20221116044647-bc3834ca7abd h1:EDPBXCAspyGV4jQlpZSudPeMmr1bNJefnuqLsRAsHZo= sigs.k8s.io/json v0.0.0-20221116044647-bc3834ca7abd/go.mod h1:B8JuhiUyNFVKdsE8h686QcCxMaH6HrOAZj4vswFpcB0= sigs.k8s.io/structured-merge-diff/v4 v4.4.1 h1:150L+0vs/8DA78h1u02ooW1/fFq/Lwr+sGiqlzvrtq4= diff --git a/test/test-mac.yaml b/test/test-mac.yaml new file mode 100644 index 00000000..7b2b6dc1 --- /dev/null +++ b/test/test-mac.yaml @@ -0,0 +1,31 @@ +# Copyright 2022 The Witness Contributors +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +run: + signer-file-key-path: testkey.pem + step: build + trace: false + attestations: + - environment + - git +sign: + signer-file-key-path: testkey.pem + outfile: policy-signed.json +verify: + attestations: + - "build.attestation.json" + - "package.attestation.json" + policy: policy-signed.json + publickey: testpub.pem + artifactfile: testapp diff --git a/test/test.sh b/test/test.sh index 7c801b9e..2dd8650d 100755 --- a/test/test.sh +++ b/test/test.sh @@ -20,31 +20,39 @@ DIR="$( cd -- "$(dirname "$0")" >/dev/null 2>&1 pwd -P )" + . "$DIR/common.sh" if ! checkprograms make tar; then exit 1 fi +test_config=test.yaml + +# if Darwin use test-mac.yaml +if [ "$(uname)" = "Darwin" ]; then + test_config=test-mac.yaml +fi + make -C ../ build rm -f ./policy-signed.json ./build.attestation.json ./package.attestation.json ./fail.attestation.json ./testapp ./testapp.tar.tgz echo "testing signing policy" -../bin/witness -c test.yaml -l debug sign -f policy.json +../bin/witness -c $test_config -l debug sign -f policy.json # successful test echo "testing witness run on build step" -../bin/witness -c test.yaml run -o build.attestation.json -- go build -o=testapp . +../bin/witness -c $test_config run -o build.attestation.json -- go build -o=testapp . echo "testing witness run on packaging step" -../bin/witness -c test.yaml run -s package -k ./testkey2.pem -o package.attestation.json -- tar czf ./testapp.tar.tgz ./testapp +../bin/witness -c $test_config run -s package -k ./testkey2.pem -o package.attestation.json -- tar czf ./testapp.tar.tgz ./testapp echo "testing witness verify" -../bin/witness -c test.yaml verify +../bin/witness -c $test_config verify # make sure we fail if we run with a key not in the policy echo "testing that witness verify fails with a key not in the policy" -../bin/witness -c test.yaml run -k failkey.pem -o ./fail.attestation.json -- go build -o=testapp . -../bin/witness -c test.yaml run -s package -k ./testkey2.pem -o package.attestation.json -- tar czf ./testapp.tar.tgz ./testapp +../bin/witness -c $test_config run -k failkey.pem -o ./fail.attestation.json -- go build -o=testapp . +../bin/witness -c $test_config run -s package -k ./testkey2.pem -o package.attestation.json -- tar czf ./testapp.tar.tgz ./testapp set +e -if ../bin/witness -c test.yaml verify -a ./fail.attestation.json -a ./package.attestation.json; then +if ../bin/witness -c $test_config verify -a ./fail.attestation.json -a ./package.attestation.json; then echo "expected verify to fail" exit 1 fi From 584b3ff8bd433cb6ec26905c0f6f6dca0453b9d8 Mon Sep 17 00:00:00 2001 From: John Kjell Date: Thu, 13 Jun 2024 15:05:27 -0500 Subject: [PATCH 4/5] Add testing and policy for SBOM attestations Signed-off-by: John Kjell --- test/sbom-policy-signed.json | 1 + test/sbom-policy.json | 38 ++++++++++++++++++++++++++++++++++++ test/sbom.spdx.json | 1 + test/spdx-att.json | 1 + test/test.sh | 3 +++ 5 files changed, 44 insertions(+) create mode 100644 test/sbom-policy-signed.json create mode 100644 test/sbom-policy.json create mode 100644 test/sbom.spdx.json create mode 100644 test/spdx-att.json diff --git a/test/sbom-policy-signed.json b/test/sbom-policy-signed.json new file mode 100644 index 00000000..b8c4343b --- /dev/null +++ b/test/sbom-policy-signed.json @@ -0,0 +1 @@ +{"payload":"ewogICJleHBpcmVzIjogIjIwMjUtMTItMTdUMjM6NTc6NDAtMDU6MDAiLAogICJzdGVwcyI6IHsKICAgICJzYm9tIjogewogICAgICAibmFtZSI6ICJzYm9tIiwKICAgICAgImF0dGVzdGF0aW9ucyI6IFsKICAgICAgICB7CiAgICAgICAgICAidHlwZSI6ICJodHRwczovL3dpdG5lc3MuZGV2L2F0dGVzdGF0aW9ucy9tYXRlcmlhbC92MC4xIiwKICAgICAgICAgICJyZWdvcG9saWNpZXMiOiBbXQogICAgICAgIH0sCiAgICAgICAgewogICAgICAgICAgInR5cGUiOiAiaHR0cHM6Ly93aXRuZXNzLmRldi9hdHRlc3RhdGlvbnMvY29tbWFuZC1ydW4vdjAuMSIsCiAgICAgICAgICAicmVnb3BvbGljaWVzIjogW10KICAgICAgICB9LAogICAgICAgIHsKICAgICAgICAgICJ0eXBlIjogImh0dHBzOi8vd2l0bmVzcy5kZXYvYXR0ZXN0YXRpb25zL2NvbW1hbmQtcnVuL3YwLjEiLAogICAgICAgICAgInJlZ29wb2xpY2llcyI6IFtdCiAgICAgICAgfSwKICAgICAgICB7CiAgICAgICAgICAidHlwZSI6ICJodHRwczovL3dpdG5lc3MuZGV2L2F0dGVzdGF0aW9ucy9wcm9kdWN0L3YwLjEiLAogICAgICAgICAgInJlZ29wb2xpY2llcyI6IFtdCiAgICAgICAgfQogICAgICBdLAogICAgICAiZnVuY3Rpb25hcmllcyI6IFsKICAgICAgICB7CiAgICAgICAgICAidHlwZSI6ICJwdWJsaWNrZXkiLAogICAgICAgICAgInB1YmxpY2tleWlkIjogImFlMmRjYzk4OWVhOWMxMDlhMzZlOGViYTVjNGJjMTZkOGZhZmNmZThlMWE2MTQxNjQ2NzBkNTBhZWRhY2Q2NDciCiAgICAgICAgfQogICAgICBdCiAgICB9CiAgfSwKICAicHVibGlja2V5cyI6IHsKICAgICJhZTJkY2M5ODllYTljMTA5YTM2ZThlYmE1YzRiYzE2ZDhmYWZjZmU4ZTFhNjE0MTY0NjcwZDUwYWVkYWNkNjQ3IjogewogICAgICAia2V5aWQiOiAiYWUyZGNjOTg5ZWE5YzEwOWEzNmU4ZWJhNWM0YmMxNmQ4ZmFmY2ZlOGUxYTYxNDE2NDY3MGQ1MGFlZGFjZDY0NyIsCiAgICAgICJrZXkiOiAiTFMwdExTMUNSVWRKVGlCUVZVSk1TVU1nUzBWWkxTMHRMUzBLVFVOdmQwSlJXVVJMTWxaM1FYbEZRV1l5T1c5UVVEaFZaMmhDZVVjNE5USjFRbVJQZUhKS1MwdHVOMDFOTldoVVlsQTVaWE5uVDFvdmF6QTlDaTB0TFMwdFJVNUVJRkJWUWt4SlF5QkxSVmt0TFMwdExRbz0iCiAgICB9CiAgfQp9Cg==","payloadType":"https://witness.testifysec.com/policy/v0.1","signatures":[{"keyid":"ae2dcc989ea9c109a36e8eba5c4bc16d8fafcfe8e1a614164670d50aedacd647","sig":"8CZIdUNegugaCxdekSJLscZ6D9+GatKj9ZqWdAtiScHr3ir8n6jB2iCKPYKestX8CASq3Kumq8s06zxHfMvXCw=="}]} diff --git a/test/sbom-policy.json b/test/sbom-policy.json new file mode 100644 index 00000000..8b756765 --- /dev/null +++ b/test/sbom-policy.json @@ -0,0 +1,38 @@ +{ + "expires": "2025-12-17T23:57:40-05:00", + "steps": { + "sbom": { + "name": "sbom", + "attestations": [ + { + "type": "https://witness.dev/attestations/material/v0.1", + "regopolicies": [] + }, + { + "type": "https://witness.dev/attestations/command-run/v0.1", + "regopolicies": [] + }, + { + "type": "https://witness.dev/attestations/command-run/v0.1", + "regopolicies": [] + }, + { + "type": "https://witness.dev/attestations/product/v0.1", + "regopolicies": [] + } + ], + "functionaries": [ + { + "type": "publickey", + "publickeyid": "ae2dcc989ea9c109a36e8eba5c4bc16d8fafcfe8e1a614164670d50aedacd647" + } + ] + } + }, + "publickeys": { + "ae2dcc989ea9c109a36e8eba5c4bc16d8fafcfe8e1a614164670d50aedacd647": { + "keyid": "ae2dcc989ea9c109a36e8eba5c4bc16d8fafcfe8e1a614164670d50aedacd647", + "key": "LS0tLS1CRUdJTiBQVUJMSUMgS0VZLS0tLS0KTUNvd0JRWURLMlZ3QXlFQWYyOW9QUDhVZ2hCeUc4NTJ1QmRPeHJKS0tuN01NNWhUYlA5ZXNnT1ovazA9Ci0tLS0tRU5EIFBVQkxJQyBLRVktLS0tLQo=" + } + } +} diff --git a/test/sbom.spdx.json b/test/sbom.spdx.json new file mode 100644 index 00000000..4dfcd311 --- /dev/null +++ b/test/sbom.spdx.json @@ -0,0 +1 @@ +{"spdxVersion":"SPDX-2.3","dataLicense":"CC0-1.0","SPDXID":"SPDXRef-DOCUMENT","name":"alpine","documentNamespace":"https://anchore.com/syft/image/alpine-7d3763fe-b0b0-4bb8-8d36-2fd15cf369ac","creationInfo":{"licenseListVersion":"3.24","creators":["Organization: Anchore, Inc","Tool: syft-1.5.0"],"created":"2024-06-13T18:27:26Z"},"packages":[{"name":"alpine-baselayout","SPDXID":"SPDXRef-Package-apk-alpine-baselayout-21e54be9d7ca763c","versionInfo":"3.6.5-r0","supplier":"Person: Natanael Copa (ncopa@alpinelinux.org)","originator":"Person: Natanael Copa (ncopa@alpinelinux.org)","downloadLocation":"https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout","filesAnalyzed":true,"packageVerificationCode":{"packageVerificationCodeValue":"6a22bff30e2aed347029eeb9d51c810613705455"},"sourceInfo":"acquired package info from APK DB: /lib/apk/db/installed","licenseConcluded":"NOASSERTION","licenseDeclared":"GPL-2.0-only","copyrightText":"NOASSERTION","description":"Alpine base dir structure and init scripts","externalRefs":[{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:alpine-baselayout:alpine-baselayout:3.6.5-r0:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:alpine-baselayout:alpine_baselayout:3.6.5-r0:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:alpine_baselayout:alpine-baselayout:3.6.5-r0:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:alpine_baselayout:alpine_baselayout:3.6.5-r0:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:alpine:alpine-baselayout:3.6.5-r0:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:alpine:alpine_baselayout:3.6.5-r0:*:*:*:*:*:*:*"},{"referenceCategory":"PACKAGE-MANAGER","referenceType":"purl","referenceLocator":"pkg:apk/alpine/alpine-baselayout@3.6.5-r0?arch=aarch64&distro=alpine-3.20.0"}]},{"name":"alpine-baselayout-data","SPDXID":"SPDXRef-Package-apk-alpine-baselayout-data-9ff96f942d2401f2","versionInfo":"3.6.5-r0","supplier":"Person: Natanael Copa (ncopa@alpinelinux.org)","originator":"Person: Natanael Copa (ncopa@alpinelinux.org)","downloadLocation":"https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout","filesAnalyzed":true,"packageVerificationCode":{"packageVerificationCodeValue":"6a7d69893b8bca00a39ad9a06c6a7e2833593ad0"},"sourceInfo":"acquired package info from APK DB: /lib/apk/db/installed","licenseConcluded":"NOASSERTION","licenseDeclared":"GPL-2.0-only","copyrightText":"NOASSERTION","description":"Alpine base dir structure and init scripts","externalRefs":[{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:alpine-baselayout-data:alpine-baselayout-data:3.6.5-r0:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:alpine-baselayout-data:alpine_baselayout_data:3.6.5-r0:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:alpine_baselayout_data:alpine-baselayout-data:3.6.5-r0:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:alpine_baselayout_data:alpine_baselayout_data:3.6.5-r0:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:alpine-baselayout:alpine-baselayout-data:3.6.5-r0:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:alpine-baselayout:alpine_baselayout_data:3.6.5-r0:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:alpine_baselayout:alpine-baselayout-data:3.6.5-r0:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:alpine_baselayout:alpine_baselayout_data:3.6.5-r0:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:alpine:alpine-baselayout-data:3.6.5-r0:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:alpine:alpine_baselayout_data:3.6.5-r0:*:*:*:*:*:*:*"},{"referenceCategory":"PACKAGE-MANAGER","referenceType":"purl","referenceLocator":"pkg:apk/alpine/alpine-baselayout-data@3.6.5-r0?arch=aarch64&upstream=alpine-baselayout&distro=alpine-3.20.0"}]},{"name":"alpine-keys","SPDXID":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135","versionInfo":"2.4-r1","supplier":"Person: Natanael Copa (ncopa@alpinelinux.org)","originator":"Person: Natanael Copa (ncopa@alpinelinux.org)","downloadLocation":"https://alpinelinux.org","filesAnalyzed":true,"packageVerificationCode":{"packageVerificationCodeValue":"555910826b4a68482679b6d4809b1502dd6d46ab"},"sourceInfo":"acquired package info from APK DB: /lib/apk/db/installed","licenseConcluded":"NOASSERTION","licenseDeclared":"MIT","copyrightText":"NOASSERTION","description":"Public keys for Alpine Linux packages","externalRefs":[{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:alpine-keys:alpine-keys:2.4-r1:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:alpine-keys:alpine_keys:2.4-r1:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:alpine_keys:alpine-keys:2.4-r1:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:alpine_keys:alpine_keys:2.4-r1:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:alpine:alpine-keys:2.4-r1:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:alpine:alpine_keys:2.4-r1:*:*:*:*:*:*:*"},{"referenceCategory":"PACKAGE-MANAGER","referenceType":"purl","referenceLocator":"pkg:apk/alpine/alpine-keys@2.4-r1?arch=aarch64&distro=alpine-3.20.0"}]},{"name":"apk-tools","SPDXID":"SPDXRef-Package-apk-apk-tools-78c55d64ab350462","versionInfo":"2.14.4-r0","supplier":"Person: Natanael Copa (ncopa@alpinelinux.org)","originator":"Person: Natanael Copa (ncopa@alpinelinux.org)","downloadLocation":"https://gitlab.alpinelinux.org/alpine/apk-tools","filesAnalyzed":true,"packageVerificationCode":{"packageVerificationCodeValue":"e09707a797756cf9daf1c3f5832e7c4499a04266"},"sourceInfo":"acquired package info from APK DB: /lib/apk/db/installed","licenseConcluded":"NOASSERTION","licenseDeclared":"GPL-2.0-only","copyrightText":"NOASSERTION","description":"Alpine Package Keeper - package manager for alpine","externalRefs":[{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:apk-tools:apk-tools:2.14.4-r0:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:apk-tools:apk_tools:2.14.4-r0:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:apk_tools:apk-tools:2.14.4-r0:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:apk_tools:apk_tools:2.14.4-r0:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:apk:apk-tools:2.14.4-r0:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:apk:apk_tools:2.14.4-r0:*:*:*:*:*:*:*"},{"referenceCategory":"PACKAGE-MANAGER","referenceType":"purl","referenceLocator":"pkg:apk/alpine/apk-tools@2.14.4-r0?arch=aarch64&distro=alpine-3.20.0"}]},{"name":"busybox","SPDXID":"SPDXRef-Package-apk-busybox-4cea7ce2e2974c99","versionInfo":"1.36.1-r28","supplier":"NOASSERTION","downloadLocation":"https://busybox.net/","filesAnalyzed":true,"packageVerificationCode":{"packageVerificationCodeValue":"c873508e0b37506b4b2d3006b4ce096069b6ab9a"},"sourceInfo":"acquired package info from APK DB: /lib/apk/db/installed","licenseConcluded":"NOASSERTION","licenseDeclared":"GPL-2.0-only","copyrightText":"NOASSERTION","description":"Size optimized toolbox of many common UNIX utilities","externalRefs":[{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:busybox:busybox:1.36.1-r28:*:*:*:*:*:*:*"},{"referenceCategory":"PACKAGE-MANAGER","referenceType":"purl","referenceLocator":"pkg:apk/alpine/busybox@1.36.1-r28?arch=aarch64&distro=alpine-3.20.0"}]},{"name":"busybox-binsh","SPDXID":"SPDXRef-Package-apk-busybox-binsh-1fd95b4d43a9f438","versionInfo":"1.36.1-r28","supplier":"NOASSERTION","downloadLocation":"https://busybox.net/","filesAnalyzed":true,"packageVerificationCode":{"packageVerificationCodeValue":"71bd3a1b510b531ba920457cfaa87f907c6cd091"},"sourceInfo":"acquired package info from APK DB: /lib/apk/db/installed","licenseConcluded":"NOASSERTION","licenseDeclared":"GPL-2.0-only","copyrightText":"NOASSERTION","description":"busybox ash /bin/sh","externalRefs":[{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:busybox-binsh:busybox-binsh:1.36.1-r28:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:busybox-binsh:busybox_binsh:1.36.1-r28:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:busybox_binsh:busybox-binsh:1.36.1-r28:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:busybox_binsh:busybox_binsh:1.36.1-r28:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:busybox:busybox-binsh:1.36.1-r28:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:busybox:busybox_binsh:1.36.1-r28:*:*:*:*:*:*:*"},{"referenceCategory":"PACKAGE-MANAGER","referenceType":"purl","referenceLocator":"pkg:apk/alpine/busybox-binsh@1.36.1-r28?arch=aarch64&upstream=busybox&distro=alpine-3.20.0"}]},{"name":"ca-certificates-bundle","SPDXID":"SPDXRef-Package-apk-ca-certificates-bundle-bf42440dd0b61727","versionInfo":"20240226-r0","supplier":"Person: Natanael Copa (ncopa@alpinelinux.org)","originator":"Person: Natanael Copa (ncopa@alpinelinux.org)","downloadLocation":"https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/","filesAnalyzed":true,"packageVerificationCode":{"packageVerificationCodeValue":"ed7a773d52aea0765c0db03bb25b01b5f0f50f3c"},"sourceInfo":"acquired package info from APK DB: /lib/apk/db/installed","licenseConcluded":"NOASSERTION","licenseDeclared":"(MPL-2.0 AND MIT)","copyrightText":"NOASSERTION","description":"Pre generated bundle of Mozilla certificates","externalRefs":[{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:ca-certificates-bundle:ca-certificates-bundle:20240226-r0:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:ca-certificates-bundle:ca_certificates_bundle:20240226-r0:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:ca_certificates_bundle:ca-certificates-bundle:20240226-r0:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:ca_certificates_bundle:ca_certificates_bundle:20240226-r0:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:ca-certificates:ca-certificates-bundle:20240226-r0:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:ca-certificates:ca_certificates_bundle:20240226-r0:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:ca_certificates:ca-certificates-bundle:20240226-r0:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:ca_certificates:ca_certificates_bundle:20240226-r0:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:mozilla:ca-certificates-bundle:20240226-r0:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:mozilla:ca_certificates_bundle:20240226-r0:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:ca:ca-certificates-bundle:20240226-r0:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:ca:ca_certificates_bundle:20240226-r0:*:*:*:*:*:*:*"},{"referenceCategory":"PACKAGE-MANAGER","referenceType":"purl","referenceLocator":"pkg:apk/alpine/ca-certificates-bundle@20240226-r0?arch=aarch64&upstream=ca-certificates&distro=alpine-3.20.0"}]},{"name":"libcrypto3","SPDXID":"SPDXRef-Package-apk-libcrypto3-0cfcda1a242dfd13","versionInfo":"3.3.0-r2","supplier":"Person: Natanael Copa (ncopa@alpinelinux.org)","originator":"Person: Natanael Copa (ncopa@alpinelinux.org)","downloadLocation":"https://www.openssl.org/","filesAnalyzed":true,"packageVerificationCode":{"packageVerificationCodeValue":"ae6bdffda4acbdf371b8ccc19dba2e7a525d08e1"},"sourceInfo":"acquired package info from APK DB: /lib/apk/db/installed","licenseConcluded":"NOASSERTION","licenseDeclared":"Apache-2.0","copyrightText":"NOASSERTION","description":"Crypto library from openssl","externalRefs":[{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:libcrypto3:libcrypto3:3.3.0-r2:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:libcrypto3:libcrypto:3.3.0-r2:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:libcrypto:libcrypto3:3.3.0-r2:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:libcrypto:libcrypto:3.3.0-r2:*:*:*:*:*:*:*"},{"referenceCategory":"PACKAGE-MANAGER","referenceType":"purl","referenceLocator":"pkg:apk/alpine/libcrypto3@3.3.0-r2?arch=aarch64&upstream=openssl&distro=alpine-3.20.0"}]},{"name":"libssl3","SPDXID":"SPDXRef-Package-apk-libssl3-1bffb507b1b535bc","versionInfo":"3.3.0-r2","supplier":"Person: Natanael Copa (ncopa@alpinelinux.org)","originator":"Person: Natanael Copa (ncopa@alpinelinux.org)","downloadLocation":"https://www.openssl.org/","filesAnalyzed":true,"packageVerificationCode":{"packageVerificationCodeValue":"bdcc4aef521963183255243c4256cc3348a6796b"},"sourceInfo":"acquired package info from APK DB: /lib/apk/db/installed","licenseConcluded":"NOASSERTION","licenseDeclared":"Apache-2.0","copyrightText":"NOASSERTION","description":"SSL shared libraries","externalRefs":[{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:libssl3:libssl3:3.3.0-r2:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:libssl3:libssl:3.3.0-r2:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:libssl:libssl3:3.3.0-r2:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:libssl:libssl:3.3.0-r2:*:*:*:*:*:*:*"},{"referenceCategory":"PACKAGE-MANAGER","referenceType":"purl","referenceLocator":"pkg:apk/alpine/libssl3@3.3.0-r2?arch=aarch64&upstream=openssl&distro=alpine-3.20.0"}]},{"name":"musl","SPDXID":"SPDXRef-Package-apk-musl-03e521237cbed45a","versionInfo":"1.2.5-r0","supplier":"Person: Natanael Copa (ncopa@alpinelinux.org)","originator":"Person: Natanael Copa (ncopa@alpinelinux.org)","downloadLocation":"https://musl.libc.org/","filesAnalyzed":true,"packageVerificationCode":{"packageVerificationCodeValue":"498ba4340e8deb05fbea7e1053b734717307dd81"},"sourceInfo":"acquired package info from APK DB: /lib/apk/db/installed","licenseConcluded":"NOASSERTION","licenseDeclared":"MIT","copyrightText":"NOASSERTION","description":"the musl c library (libc) implementation","externalRefs":[{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:musl-libc:musl:1.2.5-r0:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:musl_libc:musl:1.2.5-r0:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:musl:musl:1.2.5-r0:*:*:*:*:*:*:*"},{"referenceCategory":"PACKAGE-MANAGER","referenceType":"purl","referenceLocator":"pkg:apk/alpine/musl@1.2.5-r0?arch=aarch64&distro=alpine-3.20.0"}]},{"name":"musl-utils","SPDXID":"SPDXRef-Package-apk-musl-utils-c84ae08b59df5c6e","versionInfo":"1.2.5-r0","supplier":"Person: Natanael Copa (ncopa@alpinelinux.org)","originator":"Person: Natanael Copa (ncopa@alpinelinux.org)","downloadLocation":"https://musl.libc.org/","filesAnalyzed":true,"packageVerificationCode":{"packageVerificationCodeValue":"c05211eeb2d680bcd129b57790feea2157222f93"},"sourceInfo":"acquired package info from APK DB: /lib/apk/db/installed","licenseConcluded":"NOASSERTION","licenseDeclared":"(MIT AND BSD-2-Clause AND GPL-2.0-or-later)","copyrightText":"NOASSERTION","description":"the musl c library (libc) implementation","externalRefs":[{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:musl-utils:musl-utils:1.2.5-r0:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:musl-utils:musl_utils:1.2.5-r0:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:musl_utils:musl-utils:1.2.5-r0:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:musl_utils:musl_utils:1.2.5-r0:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:musl-libc:musl-utils:1.2.5-r0:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:musl-libc:musl_utils:1.2.5-r0:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:musl:musl-utils:1.2.5-r0:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:musl:musl_utils:1.2.5-r0:*:*:*:*:*:*:*"},{"referenceCategory":"PACKAGE-MANAGER","referenceType":"purl","referenceLocator":"pkg:apk/alpine/musl-utils@1.2.5-r0?arch=aarch64&upstream=musl&distro=alpine-3.20.0"}]},{"name":"scanelf","SPDXID":"SPDXRef-Package-apk-scanelf-54f3623fdd8fb8d4","versionInfo":"1.3.7-r2","supplier":"Person: Natanael Copa (ncopa@alpinelinux.org)","originator":"Person: Natanael Copa (ncopa@alpinelinux.org)","downloadLocation":"https://wiki.gentoo.org/wiki/Hardened/PaX_Utilities","filesAnalyzed":true,"packageVerificationCode":{"packageVerificationCodeValue":"98c686afd83394fddb10bd9239ec6b5a474397f1"},"sourceInfo":"acquired package info from APK DB: /lib/apk/db/installed","licenseConcluded":"NOASSERTION","licenseDeclared":"GPL-2.0-only","copyrightText":"NOASSERTION","description":"Scan ELF binaries for stuff","externalRefs":[{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:scanelf:scanelf:1.3.7-r2:*:*:*:*:*:*:*"},{"referenceCategory":"PACKAGE-MANAGER","referenceType":"purl","referenceLocator":"pkg:apk/alpine/scanelf@1.3.7-r2?arch=aarch64&upstream=pax-utils&distro=alpine-3.20.0"}]},{"name":"ssl_client","SPDXID":"SPDXRef-Package-apk-ssl-client-6bbb10e52b8e7eb4","versionInfo":"1.36.1-r28","supplier":"NOASSERTION","downloadLocation":"https://busybox.net/","filesAnalyzed":true,"packageVerificationCode":{"packageVerificationCodeValue":"7d5a1591577ff883690877e5b50998b7950f9ac7"},"sourceInfo":"acquired package info from APK DB: /lib/apk/db/installed","licenseConcluded":"NOASSERTION","licenseDeclared":"GPL-2.0-only","copyrightText":"NOASSERTION","description":"EXternal ssl_client for busybox wget","externalRefs":[{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:ssl-client:ssl-client:1.36.1-r28:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:ssl-client:ssl_client:1.36.1-r28:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:ssl_client:ssl-client:1.36.1-r28:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:ssl_client:ssl_client:1.36.1-r28:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:ssl:ssl-client:1.36.1-r28:*:*:*:*:*:*:*"},{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:ssl:ssl_client:1.36.1-r28:*:*:*:*:*:*:*"},{"referenceCategory":"PACKAGE-MANAGER","referenceType":"purl","referenceLocator":"pkg:apk/alpine/ssl_client@1.36.1-r28?arch=aarch64&upstream=busybox&distro=alpine-3.20.0"}]},{"name":"zlib","SPDXID":"SPDXRef-Package-apk-zlib-d8258d3d7c48cfbf","versionInfo":"1.3.1-r1","supplier":"Person: Natanael Copa (ncopa@alpinelinux.org)","originator":"Person: Natanael Copa (ncopa@alpinelinux.org)","downloadLocation":"https://zlib.net/","filesAnalyzed":true,"packageVerificationCode":{"packageVerificationCodeValue":"144c1bbadb241708c66589af3af429734cb73bb0"},"sourceInfo":"acquired package info from APK DB: /lib/apk/db/installed","licenseConcluded":"NOASSERTION","licenseDeclared":"Zlib","copyrightText":"NOASSERTION","description":"A compression/decompression Library","externalRefs":[{"referenceCategory":"SECURITY","referenceType":"cpe23Type","referenceLocator":"cpe:2.3:a:zlib:zlib:1.3.1-r1:*:*:*:*:*:*:*"},{"referenceCategory":"PACKAGE-MANAGER","referenceType":"purl","referenceLocator":"pkg:apk/alpine/zlib@1.3.1-r1?arch=aarch64&distro=alpine-3.20.0"}]},{"name":"alpine","SPDXID":"SPDXRef-DocumentRoot-Image-alpine","versionInfo":"sha256:8946eb426fbf9ed6260ee859e60462b834c8d1d50349f15e73aa17928f7991e8","supplier":"NOASSERTION","downloadLocation":"NOASSERTION","filesAnalyzed":false,"checksums":[{"algorithm":"SHA256","checksumValue":"8946eb426fbf9ed6260ee859e60462b834c8d1d50349f15e73aa17928f7991e8"}],"licenseConcluded":"NOASSERTION","licenseDeclared":"NOASSERTION","externalRefs":[{"referenceCategory":"PACKAGE-MANAGER","referenceType":"purl","referenceLocator":"pkg:oci/alpine@sha256:8946eb426fbf9ed6260ee859e60462b834c8d1d50349f15e73aa17928f7991e8?arch=arm64"}],"primaryPackagePurpose":"CONTAINER"}],"files":[{"fileName":"/bin/busybox","SPDXID":"SPDXRef-File-bin-busybox-909c5f40cb01cb38","fileTypes":["APPLICATION","BINARY"],"checksums":[{"algorithm":"SHA1","checksumValue":"db850d50e6edff81a9f1af582aaf9b843b0981e3"},{"algorithm":"SHA256","checksumValue":"19f15cbea8d91421f7f8d5086a494048d305a922a8cad88f0a4836299411ac12"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/etc/apk/keys/alpine-devel@lists.alpinelinux.org-524d27bb.rsa.pub","SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-524d27bb.rsa.pub-6742b949ff851b46","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"053a92f87fd4532850bb31f0881978efe0532ae5"},{"algorithm":"SHA256","checksumValue":"1bb2a846c0ea4ca9d0e7862f970863857fc33c32f5506098c636a62a726a847b"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/etc/apk/keys/alpine-devel@lists.alpinelinux.org-58199dcc.rsa.pub","SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-58199dcc.rsa.pub-444fb4815b9c5fa7","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"39ac5d72c6ba018a0f74b8b453894edc9db07b5f"},{"algorithm":"SHA256","checksumValue":"73867d92083f2f8ab899a26ccda7ef63dfaa0032a938620eda605558958a8041"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/etc/apk/keys/alpine-devel@lists.alpinelinux.org-616a9724.rsa.pub","SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-616a9724.rsa.pub-cfc1d017a48ee9e7","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"23d0f2ea1af269c2f66165e0f8a944e96bf011de"},{"algorithm":"SHA256","checksumValue":"10877cce0a935e46ad88cb79e174a2491680508eccda08e92bf04fb9bf37fbc1"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/etc/apk/keys/alpine-devel@lists.alpinelinux.org-616adfeb.rsa.pub","SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-616adfeb.rsa.pub-ed83cb346d241bdf","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"de1241307014aae3dba798e900f163408d98d6f4"},{"algorithm":"SHA256","checksumValue":"ebe717d228555aa58133c202314a451f81e71f174781fd7ff8d8970d6cfa60da"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/etc/apk/keys/alpine-devel@lists.alpinelinux.org-616ae350.rsa.pub","SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-616ae350.rsa.pub-76207aeaad529724","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"57f6b93fda4a4496fab62844ddef0eeb168f80b5"},{"algorithm":"SHA256","checksumValue":"d11f6b21c61b4274e182eb888883a8ba8acdbf820dcc7a6d82a7d9fc2fd2836d"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/etc/busybox-paths.d/busybox","SPDXID":"SPDXRef-File-etc-busybox-paths.d-busybox-6a326fdbd2e5a86c","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"af9972dab927fb4bfcbf574de8cf870492a66657"},{"algorithm":"SHA256","checksumValue":"e12e0822f5c6426b62f07799a0fc20394241535c5bc2cc8f10c8a25088b8defa"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/etc/crontabs/root","SPDXID":"SPDXRef-File-etc-crontabs-root-351da988aba8a527","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"bdf9356a9516238c8b2468613517749098b17ef6"},{"algorithm":"SHA256","checksumValue":"575d810a9fae5f2f0671c9b2c0ce973e46c7207fbe5cb8d1b0d1836a6a0470e3"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/etc/fstab","SPDXID":"SPDXRef-File-etc-fstab-0c5c3473875a5b85","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"d50ee135ef10a434b9df582ea8276b5c1ce803fa"},{"algorithm":"SHA256","checksumValue":"a3efca2e8d62785c87517283092b4c800d88612b6f3f06b80a4c2f39d8e68841"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/etc/group","SPDXID":"SPDXRef-File-etc-group-cc490babc7ba6984","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"d8eb64e0cdfd7cfd998e4a1bbb49c2f45be5448d"},{"algorithm":"SHA256","checksumValue":"6fb6ab5a5526e6f4896b70c7e3c350fd475158a1f0d7b5fc0f3f9bd57f1c3be8"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/etc/hostname","SPDXID":"SPDXRef-File-etc-hostname-18f4143fa24a5309","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"ea75706155cffed0a1bd43ddba4543da27d73a67"},{"algorithm":"SHA256","checksumValue":"d906aecb61d076a967d9ffe8821c7b04b063f72df9d9e35b33ef36b1c0d98f16"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/etc/hosts","SPDXID":"SPDXRef-File-etc-hosts-097d60485ef1a565","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"043eb324a653456caa1a73e2e2d49f77792bb0c5"},{"algorithm":"SHA256","checksumValue":"e3998dbe02b51dada33de87ae43d18a93ab6915b9e34f5a751bf2b9b25a55492"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/etc/inittab","SPDXID":"SPDXRef-File-etc-inittab-273285a459443001","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"ce9586d2acf1d9462765259a21ccc4f96a402151"},{"algorithm":"SHA256","checksumValue":"7326d8ad56bf5fea63b1ca516a747ff6e6723e25ae84a93c31620b03de6c001d"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/etc/logrotate.d/acpid","SPDXID":"SPDXRef-File-etc-logrotate.d-acpid-e47331443c3f2fdc","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"4f29720883559a74be03f4de69de2f66113b064b"},{"algorithm":"SHA256","checksumValue":"d608a3b7715886b5735def0cc50a6359fd364fac2e0e0a459c588c04be471031"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/etc/modprobe.d/aliases.conf","SPDXID":"SPDXRef-File-etc-modprobe.d-aliases.conf-8ac9ab5944e0b537","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"5946e1e930583552bb7b863eb94bcbb3feef8aa9"},{"algorithm":"SHA256","checksumValue":"3ebaba946f213670170c7d69949f690a3854553bd0b1560f1d980cba4c83a942"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/etc/modprobe.d/blacklist.conf","SPDXID":"SPDXRef-File-etc-modprobe.d-blacklist.conf-abf9fc46510ff77c","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"e1376014791376ddee402f8d06dae7b4e9e6f67e"},{"algorithm":"SHA256","checksumValue":"5cd46031fc7dc7186e67c97fd34780597de4ebff51dbe41eba27220fe5e0d866"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/etc/modprobe.d/i386.conf","SPDXID":"SPDXRef-File-etc-modprobe.d-i386.conf-e9054a53c22e88cf","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"a676b2fe78e7ea897d702b2c2fb2a2659f1eb657"},{"algorithm":"SHA256","checksumValue":"6c46c4cbfb8b7594f19eb94801a350fa2221ae9ac5239a8819d15555caa76ae8"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/etc/modprobe.d/kms.conf","SPDXID":"SPDXRef-File-etc-modprobe.d-kms.conf-77f620d7a99cffa8","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"ca76cb9f71980e9bda8db6bf95da759e26b27a88"},{"algorithm":"SHA256","checksumValue":"50467fa732f809f3a2bb5738628765c5f895c3a237e1c1ad09f85d41fd9ca7c5"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/etc/modules","SPDXID":"SPDXRef-File-etc-modules-f9e050b82be1ad75","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"b68a208d48a91c670c8040a03c95fae12c144f53"},{"algorithm":"SHA256","checksumValue":"2c881de75a5409c35d2433a24f180b8b02ba478ef2c1c60ea3434a35bcbc335d"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/etc/motd","SPDXID":"SPDXRef-File-etc-motd-9a55980593b74a03","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"48b912f610627546cfc30af0f974745a1bf7c30f"},{"algorithm":"SHA256","checksumValue":"ff044e9be5daa2eee2d3d10a4da72e5477e4c24c16f1792de2c91dae844c0e30"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/etc/network/if-up.d/dad","SPDXID":"SPDXRef-File-etc-network-if-up.d-dad-e17f6cd71c480b11","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"ddd99bc197c36e8a9aab9463aaeebda44a7a8029"},{"algorithm":"SHA256","checksumValue":"2fd20d1bc67d9ee711990002b24f156635a73f56b8935b2f76592938817fa4e7"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/etc/nsswitch.conf","SPDXID":"SPDXRef-File-etc-nsswitch.conf-26adb8feffe4129b","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"f4306c327bf44767da8da4e3a13bf40bdd4d3aaa"},{"algorithm":"SHA256","checksumValue":"0afd94c183d30a348b45057f6bf468e121aa448a7641109addb5bb8e282f514d"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/etc/passwd","SPDXID":"SPDXRef-File-etc-passwd-7accffa8923d35e9","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"afe6cba27664032062c7f1cb812783b1ecf6d99b"},{"algorithm":"SHA256","checksumValue":"31a94f06f17bc3b9085fccab1d0fa6ee9e79c4a1e4d91f617fa5de95863be015"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/etc/profile","SPDXID":"SPDXRef-File-etc-profile-6dfdb9518e6b63ef","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"54dd1d99ac0383798113f96307ee9b52b0bb0f37"},{"algorithm":"SHA256","checksumValue":"87e8643d3ce156de0c09370d4d39446f30bd00d264bea248abc191c4d7b9df3e"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/etc/profile.d/20locale.sh","SPDXID":"SPDXRef-File-etc-profile.d-20locale.sh-4738cb952eababba","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"96adbd950ccf992085295990f9bbe667f0cf4c4e"},{"algorithm":"SHA256","checksumValue":"284a6ef56ab97a13a777c6b01ae14f2cc3d2b7a29c19e750e622e70cc3c73186"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/etc/profile.d/README","SPDXID":"SPDXRef-File-etc-profile.d-README-3be87e7f154adb63","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"df9396b02cf3be70767e6171eb691baa6d40c759"},{"algorithm":"SHA256","checksumValue":"b73284f27fe2da9ae1902b1fe9596c3ffc61a154e2805a034184f0468f8b09b0"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/etc/profile.d/color_prompt.sh.disabled","SPDXID":"SPDXRef-File-etc-profile.d-color-prompt.sh.disabled-eeb93048af63bf64","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"d5733d99d7b5676f6d58c19a3a47a8bc3fe6e2e5"},{"algorithm":"SHA256","checksumValue":"ba24425c6864a5d17fa0fdaf914c4d21419e47c4d62080c33830af059fe46617"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/etc/protocols","SPDXID":"SPDXRef-File-etc-protocols-5f1d8d1482d973b6","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"d5f9654539089b96f1b1956848d783527da6fb47"},{"algorithm":"SHA256","checksumValue":"4959498abbadaa1e50894a266f8d0d94500101cfe5b5f09dcad82e9d5bdfab46"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/etc/securetty","SPDXID":"SPDXRef-File-etc-securetty-f5826ff16d6eaebb","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"0e29ce7fa251a4246033abcdaa339ec5dde84a75"},{"algorithm":"SHA256","checksumValue":"713fcea5109728883b9147e822429133fcc8b5e253afd3c2a197b10cd0bc3b4d"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/etc/services","SPDXID":"SPDXRef-File-etc-services-812b3f1a2d583f29","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"a0d7a229bf049f7fe17e8445226236e4024535d0"},{"algorithm":"SHA256","checksumValue":"f6183055fd949f9c53d49ee620f85d0150123ea691d25ed1bba0c641b4ee2f48"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/etc/shadow","SPDXID":"SPDXRef-File-etc-shadow-a1d64c72d061cd92","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"fdcce813d9a3aa27fffcf07126d2deabf17cb057"},{"algorithm":"SHA256","checksumValue":"d5992a27f05f380fc5faeb82a3359e2f230fd1d6ea6517b45892b771a2194ddb"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/etc/shells","SPDXID":"SPDXRef-File-etc-shells-2dc73ba417bebb75","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"a239b661da4227a07f6a9183699fd275bdb12640"},{"algorithm":"SHA256","checksumValue":"24be6ceb236610df45684c83b06c918ae45635be55f69975e43676b7595bbc5f"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/etc/ssl/certs/ca-certificates.crt","SPDXID":"SPDXRef-File-etc-ssl-certs-ca-certificates.crt-c7ec96e3f9d22e5e","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"ef142b502de28cb73fab260c80032bbb9013f2bd"},{"algorithm":"SHA256","checksumValue":"37acffef4900dc598edca36a177c60ca77f9130b5a93b1344d713ac4abcf94c1"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/etc/ssl/ct_log_list.cnf","SPDXID":"SPDXRef-File-etc-ssl-ct-log-list.cnf-7c00b4ab1629d304","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"a2587c4e97408b64274e5e052b74e3754892c13a"},{"algorithm":"SHA256","checksumValue":"f1c1803d13d1d0b755b13b23c28bd4e20e07baf9f2b744c9337ba5866aa0ec3b"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/etc/ssl/ct_log_list.cnf.dist","SPDXID":"SPDXRef-File-etc-ssl-ct-log-list.cnf.dist-4706267d3fefbca6","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"a2587c4e97408b64274e5e052b74e3754892c13a"},{"algorithm":"SHA256","checksumValue":"f1c1803d13d1d0b755b13b23c28bd4e20e07baf9f2b744c9337ba5866aa0ec3b"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/etc/ssl/openssl.cnf","SPDXID":"SPDXRef-File-etc-ssl-openssl.cnf-e2fe362bf9fd5340","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"c6aaa437fab0d4186ff361da58952c45447f0181"},{"algorithm":"SHA256","checksumValue":"3a0c65ff954aff207420846926d31d1b6056be525a0f3d38dff21f5b89f90688"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/etc/ssl/openssl.cnf.dist","SPDXID":"SPDXRef-File-etc-ssl-openssl.cnf.dist-a2fcecd0c7860aea","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"c6aaa437fab0d4186ff361da58952c45447f0181"},{"algorithm":"SHA256","checksumValue":"3a0c65ff954aff207420846926d31d1b6056be525a0f3d38dff21f5b89f90688"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/etc/sysctl.conf","SPDXID":"SPDXRef-File-etc-sysctl.conf-2eede682f1d2d57e","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"e2ea73ded7e7371664204b148569fb5e88b0f7a8"},{"algorithm":"SHA256","checksumValue":"8bba47da45bc8715c69ac904a60410eabffaa7bbbef640f9c1368ab9c48493d0"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/etc/udhcpc/udhcpc.conf","SPDXID":"SPDXRef-File-etc-udhcpc-udhcpc.conf-a8f34a90829fb0c8","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"9bc069e434228e6ca441848bfb7a6bac23fa148a"},{"algorithm":"SHA256","checksumValue":"5b372209e01cda07c87b8afa6d1ab3d7e8daf18a1f2332d744203a6dc289eb1a"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/lib/apk/db/installed","SPDXID":"SPDXRef-File-lib-apk-db-installed-8363b4a677041553","checksums":[{"algorithm":"SHA1","checksumValue":"0000000000000000000000000000000000000000"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/lib/ld-musl-aarch64.so.1","SPDXID":"SPDXRef-File-lib-ld-musl-aarch64.so.1-15ac5a87021c605c","fileTypes":["APPLICATION","BINARY"],"checksums":[{"algorithm":"SHA1","checksumValue":"50859585e21254306aeb74426d5dd4537cbe3305"},{"algorithm":"SHA256","checksumValue":"59420a762274dddac5c3d7d612564d0d6f76c54a0edf0bdf167fea661bb6d6bf"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/lib/libapk.so.2.14.0","SPDXID":"SPDXRef-File-lib-libapk.so.2.14.0-85382abc3213df0c","fileTypes":["APPLICATION","BINARY"],"checksums":[{"algorithm":"SHA1","checksumValue":"d6eed4bf4133792285922c44322d42e196405e50"},{"algorithm":"SHA256","checksumValue":"3d9d886647cc576d1c3bab0dc1a4d4e752a2f4b7d8bd5c6abfe11acccb3e4409"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/lib/libcrypto.so.3","SPDXID":"SPDXRef-File-lib-libcrypto.so.3-d7aa31f07714a25f","fileTypes":["APPLICATION","BINARY"],"checksums":[{"algorithm":"SHA1","checksumValue":"eddc1d6d87670038a43530097662cb6eee36e624"},{"algorithm":"SHA256","checksumValue":"0f9439f7e7f83e4ae355fa957ffe6878b03c467cb289dbc56f65ce058729de6d"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/lib/libssl.so.3","SPDXID":"SPDXRef-File-lib-libssl.so.3-942e1a73404f4c12","fileTypes":["APPLICATION","BINARY"],"checksums":[{"algorithm":"SHA1","checksumValue":"3f1e772e6d4a99fecf0a608f6e42d7da2069c73c"},{"algorithm":"SHA256","checksumValue":"5136a0a97053a7694de117eaec692c85bee2062b8e6907dc875599dc56629384"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/lib/libz.so.1.3.1","SPDXID":"SPDXRef-File-lib-libz.so.1.3.1-cfebf8b5dc1f6374","fileTypes":["APPLICATION","BINARY"],"checksums":[{"algorithm":"SHA1","checksumValue":"70949f5bdc478b4552562050c43b1e4b6bf014bb"},{"algorithm":"SHA256","checksumValue":"540bf9ba24238ac85b21755126dfa3a9c8ca947e0d0c938b6c1fea43d6927a7e"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/lib/sysctl.d/00-alpine.conf","SPDXID":"SPDXRef-File-lib-sysctl.d-00-alpine.conf-812cee121e721231","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"1e9125cd6d7112098a7c446d4f2ee8a269a7aba7"},{"algorithm":"SHA256","checksumValue":"ee169bea2cb6859420b55ca7a9c23fb68b50adc1d26c951f904dec9e8f767380"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/sbin/apk","SPDXID":"SPDXRef-File-sbin-apk-03a303c2f408ad75","fileTypes":["APPLICATION","BINARY"],"checksums":[{"algorithm":"SHA1","checksumValue":"191b64288f8976f9cb5875ad24481671998eceed"},{"algorithm":"SHA256","checksumValue":"d15d690cdb7e32b735a0b47806710fbfc2f8e7faabe3b3059b2009c8fbda8cdc"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/sbin/ldconfig","SPDXID":"SPDXRef-File-sbin-ldconfig-6dd00345fd25dfbe","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"2a36b6f8f3992b112450e66ac128c2ea499a103e"},{"algorithm":"SHA256","checksumValue":"b4a2c06db38742e8c42c3c9838b285a7d8cdac6c091ff3df5ff9a15f1e41b9c7"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/usr/bin/getconf","SPDXID":"SPDXRef-File-usr-bin-getconf-aa569a0b492dbc3e","fileTypes":["APPLICATION","BINARY"],"checksums":[{"algorithm":"SHA1","checksumValue":"a7c92a25adeb9f46272bf52c5d33d3babedb312d"},{"algorithm":"SHA256","checksumValue":"5238595ed22353d8c6adb8d78652b3b252f3c2ba6cffdf6eecf419eb78ff0209"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/usr/bin/getent","SPDXID":"SPDXRef-File-usr-bin-getent-dfc1d5b68ea46609","fileTypes":["APPLICATION","BINARY"],"checksums":[{"algorithm":"SHA1","checksumValue":"db0ec5b54f31a315956027172ecfee6aa60a2581"},{"algorithm":"SHA256","checksumValue":"ace5b03661ca07022837d3d7cd4781cb5a30ef6d3fc5d591d83b9263368ec0ac"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/usr/bin/iconv","SPDXID":"SPDXRef-File-usr-bin-iconv-b4f317a0c3ae4126","fileTypes":["APPLICATION","BINARY"],"checksums":[{"algorithm":"SHA1","checksumValue":"913d4848ef8289b2ff1a8f6386c3771380c601bf"},{"algorithm":"SHA256","checksumValue":"e6fcc190f17c0dc4fb691256440a6e83dc52e9fb1217e35d2a882e32296c48a6"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/usr/bin/ldd","SPDXID":"SPDXRef-File-usr-bin-ldd-0f8acf82bbb616a2","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"afe298b72fc708b978a7876f3edf2409bd66841d"},{"algorithm":"SHA256","checksumValue":"5f115be8562262bcc50ec469e25c0af2fda3bad72a960c6aa3488acd7a7da8cf"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/usr/bin/scanelf","SPDXID":"SPDXRef-File-usr-bin-scanelf-42e6597f9fa4518a","fileTypes":["APPLICATION","BINARY"],"checksums":[{"algorithm":"SHA1","checksumValue":"429e07005a605dcf7afa72a2926033c6c2cfb07d"},{"algorithm":"SHA256","checksumValue":"5ef9e7df17d4f20ad9dec44a5fdc39ea581377680cfdc1994ac48986c9254351"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/usr/bin/ssl_client","SPDXID":"SPDXRef-File-usr-bin-ssl-client-90e1da58238b5003","fileTypes":["APPLICATION","BINARY"],"checksums":[{"algorithm":"SHA1","checksumValue":"f17cb9d9effd3a5597f5dc79f50349f7b5971d31"},{"algorithm":"SHA256","checksumValue":"0094d52eac21454dedd2fce85262bba9e8538f45a3125a9e3a767ba6b8056f67"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/usr/lib/engines-3/afalg.so","SPDXID":"SPDXRef-File-usr-lib-engines-3-afalg.so-2dd02daf0dc8736e","fileTypes":["APPLICATION","BINARY"],"checksums":[{"algorithm":"SHA1","checksumValue":"feb5d2147e9a48d12cc936e1ccb8aeedd3e4c330"},{"algorithm":"SHA256","checksumValue":"24d5276e7ebb6e2c898d5329ffabb62adb0212a6bf90829b4bf88e692b669b93"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/usr/lib/engines-3/capi.so","SPDXID":"SPDXRef-File-usr-lib-engines-3-capi.so-ec9b7c1e1d7152b6","fileTypes":["APPLICATION","BINARY"],"checksums":[{"algorithm":"SHA1","checksumValue":"ddea94ab48fc5f001be7c04733be2232650b2af1"},{"algorithm":"SHA256","checksumValue":"936611a77d0786c572fcd931cd745a3e98570c82d1a1f119b8cd12062ff6da58"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/usr/lib/engines-3/loader_attic.so","SPDXID":"SPDXRef-File-usr-lib-engines-3-loader-attic.so-592a2f6a8711eea8","fileTypes":["APPLICATION","BINARY"],"checksums":[{"algorithm":"SHA1","checksumValue":"b4be46c34fcb2a01faa45819b05d0904739b0c61"},{"algorithm":"SHA256","checksumValue":"5211c7f5c60792672d4b329fc6618f4852e44ad524a480dae785b4c3fdf2e294"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/usr/lib/engines-3/padlock.so","SPDXID":"SPDXRef-File-usr-lib-engines-3-padlock.so-cb12bf2787e0b4d0","fileTypes":["APPLICATION","BINARY"],"checksums":[{"algorithm":"SHA1","checksumValue":"867d553d0d11f999eb8b9e69f66421fa0a024eb2"},{"algorithm":"SHA256","checksumValue":"129501fb2e14a42fcb8435235ef5811ff1ebc2bbebb6de9ad8d20142cadb7a97"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/usr/lib/ossl-modules/legacy.so","SPDXID":"SPDXRef-File-usr-lib-ossl-modules-legacy.so-fda2c463fe1d1275","fileTypes":["APPLICATION","BINARY"],"checksums":[{"algorithm":"SHA1","checksumValue":"1d8693b5b9b8cb13bb679d5f8bdd92038fe05850"},{"algorithm":"SHA256","checksumValue":"96e39fb0e1e386543d6d46259bc3cf77c5b5a938eda714e440ca8066b471c5d2"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-4a6a0840.rsa.pub","SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-4a6a0840.rsa.pub-410a0a130a42ece8","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"3af08548ef78cfdedcf349880c2c6a1a48763a0e"},{"algorithm":"SHA256","checksumValue":"9c102bcc376af1498d549b77bdbfa815ae86faa1d2d82f040e616b18ef2df2d4"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-5243ef4b.rsa.pub","SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-5243ef4b.rsa.pub-b5b8c9e17450db1c","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"bfb616658cc05a872568b0c8e398c482e23b60dd"},{"algorithm":"SHA256","checksumValue":"ebf31683b56410ecc4c00acd9f6e2839e237a3b62b5ae7ef686705c7ba0396a9"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-524d27bb.rsa.pub","SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-524d27bb.rsa.pub-050339be1296c5a7","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"053a92f87fd4532850bb31f0881978efe0532ae5"},{"algorithm":"SHA256","checksumValue":"1bb2a846c0ea4ca9d0e7862f970863857fc33c32f5506098c636a62a726a847b"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-5261cecb.rsa.pub","SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-5261cecb.rsa.pub-3840c02005b419b2","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"3671ae0ec7503b1e193587c1dcdf7b78bc863e42"},{"algorithm":"SHA256","checksumValue":"12f899e55a7691225603d6fb3324940fc51cd7f133e7ead788663c2b7eecb00c"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-58199dcc.rsa.pub","SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-58199dcc.rsa.pub-df4b284ea560bc2f","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"39ac5d72c6ba018a0f74b8b453894edc9db07b5f"},{"algorithm":"SHA256","checksumValue":"73867d92083f2f8ab899a26ccda7ef63dfaa0032a938620eda605558958a8041"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-58cbb476.rsa.pub","SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-58cbb476.rsa.pub-fc38dbb1c534a98b","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"c8fabeb2eeb992c368c77b9707e0d1ecfd7cf905"},{"algorithm":"SHA256","checksumValue":"9a4cd858d9710963848e6d5f555325dc199d1c952b01cf6e64da2c15deedbd97"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-58e4f17d.rsa.pub","SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-58e4f17d.rsa.pub-793318842ffeec8c","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"329643357d0b78b1ef48ec155325e25f1d7534dd"},{"algorithm":"SHA256","checksumValue":"780b3ed41786772cbc7b68136546fa3f897f28a23b30c72dde6225319c44cfff"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-5e69ca50.rsa.pub","SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-5e69ca50.rsa.pub-fb2a93a263fc77d5","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"825090fde25bbc0e71a9cb3076316b5afe459e4d"},{"algorithm":"SHA256","checksumValue":"59c01c57b446633249f67c04b115dd6787f4378f183dff2bbf65406df93f176d"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-60ac2099.rsa.pub","SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-60ac2099.rsa.pub-05c47cc8cdd4f66e","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"5d4743128353b6396fad2fa2ba793ace21602295"},{"algorithm":"SHA256","checksumValue":"db0b49163f07ffba64a5ca198bcf1688610b0bd1f0d8d5afeaf78559d73f2278"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-6165ee59.rsa.pub","SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-6165ee59.rsa.pub-5576929bc9db6198","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"95995311236b7a55933642ffa10ce6014f1af7d0"},{"algorithm":"SHA256","checksumValue":"207e4696d3c05f7cb05966aee557307151f1f00217af4143c1bcaf33b8df733f"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-61666e3f.rsa.pub","SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-61666e3f.rsa.pub-fdccfa670e123d3d","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"58d5ba4b2f3b1e927721d7a6432f298eedf72a6b"},{"algorithm":"SHA256","checksumValue":"128d34d4aec39b0daedea8163cd8dc24dff36fd3d848630ab97eeb1d3084bbb3"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616a9724.rsa.pub","SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-616a9724.rsa.pub-fe0797f3d753de34","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"23d0f2ea1af269c2f66165e0f8a944e96bf011de"},{"algorithm":"SHA256","checksumValue":"10877cce0a935e46ad88cb79e174a2491680508eccda08e92bf04fb9bf37fbc1"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616abc23.rsa.pub","SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-616abc23.rsa.pub-83f8824a9e8a4daf","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"3529ec82670c6d4e20ee3e4968db34b551e91d50"},{"algorithm":"SHA256","checksumValue":"4a095a9daca86da496a3cd9adcd95ee2197fdbeb84638656d469f05a4d740751"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616ac3bc.rsa.pub","SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-616ac3bc.rsa.pub-22d34d5fbfa617ab","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"55a301064e11c6fe9ba0f2ca17e234f3943ccb61"},{"algorithm":"SHA256","checksumValue":"0caf5662fde45616d88cfd7021b7bda269a2fcaf311e51c48945a967a609ec0b"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616adfeb.rsa.pub","SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-616adfeb.rsa.pub-951eb66cb4549509","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"de1241307014aae3dba798e900f163408d98d6f4"},{"algorithm":"SHA256","checksumValue":"ebe717d228555aa58133c202314a451f81e71f174781fd7ff8d8970d6cfa60da"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616ae350.rsa.pub","SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-616ae350.rsa.pub-44fa2966c51f0c1f","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"57f6b93fda4a4496fab62844ddef0eeb168f80b5"},{"algorithm":"SHA256","checksumValue":"d11f6b21c61b4274e182eb888883a8ba8acdbf820dcc7a6d82a7d9fc2fd2836d"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616db30d.rsa.pub","SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-616db30d.rsa.pub-b14251d1f8bcfe18","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"df02c9adc2906a3aa5e5ad69f50e3953e65710d0"},{"algorithm":"SHA256","checksumValue":"40a216cbd163f22e5f16a9e0929de7cde221b9cbae8e36aa368b1e128afe0a31"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"},{"fileName":"/usr/share/udhcpc/default.script","SPDXID":"SPDXRef-File-usr-share-udhcpc-default.script-4fc79137008d263f","fileTypes":["TEXT"],"checksums":[{"algorithm":"SHA1","checksumValue":"1d6a46dde403f14a22e2692cd84dd24af3805216"},{"algorithm":"SHA256","checksumValue":"c4e5a7c4783a7a73dec48dee009ee687015d2de7ff86b269679b95bef2c60e13"}],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"],"copyrightText":"","comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc"}],"relationships":[{"spdxElementId":"SPDXRef-Package-apk-musl-03e521237cbed45a","relatedSpdxElement":"SPDXRef-Package-apk-libcrypto3-0cfcda1a242dfd13","relationshipType":"DEPENDENCY_OF"},{"spdxElementId":"SPDXRef-Package-apk-musl-03e521237cbed45a","relatedSpdxElement":"SPDXRef-File-lib-ld-musl-aarch64.so.1-15ac5a87021c605c","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-musl-03e521237cbed45a","relatedSpdxElement":"SPDXRef-Package-apk-libssl3-1bffb507b1b535bc","relationshipType":"DEPENDENCY_OF"},{"spdxElementId":"SPDXRef-Package-apk-musl-03e521237cbed45a","relatedSpdxElement":"SPDXRef-Package-apk-busybox-4cea7ce2e2974c99","relationshipType":"DEPENDENCY_OF"},{"spdxElementId":"SPDXRef-Package-apk-musl-03e521237cbed45a","relatedSpdxElement":"SPDXRef-Package-apk-scanelf-54f3623fdd8fb8d4","relationshipType":"DEPENDENCY_OF"},{"spdxElementId":"SPDXRef-Package-apk-musl-03e521237cbed45a","relatedSpdxElement":"SPDXRef-Package-apk-ssl-client-6bbb10e52b8e7eb4","relationshipType":"DEPENDENCY_OF"},{"spdxElementId":"SPDXRef-Package-apk-musl-03e521237cbed45a","relatedSpdxElement":"SPDXRef-Package-apk-apk-tools-78c55d64ab350462","relationshipType":"DEPENDENCY_OF"},{"spdxElementId":"SPDXRef-Package-apk-musl-03e521237cbed45a","relatedSpdxElement":"SPDXRef-File-lib-apk-db-installed-8363b4a677041553","relationshipType":"OTHER","comment":"evident-by: indicates the package's existence is evident by the given file"},{"spdxElementId":"SPDXRef-Package-apk-musl-03e521237cbed45a","relatedSpdxElement":"SPDXRef-Package-apk-musl-utils-c84ae08b59df5c6e","relationshipType":"DEPENDENCY_OF"},{"spdxElementId":"SPDXRef-Package-apk-musl-03e521237cbed45a","relatedSpdxElement":"SPDXRef-Package-apk-zlib-d8258d3d7c48cfbf","relationshipType":"DEPENDENCY_OF"},{"spdxElementId":"SPDXRef-Package-apk-libcrypto3-0cfcda1a242dfd13","relatedSpdxElement":"SPDXRef-Package-apk-libssl3-1bffb507b1b535bc","relationshipType":"DEPENDENCY_OF"},{"spdxElementId":"SPDXRef-Package-apk-libcrypto3-0cfcda1a242dfd13","relatedSpdxElement":"SPDXRef-File-usr-lib-engines-3-afalg.so-2dd02daf0dc8736e","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-libcrypto3-0cfcda1a242dfd13","relatedSpdxElement":"SPDXRef-File-etc-ssl-ct-log-list.cnf.dist-4706267d3fefbca6","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-libcrypto3-0cfcda1a242dfd13","relatedSpdxElement":"SPDXRef-File-usr-lib-engines-3-loader-attic.so-592a2f6a8711eea8","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-libcrypto3-0cfcda1a242dfd13","relatedSpdxElement":"SPDXRef-Package-apk-ssl-client-6bbb10e52b8e7eb4","relationshipType":"DEPENDENCY_OF"},{"spdxElementId":"SPDXRef-Package-apk-libcrypto3-0cfcda1a242dfd13","relatedSpdxElement":"SPDXRef-Package-apk-apk-tools-78c55d64ab350462","relationshipType":"DEPENDENCY_OF"},{"spdxElementId":"SPDXRef-Package-apk-libcrypto3-0cfcda1a242dfd13","relatedSpdxElement":"SPDXRef-File-etc-ssl-ct-log-list.cnf-7c00b4ab1629d304","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-libcrypto3-0cfcda1a242dfd13","relatedSpdxElement":"SPDXRef-File-lib-apk-db-installed-8363b4a677041553","relationshipType":"OTHER","comment":"evident-by: indicates the package's existence is evident by the given file"},{"spdxElementId":"SPDXRef-Package-apk-libcrypto3-0cfcda1a242dfd13","relatedSpdxElement":"SPDXRef-File-etc-ssl-openssl.cnf.dist-a2fcecd0c7860aea","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-libcrypto3-0cfcda1a242dfd13","relatedSpdxElement":"SPDXRef-File-usr-lib-engines-3-padlock.so-cb12bf2787e0b4d0","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-libcrypto3-0cfcda1a242dfd13","relatedSpdxElement":"SPDXRef-File-lib-libcrypto.so.3-d7aa31f07714a25f","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-libcrypto3-0cfcda1a242dfd13","relatedSpdxElement":"SPDXRef-File-etc-ssl-openssl.cnf-e2fe362bf9fd5340","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-libcrypto3-0cfcda1a242dfd13","relatedSpdxElement":"SPDXRef-File-usr-lib-engines-3-capi.so-ec9b7c1e1d7152b6","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-libcrypto3-0cfcda1a242dfd13","relatedSpdxElement":"SPDXRef-File-usr-lib-ossl-modules-legacy.so-fda2c463fe1d1275","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135","relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-524d27bb.rsa.pub-050339be1296c5a7","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135","relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-60ac2099.rsa.pub-05c47cc8cdd4f66e","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135","relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-616ac3bc.rsa.pub-22d34d5fbfa617ab","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135","relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-5261cecb.rsa.pub-3840c02005b419b2","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135","relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-4a6a0840.rsa.pub-410a0a130a42ece8","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135","relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-58199dcc.rsa.pub-444fb4815b9c5fa7","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135","relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-616ae350.rsa.pub-44fa2966c51f0c1f","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135","relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-6165ee59.rsa.pub-5576929bc9db6198","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135","relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-524d27bb.rsa.pub-6742b949ff851b46","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135","relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-616ae350.rsa.pub-76207aeaad529724","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135","relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-58e4f17d.rsa.pub-793318842ffeec8c","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135","relatedSpdxElement":"SPDXRef-File-lib-apk-db-installed-8363b4a677041553","relationshipType":"OTHER","comment":"evident-by: indicates the package's existence is evident by the given file"},{"spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135","relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-616abc23.rsa.pub-83f8824a9e8a4daf","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135","relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-616adfeb.rsa.pub-951eb66cb4549509","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135","relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-616db30d.rsa.pub-b14251d1f8bcfe18","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135","relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-5243ef4b.rsa.pub-b5b8c9e17450db1c","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135","relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-616a9724.rsa.pub-cfc1d017a48ee9e7","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135","relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-58199dcc.rsa.pub-df4b284ea560bc2f","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135","relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-616adfeb.rsa.pub-ed83cb346d241bdf","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135","relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-5e69ca50.rsa.pub-fb2a93a263fc77d5","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135","relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-58cbb476.rsa.pub-fc38dbb1c534a98b","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135","relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-61666e3f.rsa.pub-fdccfa670e123d3d","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135","relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-616a9724.rsa.pub-fe0797f3d753de34","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-libssl3-1bffb507b1b535bc","relatedSpdxElement":"SPDXRef-Package-apk-ssl-client-6bbb10e52b8e7eb4","relationshipType":"DEPENDENCY_OF"},{"spdxElementId":"SPDXRef-Package-apk-libssl3-1bffb507b1b535bc","relatedSpdxElement":"SPDXRef-Package-apk-apk-tools-78c55d64ab350462","relationshipType":"DEPENDENCY_OF"},{"spdxElementId":"SPDXRef-Package-apk-libssl3-1bffb507b1b535bc","relatedSpdxElement":"SPDXRef-File-lib-apk-db-installed-8363b4a677041553","relationshipType":"OTHER","comment":"evident-by: indicates the package's existence is evident by the given file"},{"spdxElementId":"SPDXRef-Package-apk-libssl3-1bffb507b1b535bc","relatedSpdxElement":"SPDXRef-File-lib-libssl.so.3-942e1a73404f4c12","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-busybox-binsh-1fd95b4d43a9f438","relatedSpdxElement":"SPDXRef-Package-apk-alpine-baselayout-21e54be9d7ca763c","relationshipType":"DEPENDENCY_OF"},{"spdxElementId":"SPDXRef-Package-apk-busybox-binsh-1fd95b4d43a9f438","relatedSpdxElement":"SPDXRef-File-lib-apk-db-installed-8363b4a677041553","relationshipType":"OTHER","comment":"evident-by: indicates the package's existence is evident by the given file"},{"spdxElementId":"SPDXRef-Package-apk-busybox-binsh-1fd95b4d43a9f438","relatedSpdxElement":"SPDXRef-File-bin-busybox-909c5f40cb01cb38","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-21e54be9d7ca763c","relatedSpdxElement":"SPDXRef-File-etc-crontabs-root-351da988aba8a527","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-21e54be9d7ca763c","relatedSpdxElement":"SPDXRef-File-etc-profile.d-README-3be87e7f154adb63","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-21e54be9d7ca763c","relatedSpdxElement":"SPDXRef-File-etc-profile.d-20locale.sh-4738cb952eababba","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-21e54be9d7ca763c","relatedSpdxElement":"SPDXRef-File-etc-modprobe.d-kms.conf-77f620d7a99cffa8","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-21e54be9d7ca763c","relatedSpdxElement":"SPDXRef-File-lib-sysctl.d-00-alpine.conf-812cee121e721231","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-21e54be9d7ca763c","relatedSpdxElement":"SPDXRef-File-lib-apk-db-installed-8363b4a677041553","relationshipType":"OTHER","comment":"evident-by: indicates the package's existence is evident by the given file"},{"spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-21e54be9d7ca763c","relatedSpdxElement":"SPDXRef-File-etc-modprobe.d-aliases.conf-8ac9ab5944e0b537","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-21e54be9d7ca763c","relatedSpdxElement":"SPDXRef-File-etc-motd-9a55980593b74a03","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-21e54be9d7ca763c","relatedSpdxElement":"SPDXRef-File-etc-modprobe.d-blacklist.conf-abf9fc46510ff77c","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-21e54be9d7ca763c","relatedSpdxElement":"SPDXRef-File-etc-modprobe.d-i386.conf-e9054a53c22e88cf","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-21e54be9d7ca763c","relatedSpdxElement":"SPDXRef-File-etc-profile.d-color-prompt.sh.disabled-eeb93048af63bf64","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-busybox-4cea7ce2e2974c99","relatedSpdxElement":"SPDXRef-Package-apk-busybox-binsh-1fd95b4d43a9f438","relationshipType":"DEPENDENCY_OF"},{"spdxElementId":"SPDXRef-Package-apk-busybox-4cea7ce2e2974c99","relatedSpdxElement":"SPDXRef-File-usr-share-udhcpc-default.script-4fc79137008d263f","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-busybox-4cea7ce2e2974c99","relatedSpdxElement":"SPDXRef-File-etc-busybox-paths.d-busybox-6a326fdbd2e5a86c","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-busybox-4cea7ce2e2974c99","relatedSpdxElement":"SPDXRef-File-lib-apk-db-installed-8363b4a677041553","relationshipType":"OTHER","comment":"evident-by: indicates the package's existence is evident by the given file"},{"spdxElementId":"SPDXRef-Package-apk-busybox-4cea7ce2e2974c99","relatedSpdxElement":"SPDXRef-File-bin-busybox-909c5f40cb01cb38","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-busybox-4cea7ce2e2974c99","relatedSpdxElement":"SPDXRef-File-etc-udhcpc-udhcpc.conf-a8f34a90829fb0c8","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-busybox-4cea7ce2e2974c99","relatedSpdxElement":"SPDXRef-File-etc-network-if-up.d-dad-e17f6cd71c480b11","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-busybox-4cea7ce2e2974c99","relatedSpdxElement":"SPDXRef-File-etc-logrotate.d-acpid-e47331443c3f2fdc","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-busybox-4cea7ce2e2974c99","relatedSpdxElement":"SPDXRef-File-etc-securetty-f5826ff16d6eaebb","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-scanelf-54f3623fdd8fb8d4","relatedSpdxElement":"SPDXRef-File-usr-bin-scanelf-42e6597f9fa4518a","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-scanelf-54f3623fdd8fb8d4","relatedSpdxElement":"SPDXRef-File-lib-apk-db-installed-8363b4a677041553","relationshipType":"OTHER","comment":"evident-by: indicates the package's existence is evident by the given file"},{"spdxElementId":"SPDXRef-Package-apk-scanelf-54f3623fdd8fb8d4","relatedSpdxElement":"SPDXRef-Package-apk-musl-utils-c84ae08b59df5c6e","relationshipType":"DEPENDENCY_OF"},{"spdxElementId":"SPDXRef-Package-apk-ssl-client-6bbb10e52b8e7eb4","relatedSpdxElement":"SPDXRef-File-lib-apk-db-installed-8363b4a677041553","relationshipType":"OTHER","comment":"evident-by: indicates the package's existence is evident by the given file"},{"spdxElementId":"SPDXRef-Package-apk-ssl-client-6bbb10e52b8e7eb4","relatedSpdxElement":"SPDXRef-File-usr-bin-ssl-client-90e1da58238b5003","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-apk-tools-78c55d64ab350462","relatedSpdxElement":"SPDXRef-File-sbin-apk-03a303c2f408ad75","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-apk-tools-78c55d64ab350462","relatedSpdxElement":"SPDXRef-File-lib-apk-db-installed-8363b4a677041553","relationshipType":"OTHER","comment":"evident-by: indicates the package's existence is evident by the given file"},{"spdxElementId":"SPDXRef-Package-apk-apk-tools-78c55d64ab350462","relatedSpdxElement":"SPDXRef-File-lib-libapk.so.2.14.0-85382abc3213df0c","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-data-9ff96f942d2401f2","relatedSpdxElement":"SPDXRef-File-etc-hosts-097d60485ef1a565","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-data-9ff96f942d2401f2","relatedSpdxElement":"SPDXRef-File-etc-fstab-0c5c3473875a5b85","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-data-9ff96f942d2401f2","relatedSpdxElement":"SPDXRef-File-etc-hostname-18f4143fa24a5309","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-data-9ff96f942d2401f2","relatedSpdxElement":"SPDXRef-Package-apk-alpine-baselayout-21e54be9d7ca763c","relationshipType":"DEPENDENCY_OF"},{"spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-data-9ff96f942d2401f2","relatedSpdxElement":"SPDXRef-File-etc-nsswitch.conf-26adb8feffe4129b","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-data-9ff96f942d2401f2","relatedSpdxElement":"SPDXRef-File-etc-inittab-273285a459443001","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-data-9ff96f942d2401f2","relatedSpdxElement":"SPDXRef-File-etc-shells-2dc73ba417bebb75","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-data-9ff96f942d2401f2","relatedSpdxElement":"SPDXRef-File-etc-sysctl.conf-2eede682f1d2d57e","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-data-9ff96f942d2401f2","relatedSpdxElement":"SPDXRef-File-etc-protocols-5f1d8d1482d973b6","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-data-9ff96f942d2401f2","relatedSpdxElement":"SPDXRef-File-etc-profile-6dfdb9518e6b63ef","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-data-9ff96f942d2401f2","relatedSpdxElement":"SPDXRef-File-etc-passwd-7accffa8923d35e9","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-data-9ff96f942d2401f2","relatedSpdxElement":"SPDXRef-File-etc-services-812b3f1a2d583f29","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-data-9ff96f942d2401f2","relatedSpdxElement":"SPDXRef-File-lib-apk-db-installed-8363b4a677041553","relationshipType":"OTHER","comment":"evident-by: indicates the package's existence is evident by the given file"},{"spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-data-9ff96f942d2401f2","relatedSpdxElement":"SPDXRef-File-etc-shadow-a1d64c72d061cd92","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-data-9ff96f942d2401f2","relatedSpdxElement":"SPDXRef-File-etc-group-cc490babc7ba6984","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-data-9ff96f942d2401f2","relatedSpdxElement":"SPDXRef-File-etc-modules-f9e050b82be1ad75","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-ca-certificates-bundle-bf42440dd0b61727","relatedSpdxElement":"SPDXRef-Package-apk-apk-tools-78c55d64ab350462","relationshipType":"DEPENDENCY_OF"},{"spdxElementId":"SPDXRef-Package-apk-ca-certificates-bundle-bf42440dd0b61727","relatedSpdxElement":"SPDXRef-File-lib-apk-db-installed-8363b4a677041553","relationshipType":"OTHER","comment":"evident-by: indicates the package's existence is evident by the given file"},{"spdxElementId":"SPDXRef-Package-apk-ca-certificates-bundle-bf42440dd0b61727","relatedSpdxElement":"SPDXRef-File-etc-ssl-certs-ca-certificates.crt-c7ec96e3f9d22e5e","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-musl-utils-c84ae08b59df5c6e","relatedSpdxElement":"SPDXRef-File-usr-bin-ldd-0f8acf82bbb616a2","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-musl-utils-c84ae08b59df5c6e","relatedSpdxElement":"SPDXRef-File-sbin-ldconfig-6dd00345fd25dfbe","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-musl-utils-c84ae08b59df5c6e","relatedSpdxElement":"SPDXRef-File-lib-apk-db-installed-8363b4a677041553","relationshipType":"OTHER","comment":"evident-by: indicates the package's existence is evident by the given file"},{"spdxElementId":"SPDXRef-Package-apk-musl-utils-c84ae08b59df5c6e","relatedSpdxElement":"SPDXRef-File-usr-bin-getconf-aa569a0b492dbc3e","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-musl-utils-c84ae08b59df5c6e","relatedSpdxElement":"SPDXRef-File-usr-bin-iconv-b4f317a0c3ae4126","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-musl-utils-c84ae08b59df5c6e","relatedSpdxElement":"SPDXRef-File-usr-bin-getent-dfc1d5b68ea46609","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-Package-apk-zlib-d8258d3d7c48cfbf","relatedSpdxElement":"SPDXRef-Package-apk-apk-tools-78c55d64ab350462","relationshipType":"DEPENDENCY_OF"},{"spdxElementId":"SPDXRef-Package-apk-zlib-d8258d3d7c48cfbf","relatedSpdxElement":"SPDXRef-File-lib-apk-db-installed-8363b4a677041553","relationshipType":"OTHER","comment":"evident-by: indicates the package's existence is evident by the given file"},{"spdxElementId":"SPDXRef-Package-apk-zlib-d8258d3d7c48cfbf","relatedSpdxElement":"SPDXRef-File-lib-libz.so.1.3.1-cfebf8b5dc1f6374","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-DocumentRoot-Image-alpine","relatedSpdxElement":"SPDXRef-Package-apk-alpine-baselayout-21e54be9d7ca763c","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-DocumentRoot-Image-alpine","relatedSpdxElement":"SPDXRef-Package-apk-alpine-baselayout-data-9ff96f942d2401f2","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-DocumentRoot-Image-alpine","relatedSpdxElement":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-DocumentRoot-Image-alpine","relatedSpdxElement":"SPDXRef-Package-apk-apk-tools-78c55d64ab350462","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-DocumentRoot-Image-alpine","relatedSpdxElement":"SPDXRef-Package-apk-busybox-4cea7ce2e2974c99","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-DocumentRoot-Image-alpine","relatedSpdxElement":"SPDXRef-Package-apk-busybox-binsh-1fd95b4d43a9f438","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-DocumentRoot-Image-alpine","relatedSpdxElement":"SPDXRef-Package-apk-ca-certificates-bundle-bf42440dd0b61727","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-DocumentRoot-Image-alpine","relatedSpdxElement":"SPDXRef-Package-apk-libcrypto3-0cfcda1a242dfd13","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-DocumentRoot-Image-alpine","relatedSpdxElement":"SPDXRef-Package-apk-libssl3-1bffb507b1b535bc","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-DocumentRoot-Image-alpine","relatedSpdxElement":"SPDXRef-Package-apk-musl-03e521237cbed45a","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-DocumentRoot-Image-alpine","relatedSpdxElement":"SPDXRef-Package-apk-musl-utils-c84ae08b59df5c6e","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-DocumentRoot-Image-alpine","relatedSpdxElement":"SPDXRef-Package-apk-scanelf-54f3623fdd8fb8d4","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-DocumentRoot-Image-alpine","relatedSpdxElement":"SPDXRef-Package-apk-ssl-client-6bbb10e52b8e7eb4","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-DocumentRoot-Image-alpine","relatedSpdxElement":"SPDXRef-Package-apk-zlib-d8258d3d7c48cfbf","relationshipType":"CONTAINS"},{"spdxElementId":"SPDXRef-DOCUMENT","relatedSpdxElement":"SPDXRef-DocumentRoot-Image-alpine","relationshipType":"DESCRIBES"}]} diff --git a/test/spdx-att.json b/test/spdx-att.json new file mode 100644 index 00000000..6c51bf81 --- /dev/null +++ b/test/spdx-att.json @@ -0,0 +1 @@ +{"payload":"{"_type":"https://in-toto.io/Statement/v0.1","subject":[{"name":"https://witness.dev/attestations/product/v0.1/file:sbom.spdx.json","digest":{"sha256":"37dc3b4bae88070a643c9858b1e7cf54cb2d27919622282d516cc327cece27f6"}},{"name":"https://spdx.dev/Document/file:sbom.spdx.json","digest":{"sha256":"37dc3b4bae88070a643c9858b1e7cf54cb2d27919622282d516cc327cece27f6"}}],"predicateType":"https://witness.testifysec.com/attestation-collection/v0.1","predicate":{"name":"sbom","attestations":[{"type":"https://witness.dev/attestations/material/v0.1","attestation":{".gitignore":{"sha256":"ebf3a73a42ed2012db0be2b9e77f9e53d73a0a0ae22081a5fc5df2326f9afbab"},"build.attestation.json":{"sha256":"0dfa5f4a9a12d37b0467c30db527b2a235d8acc2302d1707ab2b2a6db6ec5919"},"cdx-att.json":{"sha256":"114afa50919441109512c92b710b610043710363cd5c65a3d1cdd519b08509ed"},"common.sh":{"sha256":"1207b69a627cda65cafe8877a6f560e122ba3b6b757f8d619bda55bfc540029b"},"fail.attestation.json":{"sha256":"3b4ddf6b5ce538e98162fdc17d15bf93ca9f6d4b915478e2de6fbb86a727c27a"},"failkey.pem":{"sha256":"093f0f8c5922a2f66cfb4737a5007b197b36f019a47d11a00a9577ad8fe288a9"},"freetsa.pem":{"sha256":"2151b61137ffa86bf664691ba67e7da0b19f98c758e3d228d5d8ebf27e044438"},"fulcio-policy-signed.json":{"sha256":"321550112fa88fdcd9f73169a2b0dd9082b23122e5c34598ae74567ef06394a0"},"main.go":{"sha256":"310e5ce267a64dd0ccc6341a6f043d5a7d59d57acb10f31fc11c2f54c94854d3"},"package.attestation.json":{"sha256":"c6d79073569a681787aefbacd8b01cfa349b291fc3e07927a9d9b6de1648287d"},"policy-hello-signed.json":{"sha256":"442936b5240b3d144a3152e62cfd4292dad0abd794ca1092fdf3366682975ee1"},"policy-signed.json":{"sha256":"cafb483fe3588b9e73c32fd382fb46793af902190b6e9c82286214d2cc6acb84"},"policy.json":{"sha256":"cc7d55c83d46a66c9d6b612fdd61516c9e2dbd1330119412fad41f9ceea7e84f"},"sbom.cdx.json":{"sha256":"c74a28068e75360f3319cc0309de477d999046d63d22253b68132749dccc6ed1"},"test-mac.yaml":{"sha256":"b2657a51ae7ff424755a6e3b5cefc322765a411c088928f2a667486cfd1e0912"},"test-oci.sh":{"sha256":"9914a1f6eae4f206a251f7973a6e78c3fe7b5f0de8ec689dbc28fa34e86d67c1"},"test.json":{"sha256":"f5787f6623d3ab76daa528cf0fe556d1806e6f1df0c127d3bb58a706df2707fa"},"test.sh":{"sha256":"829e8dfd30b6a9224bea405596de1337e7b5e8f941ce09105580bc54835771a2"},"test.txt":{"sha256":"5891b5b522d5df086d0ff0b110fbd9d21bb4fc7163af34d08286a2e846f6be03"},"test.yaml":{"sha256":"8380544e4a2c2ec2ec3af3250559eebb317fa335a474e99ac568c4a3653142b7"},"testapp":{"sha256":"3c48701c845ee0a2d4d3fd7798c930a137defcbbf9663e0027f2dcc765c7f257"},"testapp.tar.tgz":{"sha256":"e27b47ff5fe58a2ec9a2040d25b7a0f50e03ec5723dcdf27de23e4f448834e4a"},"testkey.pem":{"sha256":"e35ce4653f566ad7165bec992b86398092d383094787216f4d59fdef37deebde"},"testkey2.pem":{"sha256":"3a6f39d761fd0e9aa4417c50a07f9f4d7b29b1ac430a01687b68400c2b968803"},"testpub.pem":{"sha256":"ae2dcc989ea9c109a36e8eba5c4bc16d8fafcfe8e1a614164670d50aedacd647"},"testpub2.pem":{"sha256":"5e8c57df8ae58fe9a29b29f9993e2fc3b25bd75eb2754f353880bad4b9ebfdb3"}},"starttime":"2024-06-13T13:27:25.76909-05:00","endtime":"2024-06-13T13:27:25.781475-05:00"},{"type":"https://witness.dev/attestations/command-run/v0.1","attestation":{"cmd":["syft","alpine","-o","spdx-json=sbom.spdx.json"],"exitcode":0},"starttime":"2024-06-13T13:27:25.781557-05:00","endtime":"2024-06-13T13:27:26.593148-05:00"},{"type":"https://witness.dev/attestations/product/v0.1","attestation":{"sbom.spdx.json":{"mime_type":"application/spdx+json","digest":{"sha256":"37dc3b4bae88070a643c9858b1e7cf54cb2d27919622282d516cc327cece27f6"}}},"starttime":"2024-06-13T13:27:26.593291-05:00","endtime":"2024-06-13T13:27:26.597307-05:00"},{"type":"https://spdx.dev/Document","attestation":{"SPDXID":"SPDXRef-DOCUMENT","creationInfo":{"created":"2024-06-13T18:27:26Z","creators":["Organization: Anchore, Inc","Tool: syft-1.5.0"],"licenseListVersion":"3.24"},"dataLicense":"CC0-1.0","documentNamespace":"https://anchore.com/syft/image/alpine-7d3763fe-b0b0-4bb8-8d36-2fd15cf369ac","files":[{"SPDXID":"SPDXRef-File-bin-busybox-909c5f40cb01cb38","checksums":[{"algorithm":"SHA1","checksumValue":"db850d50e6edff81a9f1af582aaf9b843b0981e3"},{"algorithm":"SHA256","checksumValue":"19f15cbea8d91421f7f8d5086a494048d305a922a8cad88f0a4836299411ac12"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/bin/busybox","fileTypes":["APPLICATION","BINARY"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-524d27bb.rsa.pub-6742b949ff851b46","checksums":[{"algorithm":"SHA1","checksumValue":"053a92f87fd4532850bb31f0881978efe0532ae5"},{"algorithm":"SHA256","checksumValue":"1bb2a846c0ea4ca9d0e7862f970863857fc33c32f5506098c636a62a726a847b"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/etc/apk/keys/alpine-devel@lists.alpinelinux.org-524d27bb.rsa.pub","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-58199dcc.rsa.pub-444fb4815b9c5fa7","checksums":[{"algorithm":"SHA1","checksumValue":"39ac5d72c6ba018a0f74b8b453894edc9db07b5f"},{"algorithm":"SHA256","checksumValue":"73867d92083f2f8ab899a26ccda7ef63dfaa0032a938620eda605558958a8041"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/etc/apk/keys/alpine-devel@lists.alpinelinux.org-58199dcc.rsa.pub","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-616a9724.rsa.pub-cfc1d017a48ee9e7","checksums":[{"algorithm":"SHA1","checksumValue":"23d0f2ea1af269c2f66165e0f8a944e96bf011de"},{"algorithm":"SHA256","checksumValue":"10877cce0a935e46ad88cb79e174a2491680508eccda08e92bf04fb9bf37fbc1"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/etc/apk/keys/alpine-devel@lists.alpinelinux.org-616a9724.rsa.pub","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-616adfeb.rsa.pub-ed83cb346d241bdf","checksums":[{"algorithm":"SHA1","checksumValue":"de1241307014aae3dba798e900f163408d98d6f4"},{"algorithm":"SHA256","checksumValue":"ebe717d228555aa58133c202314a451f81e71f174781fd7ff8d8970d6cfa60da"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/etc/apk/keys/alpine-devel@lists.alpinelinux.org-616adfeb.rsa.pub","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-616ae350.rsa.pub-76207aeaad529724","checksums":[{"algorithm":"SHA1","checksumValue":"57f6b93fda4a4496fab62844ddef0eeb168f80b5"},{"algorithm":"SHA256","checksumValue":"d11f6b21c61b4274e182eb888883a8ba8acdbf820dcc7a6d82a7d9fc2fd2836d"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/etc/apk/keys/alpine-devel@lists.alpinelinux.org-616ae350.rsa.pub","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-etc-busybox-paths.d-busybox-6a326fdbd2e5a86c","checksums":[{"algorithm":"SHA1","checksumValue":"af9972dab927fb4bfcbf574de8cf870492a66657"},{"algorithm":"SHA256","checksumValue":"e12e0822f5c6426b62f07799a0fc20394241535c5bc2cc8f10c8a25088b8defa"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/etc/busybox-paths.d/busybox","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-etc-crontabs-root-351da988aba8a527","checksums":[{"algorithm":"SHA1","checksumValue":"bdf9356a9516238c8b2468613517749098b17ef6"},{"algorithm":"SHA256","checksumValue":"575d810a9fae5f2f0671c9b2c0ce973e46c7207fbe5cb8d1b0d1836a6a0470e3"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/etc/crontabs/root","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-etc-fstab-0c5c3473875a5b85","checksums":[{"algorithm":"SHA1","checksumValue":"d50ee135ef10a434b9df582ea8276b5c1ce803fa"},{"algorithm":"SHA256","checksumValue":"a3efca2e8d62785c87517283092b4c800d88612b6f3f06b80a4c2f39d8e68841"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/etc/fstab","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-etc-group-cc490babc7ba6984","checksums":[{"algorithm":"SHA1","checksumValue":"d8eb64e0cdfd7cfd998e4a1bbb49c2f45be5448d"},{"algorithm":"SHA256","checksumValue":"6fb6ab5a5526e6f4896b70c7e3c350fd475158a1f0d7b5fc0f3f9bd57f1c3be8"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/etc/group","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-etc-hostname-18f4143fa24a5309","checksums":[{"algorithm":"SHA1","checksumValue":"ea75706155cffed0a1bd43ddba4543da27d73a67"},{"algorithm":"SHA256","checksumValue":"d906aecb61d076a967d9ffe8821c7b04b063f72df9d9e35b33ef36b1c0d98f16"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/etc/hostname","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-etc-hosts-097d60485ef1a565","checksums":[{"algorithm":"SHA1","checksumValue":"043eb324a653456caa1a73e2e2d49f77792bb0c5"},{"algorithm":"SHA256","checksumValue":"e3998dbe02b51dada33de87ae43d18a93ab6915b9e34f5a751bf2b9b25a55492"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/etc/hosts","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-etc-inittab-273285a459443001","checksums":[{"algorithm":"SHA1","checksumValue":"ce9586d2acf1d9462765259a21ccc4f96a402151"},{"algorithm":"SHA256","checksumValue":"7326d8ad56bf5fea63b1ca516a747ff6e6723e25ae84a93c31620b03de6c001d"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/etc/inittab","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-etc-logrotate.d-acpid-e47331443c3f2fdc","checksums":[{"algorithm":"SHA1","checksumValue":"4f29720883559a74be03f4de69de2f66113b064b"},{"algorithm":"SHA256","checksumValue":"d608a3b7715886b5735def0cc50a6359fd364fac2e0e0a459c588c04be471031"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/etc/logrotate.d/acpid","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-etc-modprobe.d-aliases.conf-8ac9ab5944e0b537","checksums":[{"algorithm":"SHA1","checksumValue":"5946e1e930583552bb7b863eb94bcbb3feef8aa9"},{"algorithm":"SHA256","checksumValue":"3ebaba946f213670170c7d69949f690a3854553bd0b1560f1d980cba4c83a942"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/etc/modprobe.d/aliases.conf","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-etc-modprobe.d-blacklist.conf-abf9fc46510ff77c","checksums":[{"algorithm":"SHA1","checksumValue":"e1376014791376ddee402f8d06dae7b4e9e6f67e"},{"algorithm":"SHA256","checksumValue":"5cd46031fc7dc7186e67c97fd34780597de4ebff51dbe41eba27220fe5e0d866"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/etc/modprobe.d/blacklist.conf","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-etc-modprobe.d-i386.conf-e9054a53c22e88cf","checksums":[{"algorithm":"SHA1","checksumValue":"a676b2fe78e7ea897d702b2c2fb2a2659f1eb657"},{"algorithm":"SHA256","checksumValue":"6c46c4cbfb8b7594f19eb94801a350fa2221ae9ac5239a8819d15555caa76ae8"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/etc/modprobe.d/i386.conf","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-etc-modprobe.d-kms.conf-77f620d7a99cffa8","checksums":[{"algorithm":"SHA1","checksumValue":"ca76cb9f71980e9bda8db6bf95da759e26b27a88"},{"algorithm":"SHA256","checksumValue":"50467fa732f809f3a2bb5738628765c5f895c3a237e1c1ad09f85d41fd9ca7c5"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/etc/modprobe.d/kms.conf","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-etc-modules-f9e050b82be1ad75","checksums":[{"algorithm":"SHA1","checksumValue":"b68a208d48a91c670c8040a03c95fae12c144f53"},{"algorithm":"SHA256","checksumValue":"2c881de75a5409c35d2433a24f180b8b02ba478ef2c1c60ea3434a35bcbc335d"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/etc/modules","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-etc-motd-9a55980593b74a03","checksums":[{"algorithm":"SHA1","checksumValue":"48b912f610627546cfc30af0f974745a1bf7c30f"},{"algorithm":"SHA256","checksumValue":"ff044e9be5daa2eee2d3d10a4da72e5477e4c24c16f1792de2c91dae844c0e30"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/etc/motd","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-etc-network-if-up.d-dad-e17f6cd71c480b11","checksums":[{"algorithm":"SHA1","checksumValue":"ddd99bc197c36e8a9aab9463aaeebda44a7a8029"},{"algorithm":"SHA256","checksumValue":"2fd20d1bc67d9ee711990002b24f156635a73f56b8935b2f76592938817fa4e7"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/etc/network/if-up.d/dad","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-etc-nsswitch.conf-26adb8feffe4129b","checksums":[{"algorithm":"SHA1","checksumValue":"f4306c327bf44767da8da4e3a13bf40bdd4d3aaa"},{"algorithm":"SHA256","checksumValue":"0afd94c183d30a348b45057f6bf468e121aa448a7641109addb5bb8e282f514d"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/etc/nsswitch.conf","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-etc-passwd-7accffa8923d35e9","checksums":[{"algorithm":"SHA1","checksumValue":"afe6cba27664032062c7f1cb812783b1ecf6d99b"},{"algorithm":"SHA256","checksumValue":"31a94f06f17bc3b9085fccab1d0fa6ee9e79c4a1e4d91f617fa5de95863be015"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/etc/passwd","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-etc-profile-6dfdb9518e6b63ef","checksums":[{"algorithm":"SHA1","checksumValue":"54dd1d99ac0383798113f96307ee9b52b0bb0f37"},{"algorithm":"SHA256","checksumValue":"87e8643d3ce156de0c09370d4d39446f30bd00d264bea248abc191c4d7b9df3e"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/etc/profile","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-etc-profile.d-20locale.sh-4738cb952eababba","checksums":[{"algorithm":"SHA1","checksumValue":"96adbd950ccf992085295990f9bbe667f0cf4c4e"},{"algorithm":"SHA256","checksumValue":"284a6ef56ab97a13a777c6b01ae14f2cc3d2b7a29c19e750e622e70cc3c73186"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/etc/profile.d/20locale.sh","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-etc-profile.d-README-3be87e7f154adb63","checksums":[{"algorithm":"SHA1","checksumValue":"df9396b02cf3be70767e6171eb691baa6d40c759"},{"algorithm":"SHA256","checksumValue":"b73284f27fe2da9ae1902b1fe9596c3ffc61a154e2805a034184f0468f8b09b0"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/etc/profile.d/README","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-etc-profile.d-color-prompt.sh.disabled-eeb93048af63bf64","checksums":[{"algorithm":"SHA1","checksumValue":"d5733d99d7b5676f6d58c19a3a47a8bc3fe6e2e5"},{"algorithm":"SHA256","checksumValue":"ba24425c6864a5d17fa0fdaf914c4d21419e47c4d62080c33830af059fe46617"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/etc/profile.d/color_prompt.sh.disabled","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-etc-protocols-5f1d8d1482d973b6","checksums":[{"algorithm":"SHA1","checksumValue":"d5f9654539089b96f1b1956848d783527da6fb47"},{"algorithm":"SHA256","checksumValue":"4959498abbadaa1e50894a266f8d0d94500101cfe5b5f09dcad82e9d5bdfab46"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/etc/protocols","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-etc-securetty-f5826ff16d6eaebb","checksums":[{"algorithm":"SHA1","checksumValue":"0e29ce7fa251a4246033abcdaa339ec5dde84a75"},{"algorithm":"SHA256","checksumValue":"713fcea5109728883b9147e822429133fcc8b5e253afd3c2a197b10cd0bc3b4d"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/etc/securetty","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-etc-services-812b3f1a2d583f29","checksums":[{"algorithm":"SHA1","checksumValue":"a0d7a229bf049f7fe17e8445226236e4024535d0"},{"algorithm":"SHA256","checksumValue":"f6183055fd949f9c53d49ee620f85d0150123ea691d25ed1bba0c641b4ee2f48"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/etc/services","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-etc-shadow-a1d64c72d061cd92","checksums":[{"algorithm":"SHA1","checksumValue":"fdcce813d9a3aa27fffcf07126d2deabf17cb057"},{"algorithm":"SHA256","checksumValue":"d5992a27f05f380fc5faeb82a3359e2f230fd1d6ea6517b45892b771a2194ddb"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/etc/shadow","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-etc-shells-2dc73ba417bebb75","checksums":[{"algorithm":"SHA1","checksumValue":"a239b661da4227a07f6a9183699fd275bdb12640"},{"algorithm":"SHA256","checksumValue":"24be6ceb236610df45684c83b06c918ae45635be55f69975e43676b7595bbc5f"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/etc/shells","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-etc-ssl-certs-ca-certificates.crt-c7ec96e3f9d22e5e","checksums":[{"algorithm":"SHA1","checksumValue":"ef142b502de28cb73fab260c80032bbb9013f2bd"},{"algorithm":"SHA256","checksumValue":"37acffef4900dc598edca36a177c60ca77f9130b5a93b1344d713ac4abcf94c1"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/etc/ssl/certs/ca-certificates.crt","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-etc-ssl-ct-log-list.cnf-7c00b4ab1629d304","checksums":[{"algorithm":"SHA1","checksumValue":"a2587c4e97408b64274e5e052b74e3754892c13a"},{"algorithm":"SHA256","checksumValue":"f1c1803d13d1d0b755b13b23c28bd4e20e07baf9f2b744c9337ba5866aa0ec3b"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/etc/ssl/ct_log_list.cnf","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-etc-ssl-ct-log-list.cnf.dist-4706267d3fefbca6","checksums":[{"algorithm":"SHA1","checksumValue":"a2587c4e97408b64274e5e052b74e3754892c13a"},{"algorithm":"SHA256","checksumValue":"f1c1803d13d1d0b755b13b23c28bd4e20e07baf9f2b744c9337ba5866aa0ec3b"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/etc/ssl/ct_log_list.cnf.dist","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-etc-ssl-openssl.cnf-e2fe362bf9fd5340","checksums":[{"algorithm":"SHA1","checksumValue":"c6aaa437fab0d4186ff361da58952c45447f0181"},{"algorithm":"SHA256","checksumValue":"3a0c65ff954aff207420846926d31d1b6056be525a0f3d38dff21f5b89f90688"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/etc/ssl/openssl.cnf","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-etc-ssl-openssl.cnf.dist-a2fcecd0c7860aea","checksums":[{"algorithm":"SHA1","checksumValue":"c6aaa437fab0d4186ff361da58952c45447f0181"},{"algorithm":"SHA256","checksumValue":"3a0c65ff954aff207420846926d31d1b6056be525a0f3d38dff21f5b89f90688"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/etc/ssl/openssl.cnf.dist","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-etc-sysctl.conf-2eede682f1d2d57e","checksums":[{"algorithm":"SHA1","checksumValue":"e2ea73ded7e7371664204b148569fb5e88b0f7a8"},{"algorithm":"SHA256","checksumValue":"8bba47da45bc8715c69ac904a60410eabffaa7bbbef640f9c1368ab9c48493d0"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/etc/sysctl.conf","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-etc-udhcpc-udhcpc.conf-a8f34a90829fb0c8","checksums":[{"algorithm":"SHA1","checksumValue":"9bc069e434228e6ca441848bfb7a6bac23fa148a"},{"algorithm":"SHA256","checksumValue":"5b372209e01cda07c87b8afa6d1ab3d7e8daf18a1f2332d744203a6dc289eb1a"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/etc/udhcpc/udhcpc.conf","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-lib-apk-db-installed-8363b4a677041553","checksums":[{"algorithm":"SHA1","checksumValue":"0000000000000000000000000000000000000000"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/lib/apk/db/installed","licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-lib-ld-musl-aarch64.so.1-15ac5a87021c605c","checksums":[{"algorithm":"SHA1","checksumValue":"50859585e21254306aeb74426d5dd4537cbe3305"},{"algorithm":"SHA256","checksumValue":"59420a762274dddac5c3d7d612564d0d6f76c54a0edf0bdf167fea661bb6d6bf"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/lib/ld-musl-aarch64.so.1","fileTypes":["APPLICATION","BINARY"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-lib-libapk.so.2.14.0-85382abc3213df0c","checksums":[{"algorithm":"SHA1","checksumValue":"d6eed4bf4133792285922c44322d42e196405e50"},{"algorithm":"SHA256","checksumValue":"3d9d886647cc576d1c3bab0dc1a4d4e752a2f4b7d8bd5c6abfe11acccb3e4409"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/lib/libapk.so.2.14.0","fileTypes":["APPLICATION","BINARY"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-lib-libcrypto.so.3-d7aa31f07714a25f","checksums":[{"algorithm":"SHA1","checksumValue":"eddc1d6d87670038a43530097662cb6eee36e624"},{"algorithm":"SHA256","checksumValue":"0f9439f7e7f83e4ae355fa957ffe6878b03c467cb289dbc56f65ce058729de6d"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/lib/libcrypto.so.3","fileTypes":["APPLICATION","BINARY"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-lib-libssl.so.3-942e1a73404f4c12","checksums":[{"algorithm":"SHA1","checksumValue":"3f1e772e6d4a99fecf0a608f6e42d7da2069c73c"},{"algorithm":"SHA256","checksumValue":"5136a0a97053a7694de117eaec692c85bee2062b8e6907dc875599dc56629384"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/lib/libssl.so.3","fileTypes":["APPLICATION","BINARY"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-lib-libz.so.1.3.1-cfebf8b5dc1f6374","checksums":[{"algorithm":"SHA1","checksumValue":"70949f5bdc478b4552562050c43b1e4b6bf014bb"},{"algorithm":"SHA256","checksumValue":"540bf9ba24238ac85b21755126dfa3a9c8ca947e0d0c938b6c1fea43d6927a7e"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/lib/libz.so.1.3.1","fileTypes":["APPLICATION","BINARY"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-lib-sysctl.d-00-alpine.conf-812cee121e721231","checksums":[{"algorithm":"SHA1","checksumValue":"1e9125cd6d7112098a7c446d4f2ee8a269a7aba7"},{"algorithm":"SHA256","checksumValue":"ee169bea2cb6859420b55ca7a9c23fb68b50adc1d26c951f904dec9e8f767380"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/lib/sysctl.d/00-alpine.conf","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-sbin-apk-03a303c2f408ad75","checksums":[{"algorithm":"SHA1","checksumValue":"191b64288f8976f9cb5875ad24481671998eceed"},{"algorithm":"SHA256","checksumValue":"d15d690cdb7e32b735a0b47806710fbfc2f8e7faabe3b3059b2009c8fbda8cdc"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/sbin/apk","fileTypes":["APPLICATION","BINARY"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-sbin-ldconfig-6dd00345fd25dfbe","checksums":[{"algorithm":"SHA1","checksumValue":"2a36b6f8f3992b112450e66ac128c2ea499a103e"},{"algorithm":"SHA256","checksumValue":"b4a2c06db38742e8c42c3c9838b285a7d8cdac6c091ff3df5ff9a15f1e41b9c7"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/sbin/ldconfig","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-usr-bin-getconf-aa569a0b492dbc3e","checksums":[{"algorithm":"SHA1","checksumValue":"a7c92a25adeb9f46272bf52c5d33d3babedb312d"},{"algorithm":"SHA256","checksumValue":"5238595ed22353d8c6adb8d78652b3b252f3c2ba6cffdf6eecf419eb78ff0209"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/usr/bin/getconf","fileTypes":["APPLICATION","BINARY"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-usr-bin-getent-dfc1d5b68ea46609","checksums":[{"algorithm":"SHA1","checksumValue":"db0ec5b54f31a315956027172ecfee6aa60a2581"},{"algorithm":"SHA256","checksumValue":"ace5b03661ca07022837d3d7cd4781cb5a30ef6d3fc5d591d83b9263368ec0ac"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/usr/bin/getent","fileTypes":["APPLICATION","BINARY"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-usr-bin-iconv-b4f317a0c3ae4126","checksums":[{"algorithm":"SHA1","checksumValue":"913d4848ef8289b2ff1a8f6386c3771380c601bf"},{"algorithm":"SHA256","checksumValue":"e6fcc190f17c0dc4fb691256440a6e83dc52e9fb1217e35d2a882e32296c48a6"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/usr/bin/iconv","fileTypes":["APPLICATION","BINARY"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-usr-bin-ldd-0f8acf82bbb616a2","checksums":[{"algorithm":"SHA1","checksumValue":"afe298b72fc708b978a7876f3edf2409bd66841d"},{"algorithm":"SHA256","checksumValue":"5f115be8562262bcc50ec469e25c0af2fda3bad72a960c6aa3488acd7a7da8cf"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/usr/bin/ldd","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-usr-bin-scanelf-42e6597f9fa4518a","checksums":[{"algorithm":"SHA1","checksumValue":"429e07005a605dcf7afa72a2926033c6c2cfb07d"},{"algorithm":"SHA256","checksumValue":"5ef9e7df17d4f20ad9dec44a5fdc39ea581377680cfdc1994ac48986c9254351"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/usr/bin/scanelf","fileTypes":["APPLICATION","BINARY"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-usr-bin-ssl-client-90e1da58238b5003","checksums":[{"algorithm":"SHA1","checksumValue":"f17cb9d9effd3a5597f5dc79f50349f7b5971d31"},{"algorithm":"SHA256","checksumValue":"0094d52eac21454dedd2fce85262bba9e8538f45a3125a9e3a767ba6b8056f67"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/usr/bin/ssl_client","fileTypes":["APPLICATION","BINARY"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-usr-lib-engines-3-afalg.so-2dd02daf0dc8736e","checksums":[{"algorithm":"SHA1","checksumValue":"feb5d2147e9a48d12cc936e1ccb8aeedd3e4c330"},{"algorithm":"SHA256","checksumValue":"24d5276e7ebb6e2c898d5329ffabb62adb0212a6bf90829b4bf88e692b669b93"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/usr/lib/engines-3/afalg.so","fileTypes":["APPLICATION","BINARY"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-usr-lib-engines-3-capi.so-ec9b7c1e1d7152b6","checksums":[{"algorithm":"SHA1","checksumValue":"ddea94ab48fc5f001be7c04733be2232650b2af1"},{"algorithm":"SHA256","checksumValue":"936611a77d0786c572fcd931cd745a3e98570c82d1a1f119b8cd12062ff6da58"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/usr/lib/engines-3/capi.so","fileTypes":["APPLICATION","BINARY"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-usr-lib-engines-3-loader-attic.so-592a2f6a8711eea8","checksums":[{"algorithm":"SHA1","checksumValue":"b4be46c34fcb2a01faa45819b05d0904739b0c61"},{"algorithm":"SHA256","checksumValue":"5211c7f5c60792672d4b329fc6618f4852e44ad524a480dae785b4c3fdf2e294"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/usr/lib/engines-3/loader_attic.so","fileTypes":["APPLICATION","BINARY"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-usr-lib-engines-3-padlock.so-cb12bf2787e0b4d0","checksums":[{"algorithm":"SHA1","checksumValue":"867d553d0d11f999eb8b9e69f66421fa0a024eb2"},{"algorithm":"SHA256","checksumValue":"129501fb2e14a42fcb8435235ef5811ff1ebc2bbebb6de9ad8d20142cadb7a97"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/usr/lib/engines-3/padlock.so","fileTypes":["APPLICATION","BINARY"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-usr-lib-ossl-modules-legacy.so-fda2c463fe1d1275","checksums":[{"algorithm":"SHA1","checksumValue":"1d8693b5b9b8cb13bb679d5f8bdd92038fe05850"},{"algorithm":"SHA256","checksumValue":"96e39fb0e1e386543d6d46259bc3cf77c5b5a938eda714e440ca8066b471c5d2"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/usr/lib/ossl-modules/legacy.so","fileTypes":["APPLICATION","BINARY"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-4a6a0840.rsa.pub-410a0a130a42ece8","checksums":[{"algorithm":"SHA1","checksumValue":"3af08548ef78cfdedcf349880c2c6a1a48763a0e"},{"algorithm":"SHA256","checksumValue":"9c102bcc376af1498d549b77bdbfa815ae86faa1d2d82f040e616b18ef2df2d4"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-4a6a0840.rsa.pub","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-5243ef4b.rsa.pub-b5b8c9e17450db1c","checksums":[{"algorithm":"SHA1","checksumValue":"bfb616658cc05a872568b0c8e398c482e23b60dd"},{"algorithm":"SHA256","checksumValue":"ebf31683b56410ecc4c00acd9f6e2839e237a3b62b5ae7ef686705c7ba0396a9"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-5243ef4b.rsa.pub","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-524d27bb.rsa.pub-050339be1296c5a7","checksums":[{"algorithm":"SHA1","checksumValue":"053a92f87fd4532850bb31f0881978efe0532ae5"},{"algorithm":"SHA256","checksumValue":"1bb2a846c0ea4ca9d0e7862f970863857fc33c32f5506098c636a62a726a847b"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-524d27bb.rsa.pub","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-5261cecb.rsa.pub-3840c02005b419b2","checksums":[{"algorithm":"SHA1","checksumValue":"3671ae0ec7503b1e193587c1dcdf7b78bc863e42"},{"algorithm":"SHA256","checksumValue":"12f899e55a7691225603d6fb3324940fc51cd7f133e7ead788663c2b7eecb00c"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-5261cecb.rsa.pub","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-58199dcc.rsa.pub-df4b284ea560bc2f","checksums":[{"algorithm":"SHA1","checksumValue":"39ac5d72c6ba018a0f74b8b453894edc9db07b5f"},{"algorithm":"SHA256","checksumValue":"73867d92083f2f8ab899a26ccda7ef63dfaa0032a938620eda605558958a8041"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-58199dcc.rsa.pub","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-58cbb476.rsa.pub-fc38dbb1c534a98b","checksums":[{"algorithm":"SHA1","checksumValue":"c8fabeb2eeb992c368c77b9707e0d1ecfd7cf905"},{"algorithm":"SHA256","checksumValue":"9a4cd858d9710963848e6d5f555325dc199d1c952b01cf6e64da2c15deedbd97"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-58cbb476.rsa.pub","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-58e4f17d.rsa.pub-793318842ffeec8c","checksums":[{"algorithm":"SHA1","checksumValue":"329643357d0b78b1ef48ec155325e25f1d7534dd"},{"algorithm":"SHA256","checksumValue":"780b3ed41786772cbc7b68136546fa3f897f28a23b30c72dde6225319c44cfff"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-58e4f17d.rsa.pub","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-5e69ca50.rsa.pub-fb2a93a263fc77d5","checksums":[{"algorithm":"SHA1","checksumValue":"825090fde25bbc0e71a9cb3076316b5afe459e4d"},{"algorithm":"SHA256","checksumValue":"59c01c57b446633249f67c04b115dd6787f4378f183dff2bbf65406df93f176d"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-5e69ca50.rsa.pub","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-60ac2099.rsa.pub-05c47cc8cdd4f66e","checksums":[{"algorithm":"SHA1","checksumValue":"5d4743128353b6396fad2fa2ba793ace21602295"},{"algorithm":"SHA256","checksumValue":"db0b49163f07ffba64a5ca198bcf1688610b0bd1f0d8d5afeaf78559d73f2278"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-60ac2099.rsa.pub","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-6165ee59.rsa.pub-5576929bc9db6198","checksums":[{"algorithm":"SHA1","checksumValue":"95995311236b7a55933642ffa10ce6014f1af7d0"},{"algorithm":"SHA256","checksumValue":"207e4696d3c05f7cb05966aee557307151f1f00217af4143c1bcaf33b8df733f"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-6165ee59.rsa.pub","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-61666e3f.rsa.pub-fdccfa670e123d3d","checksums":[{"algorithm":"SHA1","checksumValue":"58d5ba4b2f3b1e927721d7a6432f298eedf72a6b"},{"algorithm":"SHA256","checksumValue":"128d34d4aec39b0daedea8163cd8dc24dff36fd3d848630ab97eeb1d3084bbb3"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-61666e3f.rsa.pub","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-616a9724.rsa.pub-fe0797f3d753de34","checksums":[{"algorithm":"SHA1","checksumValue":"23d0f2ea1af269c2f66165e0f8a944e96bf011de"},{"algorithm":"SHA256","checksumValue":"10877cce0a935e46ad88cb79e174a2491680508eccda08e92bf04fb9bf37fbc1"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616a9724.rsa.pub","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-616abc23.rsa.pub-83f8824a9e8a4daf","checksums":[{"algorithm":"SHA1","checksumValue":"3529ec82670c6d4e20ee3e4968db34b551e91d50"},{"algorithm":"SHA256","checksumValue":"4a095a9daca86da496a3cd9adcd95ee2197fdbeb84638656d469f05a4d740751"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616abc23.rsa.pub","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-616ac3bc.rsa.pub-22d34d5fbfa617ab","checksums":[{"algorithm":"SHA1","checksumValue":"55a301064e11c6fe9ba0f2ca17e234f3943ccb61"},{"algorithm":"SHA256","checksumValue":"0caf5662fde45616d88cfd7021b7bda269a2fcaf311e51c48945a967a609ec0b"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616ac3bc.rsa.pub","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-616adfeb.rsa.pub-951eb66cb4549509","checksums":[{"algorithm":"SHA1","checksumValue":"de1241307014aae3dba798e900f163408d98d6f4"},{"algorithm":"SHA256","checksumValue":"ebe717d228555aa58133c202314a451f81e71f174781fd7ff8d8970d6cfa60da"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616adfeb.rsa.pub","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-616ae350.rsa.pub-44fa2966c51f0c1f","checksums":[{"algorithm":"SHA1","checksumValue":"57f6b93fda4a4496fab62844ddef0eeb168f80b5"},{"algorithm":"SHA256","checksumValue":"d11f6b21c61b4274e182eb888883a8ba8acdbf820dcc7a6d82a7d9fc2fd2836d"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616ae350.rsa.pub","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-616db30d.rsa.pub-b14251d1f8bcfe18","checksums":[{"algorithm":"SHA1","checksumValue":"df02c9adc2906a3aa5e5ad69f50e3953e65710d0"},{"algorithm":"SHA256","checksumValue":"40a216cbd163f22e5f16a9e0929de7cde221b9cbae8e36aa368b1e128afe0a31"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616db30d.rsa.pub","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]},{"SPDXID":"SPDXRef-File-usr-share-udhcpc-default.script-4fc79137008d263f","checksums":[{"algorithm":"SHA1","checksumValue":"1d6a46dde403f14a22e2692cd84dd24af3805216"},{"algorithm":"SHA256","checksumValue":"c4e5a7c4783a7a73dec48dee009ee687015d2de7ff86b269679b95bef2c60e13"}],"comment":"layerID: sha256:50171d1acbd537989c0740e2cba2b8288d1029dde7772c1db0c1288a634201fc","copyrightText":"","fileName":"/usr/share/udhcpc/default.script","fileTypes":["TEXT"],"licenseConcluded":"NOASSERTION","licenseInfoInFiles":["NOASSERTION"]}],"name":"alpine","packages":[{"SPDXID":"SPDXRef-Package-apk-alpine-baselayout-21e54be9d7ca763c","copyrightText":"NOASSERTION","description":"Alpine base dir structure and init scripts","downloadLocation":"https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout","externalRefs":[{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:alpine-baselayout:alpine-baselayout:3.6.5-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:alpine-baselayout:alpine_baselayout:3.6.5-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:alpine_baselayout:alpine-baselayout:3.6.5-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:alpine_baselayout:alpine_baselayout:3.6.5-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:alpine:alpine-baselayout:3.6.5-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:alpine:alpine_baselayout:3.6.5-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"PACKAGE-MANAGER","referenceLocator":"pkg:apk/alpine/alpine-baselayout@3.6.5-r0?arch=aarch64\u0026distro=alpine-3.20.0","referenceType":"purl"}],"filesAnalyzed":true,"licenseConcluded":"NOASSERTION","licenseDeclared":"GPL-2.0-only","name":"alpine-baselayout","originator":"Person: Natanael Copa (ncopa@alpinelinux.org)","packageVerificationCode":{"packageVerificationCodeValue":"6a22bff30e2aed347029eeb9d51c810613705455"},"sourceInfo":"acquired package info from APK DB: /lib/apk/db/installed","supplier":"Person: Natanael Copa (ncopa@alpinelinux.org)","versionInfo":"3.6.5-r0"},{"SPDXID":"SPDXRef-Package-apk-alpine-baselayout-data-9ff96f942d2401f2","copyrightText":"NOASSERTION","description":"Alpine base dir structure and init scripts","downloadLocation":"https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout","externalRefs":[{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:alpine-baselayout-data:alpine-baselayout-data:3.6.5-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:alpine-baselayout-data:alpine_baselayout_data:3.6.5-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:alpine_baselayout_data:alpine-baselayout-data:3.6.5-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:alpine_baselayout_data:alpine_baselayout_data:3.6.5-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:alpine-baselayout:alpine-baselayout-data:3.6.5-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:alpine-baselayout:alpine_baselayout_data:3.6.5-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:alpine_baselayout:alpine-baselayout-data:3.6.5-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:alpine_baselayout:alpine_baselayout_data:3.6.5-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:alpine:alpine-baselayout-data:3.6.5-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:alpine:alpine_baselayout_data:3.6.5-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"PACKAGE-MANAGER","referenceLocator":"pkg:apk/alpine/alpine-baselayout-data@3.6.5-r0?arch=aarch64\u0026upstream=alpine-baselayout\u0026distro=alpine-3.20.0","referenceType":"purl"}],"filesAnalyzed":true,"licenseConcluded":"NOASSERTION","licenseDeclared":"GPL-2.0-only","name":"alpine-baselayout-data","originator":"Person: Natanael Copa (ncopa@alpinelinux.org)","packageVerificationCode":{"packageVerificationCodeValue":"6a7d69893b8bca00a39ad9a06c6a7e2833593ad0"},"sourceInfo":"acquired package info from APK DB: /lib/apk/db/installed","supplier":"Person: Natanael Copa (ncopa@alpinelinux.org)","versionInfo":"3.6.5-r0"},{"SPDXID":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135","copyrightText":"NOASSERTION","description":"Public keys for Alpine Linux packages","downloadLocation":"https://alpinelinux.org","externalRefs":[{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:alpine-keys:alpine-keys:2.4-r1:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:alpine-keys:alpine_keys:2.4-r1:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:alpine_keys:alpine-keys:2.4-r1:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:alpine_keys:alpine_keys:2.4-r1:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:alpine:alpine-keys:2.4-r1:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:alpine:alpine_keys:2.4-r1:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"PACKAGE-MANAGER","referenceLocator":"pkg:apk/alpine/alpine-keys@2.4-r1?arch=aarch64\u0026distro=alpine-3.20.0","referenceType":"purl"}],"filesAnalyzed":true,"licenseConcluded":"NOASSERTION","licenseDeclared":"MIT","name":"alpine-keys","originator":"Person: Natanael Copa (ncopa@alpinelinux.org)","packageVerificationCode":{"packageVerificationCodeValue":"555910826b4a68482679b6d4809b1502dd6d46ab"},"sourceInfo":"acquired package info from APK DB: /lib/apk/db/installed","supplier":"Person: Natanael Copa (ncopa@alpinelinux.org)","versionInfo":"2.4-r1"},{"SPDXID":"SPDXRef-Package-apk-apk-tools-78c55d64ab350462","copyrightText":"NOASSERTION","description":"Alpine Package Keeper - package manager for alpine","downloadLocation":"https://gitlab.alpinelinux.org/alpine/apk-tools","externalRefs":[{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:apk-tools:apk-tools:2.14.4-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:apk-tools:apk_tools:2.14.4-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:apk_tools:apk-tools:2.14.4-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:apk_tools:apk_tools:2.14.4-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:apk:apk-tools:2.14.4-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:apk:apk_tools:2.14.4-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"PACKAGE-MANAGER","referenceLocator":"pkg:apk/alpine/apk-tools@2.14.4-r0?arch=aarch64\u0026distro=alpine-3.20.0","referenceType":"purl"}],"filesAnalyzed":true,"licenseConcluded":"NOASSERTION","licenseDeclared":"GPL-2.0-only","name":"apk-tools","originator":"Person: Natanael Copa (ncopa@alpinelinux.org)","packageVerificationCode":{"packageVerificationCodeValue":"e09707a797756cf9daf1c3f5832e7c4499a04266"},"sourceInfo":"acquired package info from APK DB: /lib/apk/db/installed","supplier":"Person: Natanael Copa (ncopa@alpinelinux.org)","versionInfo":"2.14.4-r0"},{"SPDXID":"SPDXRef-Package-apk-busybox-4cea7ce2e2974c99","copyrightText":"NOASSERTION","description":"Size optimized toolbox of many common UNIX utilities","downloadLocation":"https://busybox.net/","externalRefs":[{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:busybox:busybox:1.36.1-r28:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"PACKAGE-MANAGER","referenceLocator":"pkg:apk/alpine/busybox@1.36.1-r28?arch=aarch64\u0026distro=alpine-3.20.0","referenceType":"purl"}],"filesAnalyzed":true,"licenseConcluded":"NOASSERTION","licenseDeclared":"GPL-2.0-only","name":"busybox","packageVerificationCode":{"packageVerificationCodeValue":"c873508e0b37506b4b2d3006b4ce096069b6ab9a"},"sourceInfo":"acquired package info from APK DB: /lib/apk/db/installed","supplier":"NOASSERTION","versionInfo":"1.36.1-r28"},{"SPDXID":"SPDXRef-Package-apk-busybox-binsh-1fd95b4d43a9f438","copyrightText":"NOASSERTION","description":"busybox ash /bin/sh","downloadLocation":"https://busybox.net/","externalRefs":[{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:busybox-binsh:busybox-binsh:1.36.1-r28:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:busybox-binsh:busybox_binsh:1.36.1-r28:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:busybox_binsh:busybox-binsh:1.36.1-r28:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:busybox_binsh:busybox_binsh:1.36.1-r28:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:busybox:busybox-binsh:1.36.1-r28:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:busybox:busybox_binsh:1.36.1-r28:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"PACKAGE-MANAGER","referenceLocator":"pkg:apk/alpine/busybox-binsh@1.36.1-r28?arch=aarch64\u0026upstream=busybox\u0026distro=alpine-3.20.0","referenceType":"purl"}],"filesAnalyzed":true,"licenseConcluded":"NOASSERTION","licenseDeclared":"GPL-2.0-only","name":"busybox-binsh","packageVerificationCode":{"packageVerificationCodeValue":"71bd3a1b510b531ba920457cfaa87f907c6cd091"},"sourceInfo":"acquired package info from APK DB: /lib/apk/db/installed","supplier":"NOASSERTION","versionInfo":"1.36.1-r28"},{"SPDXID":"SPDXRef-Package-apk-ca-certificates-bundle-bf42440dd0b61727","copyrightText":"NOASSERTION","description":"Pre generated bundle of Mozilla certificates","downloadLocation":"https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/","externalRefs":[{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:ca-certificates-bundle:ca-certificates-bundle:20240226-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:ca-certificates-bundle:ca_certificates_bundle:20240226-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:ca_certificates_bundle:ca-certificates-bundle:20240226-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:ca_certificates_bundle:ca_certificates_bundle:20240226-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:ca-certificates:ca-certificates-bundle:20240226-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:ca-certificates:ca_certificates_bundle:20240226-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:ca_certificates:ca-certificates-bundle:20240226-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:ca_certificates:ca_certificates_bundle:20240226-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:mozilla:ca-certificates-bundle:20240226-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:mozilla:ca_certificates_bundle:20240226-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:ca:ca-certificates-bundle:20240226-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:ca:ca_certificates_bundle:20240226-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"PACKAGE-MANAGER","referenceLocator":"pkg:apk/alpine/ca-certificates-bundle@20240226-r0?arch=aarch64\u0026upstream=ca-certificates\u0026distro=alpine-3.20.0","referenceType":"purl"}],"filesAnalyzed":true,"licenseConcluded":"NOASSERTION","licenseDeclared":"(MPL-2.0 AND MIT)","name":"ca-certificates-bundle","originator":"Person: Natanael Copa (ncopa@alpinelinux.org)","packageVerificationCode":{"packageVerificationCodeValue":"ed7a773d52aea0765c0db03bb25b01b5f0f50f3c"},"sourceInfo":"acquired package info from APK DB: /lib/apk/db/installed","supplier":"Person: Natanael Copa (ncopa@alpinelinux.org)","versionInfo":"20240226-r0"},{"SPDXID":"SPDXRef-Package-apk-libcrypto3-0cfcda1a242dfd13","copyrightText":"NOASSERTION","description":"Crypto library from openssl","downloadLocation":"https://www.openssl.org/","externalRefs":[{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:libcrypto3:libcrypto3:3.3.0-r2:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:libcrypto3:libcrypto:3.3.0-r2:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:libcrypto:libcrypto3:3.3.0-r2:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:libcrypto:libcrypto:3.3.0-r2:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"PACKAGE-MANAGER","referenceLocator":"pkg:apk/alpine/libcrypto3@3.3.0-r2?arch=aarch64\u0026upstream=openssl\u0026distro=alpine-3.20.0","referenceType":"purl"}],"filesAnalyzed":true,"licenseConcluded":"NOASSERTION","licenseDeclared":"Apache-2.0","name":"libcrypto3","originator":"Person: Natanael Copa (ncopa@alpinelinux.org)","packageVerificationCode":{"packageVerificationCodeValue":"ae6bdffda4acbdf371b8ccc19dba2e7a525d08e1"},"sourceInfo":"acquired package info from APK DB: /lib/apk/db/installed","supplier":"Person: Natanael Copa (ncopa@alpinelinux.org)","versionInfo":"3.3.0-r2"},{"SPDXID":"SPDXRef-Package-apk-libssl3-1bffb507b1b535bc","copyrightText":"NOASSERTION","description":"SSL shared libraries","downloadLocation":"https://www.openssl.org/","externalRefs":[{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:libssl3:libssl3:3.3.0-r2:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:libssl3:libssl:3.3.0-r2:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:libssl:libssl3:3.3.0-r2:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:libssl:libssl:3.3.0-r2:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"PACKAGE-MANAGER","referenceLocator":"pkg:apk/alpine/libssl3@3.3.0-r2?arch=aarch64\u0026upstream=openssl\u0026distro=alpine-3.20.0","referenceType":"purl"}],"filesAnalyzed":true,"licenseConcluded":"NOASSERTION","licenseDeclared":"Apache-2.0","name":"libssl3","originator":"Person: Natanael Copa (ncopa@alpinelinux.org)","packageVerificationCode":{"packageVerificationCodeValue":"bdcc4aef521963183255243c4256cc3348a6796b"},"sourceInfo":"acquired package info from APK DB: /lib/apk/db/installed","supplier":"Person: Natanael Copa (ncopa@alpinelinux.org)","versionInfo":"3.3.0-r2"},{"SPDXID":"SPDXRef-Package-apk-musl-03e521237cbed45a","copyrightText":"NOASSERTION","description":"the musl c library (libc) implementation","downloadLocation":"https://musl.libc.org/","externalRefs":[{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:musl-libc:musl:1.2.5-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:musl_libc:musl:1.2.5-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:musl:musl:1.2.5-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"PACKAGE-MANAGER","referenceLocator":"pkg:apk/alpine/musl@1.2.5-r0?arch=aarch64\u0026distro=alpine-3.20.0","referenceType":"purl"}],"filesAnalyzed":true,"licenseConcluded":"NOASSERTION","licenseDeclared":"MIT","name":"musl","originator":"Person: Natanael Copa (ncopa@alpinelinux.org)","packageVerificationCode":{"packageVerificationCodeValue":"498ba4340e8deb05fbea7e1053b734717307dd81"},"sourceInfo":"acquired package info from APK DB: /lib/apk/db/installed","supplier":"Person: Natanael Copa (ncopa@alpinelinux.org)","versionInfo":"1.2.5-r0"},{"SPDXID":"SPDXRef-Package-apk-musl-utils-c84ae08b59df5c6e","copyrightText":"NOASSERTION","description":"the musl c library (libc) implementation","downloadLocation":"https://musl.libc.org/","externalRefs":[{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:musl-utils:musl-utils:1.2.5-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:musl-utils:musl_utils:1.2.5-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:musl_utils:musl-utils:1.2.5-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:musl_utils:musl_utils:1.2.5-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:musl-libc:musl-utils:1.2.5-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:musl-libc:musl_utils:1.2.5-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:musl:musl-utils:1.2.5-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:musl:musl_utils:1.2.5-r0:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"PACKAGE-MANAGER","referenceLocator":"pkg:apk/alpine/musl-utils@1.2.5-r0?arch=aarch64\u0026upstream=musl\u0026distro=alpine-3.20.0","referenceType":"purl"}],"filesAnalyzed":true,"licenseConcluded":"NOASSERTION","licenseDeclared":"(MIT AND BSD-2-Clause AND GPL-2.0-or-later)","name":"musl-utils","originator":"Person: Natanael Copa (ncopa@alpinelinux.org)","packageVerificationCode":{"packageVerificationCodeValue":"c05211eeb2d680bcd129b57790feea2157222f93"},"sourceInfo":"acquired package info from APK DB: /lib/apk/db/installed","supplier":"Person: Natanael Copa (ncopa@alpinelinux.org)","versionInfo":"1.2.5-r0"},{"SPDXID":"SPDXRef-Package-apk-scanelf-54f3623fdd8fb8d4","copyrightText":"NOASSERTION","description":"Scan ELF binaries for stuff","downloadLocation":"https://wiki.gentoo.org/wiki/Hardened/PaX_Utilities","externalRefs":[{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:scanelf:scanelf:1.3.7-r2:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"PACKAGE-MANAGER","referenceLocator":"pkg:apk/alpine/scanelf@1.3.7-r2?arch=aarch64\u0026upstream=pax-utils\u0026distro=alpine-3.20.0","referenceType":"purl"}],"filesAnalyzed":true,"licenseConcluded":"NOASSERTION","licenseDeclared":"GPL-2.0-only","name":"scanelf","originator":"Person: Natanael Copa (ncopa@alpinelinux.org)","packageVerificationCode":{"packageVerificationCodeValue":"98c686afd83394fddb10bd9239ec6b5a474397f1"},"sourceInfo":"acquired package info from APK DB: /lib/apk/db/installed","supplier":"Person: Natanael Copa (ncopa@alpinelinux.org)","versionInfo":"1.3.7-r2"},{"SPDXID":"SPDXRef-Package-apk-ssl-client-6bbb10e52b8e7eb4","copyrightText":"NOASSERTION","description":"EXternal ssl_client for busybox wget","downloadLocation":"https://busybox.net/","externalRefs":[{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:ssl-client:ssl-client:1.36.1-r28:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:ssl-client:ssl_client:1.36.1-r28:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:ssl_client:ssl-client:1.36.1-r28:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:ssl_client:ssl_client:1.36.1-r28:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:ssl:ssl-client:1.36.1-r28:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:ssl:ssl_client:1.36.1-r28:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"PACKAGE-MANAGER","referenceLocator":"pkg:apk/alpine/ssl_client@1.36.1-r28?arch=aarch64\u0026upstream=busybox\u0026distro=alpine-3.20.0","referenceType":"purl"}],"filesAnalyzed":true,"licenseConcluded":"NOASSERTION","licenseDeclared":"GPL-2.0-only","name":"ssl_client","packageVerificationCode":{"packageVerificationCodeValue":"7d5a1591577ff883690877e5b50998b7950f9ac7"},"sourceInfo":"acquired package info from APK DB: /lib/apk/db/installed","supplier":"NOASSERTION","versionInfo":"1.36.1-r28"},{"SPDXID":"SPDXRef-Package-apk-zlib-d8258d3d7c48cfbf","copyrightText":"NOASSERTION","description":"A compression/decompression Library","downloadLocation":"https://zlib.net/","externalRefs":[{"referenceCategory":"SECURITY","referenceLocator":"cpe:2.3:a:zlib:zlib:1.3.1-r1:*:*:*:*:*:*:*","referenceType":"cpe23Type"},{"referenceCategory":"PACKAGE-MANAGER","referenceLocator":"pkg:apk/alpine/zlib@1.3.1-r1?arch=aarch64\u0026distro=alpine-3.20.0","referenceType":"purl"}],"filesAnalyzed":true,"licenseConcluded":"NOASSERTION","licenseDeclared":"Zlib","name":"zlib","originator":"Person: Natanael Copa (ncopa@alpinelinux.org)","packageVerificationCode":{"packageVerificationCodeValue":"144c1bbadb241708c66589af3af429734cb73bb0"},"sourceInfo":"acquired package info from APK DB: /lib/apk/db/installed","supplier":"Person: Natanael Copa (ncopa@alpinelinux.org)","versionInfo":"1.3.1-r1"},{"SPDXID":"SPDXRef-DocumentRoot-Image-alpine","checksums":[{"algorithm":"SHA256","checksumValue":"8946eb426fbf9ed6260ee859e60462b834c8d1d50349f15e73aa17928f7991e8"}],"downloadLocation":"NOASSERTION","externalRefs":[{"referenceCategory":"PACKAGE-MANAGER","referenceLocator":"pkg:oci/alpine@sha256:8946eb426fbf9ed6260ee859e60462b834c8d1d50349f15e73aa17928f7991e8?arch=arm64","referenceType":"purl"}],"filesAnalyzed":false,"licenseConcluded":"NOASSERTION","licenseDeclared":"NOASSERTION","name":"alpine","primaryPackagePurpose":"CONTAINER","supplier":"NOASSERTION","versionInfo":"sha256:8946eb426fbf9ed6260ee859e60462b834c8d1d50349f15e73aa17928f7991e8"}],"relationships":[{"relatedSpdxElement":"SPDXRef-Package-apk-libcrypto3-0cfcda1a242dfd13","relationshipType":"DEPENDENCY_OF","spdxElementId":"SPDXRef-Package-apk-musl-03e521237cbed45a"},{"relatedSpdxElement":"SPDXRef-File-lib-ld-musl-aarch64.so.1-15ac5a87021c605c","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-musl-03e521237cbed45a"},{"relatedSpdxElement":"SPDXRef-Package-apk-libssl3-1bffb507b1b535bc","relationshipType":"DEPENDENCY_OF","spdxElementId":"SPDXRef-Package-apk-musl-03e521237cbed45a"},{"relatedSpdxElement":"SPDXRef-Package-apk-busybox-4cea7ce2e2974c99","relationshipType":"DEPENDENCY_OF","spdxElementId":"SPDXRef-Package-apk-musl-03e521237cbed45a"},{"relatedSpdxElement":"SPDXRef-Package-apk-scanelf-54f3623fdd8fb8d4","relationshipType":"DEPENDENCY_OF","spdxElementId":"SPDXRef-Package-apk-musl-03e521237cbed45a"},{"relatedSpdxElement":"SPDXRef-Package-apk-ssl-client-6bbb10e52b8e7eb4","relationshipType":"DEPENDENCY_OF","spdxElementId":"SPDXRef-Package-apk-musl-03e521237cbed45a"},{"relatedSpdxElement":"SPDXRef-Package-apk-apk-tools-78c55d64ab350462","relationshipType":"DEPENDENCY_OF","spdxElementId":"SPDXRef-Package-apk-musl-03e521237cbed45a"},{"comment":"evident-by: indicates the package's existence is evident by the given file","relatedSpdxElement":"SPDXRef-File-lib-apk-db-installed-8363b4a677041553","relationshipType":"OTHER","spdxElementId":"SPDXRef-Package-apk-musl-03e521237cbed45a"},{"relatedSpdxElement":"SPDXRef-Package-apk-musl-utils-c84ae08b59df5c6e","relationshipType":"DEPENDENCY_OF","spdxElementId":"SPDXRef-Package-apk-musl-03e521237cbed45a"},{"relatedSpdxElement":"SPDXRef-Package-apk-zlib-d8258d3d7c48cfbf","relationshipType":"DEPENDENCY_OF","spdxElementId":"SPDXRef-Package-apk-musl-03e521237cbed45a"},{"relatedSpdxElement":"SPDXRef-Package-apk-libssl3-1bffb507b1b535bc","relationshipType":"DEPENDENCY_OF","spdxElementId":"SPDXRef-Package-apk-libcrypto3-0cfcda1a242dfd13"},{"relatedSpdxElement":"SPDXRef-File-usr-lib-engines-3-afalg.so-2dd02daf0dc8736e","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-libcrypto3-0cfcda1a242dfd13"},{"relatedSpdxElement":"SPDXRef-File-etc-ssl-ct-log-list.cnf.dist-4706267d3fefbca6","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-libcrypto3-0cfcda1a242dfd13"},{"relatedSpdxElement":"SPDXRef-File-usr-lib-engines-3-loader-attic.so-592a2f6a8711eea8","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-libcrypto3-0cfcda1a242dfd13"},{"relatedSpdxElement":"SPDXRef-Package-apk-ssl-client-6bbb10e52b8e7eb4","relationshipType":"DEPENDENCY_OF","spdxElementId":"SPDXRef-Package-apk-libcrypto3-0cfcda1a242dfd13"},{"relatedSpdxElement":"SPDXRef-Package-apk-apk-tools-78c55d64ab350462","relationshipType":"DEPENDENCY_OF","spdxElementId":"SPDXRef-Package-apk-libcrypto3-0cfcda1a242dfd13"},{"relatedSpdxElement":"SPDXRef-File-etc-ssl-ct-log-list.cnf-7c00b4ab1629d304","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-libcrypto3-0cfcda1a242dfd13"},{"comment":"evident-by: indicates the package's existence is evident by the given file","relatedSpdxElement":"SPDXRef-File-lib-apk-db-installed-8363b4a677041553","relationshipType":"OTHER","spdxElementId":"SPDXRef-Package-apk-libcrypto3-0cfcda1a242dfd13"},{"relatedSpdxElement":"SPDXRef-File-etc-ssl-openssl.cnf.dist-a2fcecd0c7860aea","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-libcrypto3-0cfcda1a242dfd13"},{"relatedSpdxElement":"SPDXRef-File-usr-lib-engines-3-padlock.so-cb12bf2787e0b4d0","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-libcrypto3-0cfcda1a242dfd13"},{"relatedSpdxElement":"SPDXRef-File-lib-libcrypto.so.3-d7aa31f07714a25f","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-libcrypto3-0cfcda1a242dfd13"},{"relatedSpdxElement":"SPDXRef-File-etc-ssl-openssl.cnf-e2fe362bf9fd5340","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-libcrypto3-0cfcda1a242dfd13"},{"relatedSpdxElement":"SPDXRef-File-usr-lib-engines-3-capi.so-ec9b7c1e1d7152b6","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-libcrypto3-0cfcda1a242dfd13"},{"relatedSpdxElement":"SPDXRef-File-usr-lib-ossl-modules-legacy.so-fda2c463fe1d1275","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-libcrypto3-0cfcda1a242dfd13"},{"relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-524d27bb.rsa.pub-050339be1296c5a7","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135"},{"relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-60ac2099.rsa.pub-05c47cc8cdd4f66e","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135"},{"relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-616ac3bc.rsa.pub-22d34d5fbfa617ab","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135"},{"relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-5261cecb.rsa.pub-3840c02005b419b2","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135"},{"relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-4a6a0840.rsa.pub-410a0a130a42ece8","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135"},{"relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-58199dcc.rsa.pub-444fb4815b9c5fa7","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135"},{"relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-616ae350.rsa.pub-44fa2966c51f0c1f","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135"},{"relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-6165ee59.rsa.pub-5576929bc9db6198","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135"},{"relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-524d27bb.rsa.pub-6742b949ff851b46","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135"},{"relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-616ae350.rsa.pub-76207aeaad529724","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135"},{"relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-58e4f17d.rsa.pub-793318842ffeec8c","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135"},{"comment":"evident-by: indicates the package's existence is evident by the given file","relatedSpdxElement":"SPDXRef-File-lib-apk-db-installed-8363b4a677041553","relationshipType":"OTHER","spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135"},{"relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-616abc23.rsa.pub-83f8824a9e8a4daf","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135"},{"relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-616adfeb.rsa.pub-951eb66cb4549509","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135"},{"relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-616db30d.rsa.pub-b14251d1f8bcfe18","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135"},{"relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-5243ef4b.rsa.pub-b5b8c9e17450db1c","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135"},{"relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-616a9724.rsa.pub-cfc1d017a48ee9e7","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135"},{"relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-58199dcc.rsa.pub-df4b284ea560bc2f","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135"},{"relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-616adfeb.rsa.pub-ed83cb346d241bdf","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135"},{"relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-5e69ca50.rsa.pub-fb2a93a263fc77d5","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135"},{"relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-58cbb476.rsa.pub-fc38dbb1c534a98b","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135"},{"relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-61666e3f.rsa.pub-fdccfa670e123d3d","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135"},{"relatedSpdxElement":"SPDXRef-File-...alpine-devel-lists.alpinelinux.org-616a9724.rsa.pub-fe0797f3d753de34","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135"},{"relatedSpdxElement":"SPDXRef-Package-apk-ssl-client-6bbb10e52b8e7eb4","relationshipType":"DEPENDENCY_OF","spdxElementId":"SPDXRef-Package-apk-libssl3-1bffb507b1b535bc"},{"relatedSpdxElement":"SPDXRef-Package-apk-apk-tools-78c55d64ab350462","relationshipType":"DEPENDENCY_OF","spdxElementId":"SPDXRef-Package-apk-libssl3-1bffb507b1b535bc"},{"comment":"evident-by: indicates the package's existence is evident by the given file","relatedSpdxElement":"SPDXRef-File-lib-apk-db-installed-8363b4a677041553","relationshipType":"OTHER","spdxElementId":"SPDXRef-Package-apk-libssl3-1bffb507b1b535bc"},{"relatedSpdxElement":"SPDXRef-File-lib-libssl.so.3-942e1a73404f4c12","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-libssl3-1bffb507b1b535bc"},{"relatedSpdxElement":"SPDXRef-Package-apk-alpine-baselayout-21e54be9d7ca763c","relationshipType":"DEPENDENCY_OF","spdxElementId":"SPDXRef-Package-apk-busybox-binsh-1fd95b4d43a9f438"},{"comment":"evident-by: indicates the package's existence is evident by the given file","relatedSpdxElement":"SPDXRef-File-lib-apk-db-installed-8363b4a677041553","relationshipType":"OTHER","spdxElementId":"SPDXRef-Package-apk-busybox-binsh-1fd95b4d43a9f438"},{"relatedSpdxElement":"SPDXRef-File-bin-busybox-909c5f40cb01cb38","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-busybox-binsh-1fd95b4d43a9f438"},{"relatedSpdxElement":"SPDXRef-File-etc-crontabs-root-351da988aba8a527","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-21e54be9d7ca763c"},{"relatedSpdxElement":"SPDXRef-File-etc-profile.d-README-3be87e7f154adb63","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-21e54be9d7ca763c"},{"relatedSpdxElement":"SPDXRef-File-etc-profile.d-20locale.sh-4738cb952eababba","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-21e54be9d7ca763c"},{"relatedSpdxElement":"SPDXRef-File-etc-modprobe.d-kms.conf-77f620d7a99cffa8","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-21e54be9d7ca763c"},{"relatedSpdxElement":"SPDXRef-File-lib-sysctl.d-00-alpine.conf-812cee121e721231","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-21e54be9d7ca763c"},{"comment":"evident-by: indicates the package's existence is evident by the given file","relatedSpdxElement":"SPDXRef-File-lib-apk-db-installed-8363b4a677041553","relationshipType":"OTHER","spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-21e54be9d7ca763c"},{"relatedSpdxElement":"SPDXRef-File-etc-modprobe.d-aliases.conf-8ac9ab5944e0b537","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-21e54be9d7ca763c"},{"relatedSpdxElement":"SPDXRef-File-etc-motd-9a55980593b74a03","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-21e54be9d7ca763c"},{"relatedSpdxElement":"SPDXRef-File-etc-modprobe.d-blacklist.conf-abf9fc46510ff77c","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-21e54be9d7ca763c"},{"relatedSpdxElement":"SPDXRef-File-etc-modprobe.d-i386.conf-e9054a53c22e88cf","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-21e54be9d7ca763c"},{"relatedSpdxElement":"SPDXRef-File-etc-profile.d-color-prompt.sh.disabled-eeb93048af63bf64","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-21e54be9d7ca763c"},{"relatedSpdxElement":"SPDXRef-Package-apk-busybox-binsh-1fd95b4d43a9f438","relationshipType":"DEPENDENCY_OF","spdxElementId":"SPDXRef-Package-apk-busybox-4cea7ce2e2974c99"},{"relatedSpdxElement":"SPDXRef-File-usr-share-udhcpc-default.script-4fc79137008d263f","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-busybox-4cea7ce2e2974c99"},{"relatedSpdxElement":"SPDXRef-File-etc-busybox-paths.d-busybox-6a326fdbd2e5a86c","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-busybox-4cea7ce2e2974c99"},{"comment":"evident-by: indicates the package's existence is evident by the given file","relatedSpdxElement":"SPDXRef-File-lib-apk-db-installed-8363b4a677041553","relationshipType":"OTHER","spdxElementId":"SPDXRef-Package-apk-busybox-4cea7ce2e2974c99"},{"relatedSpdxElement":"SPDXRef-File-bin-busybox-909c5f40cb01cb38","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-busybox-4cea7ce2e2974c99"},{"relatedSpdxElement":"SPDXRef-File-etc-udhcpc-udhcpc.conf-a8f34a90829fb0c8","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-busybox-4cea7ce2e2974c99"},{"relatedSpdxElement":"SPDXRef-File-etc-network-if-up.d-dad-e17f6cd71c480b11","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-busybox-4cea7ce2e2974c99"},{"relatedSpdxElement":"SPDXRef-File-etc-logrotate.d-acpid-e47331443c3f2fdc","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-busybox-4cea7ce2e2974c99"},{"relatedSpdxElement":"SPDXRef-File-etc-securetty-f5826ff16d6eaebb","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-busybox-4cea7ce2e2974c99"},{"relatedSpdxElement":"SPDXRef-File-usr-bin-scanelf-42e6597f9fa4518a","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-scanelf-54f3623fdd8fb8d4"},{"comment":"evident-by: indicates the package's existence is evident by the given file","relatedSpdxElement":"SPDXRef-File-lib-apk-db-installed-8363b4a677041553","relationshipType":"OTHER","spdxElementId":"SPDXRef-Package-apk-scanelf-54f3623fdd8fb8d4"},{"relatedSpdxElement":"SPDXRef-Package-apk-musl-utils-c84ae08b59df5c6e","relationshipType":"DEPENDENCY_OF","spdxElementId":"SPDXRef-Package-apk-scanelf-54f3623fdd8fb8d4"},{"comment":"evident-by: indicates the package's existence is evident by the given file","relatedSpdxElement":"SPDXRef-File-lib-apk-db-installed-8363b4a677041553","relationshipType":"OTHER","spdxElementId":"SPDXRef-Package-apk-ssl-client-6bbb10e52b8e7eb4"},{"relatedSpdxElement":"SPDXRef-File-usr-bin-ssl-client-90e1da58238b5003","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-ssl-client-6bbb10e52b8e7eb4"},{"relatedSpdxElement":"SPDXRef-File-sbin-apk-03a303c2f408ad75","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-apk-tools-78c55d64ab350462"},{"comment":"evident-by: indicates the package's existence is evident by the given file","relatedSpdxElement":"SPDXRef-File-lib-apk-db-installed-8363b4a677041553","relationshipType":"OTHER","spdxElementId":"SPDXRef-Package-apk-apk-tools-78c55d64ab350462"},{"relatedSpdxElement":"SPDXRef-File-lib-libapk.so.2.14.0-85382abc3213df0c","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-apk-tools-78c55d64ab350462"},{"relatedSpdxElement":"SPDXRef-File-etc-hosts-097d60485ef1a565","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-data-9ff96f942d2401f2"},{"relatedSpdxElement":"SPDXRef-File-etc-fstab-0c5c3473875a5b85","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-data-9ff96f942d2401f2"},{"relatedSpdxElement":"SPDXRef-File-etc-hostname-18f4143fa24a5309","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-data-9ff96f942d2401f2"},{"relatedSpdxElement":"SPDXRef-Package-apk-alpine-baselayout-21e54be9d7ca763c","relationshipType":"DEPENDENCY_OF","spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-data-9ff96f942d2401f2"},{"relatedSpdxElement":"SPDXRef-File-etc-nsswitch.conf-26adb8feffe4129b","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-data-9ff96f942d2401f2"},{"relatedSpdxElement":"SPDXRef-File-etc-inittab-273285a459443001","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-data-9ff96f942d2401f2"},{"relatedSpdxElement":"SPDXRef-File-etc-shells-2dc73ba417bebb75","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-data-9ff96f942d2401f2"},{"relatedSpdxElement":"SPDXRef-File-etc-sysctl.conf-2eede682f1d2d57e","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-data-9ff96f942d2401f2"},{"relatedSpdxElement":"SPDXRef-File-etc-protocols-5f1d8d1482d973b6","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-data-9ff96f942d2401f2"},{"relatedSpdxElement":"SPDXRef-File-etc-profile-6dfdb9518e6b63ef","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-data-9ff96f942d2401f2"},{"relatedSpdxElement":"SPDXRef-File-etc-passwd-7accffa8923d35e9","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-data-9ff96f942d2401f2"},{"relatedSpdxElement":"SPDXRef-File-etc-services-812b3f1a2d583f29","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-data-9ff96f942d2401f2"},{"comment":"evident-by: indicates the package's existence is evident by the given file","relatedSpdxElement":"SPDXRef-File-lib-apk-db-installed-8363b4a677041553","relationshipType":"OTHER","spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-data-9ff96f942d2401f2"},{"relatedSpdxElement":"SPDXRef-File-etc-shadow-a1d64c72d061cd92","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-data-9ff96f942d2401f2"},{"relatedSpdxElement":"SPDXRef-File-etc-group-cc490babc7ba6984","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-data-9ff96f942d2401f2"},{"relatedSpdxElement":"SPDXRef-File-etc-modules-f9e050b82be1ad75","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-alpine-baselayout-data-9ff96f942d2401f2"},{"relatedSpdxElement":"SPDXRef-Package-apk-apk-tools-78c55d64ab350462","relationshipType":"DEPENDENCY_OF","spdxElementId":"SPDXRef-Package-apk-ca-certificates-bundle-bf42440dd0b61727"},{"comment":"evident-by: indicates the package's existence is evident by the given file","relatedSpdxElement":"SPDXRef-File-lib-apk-db-installed-8363b4a677041553","relationshipType":"OTHER","spdxElementId":"SPDXRef-Package-apk-ca-certificates-bundle-bf42440dd0b61727"},{"relatedSpdxElement":"SPDXRef-File-etc-ssl-certs-ca-certificates.crt-c7ec96e3f9d22e5e","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-ca-certificates-bundle-bf42440dd0b61727"},{"relatedSpdxElement":"SPDXRef-File-usr-bin-ldd-0f8acf82bbb616a2","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-musl-utils-c84ae08b59df5c6e"},{"relatedSpdxElement":"SPDXRef-File-sbin-ldconfig-6dd00345fd25dfbe","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-musl-utils-c84ae08b59df5c6e"},{"comment":"evident-by: indicates the package's existence is evident by the given file","relatedSpdxElement":"SPDXRef-File-lib-apk-db-installed-8363b4a677041553","relationshipType":"OTHER","spdxElementId":"SPDXRef-Package-apk-musl-utils-c84ae08b59df5c6e"},{"relatedSpdxElement":"SPDXRef-File-usr-bin-getconf-aa569a0b492dbc3e","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-musl-utils-c84ae08b59df5c6e"},{"relatedSpdxElement":"SPDXRef-File-usr-bin-iconv-b4f317a0c3ae4126","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-musl-utils-c84ae08b59df5c6e"},{"relatedSpdxElement":"SPDXRef-File-usr-bin-getent-dfc1d5b68ea46609","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-musl-utils-c84ae08b59df5c6e"},{"relatedSpdxElement":"SPDXRef-Package-apk-apk-tools-78c55d64ab350462","relationshipType":"DEPENDENCY_OF","spdxElementId":"SPDXRef-Package-apk-zlib-d8258d3d7c48cfbf"},{"comment":"evident-by: indicates the package's existence is evident by the given file","relatedSpdxElement":"SPDXRef-File-lib-apk-db-installed-8363b4a677041553","relationshipType":"OTHER","spdxElementId":"SPDXRef-Package-apk-zlib-d8258d3d7c48cfbf"},{"relatedSpdxElement":"SPDXRef-File-lib-libz.so.1.3.1-cfebf8b5dc1f6374","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-Package-apk-zlib-d8258d3d7c48cfbf"},{"relatedSpdxElement":"SPDXRef-Package-apk-alpine-baselayout-21e54be9d7ca763c","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-DocumentRoot-Image-alpine"},{"relatedSpdxElement":"SPDXRef-Package-apk-alpine-baselayout-data-9ff96f942d2401f2","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-DocumentRoot-Image-alpine"},{"relatedSpdxElement":"SPDXRef-Package-apk-alpine-keys-0e5100e3d266a135","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-DocumentRoot-Image-alpine"},{"relatedSpdxElement":"SPDXRef-Package-apk-apk-tools-78c55d64ab350462","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-DocumentRoot-Image-alpine"},{"relatedSpdxElement":"SPDXRef-Package-apk-busybox-4cea7ce2e2974c99","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-DocumentRoot-Image-alpine"},{"relatedSpdxElement":"SPDXRef-Package-apk-busybox-binsh-1fd95b4d43a9f438","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-DocumentRoot-Image-alpine"},{"relatedSpdxElement":"SPDXRef-Package-apk-ca-certificates-bundle-bf42440dd0b61727","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-DocumentRoot-Image-alpine"},{"relatedSpdxElement":"SPDXRef-Package-apk-libcrypto3-0cfcda1a242dfd13","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-DocumentRoot-Image-alpine"},{"relatedSpdxElement":"SPDXRef-Package-apk-libssl3-1bffb507b1b535bc","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-DocumentRoot-Image-alpine"},{"relatedSpdxElement":"SPDXRef-Package-apk-musl-03e521237cbed45a","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-DocumentRoot-Image-alpine"},{"relatedSpdxElement":"SPDXRef-Package-apk-musl-utils-c84ae08b59df5c6e","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-DocumentRoot-Image-alpine"},{"relatedSpdxElement":"SPDXRef-Package-apk-scanelf-54f3623fdd8fb8d4","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-DocumentRoot-Image-alpine"},{"relatedSpdxElement":"SPDXRef-Package-apk-ssl-client-6bbb10e52b8e7eb4","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-DocumentRoot-Image-alpine"},{"relatedSpdxElement":"SPDXRef-Package-apk-zlib-d8258d3d7c48cfbf","relationshipType":"CONTAINS","spdxElementId":"SPDXRef-DocumentRoot-Image-alpine"},{"relatedSpdxElement":"SPDXRef-DocumentRoot-Image-alpine","relationshipType":"DESCRIBES","spdxElementId":"SPDXRef-DOCUMENT"}],"spdxVersion":"SPDX-2.3"},"starttime":"2024-06-13T13:27:26.597355-05:00","endtime":"2024-06-13T13:27:26.598769-05:00"}]}}","payloadType":"application/vnd.in-toto+json","signatures":[{"keyid":"ae2dcc989ea9c109a36e8eba5c4bc16d8fafcfe8e1a614164670d50aedacd647","sig":"RIQOqwpkQcN4HuovLss1NPMDTbHaM+3edVyfNOwxCyZXicjOWFlXOlO4iZ+ZUpLjqmsABVhdaOL0VVwRemr+BA=="}]} diff --git a/test/test.sh b/test/test.sh index 2dd8650d..a7aa5523 100755 --- a/test/test.sh +++ b/test/test.sh @@ -56,3 +56,6 @@ if ../bin/witness -c $test_config verify -a ./fail.attestation.json -a ./package echo "expected verify to fail" exit 1 fi + +# test policy with multi-type attestor (ie. SBOM) +../bin/witness verify -p sbom-policy-signed.json -a spdx-att.json -k testpub.pem -f sbom.spdx.json --log-level debug From 55d15abd60a85a8ce3a902cebd0c2eff365eee72 Mon Sep 17 00:00:00 2001 From: John Kjell Date: Thu, 13 Jun 2024 15:16:01 -0500 Subject: [PATCH 5/5] Update to go-witness v0.5.1 Signed-off-by: John Kjell --- go.mod | 2 +- go.sum | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/go.mod b/go.mod index 7a613cac..b3841378 100644 --- a/go.mod +++ b/go.mod @@ -5,7 +5,7 @@ go 1.22.0 toolchain go1.22.2 require ( - github.com/in-toto/go-witness v0.5.0 + github.com/in-toto/go-witness v0.5.1 github.com/invopop/jsonschema v0.12.0 github.com/olekukonko/tablewriter v0.0.5 github.com/sigstore/fulcio v1.4.5 diff --git a/go.sum b/go.sum index 8d743ea3..73c1d54d 100644 --- a/go.sum +++ b/go.sum @@ -218,8 +218,8 @@ github.com/in-toto/archivista v0.5.1 h1:mAPt1lW9VAMnEGiS38OGvej4t2AZ4Irfh8+y5koq github.com/in-toto/archivista v0.5.1/go.mod h1:wzOSEgvDdV27CZUWm6H72sQ+vzAWjQLX1qhBJIJUSYI= github.com/in-toto/attestation v1.0.2 h1:ICqV41bfaDC3ixVUzAtFxFu+Dy56EPcjiIrJQe+4LVM= github.com/in-toto/attestation v1.0.2/go.mod h1:3uRayZSKuCHDDZOxLm5UfYulqqd1L1NdzYvxX/jyZEM= -github.com/in-toto/go-witness v0.5.0 h1:ViES51SWrgOByFdZTny+ZRFPClJcFQ8WId/YlxdPG7Q= -github.com/in-toto/go-witness v0.5.0/go.mod h1:RN10WG5hFnK9OSHFlQD4mql54uCrtWdZ08/bl1vPuMI= +github.com/in-toto/go-witness v0.5.1 h1:lrnFttDWEZqHxSfupcDGWTxSw8Uk/pNtVM1Wr3St0fo= +github.com/in-toto/go-witness v0.5.1/go.mod h1:RN10WG5hFnK9OSHFlQD4mql54uCrtWdZ08/bl1vPuMI= github.com/inconshreveable/mousetrap v1.1.0 h1:wN+x4NVGpMsO7ErUn/mUI3vEoE6Jt13X2s0bqwp9tc8= github.com/inconshreveable/mousetrap v1.1.0/go.mod h1:vpF70FUmC8bwa3OWnCshd2FqLfsEA9PFc4w1p2J65bw= github.com/invopop/jsonschema v0.12.0 h1:6ovsNSuvn9wEQVOyc72aycBMVQFKz7cPdMJn10CvzRI=