{
  "stage": "stage2a-sbom",
  "generated_at": "2026-03-28T21:26:57.798Z",
  "sbom_generation": {
    "syft": {
      "componentCount": 237,
      "directDeps": 1,
      "transitiveDeps": 236,
      "licenses": {
        "unknown": 186,
        "MIT": 26,
        "MIT License": 2,
        "MPL-2.0": 1,
        "BSD-3-Clause": 9,
        "Apache-2.0 OR BSD-3-Clause": 1,
        "BSD": 3,
        "Apache-2.0 OR BSD-2-Clause": 1,
        "BSD-2-Clause": 1,
        "Apache-2.0": 3,
        "PSF": 1,
        "Apache Software License": 1,
        "MIT OR Apache-2.0": 1,
        "PSF-2.0": 1
      },
      "toolVersion": "syft 1.42.1",
      "durationMs": 88341,
      "cdxPath": "C:\\Users\\scott\\Desktop\\Projects\\contract-pipeline\\pipeline\\data\\capabilities\\mcp-server-fetch\\mcp-server-fetch.cdx.json",
      "spdxPath": "C:\\Users\\scott\\Desktop\\Projects\\contract-pipeline\\pipeline\\data\\capabilities\\mcp-server-fetch\\mcp-server-fetch.spdx.json"
    },
    "cdxgen": {
      "componentCount": 58,
      "durationMs": 8574,
      "cdxgenPath": "C:\\Users\\scott\\Desktop\\Projects\\contract-pipeline\\pipeline\\data\\capabilities\\mcp-server-fetch\\mcp-server-fetch-cdxgen.cdx.json"
    }
  },
  "contract_supply_chain_sbom": {
    "format": "CycloneDX",
    "version": "1.5",
    "generated_at": "2026-03-28T21:26:57.798Z",
    "component_count": 237,
    "direct_dependencies": 1,
    "transitive_dependencies": 236,
    "vulnerability_summary": {
      "critical": 3,
      "high": 15,
      "medium": 23,
      "low": 14,
      "none": 0,
      "total": 55
    },
    "flagged_components": [
      {
        "name": "Scintilla",
        "version": "4.4.6",
        "vulnerability": "CVE-2019-16294",
        "severity": "high",
        "status": "open",
        "notes": "found by: grype"
      },
      {
        "name": "tough-cookie",
        "version": "3.0.1",
        "vulnerability": "CVE-2023-26136",
        "severity": "medium",
        "status": "patched",
        "notes": "found by: grype, osv-scanner; fix: 4.1.3"
      },
      {
        "name": "json-schema",
        "version": "0.2.3",
        "vulnerability": "CVE-2021-3918",
        "severity": "critical",
        "status": "patched",
        "notes": "found by: grype, osv-scanner; fix: 0.4.0"
      },
      {
        "name": "qs",
        "version": "6.5.2",
        "vulnerability": "CVE-2022-24999",
        "severity": "high",
        "status": "patched",
        "notes": "scope: runtime; found by: grype, osv-scanner; fix: 6.5.3"
      },
      {
        "name": "minimist",
        "version": "1.2.5",
        "vulnerability": "CVE-2021-44906",
        "severity": "critical",
        "status": "patched",
        "notes": "scope: development; found by: grype, osv-scanner; fix: 1.2.6"
      },
      {
        "name": "ws",
        "version": "7.3.1",
        "vulnerability": "CVE-2024-37890",
        "severity": "high",
        "status": "patched",
        "notes": "found by: grype, osv-scanner; fix: 7.5.10"
      },
      {
        "name": "lodash",
        "version": "4.17.20",
        "vulnerability": "CVE-2021-23337",
        "severity": "high",
        "status": "patched",
        "notes": "found by: grype, osv-scanner; fix: 4.17.21"
      },
      {
        "name": "request",
        "version": "2.88.2",
        "vulnerability": "CVE-2023-28155",
        "severity": "medium",
        "status": "patched",
        "notes": "found by: grype, osv-scanner; fix: 3.0.0"
      },
      {
        "name": "ws",
        "version": "7.3.1",
        "vulnerability": "CVE-2021-32640",
        "severity": "medium",
        "status": "patched",
        "notes": "found by: grype, osv-scanner; fix: 7.4.6"
      },
      {
        "name": "lodash",
        "version": "4.17.20",
        "vulnerability": "CVE-2020-28500",
        "severity": "medium",
        "status": "patched",
        "notes": "found by: grype, osv-scanner; fix: 4.17.21"
      },
      {
        "name": "Python",
        "version": "3.11.15",
        "vulnerability": "CVE-2025-13836",
        "severity": "high",
        "status": "patched",
        "notes": "found by: grype; fix: 3.13.11"
      },
      {
        "name": "Python",
        "version": "3.11.15",
        "vulnerability": "CVE-2024-3220",
        "severity": "low",
        "status": "patched",
        "notes": "found by: grype; fix: 3.14.0"
      },
      {
        "name": "Python",
        "version": "3.11.15",
        "vulnerability": "CVE-2026-0672",
        "severity": "medium",
        "status": "patched",
        "notes": "found by: grype; fix: 3.13.12"
      },
      {
        "name": "form-data",
        "version": "2.3.3",
        "vulnerability": "CVE-2025-7783",
        "severity": "critical",
        "status": "patched",
        "notes": "found by: grype, osv-scanner; fix: 2.5.4"
      },
      {
        "name": "Python",
        "version": "3.11.15",
        "vulnerability": "CVE-2026-0865",
        "severity": "medium",
        "status": "patched",
        "notes": "found by: grype; fix: 3.13.12"
      },
      {
        "name": "Python",
        "version": "3.11.15",
        "vulnerability": "CVE-2026-3644",
        "severity": "medium",
        "status": "open",
        "notes": "found by: grype"
      },
      {
        "name": "Python",
        "version": "3.11.15",
        "vulnerability": "CVE-2025-15366",
        "severity": "medium",
        "status": "patched",
        "notes": "found by: grype; fix: 3.15.0a6"
      },
      {
        "name": "Python",
        "version": "3.11.15",
        "vulnerability": "CVE-2025-15367",
        "severity": "medium",
        "status": "patched",
        "notes": "found by: grype; fix: 3.15.0a6"
      },
      {
        "name": "qs",
        "version": "6.5.2",
        "vulnerability": "CVE-2025-15284",
        "severity": "medium",
        "status": "patched",
        "notes": "scope: runtime; found by: grype, osv-scanner; fix: 6.14.1"
      },
      {
        "name": "Python",
        "version": "3.11.15",
        "vulnerability": "CVE-2025-12084",
        "severity": "medium",
        "status": "patched",
        "notes": "found by: grype; fix: 3.13.11"
      },
      {
        "name": "Python",
        "version": "3.11.15",
        "vulnerability": "CVE-2026-4519",
        "severity": "high",
        "status": "open",
        "notes": "found by: grype"
      },
      {
        "name": "Python",
        "version": "3.11.15",
        "vulnerability": "CVE-2025-15282",
        "severity": "medium",
        "status": "patched",
        "notes": "found by: grype; fix: 3.13.12"
      },
      {
        "name": "Python",
        "version": "3.11.15",
        "vulnerability": "CVE-2026-1299",
        "severity": "medium",
        "status": "patched",
        "notes": "found by: grype; fix: 3.13.12"
      },
      {
        "name": "Python",
        "version": "3.11.15",
        "vulnerability": "CVE-2025-11468",
        "severity": "medium",
        "status": "patched",
        "notes": "found by: grype; fix: 3.13.12"
      },
      {
        "name": "lodash",
        "version": "4.17.20",
        "vulnerability": "CVE-2025-13465",
        "severity": "medium",
        "status": "patched",
        "notes": "found by: grype, osv-scanner; fix: 4.17.23"
      },
      {
        "name": "word-wrap",
        "version": "1.2.3",
        "vulnerability": "CVE-2023-26115",
        "severity": "medium",
        "status": "patched",
        "notes": "found by: grype, osv-scanner; fix: 1.2.4"
      },
      {
        "name": "Python",
        "version": "3.11.15",
        "vulnerability": "CVE-2025-6075",
        "severity": "medium",
        "status": "patched",
        "notes": "found by: grype; fix: 3.13.10"
      },
      {
        "name": "Python",
        "version": "3.11.15",
        "vulnerability": "CVE-2025-13837",
        "severity": "medium",
        "status": "patched",
        "notes": "found by: grype; fix: 3.13.10"
      },
      {
        "name": "Python",
        "version": "3.11.15",
        "vulnerability": "CVE-2026-4224",
        "severity": "medium",
        "status": "open",
        "notes": "found by: grype"
      },
      {
        "name": "ajv",
        "version": "6.12.5",
        "vulnerability": "CVE-2025-69873",
        "severity": "medium",
        "status": "patched",
        "notes": "scope: runtime; found by: grype, osv-scanner; fix: 6.14.0"
      },
      {
        "name": "Python",
        "version": "3.11.15",
        "vulnerability": "CVE-2025-12781",
        "severity": "medium",
        "status": "open",
        "notes": "found by: grype"
      },
      {
        "name": "Python",
        "version": "3.11.15",
        "vulnerability": "CVE-2026-2297",
        "severity": "medium",
        "status": "open",
        "notes": "found by: grype"
      },
      {
        "name": "pyjwt",
        "version": "2.10.1",
        "vulnerability": "CVE-2026-32597",
        "severity": "high",
        "status": "patched",
        "notes": "found by: grype, osv-scanner; fix: 2.12.0"
      },
      {
        "name": "pygments",
        "version": "2.19.2",
        "vulnerability": "CVE-2026-4539",
        "severity": "low",
        "status": "open",
        "notes": "found by: grype, osv-scanner"
      },
      {
        "name": "Python",
        "version": "3.11.15",
        "vulnerability": "CVE-2025-13462",
        "severity": "low",
        "status": "open",
        "notes": "found by: grype"
      },
      {
        "name": "requests",
        "version": "2.32.4",
        "vulnerability": "CVE-2026-25645",
        "severity": "medium",
        "status": "patched",
        "notes": "found by: grype, osv-scanner; fix: 2.33.0"
      },
      {
        "name": "Python",
        "version": "3.11.15",
        "vulnerability": "CVE-2026-3479",
        "severity": "low",
        "status": "open",
        "notes": "found by: grype"
      },
      {
        "name": "cryptography",
        "version": "46.0.5",
        "vulnerability": "CVE-2026-34073",
        "severity": "low",
        "status": "patched",
        "notes": "found by: grype, osv-scanner; fix: 46.0.6"
      },
      {
        "name": "@hono/node-server",
        "version": "<1.19.10",
        "vulnerability": "GHSA-wc8c-qw6v-h7f6",
        "severity": "high",
        "status": "patched",
        "notes": "scope: runtime; found by: npm-audit; fix: available"
      },
      {
        "name": "ajv",
        "version": "7.0.0-alpha.0 - 8.17.1",
        "vulnerability": "GHSA-2g4f-4pwh-qvx6",
        "severity": "low",
        "status": "patched",
        "notes": "scope: runtime; found by: npm-audit; fix: available"
      },
      {
        "name": "brace-expansion",
        "version": "<1.1.13 || >=2.0.0 <2.0.3",
        "vulnerability": "GHSA-f886-m6hf-6m8v",
        "severity": "low",
        "status": "patched",
        "notes": "scope: development; found by: npm-audit; fix: available"
      },
      {
        "name": "esbuild",
        "version": "<=0.24.2",
        "vulnerability": "GHSA-67mh-4wv8-2f99",
        "severity": "low",
        "status": "patched",
        "notes": "scope: development; found by: npm-audit; fix: 4.1.2"
      },
      {
        "name": "express-rate-limit",
        "version": "8.2.0 - 8.2.1",
        "vulnerability": "GHSA-46wh-pxpv-q5gq",
        "severity": "high",
        "status": "patched",
        "notes": "scope: runtime; found by: npm-audit; fix: available"
      },
      {
        "name": "hono",
        "version": "<=4.12.6",
        "vulnerability": "GHSA-gq3j-xvxp-8hrf",
        "severity": "low",
        "status": "patched",
        "notes": "scope: runtime; found by: npm-audit; fix: available"
      },
      {
        "name": "hono",
        "version": "<=4.12.6",
        "vulnerability": "GHSA-5pq2-9x2x-5p6w",
        "severity": "low",
        "status": "patched",
        "notes": "scope: runtime; found by: npm-audit; fix: available"
      },
      {
        "name": "hono",
        "version": "<=4.12.6",
        "vulnerability": "GHSA-p6xx-57qc-3wxr",
        "severity": "low",
        "status": "patched",
        "notes": "scope: runtime; found by: npm-audit; fix: available"
      },
      {
        "name": "hono",
        "version": "<=4.12.6",
        "vulnerability": "GHSA-q5qw-h33p-qvwr",
        "severity": "high",
        "status": "patched",
        "notes": "scope: runtime; found by: npm-audit; fix: available"
      },
      {
        "name": "hono",
        "version": "<=4.12.6",
        "vulnerability": "GHSA-v8w9-8mx6-g223",
        "severity": "low",
        "status": "patched",
        "notes": "scope: runtime; found by: npm-audit; fix: available"
      },
      {
        "name": "minimatch",
        "version": "<=3.1.3 || 9.0.0 - 9.0.6 || 10.0.0 - 10.2.2",
        "vulnerability": "GHSA-3ppc-4f35-3m26",
        "severity": "high",
        "status": "patched",
        "notes": "scope: runtime; found by: npm-audit; fix: available"
      },
      {
        "name": "minimatch",
        "version": "<=3.1.3 || 9.0.0 - 9.0.6 || 10.0.0 - 10.2.2",
        "vulnerability": "GHSA-7r86-cg39-jmmj",
        "severity": "high",
        "status": "patched",
        "notes": "scope: runtime; found by: npm-audit; fix: available"
      },
      {
        "name": "minimatch",
        "version": "<=3.1.3 || 9.0.0 - 9.0.6 || 10.0.0 - 10.2.2",
        "vulnerability": "GHSA-23c5-xmqv-rm74",
        "severity": "high",
        "status": "patched",
        "notes": "scope: runtime; found by: npm-audit; fix: available"
      },
      {
        "name": "path-to-regexp",
        "version": "8.0.0 - 8.3.0",
        "vulnerability": "GHSA-j3q9-mxjg-w52f",
        "severity": "high",
        "status": "patched",
        "notes": "scope: runtime; found by: npm-audit; fix: available"
      },
      {
        "name": "path-to-regexp",
        "version": "8.0.0 - 8.3.0",
        "vulnerability": "GHSA-27v5-c462-wpq7",
        "severity": "low",
        "status": "patched",
        "notes": "scope: runtime; found by: npm-audit; fix: available"
      },
      {
        "name": "qs",
        "version": "6.7.0 - 6.14.1",
        "vulnerability": "GHSA-w7fw-mjwx-w883",
        "severity": "low",
        "status": "patched",
        "notes": "scope: runtime; found by: npm-audit; fix: available"
      },
      {
        "name": "rollup",
        "version": "4.0.0 - 4.58.0",
        "vulnerability": "GHSA-mw96-cpmx-2vgc",
        "severity": "high",
        "status": "patched",
        "notes": "scope: development; found by: npm-audit; fix: available"
      }
    ]
  }
}