{
  "stage": "stage2a-sbom",
  "generated_at": "2026-03-28T21:31:24.460Z",
  "sbom_generation": {
    "syft": {
      "componentCount": 0,
      "directDeps": 0,
      "transitiveDeps": 0,
      "licenses": {},
      "toolVersion": "syft 1.42.1",
      "durationMs": 2020,
      "cdxPath": "C:\\Users\\scott\\Desktop\\Projects\\contract-pipeline\\pipeline\\data\\capabilities\\mcp-server-filesystem\\mcp-server-filesystem.cdx.json",
      "spdxPath": "C:\\Users\\scott\\Desktop\\Projects\\contract-pipeline\\pipeline\\data\\capabilities\\mcp-server-filesystem\\mcp-server-filesystem.spdx.json"
    },
    "cdxgen": {
      "componentCount": 1,
      "durationMs": 9999,
      "cdxgenPath": "C:\\Users\\scott\\Desktop\\Projects\\contract-pipeline\\pipeline\\data\\capabilities\\mcp-server-filesystem\\mcp-server-filesystem-cdxgen.cdx.json"
    }
  },
  "contract_supply_chain_sbom": {
    "format": "CycloneDX",
    "version": "1.5",
    "generated_at": "2026-03-28T21:31:24.459Z",
    "component_count": 281,
    "direct_dependencies": 12,
    "transitive_dependencies": 269,
    "vulnerability_summary": {
      "critical": 0,
      "high": 11,
      "medium": 0,
      "low": 9,
      "none": 0,
      "total": 20
    },
    "flagged_components": [
      {
        "name": "minimatch",
        "version": "10.0.1",
        "vulnerability": "CVE-2026-26996",
        "severity": "high",
        "status": "patched",
        "notes": "scope: runtime; found by: grype, osv-scanner; fix: 10.2.1"
      },
      {
        "name": "minimatch",
        "version": "10.0.1",
        "vulnerability": "CVE-2026-27903",
        "severity": "high",
        "status": "patched",
        "notes": "scope: runtime; found by: grype, osv-scanner; fix: 10.2.3"
      },
      {
        "name": "minimatch",
        "version": "10.0.1",
        "vulnerability": "CVE-2026-27904",
        "severity": "high",
        "status": "patched",
        "notes": "scope: runtime; found by: grype, osv-scanner; fix: 10.2.3"
      },
      {
        "name": "@hono/node-server",
        "version": "<1.19.10",
        "vulnerability": "GHSA-wc8c-qw6v-h7f6",
        "severity": "high",
        "status": "patched",
        "notes": "scope: runtime; found by: npm-audit; fix: available"
      },
      {
        "name": "ajv",
        "version": "7.0.0-alpha.0 - 8.17.1",
        "vulnerability": "GHSA-2g4f-4pwh-qvx6",
        "severity": "low",
        "status": "patched",
        "notes": "scope: runtime; found by: npm-audit; fix: available"
      },
      {
        "name": "brace-expansion",
        "version": "<1.1.13 || >=2.0.0 <2.0.3",
        "vulnerability": "GHSA-f886-m6hf-6m8v",
        "severity": "low",
        "status": "patched",
        "notes": "scope: development; found by: npm-audit; fix: available"
      },
      {
        "name": "esbuild",
        "version": "<=0.24.2",
        "vulnerability": "GHSA-67mh-4wv8-2f99",
        "severity": "low",
        "status": "patched",
        "notes": "scope: development; found by: npm-audit; fix: 4.1.2"
      },
      {
        "name": "express-rate-limit",
        "version": "8.2.0 - 8.2.1",
        "vulnerability": "GHSA-46wh-pxpv-q5gq",
        "severity": "high",
        "status": "patched",
        "notes": "scope: runtime; found by: npm-audit; fix: available"
      },
      {
        "name": "hono",
        "version": "<=4.12.6",
        "vulnerability": "GHSA-gq3j-xvxp-8hrf",
        "severity": "low",
        "status": "patched",
        "notes": "scope: runtime; found by: npm-audit; fix: available"
      },
      {
        "name": "hono",
        "version": "<=4.12.6",
        "vulnerability": "GHSA-5pq2-9x2x-5p6w",
        "severity": "low",
        "status": "patched",
        "notes": "scope: runtime; found by: npm-audit; fix: available"
      },
      {
        "name": "hono",
        "version": "<=4.12.6",
        "vulnerability": "GHSA-p6xx-57qc-3wxr",
        "severity": "low",
        "status": "patched",
        "notes": "scope: runtime; found by: npm-audit; fix: available"
      },
      {
        "name": "hono",
        "version": "<=4.12.6",
        "vulnerability": "GHSA-q5qw-h33p-qvwr",
        "severity": "high",
        "status": "patched",
        "notes": "scope: runtime; found by: npm-audit; fix: available"
      },
      {
        "name": "hono",
        "version": "<=4.12.6",
        "vulnerability": "GHSA-v8w9-8mx6-g223",
        "severity": "low",
        "status": "patched",
        "notes": "scope: runtime; found by: npm-audit; fix: available"
      },
      {
        "name": "minimatch",
        "version": "<=3.1.3 || 9.0.0 - 9.0.6 || 10.0.0 - 10.2.2",
        "vulnerability": "GHSA-3ppc-4f35-3m26",
        "severity": "high",
        "status": "patched",
        "notes": "scope: runtime; found by: npm-audit; fix: available"
      },
      {
        "name": "minimatch",
        "version": "<=3.1.3 || 9.0.0 - 9.0.6 || 10.0.0 - 10.2.2",
        "vulnerability": "GHSA-7r86-cg39-jmmj",
        "severity": "high",
        "status": "patched",
        "notes": "scope: runtime; found by: npm-audit; fix: available"
      },
      {
        "name": "minimatch",
        "version": "<=3.1.3 || 9.0.0 - 9.0.6 || 10.0.0 - 10.2.2",
        "vulnerability": "GHSA-23c5-xmqv-rm74",
        "severity": "high",
        "status": "patched",
        "notes": "scope: runtime; found by: npm-audit; fix: available"
      },
      {
        "name": "path-to-regexp",
        "version": "8.0.0 - 8.3.0",
        "vulnerability": "GHSA-j3q9-mxjg-w52f",
        "severity": "high",
        "status": "patched",
        "notes": "scope: runtime; found by: npm-audit; fix: available"
      },
      {
        "name": "path-to-regexp",
        "version": "8.0.0 - 8.3.0",
        "vulnerability": "GHSA-27v5-c462-wpq7",
        "severity": "low",
        "status": "patched",
        "notes": "scope: runtime; found by: npm-audit; fix: available"
      },
      {
        "name": "qs",
        "version": "6.7.0 - 6.14.1",
        "vulnerability": "GHSA-w7fw-mjwx-w883",
        "severity": "low",
        "status": "patched",
        "notes": "scope: runtime; found by: npm-audit; fix: available"
      },
      {
        "name": "rollup",
        "version": "4.0.0 - 4.58.0",
        "vulnerability": "GHSA-mw96-cpmx-2vgc",
        "severity": "high",
        "status": "patched",
        "notes": "scope: development; found by: npm-audit; fix: available"
      }
    ]
  }
}