1+ {
2+ "_type" : " https://in-toto.io/Statement/v0.1" ,
3+ "predicateType" : " https://spdx.dev/Document" ,
4+ "subject" : [
5+ {
6+ "name" : " empty" ,
7+ "digest" : {
8+ "sha256" : " e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"
9+ }
10+ }
11+ ],
12+ "predicate" : {
13+ "SPDXID" : " SPDXRef-DOCUMENT" ,
14+ "name" : " sbom-base" ,
15+ "packages" : [
16+ {
17+ "SPDXID" : " SPDXRef-Package-apk-alpine-baselayout-5ede89861c73ee0f" ,
18+ "copyrightText" : " NOASSERTION" ,
19+ "description" : " Alpine base dir structure and init scripts" ,
20+ "downloadLocation" : " https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout" ,
21+ "externalRefs" : [
22+ {
23+ "referenceCategory" : " SECURITY" ,
24+ "referenceLocator" : " cpe:2.3:a:alpine-baselayout:alpine-baselayout:3.2.0-r18:*:*:*:*:*:*:*" ,
25+ "referenceType" : " cpe23Type"
26+ },
27+ {
28+ "referenceCategory" : " SECURITY" ,
29+ "referenceLocator" : " cpe:2.3:a:alpine-baselayout:alpine_baselayout:3.2.0-r18:*:*:*:*:*:*:*" ,
30+ "referenceType" : " cpe23Type"
31+ },
32+ {
33+ "referenceCategory" : " SECURITY" ,
34+ "referenceLocator" : " cpe:2.3:a:alpine_baselayout:alpine-baselayout:3.2.0-r18:*:*:*:*:*:*:*" ,
35+ "referenceType" : " cpe23Type"
36+ },
37+ {
38+ "referenceCategory" : " SECURITY" ,
39+ "referenceLocator" : " cpe:2.3:a:alpine_baselayout:alpine_baselayout:3.2.0-r18:*:*:*:*:*:*:*" ,
40+ "referenceType" : " cpe23Type"
41+ },
42+ {
43+ "referenceCategory" : " SECURITY" ,
44+ "referenceLocator" : " cpe:2.3:a:alpine:alpine-baselayout:3.2.0-r18:*:*:*:*:*:*:*" ,
45+ "referenceType" : " cpe23Type"
46+ },
47+ {
48+ "referenceCategory" : " SECURITY" ,
49+ "referenceLocator" : " cpe:2.3:a:alpine:alpine_baselayout:3.2.0-r18:*:*:*:*:*:*:*" ,
50+ "referenceType" : " cpe23Type"
51+ },
52+ {
53+ "referenceCategory" : " PACKAGE-MANAGER" ,
54+ "referenceLocator" : " pkg:apk/alpine/alpine-baselayout@3.2.0-r18?arch=x86_64\u0026 distro=alpine-3.15.11" ,
55+ "referenceType" : " purl"
56+ }
57+ ],
58+ "filesAnalyzed" : true ,
59+ "licenseConcluded" : " NOASSERTION" ,
60+ "licenseDeclared" : " GPL-2.0-only" ,
61+ "name" : " alpine-baselayout" ,
62+ "originator" : " Person: Natanael Copa (ncopa@alpinelinux.org)" ,
63+ "packageVerificationCode" : {
64+ "packageVerificationCodeValue" : " da39a3ee5e6b4b0d3255bfef95601890afd80709"
65+ },
66+ "sourceInfo" : " acquired package info from APK DB: /lib/apk/db/installed" ,
67+ "supplier" : " Person: Natanael Copa (ncopa@alpinelinux.org)" ,
68+ "versionInfo" : " 3.2.0-r18"
69+ }
70+ ]
71+ }
72+ }
0 commit comments