{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:24542296-f23a-5439-ae6b-975f5ae31066",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "ms",
      "purl": "pkg:npm/ms@1.0.0-tuxcare.1",
      "type": "library",
      "bom-ref": "pkg:npm/ms@1.0.0-tuxcare.1",
      "version": "1.0.0-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-2515",
      "affects": [
        {
          "ref": "pkg:npm/ms@1.0.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e3a5ea9e-1039-5392-a363-99f5fc27d3c0",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2016-2515 is a false positive for ms 1.0.0-tuxcare.1. false_positive \u2014 CVE-2016-2515 concerns the 'hawk' HTTP authentication library, but the target repository is the 'ms' time conversion utility - a completely different project. No relationship exists between the two packages."
      }
    },
    {
      "id": "CVE-2017-20162",
      "affects": [
        {
          "ref": "pkg:npm/ms@1.0.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e61a84d4-8b0e-58a4-a0df-f22dd9e580a2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-20162 is fixed in version 1.0.0-tuxcare.1 of ms."
      }
    },
    {
      "id": "CVE-2018-3739",
      "affects": [
        {
          "ref": "pkg:npm/ms@1.0.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d57ed70e-f01b-5bad-a5fa-68e1410242e2",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2018-3739 is a false positive for ms 1.0.0-tuxcare.1. false_positive \u2014 CVE-2018-3739 is a wrong-project match. The advisory affects https-proxy-agent, but this repository is the ms package (a time conversion utility). The affected component's code is entirely absent from this repository."
      }
    },
    {
      "id": "CVE-2021-33623",
      "affects": [
        {
          "ref": "pkg:npm/ms@1.0.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0b6bc3ce-ef19-50df-9f92-ad616c786745",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-33623 is a false positive for ms 1.0.0-tuxcare.1. false_positive \u2014 CVE-2021-33623 concerns the 'trim-newlines' npm package (ReDoS vulnerability in .end() method), but this repository is the 'ms' package (millisecond conversion utility). This is a wrong-project match - the two packages are completely unrelated with no dependency relationship."
      }
    },
    {
      "id": "CVE-2022-29167",
      "affects": [
        {
          "ref": "pkg:npm/ms@1.0.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:bf6dc42e-9063-568e-a5e3-43f3652f4145",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-29167 is a false positive for ms 1.0.0-tuxcare.1. false_positive \u2014 CVE-2022-29167 concerns the Hawk HTTP authentication library's Host header parsing (Hawk.utils.parseHost() ReDoS vulnerability). The target repository is the 'ms' (milliseconds) library - a time-string conversion utility unrelated to HTTP authentication or Host header parsing. This is a wrong-project match."
      }
    },
    {
      "id": "CVE-2024-47178",
      "affects": [
        {
          "ref": "pkg:npm/ms@1.0.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:51abfd25-74f0-5738-9560-350747783de1",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-47178 is a false positive for ms 1.0.0-tuxcare.1. false_positive \u2014 CVE-2024-47178 concerns 'basic-auth-connect' (an HTTP basic authentication middleware), but this repository is 'ms' (a time conversion utility). Wrong-project match - the affected component is completely absent from this repository."
      }
    },
    {
      "id": "GHSA-pc5p-h8pf-mvwp",
      "affects": [
        {
          "ref": "pkg:npm/ms@1.0.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:31936b99-21c6-5cb5-bc44-c1f276801c36",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-pc5p-h8pf-mvwp is a false positive for ms 1.0.0-tuxcare.1. false_positive \u2014 GHSA-pc5p-h8pf-mvwp concerns https-proxy-agent, a TLS proxy agent package. The target repository is 'ms', a time conversion utility with no networking or proxy functionality. This is a wrong-project match."
      }
    },
    {
      "id": "GHSA-qrg3-f6h6-vq8q",
      "affects": [
        {
          "ref": "pkg:npm/ms@1.0.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f3d1793b-17fc-5e99-b48f-00feca722194",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-qrg3-f6h6-vq8q is a false positive for ms 1.0.0-tuxcare.1."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/ms@1.0.0-tuxcare.1"
    }
  ]
}