{
  "SPDXID": "SPDXRef-DOCUMENT",
  "name": "pesign-obs-integration-0.10.1-4.oe2403sp1.aarch64.rpm",
  "spdxVersion": "SPDX-2.2",
  "creationInfo": {
    "created": "2026-05-15T04:42:06.064967212Z",
    "creators": [
      "openeuler_creator"
    ]
  },
  "dataLicense": "CC0-1.0",
  "documentNamespace": "https://sbom.openEuler.org/pesign-obs-integration-0.10.1-4.oe2403sp1.aarch64.rpm",
  "packages": [
    {
      "SPDXID": "SPDXRef-rpm-bash-5.2.15",
      "name": "bash",
      "checksums": [
        {
          "algorithm": "SHA256",
          "checksumValue": "c24a8e3aeec4c86b18fcfd1304df1f70bf829f10b015fd8c6795d555989b62df"
        }
      ],
      "description": "Bash is the GNU Project's shell. Bash is the Bourne Again SHell. Bash is an sh-compatible\nshell that incorporates useful features from the Korn shell (ksh) and C shell (csh). It is\nintended to conform to the IEEE POSIX P1003.2/ISO 9945.2 Shell and Tools standard. It offers\nfunctional improvements over sh for both programming and interactive use. In addition, most\nsh scripts can be run by Bash without modification.",
      "downloadLocation": "NOASSERTION",
      "externalRefs": [
        {
          "referenceCategory": "PACKAGE_MANAGER",
          "referenceLocator": "pkg:rpm/bash@5.2.15-14.oe2403sp1?arch=aarch64&epoch=0&upstream=bash-5.2.15-14.oe2403sp1.src.rpm",
          "referenceType": "purl"
        }
      ],
      "filesAnalyzed": false,
      "homepage": "https://www.gnu.org/software/bash",
      "sourceInfo": "acquired package info from repodata DB: repodata/825c667db78f5378f5d2c3fed8eed9e4d49e0adefc70841b9e2e06a15d74948a-primary.sqlite.bz2",
      "summary": "It is the Bourne Again Shell",
      "supplier": "Organization: http://openeuler.org",
      "versionInfo": "0:5.2.15-14.oe2403sp1"
    },
    {
      "SPDXID": "SPDXRef-rpm-fipscheck-1.5.0",
      "name": "fipscheck",
      "checksums": [
        {
          "algorithm": "SHA256",
          "checksumValue": "7997f22c03a5c005fecaa38a45152c0efe4e8bc6d9be599bcb2ac29ab8a3b9d4"
        }
      ],
      "description": "This package contains library (libfipscheck) and helper binaries which\nimplement the integrity check of libraries and binaries as required by\nFIPS-140-2 validated modules.",
      "downloadLocation": "NOASSERTION",
      "externalRefs": [
        {
          "referenceCategory": "PACKAGE_MANAGER",
          "referenceLocator": "pkg:rpm/fipscheck@1.5.0-10.oe2403sp1?arch=aarch64&epoch=0&upstream=fipscheck-1.5.0-10.oe2403sp1.src.rpm",
          "referenceType": "purl"
        }
      ],
      "filesAnalyzed": false,
      "homepage": "https://pagure.io/fipscheck",
      "sourceInfo": "acquired package info from repodata DB: repodata/825c667db78f5378f5d2c3fed8eed9e4d49e0adefc70841b9e2e06a15d74948a-primary.sqlite.bz2",
      "summary": "Helper library for FIPS integrity checking",
      "supplier": "Organization: http://openeuler.org",
      "versionInfo": "0:1.5.0-10.oe2403sp1"
    },
    {
      "SPDXID": "SPDXRef-rpm-nss-util-3.94.0",
      "name": "nss-util",
      "checksums": [
        {
          "algorithm": "SHA256",
          "checksumValue": "3f8ffb583244094a6ff89fbd69fa13d7ba4c3648058183667a8cee122eae04c6"
        }
      ],
      "description": "Utilities for Network Security Services and the Softoken module\nmanipulate the NSS certificate and key database.",
      "downloadLocation": "NOASSERTION",
      "externalRefs": [
        {
          "referenceCategory": "PACKAGE_MANAGER",
          "referenceLocator": "pkg:rpm/nss-util@3.94.0-7.oe2403sp1?arch=aarch64&epoch=0&upstream=nss-3.94.0-7.oe2403sp1.src.rpm",
          "referenceType": "purl"
        }
      ],
      "filesAnalyzed": false,
      "homepage": "http://www.mozilla.org/projects/security/pki/nss/",
      "sourceInfo": "acquired package info from repodata DB: repodata/825c667db78f5378f5d2c3fed8eed9e4d49e0adefc70841b9e2e06a15d74948a-primary.sqlite.bz2",
      "summary": "Network Security Services Utilities Library",
      "supplier": "Organization: http://openeuler.org",
      "versionInfo": "0:3.94.0-7.oe2403sp1"
    },
    {
      "SPDXID": "SPDXRef-rpm-openssl-3.0.12",
      "name": "openssl",
      "checksums": [
        {
          "algorithm": "SHA256",
          "checksumValue": "126ccf4128e6a67bb86f851aba2da6d466c92375aa312cb4ec84beee28da2efb"
        }
      ],
      "description": "OpenSSL is a robust, commercial-grade, and full-featured toolkit for the\nTransport Layer Security (TLS) and Secure Sockets Layer (SSL) protocols.",
      "downloadLocation": "NOASSERTION",
      "externalRefs": [
        {
          "referenceCategory": "PACKAGE_MANAGER",
          "referenceLocator": "pkg:rpm/openssl@3.0.12-15.oe2403sp1?arch=aarch64&epoch=1&upstream=openssl-3.0.12-15.oe2403sp1.src.rpm",
          "referenceType": "purl"
        }
      ],
      "filesAnalyzed": false,
      "homepage": "https://www.openssl.org/",
      "sourceInfo": "acquired package info from repodata DB: repodata/825c667db78f5378f5d2c3fed8eed9e4d49e0adefc70841b9e2e06a15d74948a-primary.sqlite.bz2",
      "summary": "Cryptography and SSL/TLS Toolkit",
      "supplier": "Organization: http://openeuler.org",
      "versionInfo": "1:3.0.12-15.oe2403sp1"
    },
    {
      "SPDXID": "SPDXRef-rpm-pesign-116",
      "name": "pesign",
      "checksums": [
        {
          "algorithm": "SHA256",
          "checksumValue": "b980c13ba5d7d2204bfd07e42efcc4db5fb6fa14c40d611b8cfa1c160af45f91"
        }
      ],
      "description": "pesign is a command line tool for manipulating signatures and\ncryptographic digests of UEFI applications.",
      "downloadLocation": "NOASSERTION",
      "externalRefs": [
        {
          "referenceCategory": "PACKAGE_MANAGER",
          "referenceLocator": "pkg:rpm/pesign@116-5.oe2403sp1?arch=aarch64&epoch=0&upstream=pesign-116-5.oe2403sp1.src.rpm",
          "referenceType": "purl"
        }
      ],
      "filesAnalyzed": false,
      "homepage": "https://github.com/rhboot/pesign",
      "sourceInfo": "acquired package info from repodata DB: repodata/825c667db78f5378f5d2c3fed8eed9e4d49e0adefc70841b9e2e06a15d74948a-primary.sqlite.bz2",
      "summary": "Signing utility for UEFI binaries",
      "supplier": "Organization: http://openeuler.org",
      "versionInfo": "0:116-5.oe2403sp1"
    }
  ],
  "relationships": [
    {
      "spdxElementId": "SPDXRef-rpm-pesign-obs-integration-10.1",
      "relationshipType": "DEPENDS_ON",
      "relatedSpdxElement": "SPDXRef-rpm-bash-5.2.15"
    },
    {
      "spdxElementId": "SPDXRef-rpm-pesign-obs-integration-10.1",
      "relationshipType": "DEPENDS_ON",
      "relatedSpdxElement": "SPDXRef-rpm-fipscheck-1.5.0"
    },
    {
      "spdxElementId": "SPDXRef-rpm-pesign-obs-integration-10.1",
      "relationshipType": "DEPENDS_ON",
      "relatedSpdxElement": "SPDXRef-rpm-nss-util-3.94.0"
    },
    {
      "spdxElementId": "SPDXRef-rpm-pesign-obs-integration-10.1",
      "relationshipType": "DEPENDS_ON",
      "relatedSpdxElement": "SPDXRef-rpm-openssl-3.0.12"
    },
    {
      "spdxElementId": "SPDXRef-rpm-pesign-obs-integration-10.1",
      "relationshipType": "DEPENDS_ON",
      "relatedSpdxElement": "SPDXRef-rpm-pesign-116"
    }
  ]
}
