{
  "SPDXID": "SPDXRef-DOCUMENT",
  "name": "pesign-obs-integration-0.10.1-4.oe2403sp1.aarch64.rpm",
  "spdxVersion": "SPDX-2.2",
  "creationInfo": {
    "created": "2026-05-15T03:52:34.12042879Z",
    "creators": [
      "openeuler_creator"
    ]
  },
  "dataLicense": "CC0-1.0",
  "documentNamespace": "https://sbom.openEuler.org/pesign-obs-integration-0.10.1-4.oe2403sp1.aarch64.rpm",
  "packages": [
    {
      "SPDXID": "SPDXRef-rpm-bash-5.2.15",
      "name": "bash",
      "checksums": [
        {
          "algorithm": "SHA256",
          "checksumValue": "6ee9aba5fbfed0d3a3515e72aca08564d0284127f16642166cee3b6b1dba1790"
        }
      ],
      "description": "Bash is the GNU Project's shell. Bash is the Bourne Again SHell. Bash is an sh-compatible\nshell that incorporates useful features from the Korn shell (ksh) and C shell (csh). It is\nintended to conform to the IEEE POSIX P1003.2/ISO 9945.2 Shell and Tools standard. It offers\nfunctional improvements over sh for both programming and interactive use. In addition, most\nsh scripts can be run by Bash without modification.",
      "downloadLocation": "NOASSERTION",
      "externalRefs": [
        {
          "referenceCategory": "PACKAGE_MANAGER",
          "referenceLocator": "pkg:rpm/bash@5.2.15-14.oe2403sp1?arch=x86_64&epoch=0&upstream=bash-5.2.15-14.oe2403sp1.src.rpm",
          "referenceType": "purl"
        }
      ],
      "filesAnalyzed": false,
      "homepage": "https://www.gnu.org/software/bash",
      "sourceInfo": "acquired package info from repodata DB: repodata/d7de307a9e6063fb4be58eea55b491d96524f1609636dd9a9c19f058ffcd9181-primary.sqlite.bz2",
      "summary": "It is the Bourne Again Shell",
      "supplier": "Organization: http://openeuler.org",
      "versionInfo": "0:5.2.15-14.oe2403sp1"
    },
    {
      "SPDXID": "SPDXRef-rpm-fipscheck-1.5.0",
      "name": "fipscheck",
      "checksums": [
        {
          "algorithm": "SHA256",
          "checksumValue": "ceb57e53b9914b9d92dbe7d1f56e8f4786ed2cbd268d658c8bfdadc1a57f3c29"
        }
      ],
      "description": "This package contains library (libfipscheck) and helper binaries which\nimplement the integrity check of libraries and binaries as required by\nFIPS-140-2 validated modules.",
      "downloadLocation": "NOASSERTION",
      "externalRefs": [
        {
          "referenceCategory": "PACKAGE_MANAGER",
          "referenceLocator": "pkg:rpm/fipscheck@1.5.0-10.oe2403sp1?arch=x86_64&epoch=0&upstream=fipscheck-1.5.0-10.oe2403sp1.src.rpm",
          "referenceType": "purl"
        }
      ],
      "filesAnalyzed": false,
      "homepage": "https://pagure.io/fipscheck",
      "sourceInfo": "acquired package info from repodata DB: repodata/d7de307a9e6063fb4be58eea55b491d96524f1609636dd9a9c19f058ffcd9181-primary.sqlite.bz2",
      "summary": "Helper library for FIPS integrity checking",
      "supplier": "Organization: http://openeuler.org",
      "versionInfo": "0:1.5.0-10.oe2403sp1"
    },
    {
      "SPDXID": "SPDXRef-rpm-nss-util-3.94.0",
      "name": "nss-util",
      "checksums": [
        {
          "algorithm": "SHA256",
          "checksumValue": "26cf3a2df3e02f8e6c0d0e2e78c1f011eab41dc35c25d3388c8118031d435bab"
        }
      ],
      "description": "Utilities for Network Security Services and the Softoken module\nmanipulate the NSS certificate and key database.",
      "downloadLocation": "NOASSERTION",
      "externalRefs": [
        {
          "referenceCategory": "PACKAGE_MANAGER",
          "referenceLocator": "pkg:rpm/nss-util@3.94.0-7.oe2403sp1?arch=x86_64&epoch=0&upstream=nss-3.94.0-7.oe2403sp1.src.rpm",
          "referenceType": "purl"
        }
      ],
      "filesAnalyzed": false,
      "homepage": "http://www.mozilla.org/projects/security/pki/nss/",
      "sourceInfo": "acquired package info from repodata DB: repodata/d7de307a9e6063fb4be58eea55b491d96524f1609636dd9a9c19f058ffcd9181-primary.sqlite.bz2",
      "summary": "Network Security Services Utilities Library",
      "supplier": "Organization: http://openeuler.org",
      "versionInfo": "0:3.94.0-7.oe2403sp1"
    },
    {
      "SPDXID": "SPDXRef-rpm-openssl-3.0.12",
      "name": "openssl",
      "checksums": [
        {
          "algorithm": "SHA256",
          "checksumValue": "1f8bea8deed1493a1402c8cffcdd5654df491b0be53bbff11e7f5d07aa7752f8"
        }
      ],
      "description": "OpenSSL is a robust, commercial-grade, and full-featured toolkit for the\nTransport Layer Security (TLS) and Secure Sockets Layer (SSL) protocols.",
      "downloadLocation": "NOASSERTION",
      "externalRefs": [
        {
          "referenceCategory": "PACKAGE_MANAGER",
          "referenceLocator": "pkg:rpm/openssl@3.0.12-15.oe2403sp1?arch=x86_64&epoch=1&upstream=openssl-3.0.12-15.oe2403sp1.src.rpm",
          "referenceType": "purl"
        }
      ],
      "filesAnalyzed": false,
      "homepage": "https://www.openssl.org/",
      "sourceInfo": "acquired package info from repodata DB: repodata/d7de307a9e6063fb4be58eea55b491d96524f1609636dd9a9c19f058ffcd9181-primary.sqlite.bz2",
      "summary": "Cryptography and SSL/TLS Toolkit",
      "supplier": "Organization: http://openeuler.org",
      "versionInfo": "1:3.0.12-15.oe2403sp1"
    },
    {
      "SPDXID": "SPDXRef-rpm-pesign-116",
      "name": "pesign",
      "checksums": [
        {
          "algorithm": "SHA256",
          "checksumValue": "371a600f8b428cb51b40f12380bd0cedcf41c36d9579c716b2ddb392aa552710"
        }
      ],
      "description": "pesign is a command line tool for manipulating signatures and\ncryptographic digests of UEFI applications.",
      "downloadLocation": "NOASSERTION",
      "externalRefs": [
        {
          "referenceCategory": "PACKAGE_MANAGER",
          "referenceLocator": "pkg:rpm/pesign@116-5.oe2403sp1?arch=x86_64&epoch=0&upstream=pesign-116-5.oe2403sp1.src.rpm",
          "referenceType": "purl"
        }
      ],
      "filesAnalyzed": false,
      "homepage": "https://github.com/rhboot/pesign",
      "sourceInfo": "acquired package info from repodata DB: repodata/d7de307a9e6063fb4be58eea55b491d96524f1609636dd9a9c19f058ffcd9181-primary.sqlite.bz2",
      "summary": "Signing utility for UEFI binaries",
      "supplier": "Organization: http://openeuler.org",
      "versionInfo": "0:116-5.oe2403sp1"
    }
  ],
  "relationships": [
    {
      "spdxElementId": "SPDXRef-rpm-pesign-obs-integration-10.1",
      "relationshipType": "DEPENDS_ON",
      "relatedSpdxElement": "SPDXRef-rpm-bash-5.2.15"
    },
    {
      "spdxElementId": "SPDXRef-rpm-pesign-obs-integration-10.1",
      "relationshipType": "DEPENDS_ON",
      "relatedSpdxElement": "SPDXRef-rpm-fipscheck-1.5.0"
    },
    {
      "spdxElementId": "SPDXRef-rpm-pesign-obs-integration-10.1",
      "relationshipType": "DEPENDS_ON",
      "relatedSpdxElement": "SPDXRef-rpm-nss-util-3.94.0"
    },
    {
      "spdxElementId": "SPDXRef-rpm-pesign-obs-integration-10.1",
      "relationshipType": "DEPENDS_ON",
      "relatedSpdxElement": "SPDXRef-rpm-openssl-3.0.12"
    },
    {
      "spdxElementId": "SPDXRef-rpm-pesign-obs-integration-10.1",
      "relationshipType": "DEPENDS_ON",
      "relatedSpdxElement": "SPDXRef-rpm-pesign-116"
    }
  ]
}
