{
  "SPDXID": "SPDXRef-DOCUMENT",
  "name": "pesign-obs-integration-0.10.1-4.oe2403.aarch64.rpm",
  "spdxVersion": "SPDX-2.2",
  "creationInfo": {
    "created": "2026-05-14T14:17:38.370562542Z",
    "creators": [
      "openeuler_creator"
    ]
  },
  "dataLicense": "CC0-1.0",
  "documentNamespace": "https://sbom.openEuler.org/pesign-obs-integration-0.10.1-4.oe2403.aarch64.rpm",
  "packages": [
    {
      "SPDXID": "SPDXRef-rpm-bash-5.2.15",
      "name": "bash",
      "checksums": [
        {
          "algorithm": "SHA256",
          "checksumValue": "18fccc93a7eecf2ddd9037a688248dbee9d0d80f9ea5b6bebad8908f1643735b"
        }
      ],
      "description": "Bash is the GNU Project's shell. Bash is the Bourne Again SHell. Bash is an sh-compatible\nshell that incorporates useful features from the Korn shell (ksh) and C shell (csh). It is\nintended to conform to the IEEE POSIX P1003.2/ISO 9945.2 Shell and Tools standard. It offers\nfunctional improvements over sh for both programming and interactive use. In addition, most\nsh scripts can be run by Bash without modification.",
      "downloadLocation": "NOASSERTION",
      "externalRefs": [
        {
          "referenceCategory": "PACKAGE_MANAGER",
          "referenceLocator": "pkg:rpm/bash@5.2.15-9.oe2403?arch=aarch64&epoch=0&upstream=bash-5.2.15-9.oe2403.src.rpm",
          "referenceType": "purl"
        }
      ],
      "filesAnalyzed": false,
      "homepage": "https://www.gnu.org/software/bash",
      "sourceInfo": "acquired package info from repodata DB: repodata/6a4762c6f9f76cc1a4c44e432c97d08c2803b6e0e96a0a4bdf1aec71664120f2-primary.sqlite.bz2",
      "summary": "It is the Bourne Again Shell",
      "supplier": "Organization: http://openeuler.org",
      "versionInfo": "0:5.2.15-9.oe2403"
    },
    {
      "SPDXID": "SPDXRef-rpm-fipscheck-1.5.0",
      "name": "fipscheck",
      "checksums": [
        {
          "algorithm": "SHA256",
          "checksumValue": "22e2b8b1442e662a431d24c8302b00ef849841c188386720723f3e051a1942a8"
        }
      ],
      "description": "This package contains library (libfipscheck) and helper binaries which\nimplement the integrity check of libraries and binaries as required by\nFIPS-140-2 validated modules.",
      "downloadLocation": "NOASSERTION",
      "externalRefs": [
        {
          "referenceCategory": "PACKAGE_MANAGER",
          "referenceLocator": "pkg:rpm/fipscheck@1.5.0-10.oe2403?arch=aarch64&epoch=0&upstream=fipscheck-1.5.0-10.oe2403.src.rpm",
          "referenceType": "purl"
        }
      ],
      "filesAnalyzed": false,
      "homepage": "https://pagure.io/fipscheck",
      "sourceInfo": "acquired package info from repodata DB: repodata/6a4762c6f9f76cc1a4c44e432c97d08c2803b6e0e96a0a4bdf1aec71664120f2-primary.sqlite.bz2",
      "summary": "Helper library for FIPS integrity checking",
      "supplier": "Organization: http://openeuler.org",
      "versionInfo": "0:1.5.0-10.oe2403"
    },
    {
      "SPDXID": "SPDXRef-rpm-nss-util-3.94.0",
      "name": "nss-util",
      "checksums": [
        {
          "algorithm": "SHA256",
          "checksumValue": "0ef31824256272b81b52be733a1a37cdc5177d6a1def598da3df2a32457a539b"
        }
      ],
      "description": "Utilities for Network Security Services and the Softoken module\nmanipulate the NSS certificate and key database.",
      "downloadLocation": "NOASSERTION",
      "externalRefs": [
        {
          "referenceCategory": "PACKAGE_MANAGER",
          "referenceLocator": "pkg:rpm/nss-util@3.94.0-6.oe2403?arch=aarch64&epoch=0&upstream=nss-3.94.0-6.oe2403.src.rpm",
          "referenceType": "purl"
        }
      ],
      "filesAnalyzed": false,
      "homepage": "http://www.mozilla.org/projects/security/pki/nss/",
      "sourceInfo": "acquired package info from repodata DB: repodata/6a4762c6f9f76cc1a4c44e432c97d08c2803b6e0e96a0a4bdf1aec71664120f2-primary.sqlite.bz2",
      "summary": "Network Security Services Utilities Library",
      "supplier": "Organization: http://openeuler.org",
      "versionInfo": "0:3.94.0-6.oe2403"
    },
    {
      "SPDXID": "SPDXRef-rpm-openssl-3.0.12",
      "name": "openssl",
      "checksums": [
        {
          "algorithm": "SHA256",
          "checksumValue": "c5c0ea1b849a3ec2b462b1bfdd4db52fc8d95ef9c9f9cb3ddb4719ef85c9f60f"
        }
      ],
      "description": "OpenSSL is a robust, commercial-grade, and full-featured toolkit for the\nTransport Layer Security (TLS) and Secure Sockets Layer (SSL) protocols.",
      "downloadLocation": "NOASSERTION",
      "externalRefs": [
        {
          "referenceCategory": "PACKAGE_MANAGER",
          "referenceLocator": "pkg:rpm/openssl@3.0.12-5.oe2403?arch=aarch64&epoch=1&upstream=openssl-3.0.12-5.oe2403.src.rpm",
          "referenceType": "purl"
        }
      ],
      "filesAnalyzed": false,
      "homepage": "https://www.openssl.org/",
      "sourceInfo": "acquired package info from repodata DB: repodata/6a4762c6f9f76cc1a4c44e432c97d08c2803b6e0e96a0a4bdf1aec71664120f2-primary.sqlite.bz2",
      "summary": "Cryptography and SSL/TLS Toolkit",
      "supplier": "Organization: http://openeuler.org",
      "versionInfo": "1:3.0.12-5.oe2403"
    },
    {
      "SPDXID": "SPDXRef-rpm-pesign-116",
      "name": "pesign",
      "checksums": [
        {
          "algorithm": "SHA256",
          "checksumValue": "257ca426a4b5616fdfd78180c2835575030d03d1f247baedd91665777a3f5e9e"
        }
      ],
      "description": "pesign is a command line tool for manipulating signatures and\ncryptographic digests of UEFI applications.",
      "downloadLocation": "NOASSERTION",
      "externalRefs": [
        {
          "referenceCategory": "PACKAGE_MANAGER",
          "referenceLocator": "pkg:rpm/pesign@116-4.oe2403?arch=aarch64&epoch=0&upstream=pesign-116-4.oe2403.src.rpm",
          "referenceType": "purl"
        }
      ],
      "filesAnalyzed": false,
      "homepage": "https://github.com/rhboot/pesign",
      "sourceInfo": "acquired package info from repodata DB: repodata/6a4762c6f9f76cc1a4c44e432c97d08c2803b6e0e96a0a4bdf1aec71664120f2-primary.sqlite.bz2",
      "summary": "Signing utility for UEFI binaries",
      "supplier": "Organization: http://openeuler.org",
      "versionInfo": "0:116-4.oe2403"
    }
  ],
  "relationships": [
    {
      "spdxElementId": "SPDXRef-rpm-pesign-obs-integration-10.1",
      "relationshipType": "DEPENDS_ON",
      "relatedSpdxElement": "SPDXRef-rpm-bash-5.2.15"
    },
    {
      "spdxElementId": "SPDXRef-rpm-pesign-obs-integration-10.1",
      "relationshipType": "DEPENDS_ON",
      "relatedSpdxElement": "SPDXRef-rpm-fipscheck-1.5.0"
    },
    {
      "spdxElementId": "SPDXRef-rpm-pesign-obs-integration-10.1",
      "relationshipType": "DEPENDS_ON",
      "relatedSpdxElement": "SPDXRef-rpm-nss-util-3.94.0"
    },
    {
      "spdxElementId": "SPDXRef-rpm-pesign-obs-integration-10.1",
      "relationshipType": "DEPENDS_ON",
      "relatedSpdxElement": "SPDXRef-rpm-openssl-3.0.12"
    },
    {
      "spdxElementId": "SPDXRef-rpm-pesign-obs-integration-10.1",
      "relationshipType": "DEPENDS_ON",
      "relatedSpdxElement": "SPDXRef-rpm-pesign-116"
    }
  ]
}
