{
  "SPDXID": "SPDXRef-DOCUMENT",
  "name": "pesign-obs-integration-0.10.1-4.oe2403.aarch64.rpm",
  "spdxVersion": "SPDX-2.2",
  "creationInfo": {
    "created": "2026-05-15T06:57:53.750891916Z",
    "creators": [
      "openeuler_creator"
    ]
  },
  "dataLicense": "CC0-1.0",
  "documentNamespace": "https://sbom.openEuler.org/pesign-obs-integration-0.10.1-4.oe2403.aarch64.rpm",
  "packages": [
    {
      "SPDXID": "SPDXRef-rpm-bash-5.2.15",
      "name": "bash",
      "checksums": [
        {
          "algorithm": "SHA256",
          "checksumValue": "7efac69f54416b21bdc1d052bee86bc9193d2889fb299a5c97224fe4ba7ccf7a"
        }
      ],
      "description": "Bash is the GNU Project's shell. Bash is the Bourne Again SHell. Bash is an sh-compatible\nshell that incorporates useful features from the Korn shell (ksh) and C shell (csh). It is\nintended to conform to the IEEE POSIX P1003.2/ISO 9945.2 Shell and Tools standard. It offers\nfunctional improvements over sh for both programming and interactive use. In addition, most\nsh scripts can be run by Bash without modification.",
      "downloadLocation": "NOASSERTION",
      "externalRefs": [
        {
          "referenceCategory": "PACKAGE_MANAGER",
          "referenceLocator": "pkg:rpm/bash@5.2.15-9.oe2403?arch=x86_64&epoch=0&upstream=bash-5.2.15-9.oe2403.src.rpm",
          "referenceType": "purl"
        }
      ],
      "filesAnalyzed": false,
      "homepage": "https://www.gnu.org/software/bash",
      "sourceInfo": "acquired package info from repodata DB: repodata/87ee4e92c1e5173adb9dd158ec9c2e7bd500bbe68c80fdd1cfc6721bbb15534f-primary.sqlite.bz2",
      "summary": "It is the Bourne Again Shell",
      "supplier": "Organization: http://openeuler.org",
      "versionInfo": "0:5.2.15-9.oe2403"
    },
    {
      "SPDXID": "SPDXRef-rpm-fipscheck-1.5.0",
      "name": "fipscheck",
      "checksums": [
        {
          "algorithm": "SHA256",
          "checksumValue": "30b3460eeae52a15ab0e95f89c1c2debe5dcd9b77694436b843453e55fe7f23e"
        }
      ],
      "description": "This package contains library (libfipscheck) and helper binaries which\nimplement the integrity check of libraries and binaries as required by\nFIPS-140-2 validated modules.",
      "downloadLocation": "NOASSERTION",
      "externalRefs": [
        {
          "referenceCategory": "PACKAGE_MANAGER",
          "referenceLocator": "pkg:rpm/fipscheck@1.5.0-10.oe2403?arch=x86_64&epoch=0&upstream=fipscheck-1.5.0-10.oe2403.src.rpm",
          "referenceType": "purl"
        }
      ],
      "filesAnalyzed": false,
      "homepage": "https://pagure.io/fipscheck",
      "sourceInfo": "acquired package info from repodata DB: repodata/87ee4e92c1e5173adb9dd158ec9c2e7bd500bbe68c80fdd1cfc6721bbb15534f-primary.sqlite.bz2",
      "summary": "Helper library for FIPS integrity checking",
      "supplier": "Organization: http://openeuler.org",
      "versionInfo": "0:1.5.0-10.oe2403"
    },
    {
      "SPDXID": "SPDXRef-rpm-nss-util-3.94.0",
      "name": "nss-util",
      "checksums": [
        {
          "algorithm": "SHA256",
          "checksumValue": "2d04dbeb786a20154605cae564da02c816ee8471f31a9511b61bdde00895b96f"
        }
      ],
      "description": "Utilities for Network Security Services and the Softoken module\nmanipulate the NSS certificate and key database.",
      "downloadLocation": "NOASSERTION",
      "externalRefs": [
        {
          "referenceCategory": "PACKAGE_MANAGER",
          "referenceLocator": "pkg:rpm/nss-util@3.94.0-6.oe2403?arch=x86_64&epoch=0&upstream=nss-3.94.0-6.oe2403.src.rpm",
          "referenceType": "purl"
        }
      ],
      "filesAnalyzed": false,
      "homepage": "http://www.mozilla.org/projects/security/pki/nss/",
      "sourceInfo": "acquired package info from repodata DB: repodata/87ee4e92c1e5173adb9dd158ec9c2e7bd500bbe68c80fdd1cfc6721bbb15534f-primary.sqlite.bz2",
      "summary": "Network Security Services Utilities Library",
      "supplier": "Organization: http://openeuler.org",
      "versionInfo": "0:3.94.0-6.oe2403"
    },
    {
      "SPDXID": "SPDXRef-rpm-openssl-3.0.12",
      "name": "openssl",
      "checksums": [
        {
          "algorithm": "SHA256",
          "checksumValue": "e5e38f163b0088b07e078076f6569db5aae80dc4c92b731ee5766fefd6edf3e6"
        }
      ],
      "description": "OpenSSL is a robust, commercial-grade, and full-featured toolkit for the\nTransport Layer Security (TLS) and Secure Sockets Layer (SSL) protocols.",
      "downloadLocation": "NOASSERTION",
      "externalRefs": [
        {
          "referenceCategory": "PACKAGE_MANAGER",
          "referenceLocator": "pkg:rpm/openssl@3.0.12-5.oe2403?arch=x86_64&epoch=1&upstream=openssl-3.0.12-5.oe2403.src.rpm",
          "referenceType": "purl"
        }
      ],
      "filesAnalyzed": false,
      "homepage": "https://www.openssl.org/",
      "sourceInfo": "acquired package info from repodata DB: repodata/87ee4e92c1e5173adb9dd158ec9c2e7bd500bbe68c80fdd1cfc6721bbb15534f-primary.sqlite.bz2",
      "summary": "Cryptography and SSL/TLS Toolkit",
      "supplier": "Organization: http://openeuler.org",
      "versionInfo": "1:3.0.12-5.oe2403"
    },
    {
      "SPDXID": "SPDXRef-rpm-pesign-116",
      "name": "pesign",
      "checksums": [
        {
          "algorithm": "SHA256",
          "checksumValue": "88bc9eb25d73e6361cf3f9e45d8d108f8c48caabc6e084f2cd8db6ce5d13de2c"
        }
      ],
      "description": "pesign is a command line tool for manipulating signatures and\ncryptographic digests of UEFI applications.",
      "downloadLocation": "NOASSERTION",
      "externalRefs": [
        {
          "referenceCategory": "PACKAGE_MANAGER",
          "referenceLocator": "pkg:rpm/pesign@116-4.oe2403?arch=x86_64&epoch=0&upstream=pesign-116-4.oe2403.src.rpm",
          "referenceType": "purl"
        }
      ],
      "filesAnalyzed": false,
      "homepage": "https://github.com/rhboot/pesign",
      "sourceInfo": "acquired package info from repodata DB: repodata/87ee4e92c1e5173adb9dd158ec9c2e7bd500bbe68c80fdd1cfc6721bbb15534f-primary.sqlite.bz2",
      "summary": "Signing utility for UEFI binaries",
      "supplier": "Organization: http://openeuler.org",
      "versionInfo": "0:116-4.oe2403"
    }
  ],
  "relationships": [
    {
      "spdxElementId": "SPDXRef-rpm-pesign-obs-integration-10.1",
      "relationshipType": "DEPENDS_ON",
      "relatedSpdxElement": "SPDXRef-rpm-bash-5.2.15"
    },
    {
      "spdxElementId": "SPDXRef-rpm-pesign-obs-integration-10.1",
      "relationshipType": "DEPENDS_ON",
      "relatedSpdxElement": "SPDXRef-rpm-fipscheck-1.5.0"
    },
    {
      "spdxElementId": "SPDXRef-rpm-pesign-obs-integration-10.1",
      "relationshipType": "DEPENDS_ON",
      "relatedSpdxElement": "SPDXRef-rpm-nss-util-3.94.0"
    },
    {
      "spdxElementId": "SPDXRef-rpm-pesign-obs-integration-10.1",
      "relationshipType": "DEPENDS_ON",
      "relatedSpdxElement": "SPDXRef-rpm-openssl-3.0.12"
    },
    {
      "spdxElementId": "SPDXRef-rpm-pesign-obs-integration-10.1",
      "relationshipType": "DEPENDS_ON",
      "relatedSpdxElement": "SPDXRef-rpm-pesign-116"
    }
  ]
}
