R-TF-024-001 Software Bills Of Materials
{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:xxx",
  "version": 1,
  "metadata": {
    "timestamp": "2025-07-15T07:58:27+00:00",
    "tools": {
      "components": [
        {
          "type": "application",
          "group": "aquasecurity",
          "name": "trivy",
          "version": "0.63.0"
        }
      ]
    },
    "component": {
      "bom-ref": "9a05817c-a590-43a4-a65c-adf6f0d70aba",
      "type": "container",
      "name": "medical-device/foo",
      "properties": [
        {
          "name": "aquasecurity:trivy:DiffID",
          "value": "sha256:0268687ab64e17e1b0869479b2231d359f53355e38271550d05a61d22fd48d89"
        }
      ]
    }
  },
  "components": [
    {
      "bom-ref": "79ddf090-2974-48af-9f93-ad4be19e60ab",
      "type": "operating-system",
      "name": "debian",
      "version": "12.11",
      "properties": [
        {
          "name": "aquasecurity:trivy:Class",
          "value": "os-pkgs"
        },
        {
          "name": "aquasecurity:trivy:Type",
          "value": "debian"
        }
      ]
    },
    {
      "bom-ref": "pkg:deb/debian/adduser@3.134?arch=all&distro=debian-12.11",
      "type": "library",
      "supplier": {
        "name": "Debian Adduser Developers <adduser@packages.debian.org>"
      },
      "name": "adduser",
      "version": "3.134",
      "licenses": [
        {
          "license": {
            "name": "GPL-2.0-or-later"
          }
        },
        {
          "license": {
            "name": "GPL-2.0-only"
          }
        }
      ],
      "purl": "pkg:deb/debian/adduser@3.134?arch=all&distro=debian-12.11",
      "properties": [
        {
          "name": "aquasecurity:trivy:LayerDiffID",
          "value": "sha256:385eb556134e17ef23cfd59b33526dddab1776f743b3713ff9a08a484ece4aaa"
        },
        {
          "name": "aquasecurity:trivy:PkgID",
          "value": "adduser@3.134"
        },
        {
          "name": "aquasecurity:trivy:PkgType",
          "value": "debian"
        },
        {
          "name": "aquasecurity:trivy:SrcName",
          "value": "adduser"
        },
        {
          "name": "aquasecurity:trivy:SrcVersion",
          "value": "3.134"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "79ddf090-2974-48af-9f93-ad4be19e60ab",
      "dependsOn": [
        "pkg:deb/debian/alsa-topology-conf@1.2.5.1-2?arch=all&distro=debian-12.11",
        "pkg:deb/debian/alsa-ucm-conf@1.2.8-1?arch=all&distro=debian-12.11",
        "pkg:deb/debian/apt@2.6.1?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/automake@1.16.5-1.3?arch=all&distro=debian-12.11&epoch=1",
        "pkg:deb/debian/base-passwd@3.6.1?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/bash@5.2.15-2%2Bb8?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/bsdutils@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.11&epoch=1",
        "pkg:deb/debian/ca-certificates@20230311%2Bdeb12u1?arch=all&distro=debian-12.11",
        "pkg:deb/debian/coreutils@9.1-1?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/curl@7.88.1-10%2Bdeb12u12?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/dash@0.5.12-2?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/dbus@1.14.10-1~deb12u1?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/default-libmysqlclient-dev@1.1.0?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/diffutils@3.8-4?arch=amd64&distro=debian-12.11&epoch=1",
        "pkg:deb/debian/e2fsprogs@1.47.0-2?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/ffmpeg@5.1.6-0%2Bdeb12u1?arch=amd64&distro=debian-12.11&epoch=7",
        "pkg:deb/debian/findutils@4.9.0-4?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/g%2B%2B@12.2.0-3?arch=amd64&distro=debian-12.11&epoch=4",
        "pkg:deb/debian/git@2.39.5-0%2Bdeb12u2?arch=amd64&distro=debian-12.11&epoch=1",
        "pkg:deb/debian/gnupg@2.2.40-1.1?arch=all&distro=debian-12.11",
        "pkg:deb/debian/grep@3.8-5?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/gzip@1.12-1?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/hostname@3.23%2Bnmu1?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/imagemagick@6.9.11.60%2Bdfsg-1.6%2Bdeb12u3?arch=amd64&distro=debian-12.11&epoch=8",
        "pkg:deb/debian/libaacs0@0.11.1-2?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/libacl1@2.3.1-3?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/libattr1@2.5.1-4?arch=amd64&distro=debian-12.11&epoch=1",
        "pkg:deb/debian/libbdplus0@0.2.0-3?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/libbluetooth-dev@5.66-1%2Bdeb12u2?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u10?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/libcurl4-openssl-dev@7.88.1-10%2Bdeb12u12?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/libdb-dev@5.3.2?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/libdecor-0-plugin-1-cairo@0.1.1-2?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/libevent-dev@2.1.12-stable-8?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/libext2fs2@1.47.0-2?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/libgdbm-dev@1.23-3?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/libgmp-dev@6.2.1%2Bdfsg1-1.1?arch=amd64&distro=debian-12.11&epoch=2",
        "pkg:deb/debian/libkrb5-dev@1.20.1-2%2Bdeb12u3?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/libmagickcore-dev@6.9.11.60%2Bdfsg-1.6%2Bdeb12u3?arch=all&distro=debian-12.11&epoch=8",
        "pkg:deb/debian/libmagickwand-dev@6.9.11.60%2Bdfsg-1.6%2Bdeb12u3?arch=all&distro=debian-12.11&epoch=8",
        "pkg:deb/debian/libmaxminddb-dev@1.7.1-1?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/libncurses5-dev@6.4-4?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/libncursesw5-dev@6.4-4?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/libpam-modules-bin@1.5.2-6%2Bdeb12u1?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/libpam-runtime@1.5.2-6%2Bdeb12u1?arch=all&distro=debian-12.11",
        "pkg:deb/debian/libpq-dev@15.13-0%2Bdeb12u1?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/libreadline-dev@8.2-1.3?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/libsqlite3-dev@3.40.1-2%2Bdeb12u1?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/libss2@1.47.0-2?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/libtool@2.4.7-7~deb12u1?arch=all&distro=debian-12.11",
        "pkg:deb/debian/libxslt1-dev@1.1.35-1%2Bdeb12u1?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/libyaml-dev@0.2.5-1?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/login@4.13%2Bdfsg1-1%2Bdeb12u1?arch=amd64&distro=debian-12.11&epoch=1",
        "pkg:deb/debian/mawk@1.3.4.20200120-3.1?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/mercurial@6.3.2-1%2Bdeb12u1?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/mesa-vulkan-drivers@22.3.6-1%2Bdeb12u1?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/mount@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/ncurses-base@6.4-4?arch=all&distro=debian-12.11",
        "pkg:deb/debian/netbase@6.4?arch=all&distro=debian-12.11",
        "pkg:deb/debian/openssh-client@9.2p1-2%2Bdeb12u6?arch=amd64&distro=debian-12.11&epoch=1",
        "pkg:deb/debian/pocketsphinx-en-us@0.8%2B5prealpha%2B1-15?arch=all&distro=debian-12.11",
        "pkg:deb/debian/procps@4.0.2-3?arch=amd64&distro=debian-12.11&epoch=2",
        "pkg:deb/debian/python3-minimal@3.11.2-1%2Bb1?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/sed@4.9-1?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/sq@0.27.0-2%2Bb1?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/subversion@1.14.2-4%2Bdeb12u1?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/sysvinit-utils@3.06-4?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/tk-dev@8.6.13?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/unzip@6.0-28?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/util-linux@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/va-driver-all@2.17.0-1?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/vdpau-driver-all@1.5-2?arch=amd64&distro=debian-12.11",
        "pkg:deb/debian/wget@1.21.3-1%2Bdeb12u1?arch=amd64&distro=debian-12.11"
      ]
    }
  ]
}
Signature meaning
The signatures for the approval process of this document can be found in the verified commits at the repository for the QMS. As a reference, the team members who are expected to participate in this document and their roles in the approval process, as defined in Annex I Responsibility Matrix of the GP-001, are:
- Author: Team members involved
 - Reviewer: JD-003, JD-004
 - Approver: JD-001