{
  "bomFormat": "CycloneDX",
  "specVersion": "1.7",
  "serialNumber": "urn:uuid:29b79e72-7f4d-4986-9eec-def9213e2e9d",
  "version": 1,
  "metadata": {
    "timestamp": "2026-09-14T04:27:46Z",
    "tools": {
      "components": [
        {
          "group": "@cyclonedx",
          "name": "cdxgen",
          "version": "12.8.4",
          "purl": "pkg:npm/%40cyclonedx/cdxgen@12.8.4",
          "type": "application",
          "bom-ref": "pkg:npm/@cyclonedx/cdxgen@12.8.4",
          "publisher": "OWASP Foundation",
          "authors": [
            {
              "name": "OWASP Foundation"
            }
          ]
        }
      ]
    },
    "authors": [
      {
        "name": "OWASP Foundation"
      }
    ],
    "lifecycles": [
      {
        "phase": "pre-build"
      }
    ],
    "component": {
      "name": "core",
      "group": "@garfish",
      "version": "1.19.12",
      "description": "core module.",
      "purl": "pkg:npm/%40garfish/core@1.19.12",
      "bom-ref": "pkg:npm/@garfish/core@1.19.12",
      "author": "zhouxiao<codingzx@gmail.com>",
      "properties": [
        {
          "name": "cdx:npm:scripts",
          "value": "build, dev"
        },
        {
          "name": "cdx:npm:buildScripts",
          "value": "build"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "type": "application",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/bytedance/garfish"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/bytedance/garfish.git"
        }
      ]
    },
    "properties": [
      {
        "name": "cdx:bom:componentTypes",
        "value": "npm"
      },
      {
        "name": "cdx:bom:componentNamespaces",
        "value": "@alioth-org\\n@garfish"
      },
      {
        "name": "cdx:bom:componentSrcFiles",
        "value": "node_modules/@alioth-org/es-module-lexer/package.json\\nnode_modules/@garfish/hooks/package.json\\nnode_modules/@garfish/loader/package.json\\nnode_modules/@garfish/test-suite/package.json\\nnode_modules/@garfish/utils/package.json\\nnode_modules/eventemitter2/package.json"
      }
    ]
  },
  "components": [
    {
      "authors": [
        {
          "name": "hij1nx <paolo@async.ly> http://twitter.com/hij1nx"
        }
      ],
      "group": "",
      "name": "eventemitter2",
      "version": "6.4.9",
      "description": "A feature-rich Node.js event emitter implementation with namespaces, wildcards, TTL, async listeners and browser/worker support.",
      "scope": "required",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/eventemitter2@6.4.9",
      "type": "library",
      "bom-ref": "pkg:npm/eventemitter2@6.4.9",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/eventemitter2/package.json"
        },
        {
          "name": "ImportedModules",
          "value": "eventemitter2,EventEmitter2,eventemitter2/EventEmitter2"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/eventemitter2/package.json"
              }
            ],
            "concludedValue": "node_modules/eventemitter2/package.json"
          }
        ],
        "occurrences": [
          {
            "location": "dist/esm/index.js",
            "line": 35
          },
          {
            "location": "dist/index.js",
            "line": 61
          },
          {
            "location": "src/garfish.ts",
            "line": 2
          }
        ]
      },
      "tags": [
        "event"
      ]
    },
    {
      "authors": [
        {
          "name": "zhouxiao <codingzx@gmail.com>"
        }
      ],
      "group": "@garfish",
      "name": "utils",
      "version": "1.19.12",
      "description": "utils module.",
      "scope": "required",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/%40garfish/utils@1.19.12",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/bytedance/garfish"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/bytedance/garfish.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@garfish/utils@1.19.12",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@garfish/utils/package.json"
        },
        {
          "name": "ImportedModules",
          "value": "@garfish/utils,warn,@garfish/utils/warn,assert,@garfish/utils/assert,isPlainObject,@garfish/utils/isPlainObject,__GARFISH_FLAG__,@garfish/utils/__GARFISH_FLAG__,error,@garfish/utils/error,deepMerge,@garfish/utils/deepMerge,filterUndefinedVal,@garfish/utils/filterUndefinedVal,hasOwn,@garfish/utils/hasOwn,remove,@garfish/utils/remove,Queue,@garfish/utils/Queue,coreLog,@garfish/utils/coreLog,isJsType,@garfish/utils/isJsType,isObject,@garfish/utils/isObject,isPromise,@garfish/utils/isPromise,isGarfishConfigType,@garfish/utils/isGarfishConfigType,toBoolean,@garfish/utils/toBoolean,findTarget,@garfish/utils/findTarget,evalWithEnv,@garfish/utils/evalWithEnv,transformUrl,@garfish/utils/transformUrl,__MockBody__,@garfish/utils/__MockBody__,__MockHead__,@garfish/utils/__MockHead__,getRenderNode,@garfish/utils/getRenderNode,sourceListTags,@garfish/utils/sourceListTags,createAppContainer,@garfish/utils/createAppContainer,setDocCurrentScript,@garfish/utils/setDocCurrentScript,getSourceURL,@garfish/utils/getSourceURL,Lock,@garfish/utils/Lock,isAbsolute,@garfish/utils/isAbsolute,haveSourcemap,@garfish/utils/haveSourcemap,createSourcemap,@garfish/utils/createSourcemap,idleCallback,@garfish/utils/idleCallback,safeWrapper,@garfish/utils/safeWrapper,Node,@garfish/utils/Node,Text,@garfish/utils/Text,callTestCallback,@garfish/utils/callTestCallback"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@garfish/utils/package.json"
              }
            ],
            "concludedValue": "node_modules/@garfish/utils/package.json"
          }
        ],
        "occurrences": [
          {
            "location": "dist/esm/index.js",
            "line": 36
          },
          {
            "location": "dist/esm/index.js",
            "line": 50
          },
          {
            "location": "dist/esm/index.js",
            "line": 72
          },
          {
            "location": "dist/esm/index.js",
            "line": 126
          },
          {
            "location": "dist/esm/index.js",
            "line": 141
          },
          {
            "location": "dist/esm/index.js",
            "line": 142
          },
          {
            "location": "dist/esm/index.js",
            "line": 171
          },
          {
            "location": "dist/esm/index.js",
            "line": 208
          },
          {
            "location": "dist/esm/index.js",
            "line": 214
          },
          {
            "location": "dist/esm/index.js",
            "line": 271
          },
          {
            "location": "dist/esm/index.js",
            "line": 272
          },
          {
            "location": "dist/esm/index.js",
            "line": 281
          },
          {
            "location": "dist/esm/index.js",
            "line": 338
          },
          {
            "location": "dist/esm/index.js",
            "line": 400
          },
          {
            "location": "dist/esm/index.js",
            "line": 401
          },
          {
            "location": "dist/esm/index.js",
            "line": 402
          },
          {
            "location": "dist/esm/index.js",
            "line": 430
          },
          {
            "location": "dist/esm/index.js",
            "line": 431
          },
          {
            "location": "dist/esm/index.js",
            "line": 493
          },
          {
            "location": "dist/esm/index.js",
            "line": 512
          },
          {
            "location": "dist/esm/index.js",
            "line": 515
          },
          {
            "location": "dist/esm/index.js",
            "line": 526
          },
          {
            "location": "dist/esm/index.js",
            "line": 536
          },
          {
            "location": "dist/esm/index.js",
            "line": 545
          },
          {
            "location": "dist/esm/index.js",
            "line": 604
          },
          {
            "location": "dist/esm/index.js",
            "line": 608
          },
          {
            "location": "dist/esm/index.js",
            "line": 613
          },
          {
            "location": "dist/esm/index.js",
            "line": 623
          },
          {
            "location": "dist/esm/index.js",
            "line": 641
          },
          {
            "location": "dist/esm/index.js",
            "line": 647
          },
          {
            "location": "dist/esm/index.js",
            "line": 690
          },
          {
            "location": "dist/esm/index.js",
            "line": 703
          },
          {
            "location": "dist/esm/index.js",
            "line": 706
          },
          {
            "location": "dist/esm/index.js",
            "line": 738
          },
          {
            "location": "dist/esm/index.js",
            "line": 741
          },
          {
            "location": "dist/esm/index.js",
            "line": 775
          },
          {
            "location": "dist/esm/index.js",
            "line": 779
          },
          {
            "location": "dist/esm/index.js",
            "line": 783
          },
          {
            "location": "dist/esm/index.js",
            "line": 791
          },
          {
            "location": "dist/esm/index.js",
            "line": 797
          },
          {
            "location": "dist/esm/index.js",
            "line": 826
          },
          {
            "location": "dist/esm/index.js",
            "line": 834
          },
          {
            "location": "dist/esm/index.js",
            "line": 884
          },
          {
            "location": "dist/esm/index.js",
            "line": 914
          },
          {
            "location": "dist/esm/index.js",
            "line": 922
          },
          {
            "location": "dist/esm/index.js",
            "line": 976
          },
          {
            "location": "dist/esm/index.js",
            "line": 992
          },
          {
            "location": "dist/esm/index.js",
            "line": 995
          },
          {
            "location": "dist/esm/index.js",
            "line": 996
          },
          {
            "location": "dist/esm/index.js",
            "line": 1007
          },
          {
            "location": "dist/esm/index.js",
            "line": 1008
          },
          {
            "location": "dist/esm/index.js",
            "line": 1009
          },
          {
            "location": "dist/esm/index.js",
            "line": 1017
          },
          {
            "location": "dist/esm/index.js",
            "line": 1036
          },
          {
            "location": "dist/esm/index.js",
            "line": 1052
          },
          {
            "location": "dist/esm/index.js",
            "line": 1072
          },
          {
            "location": "dist/esm/index.js",
            "line": 1079
          },
          {
            "location": "dist/esm/index.js",
            "line": 1100
          },
          {
            "location": "dist/esm/index.js",
            "line": 1108
          },
          {
            "location": "dist/esm/index.js",
            "line": 1111
          },
          {
            "location": "dist/esm/index.js",
            "line": 1126
          },
          {
            "location": "dist/esm/index.js",
            "line": 1198
          },
          {
            "location": "dist/esm/index.js",
            "line": 1221
          },
          {
            "location": "dist/esm/index.js",
            "line": 1222
          },
          {
            "location": "dist/esm/index.js",
            "line": 1251
          },
          {
            "location": "dist/esm/index.js",
            "line": 1271
          },
          {
            "location": "dist/esm/index.js",
            "line": 1284
          },
          {
            "location": "dist/esm/index.js",
            "line": 1295
          },
          {
            "location": "dist/esm/index.js",
            "line": 1304
          },
          {
            "location": "dist/esm/index.js",
            "line": 1331
          },
          {
            "location": "dist/esm/index.js",
            "line": 1336
          },
          {
            "location": "dist/esm/index.js",
            "line": 1384
          },
          {
            "location": "dist/esm/index.js",
            "line": 1419
          },
          {
            "location": "dist/esm/index.js",
            "line": 1430
          },
          {
            "location": "dist/esm/index.js",
            "line": 1437
          },
          {
            "location": "dist/esm/index.js",
            "line": 1491
          },
          {
            "location": "dist/esm/index.js",
            "line": 1495
          },
          {
            "location": "dist/esm/index.js",
            "line": 1543
          },
          {
            "location": "dist/esm/index.js",
            "line": 1557
          },
          {
            "location": "dist/esm/index.js",
            "line": 1592
          },
          {
            "location": "dist/esm/index.js",
            "line": 1599
          },
          {
            "location": "dist/esm/index.js",
            "line": 1603
          },
          {
            "location": "dist/esm/index.js",
            "line": 1610
          },
          {
            "location": "dist/esm/index.js",
            "line": 1616
          },
          {
            "location": "dist/esm/index.js",
            "line": 1622
          },
          {
            "location": "dist/esm/index.js",
            "line": 1628
          },
          {
            "location": "dist/esm/index.js",
            "line": 1674
          },
          {
            "location": "dist/esm/index.js",
            "line": 1675
          },
          {
            "location": "dist/esm/index.js",
            "line": 1685
          },
          {
            "location": "dist/esm/index.js",
            "line": 1686
          },
          {
            "location": "dist/esm/index.js",
            "line": 1689
          },
          {
            "location": "dist/esm/index.js",
            "line": 1694
          },
          {
            "location": "dist/esm/index.js",
            "line": 1705
          },
          {
            "location": "dist/esm/index.js",
            "line": 1724
          },
          {
            "location": "dist/esm/index.js",
            "line": 1726
          },
          {
            "location": "dist/esm/index.js",
            "line": 1730
          },
          {
            "location": "dist/esm/index.js",
            "line": 1737
          },
          {
            "location": "dist/esm/index.js",
            "line": 1741
          },
          {
            "location": "dist/esm/index.js",
            "line": 1751
          },
          {
            "location": "dist/esm/index.js",
            "line": 1756
          },
          {
            "location": "dist/esm/index.js",
            "line": 1760
          },
          {
            "location": "dist/esm/index.js",
            "line": 1776
          },
          {
            "location": "dist/index.js",
            "line": 62
          },
          {
            "location": "dist/index.js",
            "line": 66
          },
          {
            "location": "dist/index.js",
            "line": 165
          },
          {
            "location": "dist/index.js",
            "line": 197
          },
          {
            "location": "dist/index.js",
            "line": 198
          },
          {
            "location": "dist/index.js",
            "line": 1001
          },
          {
            "location": "dist/index.js",
            "line": 1175
          },
          {
            "location": "dist/index.js",
            "line": 1361
          },
          {
            "location": "dist/index.js",
            "line": 1569
          },
          {
            "location": "src/garfish.ts",
            "line": 3
          },
          {
            "location": "src/garfish.ts",
            "line": 66
          },
          {
            "location": "src/garfish.ts",
            "line": 67
          },
          {
            "location": "src/garfish.ts",
            "line": 82
          },
          {
            "location": "src/garfish.ts",
            "line": 83
          },
          {
            "location": "src/garfish.ts",
            "line": 86
          },
          {
            "location": "src/garfish.ts",
            "line": 93
          },
          {
            "location": "src/garfish.ts",
            "line": 105
          },
          {
            "location": "src/garfish.ts",
            "line": 130
          },
          {
            "location": "src/garfish.ts",
            "line": 132
          },
          {
            "location": "src/garfish.ts",
            "line": 139
          },
          {
            "location": "src/garfish.ts",
            "line": 147
          },
          {
            "location": "src/garfish.ts",
            "line": 152
          },
          {
            "location": "src/garfish.ts",
            "line": 166
          },
          {
            "location": "src/garfish.ts",
            "line": 175
          },
          {
            "location": "src/garfish.ts",
            "line": 182
          },
          {
            "location": "src/garfish.ts",
            "line": 218
          },
          {
            "location": "src/lifecycle.ts",
            "line": 1
          },
          {
            "location": "src/module/app.ts",
            "line": 26
          },
          {
            "location": "src/module/app.ts",
            "line": 137
          },
          {
            "location": "src/module/app.ts",
            "line": 163
          },
          {
            "location": "src/module/app.ts",
            "line": 167
          },
          {
            "location": "src/module/app.ts",
            "line": 185
          },
          {
            "location": "src/module/app.ts",
            "line": 200
          },
          {
            "location": "src/module/app.ts",
            "line": 209
          },
          {
            "location": "src/module/app.ts",
            "line": 312
          },
          {
            "location": "src/module/app.ts",
            "line": 322
          },
          {
            "location": "src/module/app.ts",
            "line": 328
          },
          {
            "location": "src/module/app.ts",
            "line": 338
          },
          {
            "location": "src/module/app.ts",
            "line": 357
          },
          {
            "location": "src/module/app.ts",
            "line": 364
          },
          {
            "location": "src/module/app.ts",
            "line": 418
          },
          {
            "location": "src/module/app.ts",
            "line": 433
          },
          {
            "location": "src/module/app.ts",
            "line": 436
          },
          {
            "location": "src/module/app.ts",
            "line": 482
          },
          {
            "location": "src/module/app.ts",
            "line": 488
          },
          {
            "location": "src/module/app.ts",
            "line": 530
          },
          {
            "location": "src/module/app.ts",
            "line": 535
          },
          {
            "location": "src/module/app.ts",
            "line": 541
          },
          {
            "location": "src/module/app.ts",
            "line": 556
          },
          {
            "location": "src/module/app.ts",
            "line": 563
          },
          {
            "location": "src/module/app.ts",
            "line": 603
          },
          {
            "location": "src/module/app.ts",
            "line": 612
          },
          {
            "location": "src/module/app.ts",
            "line": 688
          },
          {
            "location": "src/module/app.ts",
            "line": 731
          },
          {
            "location": "src/module/app.ts",
            "line": 732
          },
          {
            "location": "src/module/app.ts",
            "line": 740
          },
          {
            "location": "src/module/app.ts",
            "line": 824
          },
          {
            "location": "src/module/app.ts",
            "line": 850
          },
          {
            "location": "src/module/app.ts",
            "line": 855
          },
          {
            "location": "src/module/app.ts",
            "line": 856
          },
          {
            "location": "src/module/app.ts",
            "line": 874
          },
          {
            "location": "src/module/app.ts",
            "line": 876
          },
          {
            "location": "src/module/app.ts",
            "line": 877
          },
          {
            "location": "src/module/esModule.ts",
            "line": 3
          },
          {
            "location": "src/module/esModule.ts",
            "line": 9
          },
          {
            "location": "src/module/esModule.ts",
            "line": 113
          },
          {
            "location": "src/module/esModule.ts",
            "line": 114
          },
          {
            "location": "src/module/esModule.ts",
            "line": 132
          },
          {
            "location": "src/module/esModule.ts",
            "line": 133
          },
          {
            "location": "src/module/esModule.ts",
            "line": 232
          },
          {
            "location": "src/module/esModule.ts",
            "line": 347
          },
          {
            "location": "src/module/esModule.ts",
            "line": 348
          },
          {
            "location": "src/module/esModule.ts",
            "line": 349
          },
          {
            "location": "src/module/esModule.ts",
            "line": 391
          },
          {
            "location": "src/module/esModule.ts",
            "line": 392
          },
          {
            "location": "src/module/resource.ts",
            "line": 1
          },
          {
            "location": "src/module/resource.ts",
            "line": 44
          },
          {
            "location": "src/module/resource.ts",
            "line": 66
          },
          {
            "location": "src/module/resource.ts",
            "line": 98
          },
          {
            "location": "src/module/resource.ts",
            "line": 108
          },
          {
            "location": "src/module/resource.ts",
            "line": 139
          },
          {
            "location": "src/module/resource.ts",
            "line": 154
          },
          {
            "location": "src/module/resource.ts",
            "line": 157
          },
          {
            "location": "src/module/resource.ts",
            "line": 183
          },
          {
            "location": "src/plugins/logger.ts",
            "line": 1
          },
          {
            "location": "src/plugins/logger.ts",
            "line": 10
          },
          {
            "location": "src/plugins/logger.ts",
            "line": 14
          },
          {
            "location": "src/plugins/logger.ts",
            "line": 21
          },
          {
            "location": "src/plugins/logger.ts",
            "line": 27
          },
          {
            "location": "src/plugins/logger.ts",
            "line": 33
          },
          {
            "location": "src/plugins/logger.ts",
            "line": 39
          },
          {
            "location": "src/plugins/performance/index.ts",
            "line": 1
          },
          {
            "location": "src/plugins/performance/subAppObserver.ts",
            "line": 1
          },
          {
            "location": "src/plugins/performance/subAppObserver.ts",
            "line": 89
          },
          {
            "location": "src/plugins/performance/subAppObserver.ts",
            "line": 102
          },
          {
            "location": "src/plugins/performance/subAppObserver.ts",
            "line": 112
          },
          {
            "location": "src/plugins/performance/subAppObserver.ts",
            "line": 179
          },
          {
            "location": "src/plugins/performance/subAppObserver.ts",
            "line": 183
          },
          {
            "location": "src/plugins/performance/subAppObserver.ts",
            "line": 242
          },
          {
            "location": "src/plugins/performance/subAppObserver.ts",
            "line": 257
          },
          {
            "location": "src/plugins/preload.ts",
            "line": 9
          },
          {
            "location": "src/plugins/preload.ts",
            "line": 61
          },
          {
            "location": "src/plugins/preload.ts",
            "line": 62
          },
          {
            "location": "src/plugins/preload.ts",
            "line": 96
          },
          {
            "location": "src/plugins/preload.ts",
            "line": 97
          },
          {
            "location": "src/plugins/preload.ts",
            "line": 120
          },
          {
            "location": "src/plugins/preload.ts",
            "line": 134
          },
          {
            "location": "src/plugins/preload.ts",
            "line": 145
          },
          {
            "location": "src/plugins/preload.ts",
            "line": 154
          },
          {
            "location": "src/plugins/preload.ts",
            "line": 186
          },
          {
            "location": "src/plugins/preload.ts",
            "line": 193
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "zhouxiao <codingzx@gmail.com>"
        }
      ],
      "group": "@garfish",
      "name": "test-suite",
      "version": "1.19.12",
      "description": "garfish test suite.",
      "scope": "required",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/%40garfish/test-suite@1.19.12",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/bytedance/garfish"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/bytedance/garfish.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@garfish/test-suite@1.19.12",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@garfish/test-suite/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@garfish/test-suite/package.json"
              }
            ],
            "concludedValue": "node_modules/@garfish/test-suite/package.json"
          }
        ]
      },
      "tags": [
        "test"
      ]
    },
    {
      "authors": [
        {
          "name": "chentao.arthur <chentao.arthur@bytedance.com>"
        }
      ],
      "group": "@garfish",
      "name": "loader",
      "version": "1.19.12",
      "description": "loader module.",
      "scope": "required",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/%40garfish/loader@1.19.12",
      "externalReferences": [
        {
          "type": "website",
          "url": "http://garfish.bytedance.com"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/bytedance/garfish.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@garfish/loader@1.19.12",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@garfish/loader/package.json"
        },
        {
          "name": "ImportedModules",
          "value": "@garfish/loader,Loader,@garfish/loader/Loader,TemplateManager,@garfish/loader/TemplateManager,JavaScriptManager,@garfish/loader/JavaScriptManager,StyleManager,@garfish/loader/StyleManager,Manager,@garfish/loader/Manager"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@garfish/loader/package.json"
              }
            ],
            "concludedValue": "node_modules/@garfish/loader/package.json"
          }
        ],
        "occurrences": [
          {
            "location": "dist/esm/index.js",
            "line": 34
          },
          {
            "location": "dist/esm/index.js",
            "line": 1199
          },
          {
            "location": "dist/index.js",
            "line": 60
          },
          {
            "location": "dist/index.js",
            "line": 1176
          },
          {
            "location": "src/garfish.ts",
            "line": 1
          },
          {
            "location": "src/interface.ts",
            "line": 2
          },
          {
            "location": "src/module/app.ts",
            "line": 1
          },
          {
            "location": "src/module/esModule.ts",
            "line": 2
          },
          {
            "location": "src/module/resource.ts",
            "line": 7
          },
          {
            "location": "src/plugins/preload.ts",
            "line": 10
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "chentao.arthur <chentao.arthur@bytedance.com>"
        }
      ],
      "group": "@garfish",
      "name": "hooks",
      "version": "1.19.12",
      "description": "hooks module.",
      "scope": "required",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/%40garfish/hooks@1.19.12",
      "externalReferences": [
        {
          "type": "website",
          "url": "http://garfish.bytedance.com"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/bytedance/garfish.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@garfish/hooks@1.19.12",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@garfish/hooks/package.json"
        },
        {
          "name": "ImportedModules",
          "value": "@garfish/hooks,SyncHook,@garfish/hooks/SyncHook,AsyncHook,@garfish/hooks/AsyncHook,SyncWaterfallHook,@garfish/hooks/SyncWaterfallHook,AsyncWaterfallHook,@garfish/hooks/AsyncWaterfallHook,PluginSystem,@garfish/hooks/PluginSystem"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@garfish/hooks/package.json"
              }
            ],
            "concludedValue": "node_modules/@garfish/hooks/package.json"
          }
        ],
        "occurrences": [
          {
            "location": "dist/esm/index.js",
            "line": 43
          },
          {
            "location": "dist/esm/index.js",
            "line": 179
          },
          {
            "location": "dist/index.js",
            "line": 63
          },
          {
            "location": "dist/index.js",
            "line": 168
          },
          {
            "location": "src/garfish.ts",
            "line": 10
          },
          {
            "location": "src/interface.ts",
            "line": 1
          },
          {
            "location": "src/lifecycle.ts",
            "line": 7
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Guy Bedford"
        }
      ],
      "group": "@alioth-org",
      "name": "es-module-lexer",
      "version": "1.1.0",
      "description": "Lexes ES modules returning their import/export metadata",
      "scope": "required",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/%40alioth-org/es-module-lexer@1.1.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/guybedford/es-module-lexer#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/guybedford/es-module-lexer.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@alioth-org/es-module-lexer@1.1.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@alioth-org/es-module-lexer/package.json"
        },
        {
          "name": "ImportedModules",
          "value": "@alioth-org/es-module-lexer,init,@alioth-org/es-module-lexer/init,parse,@alioth-org/es-module-lexer/parse,ImportSpecifier,@alioth-org/es-module-lexer/ImportSpecifier"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@alioth-org/es-module-lexer/package.json"
              }
            ],
            "concludedValue": "node_modules/@alioth-org/es-module-lexer/package.json"
          }
        ],
        "occurrences": [
          {
            "location": "dist/esm/index.js",
            "line": 207
          },
          {
            "location": "dist/esm/index.js",
            "line": 299
          },
          {
            "location": "dist/esm/index.js",
            "line": 300
          },
          {
            "location": "dist/index.js",
            "line": 196
          },
          {
            "location": "src/module/esModule.ts",
            "line": 1
          },
          {
            "location": "src/module/esModule.ts",
            "line": 169
          },
          {
            "location": "src/module/esModule.ts",
            "line": 171
          }
        ]
      }
    }
  ],
  "dependencies": [],
  "annotations": [
    {
      "bom-ref": "metadata-annotations",
      "subjects": [
        "pkg:npm/@garfish/core@1.19.12"
      ],
      "annotator": {
        "component": {
          "group": "@cyclonedx",
          "name": "cdxgen",
          "version": "12.8.4",
          "purl": "pkg:npm/%40cyclonedx/cdxgen@12.8.4",
          "type": "application",
          "bom-ref": "pkg:npm/@cyclonedx/cdxgen@12.8.4",
          "publisher": "OWASP Foundation",
          "authors": [
            {
              "name": "OWASP Foundation"
            }
          ]
        }
      },
      "timestamp": "2026-09-14T04:27:46Z",
      "text": "This Software Bill-of-Materials (SBOM) document was created on Monday, September 14, 2026 with cdxgen. The data was captured during the pre-build lifecycle phase without building the application. The document describes an application named 'core' with version '1.19.12'. The package type in this SBOM is npm with 2 purl namespaces described under components. The components were identified from 6 source files."
    }
  ]
}