{
  "bomFormat": "CycloneDX",
  "specVersion": "1.7",
  "serialNumber": "urn:uuid:f9ea75d2-1a7c-4e90-b5e5-6a28d114e96f",
  "version": 1,
  "metadata": {
    "timestamp": "2026-09-15T15:21:55Z",
    "tools": {
      "components": [
        {
          "group": "@cyclonedx",
          "name": "cdxgen",
          "version": "12.8.4",
          "purl": "pkg:npm/%40cyclonedx/cdxgen@12.8.4",
          "type": "application",
          "bom-ref": "pkg:npm/@cyclonedx/cdxgen@12.8.4",
          "publisher": "OWASP Foundation",
          "authors": [
            {
              "name": "OWASP Foundation"
            }
          ]
        }
      ]
    },
    "authors": [
      {
        "name": "OWASP Foundation"
      }
    ],
    "lifecycles": [
      {
        "phase": "pre-build"
      }
    ],
    "component": {
      "name": "devtools-vite",
      "group": "@tanstack",
      "version": "0.7.0",
      "description": "TanStack Vite plugin used to enhance the core devtools with additional functionalities",
      "purl": "pkg:npm/%40tanstack/devtools-vite@0.7.0",
      "bom-ref": "pkg:npm/@tanstack/devtools-vite@0.7.0",
      "author": "Tanner Linsley",
      "properties": [
        {
          "name": "cdx:npm:bin",
          "value": "intent"
        },
        {
          "name": "cdx:npm:has_binary",
          "value": "true"
        },
        {
          "name": "cdx:npm:scripts",
          "value": "clean, lint:fix, test:eslint, test:lib, test:lib:dev, test:types, test:build, build"
        },
        {
          "name": "cdx:npm:buildScripts",
          "value": "test:build, build"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "type": "application",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "externalReferences": [
        {
          "type": "website",
          "url": "https://tanstack.com/devtools"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/TanStack/devtools.git"
        }
      ]
    },
    "properties": [
      {
        "name": "cdx:bom:componentTypes",
        "value": "npm"
      },
      {
        "name": "cdx:bom:componentNamespaces",
        "value": "@tanstack\\n@types"
      },
      {
        "name": "cdx:bom:componentSrcFiles",
        "value": "node_modules/@tanstack/devtools-client/package.json\\nnode_modules/@tanstack/devtools-event-bus/package.json\\nnode_modules/@types/picomatch/package.json\\nnode_modules/chalk/package.json\\nnode_modules/happy-dom/package.json\\nnode_modules/launch-editor/package.json\\nnode_modules/magic-string/package.json\\nnode_modules/oxc-parser/package.json\\nnode_modules/picomatch/package.json\\nnode_modules/vite/package.json"
      }
    ]
  },
  "components": [
    {
      "authors": [
        {
          "name": "Evan You"
        }
      ],
      "group": "",
      "name": "vite",
      "version": "8.0.12",
      "description": "Native-ESM powered web dev build tool",
      "scope": "required",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/vite@8.0.12",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://vite.dev"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/vitejs/vite.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/vite@8.0.12",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/vite/package.json"
        },
        {
          "name": "ImportedModules",
          "value": "vite,normalizePath,vite/normalizePath,Plugin,vite/Plugin,Connect,vite/Connect"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/vite/package.json"
              }
            ],
            "concludedValue": "node_modules/vite/package.json"
          }
        ],
        "occurrences": [
          {
            "location": "dist/esm/enhance-logs.js",
            "line": 3
          },
          {
            "location": "dist/esm/enhance-logs.js",
            "line": 13
          },
          {
            "location": "dist/esm/inject-source.js",
            "line": 4
          },
          {
            "location": "dist/esm/inject-source.js",
            "line": 87
          },
          {
            "location": "dist/esm/plugin.js",
            "line": 12
          },
          {
            "location": "dist/esm/plugin.js",
            "line": 157
          },
          {
            "location": "dist/esm/utils.js",
            "line": 1
          },
          {
            "location": "dist/esm/utils.js",
            "line": 16
          },
          {
            "location": "src/enhance-logs.ts",
            "line": 2
          },
          {
            "location": "src/enhance-logs.ts",
            "line": 14
          },
          {
            "location": "src/inject-source.ts",
            "line": 1
          },
          {
            "location": "src/inject-source.ts",
            "line": 196
          },
          {
            "location": "src/plugin.ts",
            "line": 3
          },
          {
            "location": "src/plugin.ts",
            "line": 23
          },
          {
            "location": "src/plugin.ts",
            "line": 332
          },
          {
            "location": "src/utils.ts",
            "line": 2
          },
          {
            "location": "src/utils.ts",
            "line": 3
          },
          {
            "location": "src/utils.ts",
            "line": 50
          }
        ]
      },
      "tags": [
        "web"
      ]
    },
    {
      "authors": [
        {
          "name": "Jon Schlinkert (https://github.com/jonschlinkert)"
        }
      ],
      "group": "",
      "name": "picomatch",
      "version": "4.0.4",
      "description": "Blazing fast and accurate glob matcher written in JavaScript, with no dependencies and full support for standard and extended Bash glob features, including braces, extglobs, POSIX brackets, and regular expressions.",
      "scope": "required",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/picomatch@4.0.4",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/micromatch/picomatch"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/picomatch@4.0.4",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/picomatch/package.json"
        },
        {
          "name": "ImportedModules",
          "value": "picomatch"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/picomatch/package.json"
              }
            ],
            "concludedValue": "node_modules/picomatch/package.json"
          }
        ],
        "occurrences": [
          {
            "location": "dist/esm/matcher.js",
            "line": 1
          },
          {
            "location": "dist/esm/matcher.js",
            "line": 6
          },
          {
            "location": "src/matcher.ts",
            "line": 1
          },
          {
            "location": "src/matcher.ts",
            "line": 12
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Boshen and oxc contributors"
        }
      ],
      "group": "",
      "name": "oxc-parser",
      "version": "0.120.0",
      "description": "Oxc Parser Node API",
      "scope": "required",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/oxc-parser@0.120.0",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://oxc.rs/docs/guide/usage/parser"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/oxc-project/oxc.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/oxc-parser@0.120.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/oxc-parser/package.json"
        },
        {
          "name": "ImportedModules",
          "value": "oxc-parser,parseSync,oxc-parser/parseSync,Node,oxc-parser/Node,JSXElementName,oxc-parser/JSXElementName,JSXOpeningElement,oxc-parser/JSXOpeningElement,ParamPattern,oxc-parser/ParamPattern"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/oxc-parser/package.json"
              }
            ],
            "concludedValue": "node_modules/oxc-parser/package.json"
          }
        ],
        "occurrences": [
          {
            "location": "dist/esm/enhance-logs.js",
            "line": 6
          },
          {
            "location": "dist/esm/enhance-logs.js",
            "line": 15
          },
          {
            "location": "dist/esm/inject-plugin.js",
            "line": 4
          },
          {
            "location": "dist/esm/inject-plugin.js",
            "line": 12
          },
          {
            "location": "dist/esm/inject-plugin.js",
            "line": 33
          },
          {
            "location": "dist/esm/inject-plugin.js",
            "line": 85
          },
          {
            "location": "dist/esm/inject-source.js",
            "line": 6
          },
          {
            "location": "dist/esm/inject-source.js",
            "line": 90
          },
          {
            "location": "dist/esm/remove-devtools.js",
            "line": 4
          },
          {
            "location": "dist/esm/remove-devtools.js",
            "line": 34
          },
          {
            "location": "src/ast-utils.ts",
            "line": 1
          },
          {
            "location": "src/enhance-logs.ts",
            "line": 4
          },
          {
            "location": "src/enhance-logs.ts",
            "line": 17
          },
          {
            "location": "src/inject-plugin.ts",
            "line": 3
          },
          {
            "location": "src/inject-plugin.ts",
            "line": 6
          },
          {
            "location": "src/inject-plugin.ts",
            "line": 14
          },
          {
            "location": "src/inject-plugin.ts",
            "line": 44
          },
          {
            "location": "src/inject-plugin.ts",
            "line": 148
          },
          {
            "location": "src/inject-source.ts",
            "line": 3
          },
          {
            "location": "src/inject-source.ts",
            "line": 12
          },
          {
            "location": "src/inject-source.ts",
            "line": 202
          },
          {
            "location": "src/remove-devtools.ts",
            "line": 2
          },
          {
            "location": "src/remove-devtools.ts",
            "line": 5
          },
          {
            "location": "src/remove-devtools.ts",
            "line": 80
          }
        ]
      },
      "tags": [
        "parse"
      ]
    },
    {
      "authors": [
        {
          "name": "Rich Harris"
        }
      ],
      "group": "",
      "name": "magic-string",
      "version": "0.30.21",
      "description": "Modify strings, generate sourcemaps",
      "scope": "required",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/magic-string@0.30.21",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "git+https://github.com/Rich-Harris/magic-string.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/magic-string@0.30.21",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/magic-string/package.json"
        },
        {
          "name": "ImportedModules",
          "value": "magic-string"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/magic-string/package.json"
              }
            ],
            "concludedValue": "node_modules/magic-string/package.json"
          }
        ],
        "occurrences": [
          {
            "location": "dist/esm/enhance-logs.js",
            "line": 5
          },
          {
            "location": "dist/esm/inject-plugin.js",
            "line": 3
          },
          {
            "location": "dist/esm/inject-source.js",
            "line": 5
          },
          {
            "location": "dist/esm/remove-devtools.js",
            "line": 3
          },
          {
            "location": "src/enhance-logs.ts",
            "line": 3
          },
          {
            "location": "src/inject-plugin.ts",
            "line": 2
          },
          {
            "location": "src/inject-source.ts",
            "line": 2
          },
          {
            "location": "src/remove-devtools.ts",
            "line": 1
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Evan You"
        }
      ],
      "group": "",
      "name": "launch-editor",
      "version": "2.13.2",
      "description": "launch editor from node.js",
      "scope": "required",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/launch-editor@2.13.2",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/yyx990803/launch-editor#readme"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/yyx990803/launch-editor.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/launch-editor@2.13.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/launch-editor/package.json"
        },
        {
          "name": "ImportedModules",
          "value": "launch-editor"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/launch-editor/package.json"
              }
            ],
            "concludedValue": "node_modules/launch-editor/package.json"
          }
        ],
        "occurrences": [
          {
            "location": "dist/esm/editor.js",
            "line": 5
          },
          {
            "location": "src/editor.ts",
            "line": 29
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "David Ortner"
        }
      ],
      "group": "",
      "name": "happy-dom",
      "version": "20.9.0",
      "description": "Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. It includes many web standards from WHATWG DOM and HTML.",
      "scope": "optional",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/happy-dom@20.9.0",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/capricorn86/happy-dom"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/happy-dom@20.9.0",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/happy-dom/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/happy-dom/package.json"
              }
            ],
            "concludedValue": "node_modules/happy-dom/package.json"
          }
        ]
      },
      "tags": [
        "html",
        "web"
      ]
    },
    {
      "group": "",
      "name": "chalk",
      "version": "5.6.2",
      "description": "Terminal string styling done right",
      "scope": "required",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/chalk@5.6.2",
      "type": "library",
      "bom-ref": "pkg:npm/chalk@5.6.2",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/chalk/package.json"
        },
        {
          "name": "ImportedModules",
          "value": "chalk"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/chalk/package.json"
              }
            ],
            "concludedValue": "node_modules/chalk/package.json"
          }
        ],
        "occurrences": [
          {
            "location": "dist/esm/enhance-logs.js",
            "line": 4
          },
          {
            "location": "dist/esm/enhance-logs.js",
            "line": 29
          },
          {
            "location": "dist/esm/package-manager.js",
            "line": 4
          },
          {
            "location": "dist/esm/package-manager.js",
            "line": 26
          },
          {
            "location": "dist/esm/package-manager.js",
            "line": 37
          },
          {
            "location": "dist/esm/package-manager.js",
            "line": 38
          },
          {
            "location": "dist/esm/package-manager.js",
            "line": 55
          },
          {
            "location": "dist/esm/package-manager.js",
            "line": 58
          },
          {
            "location": "dist/esm/package-manager.js",
            "line": 65
          },
          {
            "location": "dist/esm/plugin.js",
            "line": 13
          },
          {
            "location": "dist/esm/plugin.js",
            "line": 112
          },
          {
            "location": "dist/esm/plugin.js",
            "line": 113
          },
          {
            "location": "dist/esm/plugin.js",
            "line": 157
          },
          {
            "location": "dist/esm/plugin.js",
            "line": 179
          },
          {
            "location": "dist/esm/plugin.js",
            "line": 192
          },
          {
            "location": "dist/esm/plugin.js",
            "line": 202
          },
          {
            "location": "dist/esm/plugin.js",
            "line": 205
          },
          {
            "location": "dist/esm/plugin.js",
            "line": 213
          },
          {
            "location": "dist/esm/plugin.js",
            "line": 215
          },
          {
            "location": "dist/esm/plugin.js",
            "line": 222
          },
          {
            "location": "dist/esm/plugin.js",
            "line": 229
          },
          {
            "location": "dist/esm/plugin.js",
            "line": 237
          },
          {
            "location": "src/enhance-logs.ts",
            "line": 1
          },
          {
            "location": "src/enhance-logs.ts",
            "line": 41
          },
          {
            "location": "src/package-manager.ts",
            "line": 5
          },
          {
            "location": "src/package-manager.ts",
            "line": 40
          },
          {
            "location": "src/package-manager.ts",
            "line": 56
          },
          {
            "location": "src/package-manager.ts",
            "line": 62
          },
          {
            "location": "src/package-manager.ts",
            "line": 101
          },
          {
            "location": "src/package-manager.ts",
            "line": 109
          },
          {
            "location": "src/package-manager.ts",
            "line": 122
          },
          {
            "location": "src/plugin.ts",
            "line": 4
          },
          {
            "location": "src/plugin.ts",
            "line": 255
          },
          {
            "location": "src/plugin.ts",
            "line": 263
          },
          {
            "location": "src/plugin.ts",
            "line": 332
          },
          {
            "location": "src/plugin.ts",
            "line": 367
          },
          {
            "location": "src/plugin.ts",
            "line": 400
          },
          {
            "location": "src/plugin.ts",
            "line": 430
          },
          {
            "location": "src/plugin.ts",
            "line": 444
          },
          {
            "location": "src/plugin.ts",
            "line": 457
          },
          {
            "location": "src/plugin.ts",
            "line": 465
          },
          {
            "location": "src/plugin.ts",
            "line": 478
          },
          {
            "location": "src/plugin.ts",
            "line": 491
          },
          {
            "location": "src/plugin.ts",
            "line": 508
          }
        ]
      }
    },
    {
      "group": "@types",
      "name": "picomatch",
      "version": "4.0.3",
      "description": "TypeScript definitions for picomatch",
      "scope": "required",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/%40types/picomatch@4.0.3",
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/picomatch"
        },
        {
          "type": "vcs",
          "url": "https://github.com/DefinitelyTyped/DefinitelyTyped.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@types/picomatch@4.0.3",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@types/picomatch/package.json"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@types/picomatch/package.json"
              }
            ],
            "concludedValue": "node_modules/@types/picomatch/package.json"
          }
        ]
      }
    },
    {
      "authors": [
        {
          "name": "Tanner Linsley"
        }
      ],
      "group": "@tanstack",
      "name": "devtools-event-bus",
      "version": "0.4.1",
      "description": "TanStack Event Bus is a lightweight event bus for TanStack Devtools.",
      "scope": "required",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/%40tanstack/devtools-event-bus@0.4.1",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://tanstack.com/devtools"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/TanStack/devtools.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@tanstack/devtools-event-bus@0.4.1",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@tanstack/devtools-event-bus/package.json"
        },
        {
          "name": "ImportedModules",
          "value": "@tanstack/devtools-event-bus/server,ServerEventBus,@tanstack/devtools-event-bus/server/ServerEventBus,HttpServerLike,@tanstack/devtools-event-bus/server/HttpServerLike,ServerEventBusConfig,@tanstack/devtools-event-bus/server/ServerEventBusConfig"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@tanstack/devtools-event-bus/package.json"
              }
            ],
            "concludedValue": "node_modules/@tanstack/devtools-event-bus/package.json"
          }
        ],
        "occurrences": [
          {
            "location": "dist/esm/plugin.js",
            "line": 11
          },
          {
            "location": "src/plugin.ts",
            "line": 2
          },
          {
            "location": "src/plugin.ts",
            "line": 28
          }
        ]
      },
      "tags": [
        "event"
      ]
    },
    {
      "authors": [
        {
          "name": "Tanner Linsley"
        }
      ],
      "group": "@tanstack",
      "name": "devtools-client",
      "version": "0.0.6",
      "description": "TanStack Devtools client that is used to interact with the event system produced by the Devtools.",
      "scope": "required",
      "licenses": [
        {
          "license": {
            "id": "MIT",
            "url": "https://opensource.org/licenses/MIT",
            "properties": [
              {
                "name": "cdx:license:category",
                "value": "Permissive"
              },
              {
                "name": "cdx:license:foss",
                "value": "true"
              },
              {
                "name": "cdx:license:osiApproved",
                "value": "true"
              },
              {
                "name": "cdx:license:fsfLibre",
                "value": "true"
              },
              {
                "name": "cdx:license:deprecated",
                "value": "false"
              }
            ]
          }
        }
      ],
      "purl": "pkg:npm/%40tanstack/devtools-client@0.0.6",
      "externalReferences": [
        {
          "type": "website",
          "url": "https://tanstack.com/devtools"
        },
        {
          "type": "vcs",
          "url": "git+https://github.com/TanStack/devtools.git"
        }
      ],
      "type": "library",
      "bom-ref": "pkg:npm/@tanstack/devtools-client@0.0.6",
      "properties": [
        {
          "name": "SrcFile",
          "value": "node_modules/@tanstack/devtools-client/package.json"
        },
        {
          "name": "ImportedModules",
          "value": "@tanstack/devtools-client,devtoolsEventClient,@tanstack/devtools-client/devtoolsEventClient,PluginInjection,@tanstack/devtools-client/PluginInjection,OutdatedDeps,@tanstack/devtools-client/OutdatedDeps,PackageJson,@tanstack/devtools-client/PackageJson"
        },
        {
          "name": "cdx:license:category",
          "value": "Permissive"
        }
      ],
      "evidence": {
        "identity": [
          {
            "field": "purl",
            "confidence": 0.7,
            "methods": [
              {
                "technique": "manifest-analysis",
                "confidence": 0.7,
                "value": "node_modules/@tanstack/devtools-client/package.json"
              }
            ],
            "concludedValue": "node_modules/@tanstack/devtools-client/package.json"
          }
        ],
        "occurrences": [
          {
            "location": "dist/esm/package-manager.js",
            "line": 3
          },
          {
            "location": "dist/esm/package-manager.js",
            "line": 67
          },
          {
            "location": "dist/esm/package-manager.js",
            "line": 89
          },
          {
            "location": "dist/esm/plugin.js",
            "line": 10
          },
          {
            "location": "dist/esm/plugin.js",
            "line": 170
          },
          {
            "location": "dist/esm/plugin.js",
            "line": 172
          },
          {
            "location": "dist/esm/plugin.js",
            "line": 181
          },
          {
            "location": "dist/esm/plugin.js",
            "line": 186
          },
          {
            "location": "dist/esm/plugin.js",
            "line": 190
          },
          {
            "location": "dist/esm/plugin.js",
            "line": 194
          },
          {
            "location": "dist/esm/plugin.js",
            "line": 200
          },
          {
            "location": "dist/esm/plugin.js",
            "line": 206
          },
          {
            "location": "dist/esm/plugin.js",
            "line": 216
          },
          {
            "location": "dist/esm/plugin.js",
            "line": 230
          },
          {
            "location": "dist/esm/plugin.js",
            "line": 235
          },
          {
            "location": "dist/esm/plugin.js",
            "line": 238
          },
          {
            "location": "dist/esm/plugin.js",
            "line": 245
          },
          {
            "location": "dist/esm/plugin.js",
            "line": 246
          },
          {
            "location": "dist/esm/plugin.js",
            "line": 247
          },
          {
            "location": "dist/esm/plugin.js",
            "line": 253
          },
          {
            "location": "src/inject-plugin.ts",
            "line": 7
          },
          {
            "location": "src/package-manager.ts",
            "line": 4
          },
          {
            "location": "src/package-manager.ts",
            "line": 8
          },
          {
            "location": "src/package-manager.ts",
            "line": 129
          },
          {
            "location": "src/package-manager.ts",
            "line": 174
          },
          {
            "location": "src/plugin.ts",
            "line": 1
          },
          {
            "location": "src/plugin.ts",
            "line": 354
          },
          {
            "location": "src/plugin.ts",
            "line": 356
          },
          {
            "location": "src/plugin.ts",
            "line": 381
          },
          {
            "location": "src/plugin.ts",
            "line": 388
          },
          {
            "location": "src/plugin.ts",
            "line": 396
          },
          {
            "location": "src/plugin.ts",
            "line": 412
          },
          {
            "location": "src/plugin.ts",
            "line": 420
          },
          {
            "location": "src/plugin.ts",
            "line": 448
          },
          {
            "location": "src/plugin.ts",
            "line": 469
          },
          {
            "location": "src/plugin.ts",
            "line": 496
          },
          {
            "location": "src/plugin.ts",
            "line": 503
          },
          {
            "location": "src/plugin.ts",
            "line": 513
          },
          {
            "location": "src/plugin.ts",
            "line": 522
          },
          {
            "location": "src/plugin.ts",
            "line": 523
          },
          {
            "location": "src/plugin.ts",
            "line": 526
          },
          {
            "location": "src/plugin.ts",
            "line": 536
          },
          {
            "location": "src/utils.ts",
            "line": 5
          }
        ]
      },
      "tags": [
        "event"
      ]
    }
  ],
  "dependencies": [],
  "annotations": [
    {
      "bom-ref": "metadata-annotations",
      "subjects": [
        "pkg:npm/@tanstack/devtools-vite@0.7.0"
      ],
      "annotator": {
        "component": {
          "group": "@cyclonedx",
          "name": "cdxgen",
          "version": "12.8.4",
          "purl": "pkg:npm/%40cyclonedx/cdxgen@12.8.4",
          "type": "application",
          "bom-ref": "pkg:npm/@cyclonedx/cdxgen@12.8.4",
          "publisher": "OWASP Foundation",
          "authors": [
            {
              "name": "OWASP Foundation"
            }
          ]
        }
      },
      "timestamp": "2026-09-15T15:21:55Z",
      "text": "This Software Bill-of-Materials (SBOM) document was created on Tuesday, September 15, 2026 with cdxgen. The data was captured during the pre-build lifecycle phase without building the application. The document describes an application named 'devtools-vite' with version '0.7.0'. The package type in this SBOM is npm with 2 purl namespaces described under components. The components were identified from 10 source files."
    }
  ]
}