If present, return the associated SBOM for this package.

GET /api/v1/package/12680/sbom/?format=api
HTTP 200 OK
Allow: GET, HEAD, OPTIONS
Content-Type: application/json
Vary: Accept

{
    "vulnerabilities": [
        {
            "id": "CVE-2024-23337",
            "package": "jq",
            "score": "6.5",
            "severity": "medium",
            "suppressed": null,
            "published": "2025-05-21T11:16:03.920000-04:00",
            "modified": "2025-06-20T17:41:15.807000-04:00",
            "commentary": null
        },
        {
            "id": "CVE-2025-24928",
            "package": "libxml2",
            "score": "7.8",
            "severity": "high",
            "suppressed": null,
            "published": "2025-02-18T18:15:10.250000-05:00",
            "modified": "2025-03-21T18:15:34.860000-04:00",
            "commentary": null
        },
        {
            "id": "CVE-2024-56171",
            "package": "libxml2",
            "score": "7.8",
            "severity": "high",
            "suppressed": null,
            "published": "2025-02-18T17:15:12.797000-05:00",
            "modified": "2025-03-28T15:15:46.003000-04:00",
            "commentary": null
        },
        {
            "id": "OSV-2025-74",
            "package": "libxml2",
            "score": null,
            "severity": "high",
            "suppressed": null,
            "published": "2025-01-28T19:13:55.386256-05:00",
            "modified": "2025-01-28T19:13:55.386629-05:00",
            "commentary": null
        },
        {
            "id": "BIT-git-2024-52006",
            "package": "git",
            "score": null,
            "severity": null,
            "suppressed": null,
            "published": null,
            "modified": null,
            "commentary": null
        },
        {
            "id": "CVE-2024-52006",
            "package": "git",
            "score": "2.1",
            "severity": "low",
            "suppressed": null,
            "published": "2025-01-14T14:15:32.330000-05:00",
            "modified": "2025-01-21T17:15:14.423000-05:00",
            "commentary": null
        },
        {
            "id": "CVE-2024-52005",
            "package": "git",
            "score": "7.5",
            "severity": "high",
            "suppressed": null,
            "published": "2025-01-15T13:15:24.130000-05:00",
            "modified": "2025-01-15T18:15:24.130000-05:00",
            "commentary": null
        },
        {
            "id": "BIT-git-2024-50349",
            "package": "git",
            "score": null,
            "severity": null,
            "suppressed": null,
            "published": null,
            "modified": null,
            "commentary": null
        },
        {
            "id": "CVE-2024-50349",
            "package": "git",
            "score": "2.1",
            "severity": "low",
            "suppressed": null,
            "published": "2025-01-14T14:15:32.157000-05:00",
            "modified": "2025-01-21T17:15:14.287000-05:00",
            "commentary": null
        },
        {
            "id": "CVE-2024-13176",
            "package": "openssl",
            "score": "4.1",
            "severity": "medium",
            "suppressed": null,
            "published": "2025-01-20T09:15:26.247000-05:00",
            "modified": "2025-05-26T18:15:19.740000-04:00",
            "commentary": null
        },
        {
            "id": "CVE-2024-12797",
            "package": "openssl",
            "score": "6.3",
            "severity": "medium",
            "suppressed": null,
            "published": "2025-02-11T11:15:38.827000-05:00",
            "modified": "2025-02-18T14:15:27.107000-05:00",
            "commentary": null
        },
        {
            "id": "CVE-2024-12705",
            "package": "bind",
            "score": "7.5",
            "severity": "high",
            "suppressed": null,
            "published": "2025-01-29T17:15:28.800000-05:00",
            "modified": "2025-02-07T17:15:30.177000-05:00",
            "commentary": null
        },
        {
            "id": "CVE-2024-11187",
            "package": "bind",
            "score": "7.5",
            "severity": "high",
            "suppressed": null,
            "published": "2025-01-29T17:15:28.637000-05:00",
            "modified": "2025-02-11T19:15:12.640000-05:00",
            "commentary": null
        },
        {
            "id": "CVE-2024-10041",
            "package": "linux-pam",
            "score": "4.7",
            "severity": "medium",
            "suppressed": null,
            "published": "2024-10-23T10:15:03.970000-04:00",
            "modified": "2024-12-18T10:15:05.850000-05:00",
            "commentary": null
        },
        {
            "id": "CVE-2024-9143",
            "package": "openssl",
            "score": "4.3",
            "severity": "medium",
            "suppressed": null,
            "published": "2024-10-16T13:15:18.130000-04:00",
            "modified": "2024-11-21T09:54:04.817000-05:00",
            "commentary": null
        },
        {
            "id": "OSV-2024-1312",
            "package": "jq",
            "score": null,
            "severity": "medium",
            "suppressed": null,
            "published": "2024-11-14T19:16:08.928897-05:00",
            "modified": "2025-03-05T09:20:12.622041-05:00",
            "commentary": null
        },
        {
            "id": "OSV-2024-1209",
            "package": "libxml2",
            "score": null,
            "severity": "high",
            "suppressed": null,
            "published": "2024-10-10T20:15:43.610812-04:00",
            "modified": "2025-03-17T20:30:11.577855-04:00",
            "commentary": null
        },
        {
            "id": "OSV-2024-919",
            "package": "jq",
            "score": null,
            "severity": "medium",
            "suppressed": null,
            "published": "2024-08-15T20:09:34.461792-04:00",
            "modified": "2025-03-06T09:20:56.754046-05:00",
            "commentary": null
        },
        {
            "id": "OSV-2024-831",
            "package": "jq",
            "score": null,
            "severity": "medium",
            "suppressed": null,
            "published": "2024-08-15T20:03:12.871175-04:00",
            "modified": "2025-03-07T09:24:40.166702-05:00",
            "commentary": null
        },
        {
            "id": "OSV-2024-817",
            "package": "libpcap",
            "score": null,
            "severity": "medium",
            "suppressed": null,
            "published": "2024-08-15T20:02:39.185747-04:00",
            "modified": "2025-01-08T09:19:40.985698-05:00",
            "commentary": null
        },
        {
            "id": "OSV-2024-440",
            "package": "jq",
            "score": null,
            "severity": "medium",
            "suppressed": null,
            "published": "2024-05-06T20:06:11.033336-04:00",
            "modified": "2025-07-01T10:30:06.613574-04:00",
            "commentary": null
        },
        {
            "id": "OSV-2024-396",
            "package": "jq",
            "score": null,
            "severity": "medium",
            "suppressed": null,
            "published": "2024-04-30T20:11:24.552935-04:00",
            "modified": "2025-07-01T10:29:52.935440-04:00",
            "commentary": null
        },
        {
            "id": "OSV-2024-395",
            "package": "libpcap",
            "score": null,
            "severity": "medium",
            "suppressed": null,
            "published": "2024-04-30T20:04:54.392345-04:00",
            "modified": "2024-08-31T10:18:45.876646-04:00",
            "commentary": null
        },
        {
            "id": "OSV-2024-371",
            "package": "jq",
            "score": null,
            "severity": "medium",
            "suppressed": null,
            "published": "2024-04-29T20:08:27.982063-04:00",
            "modified": "2025-05-18T10:24:27.459047-04:00",
            "commentary": null
        },
        {
            "id": "OSV-2024-330",
            "package": "jq",
            "score": null,
            "severity": "medium",
            "suppressed": null,
            "published": "2024-04-29T20:00:31.577722-04:00",
            "modified": "2024-05-27T10:01:02.168724-04:00",
            "commentary": null
        },
        {
            "id": "GHSA-72fg-jqhx-c68p",
            "package": "st",
            "score": "6.1",
            "severity": "medium",
            "suppressed": null,
            "published": "2018-08-06T17:33:31-04:00",
            "modified": null,
            "commentary": null
        },
        {
            "id": "CVE-2023-7216",
            "package": "cpio",
            "score": "5.3",
            "severity": "medium",
            "suppressed": null,
            "published": "2024-02-05T10:15:08.903000-05:00",
            "modified": "2024-11-21T08:45:32.120000-05:00",
            "commentary": null
        },
        {
            "id": "OSV-2023-1398",
            "package": "file",
            "score": null,
            "severity": "medium",
            "suppressed": null,
            "published": "2024-10-31T20:02:38.719507-04:00",
            "modified": "2024-10-31T20:02:38.719949-04:00",
            "commentary": null
        },
        {
            "id": "OSV-2023-1344",
            "package": "jq",
            "score": null,
            "severity": "medium",
            "suppressed": null,
            "published": "2023-12-21T19:11:40.065456-05:00",
            "modified": "2025-03-05T09:16:07.938645-05:00",
            "commentary": null
        },
        {
            "id": "OSV-2023-1329",
            "package": "jq",
            "score": null,
            "severity": "high",
            "suppressed": null,
            "published": "2023-12-17T19:13:42.545765-05:00",
            "modified": "2025-02-17T09:14:20.492923-05:00",
            "commentary": null
        },
        {
            "id": "OSV-2023-1307",
            "package": "libbpf",
            "score": null,
            "severity": "medium",
            "suppressed": null,
            "published": "2023-12-14T19:12:51.528155-05:00",
            "modified": "2025-07-19T10:14:30.054184-04:00",
            "commentary": null
        },
        {
            "id": "OSV-2023-877",
            "package": "libbpf",
            "score": null,
            "severity": "medium",
            "suppressed": null,
            "published": "2023-09-18T10:02:44.989260-04:00",
            "modified": "2025-07-19T10:16:07.080224-04:00",
            "commentary": null
        },
        {
            "id": "OSV-2023-505",
            "package": "file",
            "score": null,
            "severity": "high",
            "suppressed": null,
            "published": "2023-06-22T10:02:20.855256-04:00",
            "modified": "2023-08-01T10:06:27.325503-04:00",
            "commentary": null
        },
        {
            "id": "OSV-2023-197",
            "package": "p11-kit",
            "score": null,
            "severity": null,
            "suppressed": null,
            "published": "2023-03-18T09:00:57.254906-04:00",
            "modified": "2024-07-04T10:16:04.301147-04:00",
            "commentary": null
        },
        {
            "id": "MAL-2022-4301",
            "package": "libidn2",
            "score": null,
            "severity": null,
            "suppressed": "Exception: This result is a false positive; the indicated package is an npm package and not the generic Linux library.",
            "published": null,
            "modified": null,
            "commentary": null
        },
        {
            "id": "CVE-2022-3219",
            "package": "gnupg",
            "score": "3.3",
            "severity": "low",
            "suppressed": null,
            "published": "2023-02-23T15:15:12.393000-05:00",
            "modified": "2025-03-12T21:15:38.207000-04:00",
            "commentary": null
        },
        {
            "id": "GHSA-rjvj-673q-4hfw",
            "package": "traceroute",
            "score": null,
            "severity": "critical",
            "suppressed": "Exception: This result is a false positive; the indicated vulnerability only applies to the npm package, not the generic Linux utility.",
            "published": "2020-09-04T13:54:31-04:00",
            "modified": null,
            "commentary": null
        },
        {
            "id": "GHSA-8rc5-mr4f-m243",
            "package": "rio",
            "score": "9.8",
            "severity": "critical",
            "suppressed": null,
            "published": "2021-08-25T16:46:57-04:00",
            "modified": null,
            "commentary": null
        },
        {
            "id": "OSV-2021-777",
            "package": "libxml2",
            "score": null,
            "severity": "high",
            "suppressed": null,
            "published": "2021-05-19T20:00:30.166614-04:00",
            "modified": "2025-07-15T10:06:11.764231-04:00",
            "commentary": null
        },
        {
            "id": "RUSTSEC-2020-0021",
            "package": "rio",
            "score": null,
            "severity": null,
            "suppressed": null,
            "published": null,
            "modified": null,
            "commentary": null
        },
        {
            "id": "CVE-2019-20633",
            "package": "patch",
            "score": "5.5",
            "severity": "medium",
            "suppressed": null,
            "published": "2020-03-25T13:15:14.013000-04:00",
            "modified": "2024-11-21T04:38:55.590000-05:00",
            "commentary": null
        },
        {
            "id": "CVE-2019-6470",
            "package": "bind",
            "score": "7.5",
            "severity": "high",
            "suppressed": "Exception: Controller DHCP functionality is provided via systemd-networkd and so are not subject to vulnerabilities in dhcpcd.",
            "published": "2019-11-01T19:15:10.510000-04:00",
            "modified": "2025-04-11T14:55:14.483000-04:00",
            "commentary": null
        },
        {
            "id": "RUSTSEC-2019-0006",
            "package": "ncurses",
            "score": null,
            "severity": null,
            "suppressed": null,
            "published": null,
            "modified": null,
            "commentary": null
        },
        {
            "id": "CVE-2016-2781",
            "package": "coreutils",
            "score": "4.6",
            "severity": "medium",
            "suppressed": null,
            "published": "2017-02-07T10:59:00.333000-05:00",
            "modified": "2025-06-09T16:15:25.013000-04:00",
            "commentary": null
        },
        {
            "id": "CVE-2013-4577",
            "package": "grub",
            "score": "2.1",
            "severity": null,
            "suppressed": "Exception: False positive; this is a Debian-specific vulnerability applicable only to Debian-based systems.",
            "published": "2014-05-12T10:55:05.023000-04:00",
            "modified": "2025-04-12T10:46:40.837000-04:00",
            "commentary": null
        },
        {
            "id": "CVE-2010-4226",
            "package": "cpio",
            "score": "7.2",
            "severity": "high",
            "suppressed": "Exception: False positive; this vulnerability only applies to systems that use RPM packaging, which Controllers do not.",
            "published": "2014-02-06T12:00:03.167000-05:00",
            "modified": "2025-06-09T15:15:22.147000-04:00",
            "commentary": null
        },
        {
            "id": "BIT-git-2024-52005",
            "package": "git",
            "score": null,
            "severity": null,
            "suppressed": null,
            "published": null,
            "modified": null,
            "commentary": null
        },
        {
            "id": "BIT-grafana-2024-11741",
            "package": "grafana",
            "score": null,
            "severity": null,
            "suppressed": null,
            "published": null,
            "modified": null,
            "commentary": null
        },
        {
            "id": "BIT-grafana-2024-10452",
            "package": "grafana",
            "score": null,
            "severity": null,
            "suppressed": null,
            "published": null,
            "modified": null,
            "commentary": null
        },
        {
            "id": "BIT-sqlite-2024-0232",
            "package": "sqlite",
            "score": null,
            "severity": null,
            "suppressed": null,
            "published": null,
            "modified": null,
            "commentary": null
        },
        {
            "id": "CVE-2025-27113",
            "package": "libxml2",
            "score": "7.5",
            "severity": "high",
            "suppressed": null,
            "published": "2025-02-18T18:15:10.960000-05:00",
            "modified": "2025-03-07T01:15:12.823000-05:00",
            "commentary": null
        },
        {
            "id": "CVE-2024-53427",
            "package": "jq",
            "score": "8.1",
            "severity": "high",
            "suppressed": null,
            "published": "2025-02-26T11:15:16.237000-05:00",
            "modified": "2025-07-01T21:25:24.020000-04:00",
            "commentary": null
        },
        {
            "id": "CVE-2025-32414",
            "package": "libxml2",
            "score": "7.5",
            "severity": "high",
            "suppressed": null,
            "published": "2025-04-07T23:15:15.940000-04:00",
            "modified": "2025-04-23T19:09:35.517000-04:00",
            "commentary": null
        },
        {
            "id": "BIT-sqlite-2025-29087",
            "package": "sqlite",
            "score": null,
            "severity": null,
            "suppressed": null,
            "published": null,
            "modified": null,
            "commentary": null
        },
        {
            "id": "CVE-2025-29087",
            "package": "sqlite",
            "score": "7.5",
            "severity": "high",
            "suppressed": null,
            "published": "2025-04-07T16:15:20.253000-04:00",
            "modified": "2025-04-30T12:43:22.310000-04:00",
            "commentary": null
        },
        {
            "id": "CVE-2025-3360",
            "package": "glib",
            "score": "3.7",
            "severity": "low",
            "suppressed": null,
            "published": "2025-04-07T09:15:43.687000-04:00",
            "modified": "2025-04-14T12:15:16.087000-04:00",
            "commentary": null
        },
        {
            "id": "BIT-sqlite-2025-3277",
            "package": "sqlite",
            "score": null,
            "severity": null,
            "suppressed": null,
            "published": null,
            "modified": null,
            "commentary": null
        },
        {
            "id": "CVE-2025-3277",
            "package": "sqlite",
            "score": "6.9",
            "severity": "medium",
            "suppressed": null,
            "published": "2025-04-14T13:15:27.297000-04:00",
            "modified": "2025-08-01T18:29:43.060000-04:00",
            "commentary": null
        },
        {
            "id": "CVE-2025-25724",
            "package": "libarchive",
            "score": "7.8",
            "severity": "high",
            "suppressed": null,
            "published": "2025-03-01T21:15:36.603000-05:00",
            "modified": "2025-07-17T15:56:36.083000-04:00",
            "commentary": null
        },
        {
            "id": "CVE-2024-57970",
            "package": "libarchive",
            "score": "4.0",
            "severity": "medium",
            "suppressed": null,
            "published": "2025-02-15T23:15:21.843000-05:00",
            "modified": "2025-02-18T17:15:19.130000-05:00",
            "commentary": null
        },
        {
            "id": "CVE-2025-1632",
            "package": "libarchive",
            "score": "4.8",
            "severity": "medium",
            "suppressed": null,
            "published": "2025-02-24T09:15:11.590000-05:00",
            "modified": "2025-03-25T15:41:41.683000-04:00",
            "commentary": null
        },
        {
            "id": "CVE-2025-46394",
            "package": "busybox",
            "score": "3.2",
            "severity": "low",
            "suppressed": null,
            "published": "2025-04-23T12:15:48.713000-04:00",
            "modified": "2025-04-29T13:52:47.470000-04:00",
            "commentary": null
        },
        {
            "id": "CVE-2025-32415",
            "package": "libxml2",
            "score": "7.5",
            "severity": "high",
            "suppressed": null,
            "published": "2025-04-17T13:15:33.733000-04:00",
            "modified": "2025-04-23T18:17:52.053000-04:00",
            "commentary": null
        },
        {
            "id": "BIT-grafana-2025-2703",
            "package": "grafana",
            "score": null,
            "severity": null,
            "suppressed": null,
            "published": null,
            "modified": null,
            "commentary": null
        },
        {
            "id": "CVE-2025-2703",
            "package": "grafana",
            "score": "6.8",
            "severity": "medium",
            "suppressed": null,
            "published": "2025-04-23T08:15:16.103000-04:00",
            "modified": "2025-06-10T11:15:52.680000-04:00",
            "commentary": null
        },
        {
            "id": "CVE-2024-58251",
            "package": "busybox",
            "score": "2.5",
            "severity": "low",
            "suppressed": null,
            "published": "2025-04-23T14:16:03.057000-04:00",
            "modified": "2025-04-29T13:52:47.470000-04:00",
            "commentary": null
        },
        {
            "id": "CVE-2024-56406",
            "package": "perl",
            "score": "8.6",
            "severity": "high",
            "suppressed": null,
            "published": "2025-04-13T10:15:14.527000-04:00",
            "modified": "2025-04-30T15:21:11.547000-04:00",
            "commentary": null
        }
    ],
    "created": "2025-02-18T22:23:35.742359-05:00",
    "package": 12680,
    "next_scan": null,
    "scanned": "2025-05-23T19:51:04.609676-04:00",
    "id": 1794,
    "has_cdx": true,
    "has_spdx": true,
    "scanning": false,
    "queued": false
}