{
	"SPDXID":"SPDXRef-DOCUMENT",
	"name":"debootstrap-0.1.0.134-1.oe2409.aarch64.rpm",
	"spdxVersion":"SPDX-2.2",
	"creationInfo":{
		"created":"2024-09-30T03:30:07.5589037Z",
		"creators":"[openeuler_creator]"
	},
	"dataLicense":"CC0-1.0",
	"documentNamespace":"https://repo.openeuler.org/security/data/sbom/debootstrap-0.1.0.134-1.oe2409.aarch64.rpm",
	"packages":[
		{
			"SPDXID":"SPDXRef-rpm-bash-5.2.21-79ee3f1b-b075-4c10-8970-bf7c22384c2c-f2f84bcd-e587-444b-8259-84a918424858",
			"name":"bash",
			"checksums":[
				{
					"algorithm":"SHA256",
					"checksumValue":"0648f5dde35fc9fcf57a6a9c95dae3273cbb784ba492931ff20874906827ed39"
				}
			],
			"description":"Bash is the GNU Project's shell. Bash is the Bourne Again SHell. Bash is an sh-compatible\nshell that incorporates useful features from the Korn shell (ksh) and C shell (csh). It is\nintended to conform to the IEEE POSIX P1003.2/ISO 9945.2 Shell and Tools standard. It offers\nfunctional improvements over sh for both programming and interactive use. In addition, most\nsh scripts can be run by Bash without modification.",
			"downloadLocation":"NOASSERTION",
			"externalRefs":[
				{
					"referenceCategory":"PACKAGE_MANAGER",
					"referenceLocator":"pkg:rpm/bash@5.2.21-1.oe2409?arch=aarch64&epoch=0&upstream=bash-5.2.21-1.oe2409.src.rpm",
					"referenceType":"purl"
				}
			],
			"filesAnalyzed":false,
			"homepage":"https://www.gnu.org/software/bash",
			"sourceInfo":"acquired package info from repodata DB: repodata/6e742f68b2ae62313d1861c02b7faa39b44c963cbbc6ac979fb577de9af9babc-primary.sqlite.bz2",
			"summary":"It is the Bourne Again Shell",
			"supplier":"Organization: http://openeuler.org",
			"versionInfo":"0:5.2.21-1.oe2409"
		},
		{
			"SPDXID":"SPDXRef-rpm-coreutils-9.5-3bf74e8c-0121-4371-b650-f2040d5a9a56-d05ac738-64bc-47c0-a249-2af1bbde71de",
			"name":"coreutils",
			"checksums":[
				{
					"algorithm":"SHA256",
					"checksumValue":"2f5af68ccffa26a602437b1920467462bfd75facc2bb18bdc2fd9140eb7dc702"
				}
			],
			"description":"These are the GNU core utilities.  This package is the combination of\nthe old GNU fileutils, sh-utils, and textutils packages.",
			"downloadLocation":"NOASSERTION",
			"externalRefs":[
				{
					"referenceCategory":"PACKAGE_MANAGER",
					"referenceLocator":"pkg:rpm/coreutils@9.5-4.oe2409?arch=aarch64&epoch=0&upstream=coreutils-9.5-4.oe2409.src.rpm",
					"referenceType":"purl"
				}
			],
			"filesAnalyzed":false,
			"homepage":"https://www.gnu.org/software/coreutils/",
			"sourceInfo":"acquired package info from repodata DB: repodata/6e742f68b2ae62313d1861c02b7faa39b44c963cbbc6ac979fb577de9af9babc-primary.sqlite.bz2",
			"summary":"A set of basic GNU tools commonly used in shell scripts",
			"supplier":"Organization: http://openeuler.org",
			"versionInfo":"0:9.5-4.oe2409"
		},
		{
			"SPDXID":"SPDXRef-rpm-dpkg-1.21.22-e050548a-ea6f-4024-8f26-5ebb1858769c-f67c1d78-09e4-4630-a325-8c52c6dd8018",
			"name":"dpkg",
			"checksums":[
				{
					"algorithm":"SHA256",
					"checksumValue":"c90f704ed02a38078cc145c4957f22f42530f99f04c4b192eba73c9f960f96a5"
				}
			],
			"description":"Dpkg is a tool to install, build, remove and manageDebian packages. The\nprimary and more user-friendly front-end for dpkg is aptitude.",
			"downloadLocation":"NOASSERTION",
			"externalRefs":[
				{
					"referenceCategory":"PACKAGE_MANAGER",
					"referenceLocator":"pkg:rpm/dpkg@1.21.22-1.oe2409?arch=aarch64&epoch=0&upstream=dpkg-1.21.22-1.oe2409.src.rpm",
					"referenceType":"purl"
				}
			],
			"filesAnalyzed":false,
			"homepage":"https://tracker.debian.org/pkg/dpkg",
			"sourceInfo":"acquired package info from repodata DB: repodata/6e742f68b2ae62313d1861c02b7faa39b44c963cbbc6ac979fb577de9af9babc-primary.sqlite.bz2",
			"summary":"Package maintenance system for Debian Linux",
			"supplier":"Organization: http://openeuler.org",
			"versionInfo":"0:1.21.22-1.oe2409"
		},
		{
			"SPDXID":"SPDXRef-rpm-gettext-0.22.5-25cde8d0-a68f-46bb-add4-daa5bfa11573-7d374b7e-d8a3-40df-8c42-121a4f1af9d6",
			"name":"gettext",
			"checksums":[
				{
					"algorithm":"SHA256",
					"checksumValue":"554bfcdbb5eb46fafb4cc6a33234fd5f97cbb1e0c48bc610b2da7a2f706ce5ca"
				}
			],
			"description":"GNU gettext is an important step for the GNU Translation Project, as it\nis an asset on which we may build many other steps. This package offers\nto programmers, translators, and even users, a well integrated set of\ntools and documentation. Specifically, the GNU gettext utilities are a\nset of tools that provides a framework to help other GNU packages\nproduce multi-lingual messages. These tools include a set of conventions\nabout how programs should be written to support message catalogs, a\ndirectory and file naming organization for the message catalogs themselves,\na runtime library supporting the retrieval of translated messages, and\na few stand-alone programs to massage in various ways the sets of\ntranslatable strings, or already translated strings. A special GNU Emacs\nmode also helps interested parties in preparing these sets, or bringing\nthem up to date.",
			"downloadLocation":"NOASSERTION",
			"externalRefs":[
				{
					"referenceCategory":"PACKAGE_MANAGER",
					"referenceLocator":"pkg:rpm/gettext@0.22.5-1.oe2409?arch=aarch64&epoch=0&upstream=gettext-0.22.5-1.oe2409.src.rpm",
					"referenceType":"purl"
				}
			],
			"filesAnalyzed":false,
			"homepage":"https://www.gnu.org/software/gettext/",
			"sourceInfo":"acquired package info from repodata DB: repodata/6e742f68b2ae62313d1861c02b7faa39b44c963cbbc6ac979fb577de9af9babc-primary.sqlite.bz2",
			"summary":"GNU gettext utilities are a set of tools that provides a framework to help other GNU packages produce multi-lingual messages.",
			"supplier":"Organization: http://openeuler.org",
			"versionInfo":"0:0.22.5-1.oe2409"
		},
		{
			"SPDXID":"SPDXRef-rpm-gzip-1.13-71af26d0-0dca-471d-84d9-9473e87f8375-7637183c-74a5-43dc-bab2-e8f803113cc4",
			"name":"gzip",
			"checksums":[
				{
					"algorithm":"SHA256",
					"checksumValue":"a59de8b92bc8607dd39cc0945d6950ae2dad34975449d072a758e3514a42fbe6"
				}
			],
			"description":"gzip is a single-file/stream lossless data compression\nutility, where the resulting compressed file generally\nhas the suffix .gz.",
			"downloadLocation":"NOASSERTION",
			"externalRefs":[
				{
					"referenceCategory":"PACKAGE_MANAGER",
					"referenceLocator":"pkg:rpm/gzip@1.13-1.oe2409?arch=aarch64&epoch=0&upstream=gzip-1.13-1.oe2409.src.rpm",
					"referenceType":"purl"
				}
			],
			"filesAnalyzed":false,
			"homepage":"https://www.gnu.org/software/gzip",
			"sourceInfo":"acquired package info from repodata DB: repodata/6e742f68b2ae62313d1861c02b7faa39b44c963cbbc6ac979fb577de9af9babc-primary.sqlite.bz2",
			"summary":"A data compression utility",
			"supplier":"Organization: http://openeuler.org",
			"versionInfo":"0:1.13-1.oe2409"
		},
		{
			"SPDXID":"SPDXRef-rpm-perl-5.38.0-3373dd29-00bf-4751-bc96-5b01fbd1f07c-acb4c46c-ed04-40ae-8a3a-8f8a5783e8dc",
			"name":"perl",
			"checksums":[
				{
					"algorithm":"SHA256",
					"checksumValue":"1cc1d4df3e2feb90c5250bb3619d63d60b9ec82bb75e180bdeecccce97e37e91"
				}
			],
			"description":"Perl 5 is a highly capable, feature-rich programming language with over 30 years of development.\nPerl 5 runs on over 100 platforms from portables to mainframes and is suitable for both rapid\nprototyping and large scale development projects.",
			"downloadLocation":"NOASSERTION",
			"externalRefs":[
				{
					"referenceCategory":"PACKAGE_MANAGER",
					"referenceLocator":"pkg:rpm/perl@5.38.0-8.oe2409?arch=aarch64&epoch=4&upstream=perl-5.38.0-8.oe2409.src.rpm",
					"referenceType":"purl"
				}
			],
			"filesAnalyzed":false,
			"homepage":"https://www.perl.org/",
			"sourceInfo":"acquired package info from repodata DB: repodata/6e742f68b2ae62313d1861c02b7faa39b44c963cbbc6ac979fb577de9af9babc-primary.sqlite.bz2",
			"summary":"A highly capable, feature-rich programming language",
			"supplier":"Organization: http://openeuler.org",
			"versionInfo":"4:5.38.0-8.oe2409"
		},
		{
			"SPDXID":"SPDXRef-rpm-tar-1.35-404d2df1-5a3a-4b8e-b2fa-14d7dd8ad2d5-59b60a7e-db8a-4d98-b9c4-7d178835044e",
			"name":"tar",
			"checksums":[
				{
					"algorithm":"SHA256",
					"checksumValue":"a2cd91ffa50e3b1e20180ee00c53e72dbb47a8db59af2119dc7b0cb4bbd743b8"
				}
			],
			"description":"GNU Tar provides the ability to create tar archives, as well as various other\nkinds of manipulation. For example, you can use Tar on previously created archives\nto extract files, to store additional files, or to update or list files which were\nalready stored.",
			"downloadLocation":"NOASSERTION",
			"externalRefs":[
				{
					"referenceCategory":"PACKAGE_MANAGER",
					"referenceLocator":"pkg:rpm/tar@1.35-2.oe2409?arch=aarch64&epoch=2&upstream=tar-1.35-2.oe2409.src.rpm",
					"referenceType":"purl"
				}
			],
			"filesAnalyzed":false,
			"homepage":"http://www.gnu.org/software/tar/",
			"sourceInfo":"acquired package info from repodata DB: repodata/6e742f68b2ae62313d1861c02b7faa39b44c963cbbc6ac979fb577de9af9babc-primary.sqlite.bz2",
			"summary":"An organized and systematic method of controlling a large amount of data",
			"supplier":"Organization: http://openeuler.org",
			"versionInfo":"2:1.35-2.oe2409"
		},
		{
			"SPDXID":"SPDXRef-rpm-wget-1.21.4-915ae1fe-0526-4bfe-bb78-2576027abe03-ddb04c78-77b7-4f14-84a9-f020d5176604",
			"name":"wget",
			"checksums":[
				{
					"algorithm":"SHA256",
					"checksumValue":"a9bff51cc05ce7c8514f2e74bbfab08a4ba8618b313600c520d94a70807920b0"
				}
			],
			"description":"GNU Wget is a free software package for retrieving files using HTTP, HTTPS,\nFTP and FTPS the most widely-used Internet protocols. It is a non-interactive\ncommandline tool, so it may easily be called from scripts, cron jobs, terminals\nwithout X-Windows support, etc.",
			"downloadLocation":"NOASSERTION",
			"externalRefs":[
				{
					"referenceCategory":"PACKAGE_MANAGER",
					"referenceLocator":"pkg:rpm/wget@1.21.4-2.oe2409?arch=aarch64&epoch=0&upstream=wget-1.21.4-2.oe2409.src.rpm",
					"referenceType":"purl"
				}
			],
			"filesAnalyzed":false,
			"homepage":"http://www.gnu.org/software/wget/",
			"sourceInfo":"acquired package info from repodata DB: repodata/6e742f68b2ae62313d1861c02b7faa39b44c963cbbc6ac979fb577de9af9babc-primary.sqlite.bz2",
			"summary":"A package for retrieving files using HTTP, HTTPS, FTP and FTPS the most widely-used Internet protocols.",
			"supplier":"Organization: http://openeuler.org",
			"versionInfo":"0:1.21.4-2.oe2409"
		},
		{
			"SPDXID":"SPDXRef-rpm-xz-5.4.7-a3276dac-5701-4078-accd-441da6142cb8-4e904939-0d24-42a6-a845-f7b3408ec48f",
			"name":"xz",
			"checksums":[
				{
					"algorithm":"SHA256",
					"checksumValue":"b0c5487eac6e3c3027f4ce0fdd9dbcb76909417529dacc4433dbc281170f1aef"
				}
			],
			"description":"XZ Utils is free general-purpose data compression software with a high compression ratio.\nXZ Utils were written for POSIX-like systems, but also work on some not-so-POSIX systems. XZ Utils are the successor to LZMA Utils.\n\nThe core of the XZ Utils compression code is based on LZMA SDK, but it has been modified quite a lot to be suitable for XZ Utils.\nThe primary compression algorithm is currently LZMA2, which is used inside the .xz container format. With typical files, XZ Utils create 30% smaller output than gzip and 15% smaller output than bzip2.",
			"downloadLocation":"NOASSERTION",
			"externalRefs":[
				{
					"referenceCategory":"PACKAGE_MANAGER",
					"referenceLocator":"pkg:rpm/xz@5.4.7-1.oe2409?arch=aarch64&epoch=0&upstream=xz-5.4.7-1.oe2409.src.rpm",
					"referenceType":"purl"
				}
			],
			"filesAnalyzed":false,
			"homepage":"http://tukaani.org/xz",
			"sourceInfo":"acquired package info from repodata DB: repodata/6e742f68b2ae62313d1861c02b7faa39b44c963cbbc6ac979fb577de9af9babc-primary.sqlite.bz2",
			"summary":"A free general-purpose data compreession software with LZMA2 algorithm",
			"supplier":"Organization: http://openeuler.org",
			"versionInfo":"0:5.4.7-1.oe2409"
		}
	],
	"relationships":[
		{
			"spdxElementId":"SPDXRef-rpm-debootstrap-1.0.134-b686ec4e-a691-41ca-8270-b3715019ac97",
			"relationshipType":"DEPENDS_ON",
			"relatedSpdxElement":"SPDXRef-rpm-bash-5.2.21-79ee3f1b-b075-4c10-8970-bf7c22384c2c-f2f84bcd-e587-444b-8259-84a918424858"
		},
		{
			"spdxElementId":"SPDXRef-rpm-debootstrap-1.0.134-b686ec4e-a691-41ca-8270-b3715019ac97",
			"relationshipType":"DEPENDS_ON",
			"relatedSpdxElement":"SPDXRef-rpm-coreutils-9.5-3bf74e8c-0121-4371-b650-f2040d5a9a56-d05ac738-64bc-47c0-a249-2af1bbde71de"
		},
		{
			"spdxElementId":"SPDXRef-rpm-debootstrap-1.0.134-b686ec4e-a691-41ca-8270-b3715019ac97",
			"relationshipType":"DEPENDS_ON",
			"relatedSpdxElement":"SPDXRef-rpm-dpkg-1.21.22-e050548a-ea6f-4024-8f26-5ebb1858769c-f67c1d78-09e4-4630-a325-8c52c6dd8018"
		},
		{
			"spdxElementId":"SPDXRef-rpm-debootstrap-1.0.134-b686ec4e-a691-41ca-8270-b3715019ac97",
			"relationshipType":"DEPENDS_ON",
			"relatedSpdxElement":"SPDXRef-rpm-gettext-0.22.5-25cde8d0-a68f-46bb-add4-daa5bfa11573-7d374b7e-d8a3-40df-8c42-121a4f1af9d6"
		},
		{
			"spdxElementId":"SPDXRef-rpm-debootstrap-1.0.134-b686ec4e-a691-41ca-8270-b3715019ac97",
			"relationshipType":"DEPENDS_ON",
			"relatedSpdxElement":"SPDXRef-rpm-gzip-1.13-71af26d0-0dca-471d-84d9-9473e87f8375-7637183c-74a5-43dc-bab2-e8f803113cc4"
		},
		{
			"spdxElementId":"SPDXRef-rpm-debootstrap-1.0.134-b686ec4e-a691-41ca-8270-b3715019ac97",
			"relationshipType":"DEPENDS_ON",
			"relatedSpdxElement":"SPDXRef-rpm-perl-5.38.0-3373dd29-00bf-4751-bc96-5b01fbd1f07c-acb4c46c-ed04-40ae-8a3a-8f8a5783e8dc"
		},
		{
			"spdxElementId":"SPDXRef-rpm-debootstrap-1.0.134-b686ec4e-a691-41ca-8270-b3715019ac97",
			"relationshipType":"DEPENDS_ON",
			"relatedSpdxElement":"SPDXRef-rpm-tar-1.35-404d2df1-5a3a-4b8e-b2fa-14d7dd8ad2d5-59b60a7e-db8a-4d98-b9c4-7d178835044e"
		},
		{
			"spdxElementId":"SPDXRef-rpm-debootstrap-1.0.134-b686ec4e-a691-41ca-8270-b3715019ac97",
			"relationshipType":"DEPENDS_ON",
			"relatedSpdxElement":"SPDXRef-rpm-wget-1.21.4-915ae1fe-0526-4bfe-bb78-2576027abe03-ddb04c78-77b7-4f14-84a9-f020d5176604"
		},
		{
			"spdxElementId":"SPDXRef-rpm-debootstrap-1.0.134-b686ec4e-a691-41ca-8270-b3715019ac97",
			"relationshipType":"DEPENDS_ON",
			"relatedSpdxElement":"SPDXRef-rpm-xz-5.4.7-a3276dac-5701-4078-accd-441da6142cb8-4e904939-0d24-42a6-a845-f7b3408ec48f"
		}
	]
}