{
  "bomFormat": "CycloneDX",
  "specVersion": "1.4",
  "version": 1,
  "serialNumber": "urn:uuid:915f5e6f-b994-466c-b876-8c8bff78a751",
  "metadata": {
    "timestamp": "2026-07-20T09:38:00Z",
    "tools": [
      {
        "name": "decode_sbom.py",
        "vendor": "coreboot"
      }
    ],
    "component": {
      "type": "firmware",
      "bom-ref": "a9032c9d-2aaa-5a25-a0e6-6d865b24e6d2",
      "name": "coreboot",
      "purl": "pkg:generic/org.coreboot.rocks/coreboot@974f6ff0838821e198e3d511c1997ce1671c7731",
      "version": "974f6ff0838821e198e3d511c1997ce1671c7731",
      "supplier": {
        "name": "coreboot"
      }
    }
  },
  "components": [
    {
      "type": "firmware",
      "bom-ref": "a9032c9d-2aaa-5a25-a0e6-6d865b24e6d2",
      "name": "coreboot",
      "purl": "pkg:generic/org.coreboot.rocks/coreboot@974f6ff0838821e198e3d511c1997ce1671c7731",
      "cpe": "cpe:2.3:o:coreboot:coreboot:*:*:*:*:*:*:*:*",
      "version": "974f6ff0838821e198e3d511c1997ce1671c7731",
      "description": "coreboot is a project to develop open source boot firmware for various architectures",
      "supplier": {
        "name": "coreboot"
      },
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/coreboot/coreboot"
        }
      ],
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0"
          }
        },
        {
          "license": {
            "id": "BSD-2-Clause-Patent"
          }
        },
        {
          "license": {
            "id": "BSD-2-Clause"
          }
        },
        {
          "license": {
            "id": "BSD-3-Clause"
          }
        },
        {
          "license": {
            "id": "BSD-4-Clause-UC"
          }
        },
        {
          "license": {
            "id": "CC-BY-4.0"
          }
        },
        {
          "license": {
            "id": "CC-BY-SA-3.0"
          }
        },
        {
          "license": {
            "id": "CC-PDDC"
          }
        },
        {
          "license": {
            "id": "GPL-2.0-only"
          }
        },
        {
          "license": {
            "id": "GPL-2.0-or-later"
          }
        },
        {
          "license": {
            "id": "GPL-3.0-only"
          }
        },
        {
          "license": {
            "id": "GPL-3.0-or-later"
          }
        },
        {
          "license": {
            "id": "HPND-sell-variant"
          }
        },
        {
          "license": {
            "id": "HPND"
          }
        },
        {
          "license": {
            "id": "ISC"
          }
        },
        {
          "license": {
            "id": "LGPL-2.1-or-later"
          }
        },
        {
          "license": {
            "id": "MIT"
          }
        },
        {
          "license": {
            "id": "X11"
          }
        },
        {
          "license": {
            "url": "https://spdx.org/licenses/exceptions.html"
          }
        }
      ]
    },
    {
      "type": "firmware",
      "bom-ref": "9579af2b-39d8-59f1-ac5a-5b1fd4c03bd0",
      "name": "Intel Management Engine",
      "purl": "pkg:generic/com.intel.me/intel-management-engine@18.1.18.2724",
      "cpe": "cpe:2.3:o:intel:management_engine_firmware:18.1.18.2724:*:*:*:*:*:*:*",
      "version": "18.1.18.2724",
      "description": "Intel Management Engine firmware",
      "supplier": {
        "name": "Intel"
      }
    },
    {
      "type": "firmware",
      "bom-ref": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
      "name": "edk2",
      "purl": "pkg:generic/org.tianocore.edk2/edk2@df70843402b8eb4be3a29364f52d043c5a2a8708",
      "cpe": "cpe:2.3:a:tianocore:edk2:*:*:*:*:*:*:*:*",
      "version": "df70843402b8eb4be3a29364f52d043c5a2a8708",
      "description": "EDK II is a modern, feature-rich, cross-platform firmware development environment for the UEFI and UEFI Platform Initialization (PI) specifications. It is used as a coreboot payload to provide a UEFI environment.",
      "supplier": {
        "name": "TianoCore"
      },
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/tianocore/edk2"
        }
      ]
    },
    {
      "type": "firmware",
      "bom-ref": "c062f4db-917e-533a-8b42-c704759ec6d8",
      "name": "edk2-platforms",
      "purl": "pkg:generic/org.tianocore.edk2-platforms/edk2-platforms@1002a59639f111a2f8178b77d1f5fde0ea8d976f",
      "version": "1002a59639f111a2f8178b77d1f5fde0ea8d976f",
      "description": "edk2-platforms provides sample platform and silicon support packages for EDK II. This build uses the Dasharo fork (github.com/Dasharo/edk2-platforms), a fork of tianocore/edk2-platforms, integrated into the edk2 UEFI payload build.",
      "supplier": {
        "name": "TianoCore"
      },
      "licenses": [
        {
          "license": {
            "id": "BSD-2-Clause-Patent"
          }
        }
      ]
    },
    {
      "type": "firmware",
      "bom-ref": "23edb84c-5d68-544e-b389-8a67f6c80247",
      "name": "Intel-Microcode",
      "purl": "pkg:generic/com.intel.microcode/intel-microcode@2025-09-24",
      "cpe": "cpe:2.3:o:intel:microcode:2025-09-24:*:*:*:*:*:*:*",
      "version": "2025-09-24",
      "description": "Micrcode Updates for Intel Processors",
      "supplier": {
        "name": "Intel"
      },
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files"
        }
      ]
    },
    {
      "type": "firmware",
      "bom-ref": "719e6299-4355-5beb-b182-9cf47928515a",
      "name": "Intel Firmware Support Package",
      "purl": "pkg:generic/com.intel.fsp/intel-firmware-support-package@6114_54",
      "version": "(6114_54)",
      "description": "Intel Firmware Support Package (FSP) is a binary blob providing memory initialization and silicon bring-up for Intel platforms",
      "supplier": {
        "name": "Intel"
      },
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/intel/FSP"
        }
      ]
    },
    {
      "type": "firmware",
      "bom-ref": "9a5e8734-7068-5502-9f6a-6e1bcffb77dd",
      "name": "Intel Flash Descriptor",
      "purl": "pkg:generic/intel-flash-descriptor@647347aea4c13e7718fc37cbcc30979f07db0067",
      "version": "647347aea4c13e7718fc37cbcc30979f07db0067",
      "description": "The Intel Flash Descriptor defines the flash layout and hardware strap settings for Intel platforms",
      "supplier": {
        "name": "coreboot"
      }
    },
    {
      "type": "firmware",
      "bom-ref": "5f700e15-4845-57b5-a4bb-44e698ce4947",
      "name": "iPXE",
      "purl": "pkg:generic/org.ipxe/ipxe@6c7068fce4bba31b4d03a6990dedc530c0727588",
      "version": "6c7068fce4bba31b4d03a6990dedc530c0727588",
      "description": "iPXE is an open source network boot firmware. It provides a full PXE implementation enhanced with additional features",
      "supplier": {
        "name": "iPXE"
      },
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://github.com/ipxe/ipxe"
        }
      ]
    },
    {
      "type": "firmware",
      "bom-ref": "7d6f330b-8561-54ac-b507-a143b12e1d32",
      "name": "vboot",
      "purl": "pkg:generic/org.chromium.vboot/vboot@f1f70f46dc5482bb7c654e53ed58d4001e386df2",
      "version": "f1f70f46dc5482bb7c654e53ed58d4001e386df2",
      "description": "Chromium OS Verified Boot reference implementation, used by coreboot for firmware verification and anti-rollback protection.",
      "supplier": {
        "name": "Google"
      },
      "externalReferences": [
        {
          "type": "vcs",
          "url": "https://chromium.googlesource.com/chromiumos/platform/vboot_reference"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "a9032c9d-2aaa-5a25-a0e6-6d865b24e6d2",
      "dependsOn": [
        "9579af2b-39d8-59f1-ac5a-5b1fd4c03bd0",
        "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
        "c062f4db-917e-533a-8b42-c704759ec6d8",
        "23edb84c-5d68-544e-b389-8a67f6c80247",
        "719e6299-4355-5beb-b182-9cf47928515a",
        "9a5e8734-7068-5502-9f6a-6e1bcffb77dd",
        "5f700e15-4845-57b5-a4bb-44e698ce4947",
        "7d6f330b-8561-54ac-b507-a143b12e1d32"
      ]
    }
  ]
}
