{"id":20202,"date":"2023-05-18T20:14:55","date_gmt":"2023-05-18T18:14:55","guid":{"rendered":"http:\/\/blog.wenzlaff.de\/?p=20202"},"modified":"2023-05-18T20:14:55","modified_gmt":"2023-05-18T18:14:55","slug":"software-bill-of-materials-sbom-mit-cyclonedx-maven-plugin-leicht-erzeugen","status":"publish","type":"post","link":"http:\/\/blog.wenzlaff.de\/?p=20202","title":{"rendered":"Software Bill of Materials (SBOM) mit CycloneDX Maven Plugin leicht erzeugen"},"content":{"rendered":"<p>In einer zunehmend vernetzten und digitalisierten Welt sind Softwarekomponenten und -anwendungen allgegenw\u00e4rtig. Unternehmen verlassen sich auf komplexe Softwarel\u00f6sungen, um ihre Gesch\u00e4ftsprozesse zu unterst\u00fctzen und innovative Produkte und Dienstleistungen anzubieten. Angesichts der wachsenden Bedrohungen durch Sicherheitsl\u00fccken und Compliance-Anforderungen wird die Transparenz \u00fcber die verwendeten Softwarekomponenten immer wichtiger. Hier kommt die Software Bill of Materials (SBOM) ins Spiel, die eine detaillierte und strukturierte Auflistung aller Softwarekomponenten eines Projekts bietet. Vor <a href=\"http:\/\/blog.wenzlaff.de\/?p=19459\" rel=\"noopener\" target=\"_blank\">einem Jahr<\/a> hatte ich schon mal davon berichtet. In diesem Artikel werden die Vorteile einer SBOM genauer betrachtet.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.wenzlaff.de\/wp-content\/uploads\/2023\/05\/geduld-ueben-6.png\" alt=\"\" width=\"1920\" height=\"1080\" class=\"aligncenter size-full wp-image-20203\" srcset=\"http:\/\/blog.wenzlaff.de\/wp-content\/uploads\/2023\/05\/geduld-ueben-6.png 1920w, http:\/\/blog.wenzlaff.de\/wp-content\/uploads\/2023\/05\/geduld-ueben-6-300x169.png 300w, http:\/\/blog.wenzlaff.de\/wp-content\/uploads\/2023\/05\/geduld-ueben-6-1024x576.png 1024w, http:\/\/blog.wenzlaff.de\/wp-content\/uploads\/2023\/05\/geduld-ueben-6-768x432.png 768w, http:\/\/blog.wenzlaff.de\/wp-content\/uploads\/2023\/05\/geduld-ueben-6-1536x864.png 1536w\" sizes=\"auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" \/><\/p>\n<p>    <strong>Transparenz \u00fcber Softwarekomponenten:<\/strong><br \/>\n    Eine SBOM erm\u00f6glicht eine umfassende Transparenz \u00fcber die verwendeten Softwarekomponenten in einem Projekt. Sie listet alle Komponenten auf, einschlie\u00dflich Open-Source-Software, Drittanbieterbibliotheken und propriet\u00e4re Codebasis. Dies schafft Klarheit \u00fcber den Ursprung und die Lizenzierung der Software, was f\u00fcr die Einhaltung von Compliance-Anforderungen und die Vermeidung von rechtlichen Problemen von entscheidender Bedeutung ist.<br \/>\n<!--more--><\/p>\n<p> <strong>Effektives Sicherheitsmanagement:<\/strong><br \/>\n    Mit einer SBOM erhalten Unternehmen eine detaillierte \u00dcbersicht \u00fcber die in ihrer Software verwendeten Komponenten. Dies erm\u00f6glicht es ihnen, potenzielle Sicherheitsl\u00fccken oder Schwachstellen zu identifizieren und geeignete Ma\u00dfnahmen zu ergreifen, um das Risiko von Cyberangriffen zu minimieren. Durch regelm\u00e4\u00dfige Aktualisierung der SBOM k\u00f6nnen Unternehmen sicherstellen, dass sie \u00fcber die neuesten Versionen der Komponenten verf\u00fcgen, die m\u00f6glicherweise Patches oder Sicherheitsupdates enthalten.<\/p>\n<p>    <strong>Effizientes Lizenzmanagement:<\/strong><br \/>\n    Lizenzkonformit\u00e4t ist ein wichtiges Thema, insbesondere wenn es um die Verwendung von Open-Source-Software geht. Eine SBOM hilft Unternehmen dabei, den \u00dcberblick \u00fcber die Lizenzvereinbarungen f\u00fcr ihre verwendeten Softwarekomponenten zu behalten. Sie erm\u00f6glicht eine rechtzeitige Identifizierung von lizenzrechtlichen Anforderungen und verhindert potenzielle Verst\u00f6\u00dfe gegen die Lizenzbestimmungen. Dies spart Unternehmen Zeit und Kosten, die mit nachtr\u00e4glichen Lizenzierungsproblemen verbunden sein k\u00f6nnen.<\/p>\n<p>    <strong>Verbesserte Zusammenarbeit und Kommunikation:<\/strong><br \/>\n    Eine SBOM f\u00f6rdert die Zusammenarbeit zwischen Entwicklern, Sicherheitsteams und anderen Interessengruppen. Durch die klare und einheitliche Darstellung der Softwarekomponenten werden Diskussionen \u00fcber Sicherheitsaspekte, Lizenzfragen oder Abh\u00e4ngigkeiten zwischen den Komponenten erleichtert. Dadurch k\u00f6nnen alle beteiligten Parteien ein gemeinsames Verst\u00e4ndnis f\u00fcr den Software-Stack entwickeln und effektive Entscheidungen treffen.<\/p>\n<p>    <strong>H\u00f6here Qualit\u00e4t und Stabilit\u00e4t:<\/strong><br \/>\n    Eine SBOM tr\u00e4gt zur Verbesserung der Qualit\u00e4t und Stabilit\u00e4t von Softwareprojekten bei. Durch die Dokumentation aller verwendeten Komponenten k\u00f6nnen Fehler oder Inkompatibilit\u00e4ten leichter erkannt und behoben werden. Entwickler k\u00f6nnen schnell auf Sicherheitswarnungen oder veraltete Komponenten reagieren und geeignete Ma\u00dfnahmen ergreifen, um die Qualit\u00e4t und Stabilit\u00e4t der Software zu gew\u00e4hrleisten. Dies f\u00fchrt zu robusten und zuverl\u00e4ssigen Produkten, die den Anforderungen der Benutzer besser gerecht werden.<\/p>\n<p>    <strong>Risikomanagement:<\/strong><br \/>\n    Eine umfassende SBOM erm\u00f6glicht es Unternehmen, potenzielle Risiken im Zusammenhang mit ihren Softwarekomponenten zu identifizieren und proaktiv darauf zu reagieren. Durch die Erfassung von Informationen \u00fcber Schwachstellen, bekannte Sicherheitsl\u00fccken oder veraltete Komponenten k\u00f6nnen Unternehmen geeignete Ma\u00dfnahmen ergreifen, um Risiken zu mindern und Sicherheitsvorf\u00e4lle zu vermeiden. Dies tr\u00e4gt zur St\u00e4rkung der Resilienz und zur Minimierung von Risiken im Zusammenhang mit der Software bei.<\/p>\n<p>    <strong>Reputations- und Markenschutz:<\/strong><br \/>\n    Die Offenlegung der Softwarekomponenten durch eine SBOM sch\u00fctzt die Reputation und Marke eines Unternehmens. Durch die Einhaltung von Compliance-Anforderungen und den Schutz vor Sicherheitsverletzungen zeigt ein Unternehmen seinen Kunden, dass es sich um Transparenz und Sicherheit bem\u00fcht. Dies st\u00e4rkt das Vertrauen der Kunden und Partner und tr\u00e4gt zur langfristigen Bindung und Loyalit\u00e4t bei.<\/p>\n<p><strong>Fazit:<\/strong><br \/>\nDie Software Bill of Materials (SBOM) bietet eine Vielzahl von Vorteilen f\u00fcr Unternehmen, die auf Softwarel\u00f6sungen angewiesen sind. Die Transparenz \u00fcber die verwendeten Softwarekomponenten, das effektive Sicherheitsmanagement, das effiziente Lizenzmanagement, die verbesserte Zusammenarbeit und Kommunikation, die h\u00f6here Qualit\u00e4t und Stabilit\u00e4t, das Risikomanagement und der Reputations- und Markenschutz sind nur einige der Vorteile, die eine SBOM bietet. Unternehmen sollten die Implementierung einer SBOM in ihren Entwicklungs- und Lieferprozessen in Betracht ziehen, um von diesen Vorteilen zu profitieren und die Sicherheit, Qualit\u00e4t und Compliance ihrer Softwarel\u00f6sungen zu gew\u00e4hrleisten.<\/p>\n<p>In Java Projekten kann solch eine SBOM leicht mit einem <a href=\"https:\/\/github.com\/CycloneDX\/cyclonedx-maven-plugin\" rel=\"noopener\" target=\"_blank\">CycloneDX Maven Plugin<\/a> in der Package-Phase erzeugt werden. Vor zwei Tagen gabe es auch eine neue Version 2.7.9.<\/p>\n<p>Ein einfacher Eintrag in der pom.xml:<\/p>\n<pre class=\"lang:xhtml decode:true \" >&lt;!-- f\u00fcr die Erzeugung von SBOMs im Target Verzeichnis --&gt;\r\n\t\t\t&lt;plugin&gt;\r\n\t\t\t\t&lt;groupId&gt;org.cyclonedx&lt;\/groupId&gt;\r\n\t\t\t\t&lt;artifactId&gt;cyclonedx-maven-plugin&lt;\/artifactId&gt;\r\n\t\t\t\t&lt;version&gt;2.7.9&lt;\/version&gt;\r\n\t\t\t\t&lt;executions&gt;\r\n\t\t\t\t\t&lt;execution&gt;\r\n\t\t\t\t\t\t&lt;phase&gt;package&lt;\/phase&gt;\r\n\t\t\t\t\t\t&lt;goals&gt;\r\n\t\t\t\t\t\t\t&lt;goal&gt;makeAggregateBom&lt;\/goal&gt;\r\n\t\t\t\t\t\t&lt;\/goals&gt;\r\n\t\t\t\t\t&lt;\/execution&gt;\r\n\t\t\t\t&lt;\/executions&gt;\r\n\t\t\t\t&lt;configuration&gt;\r\n\t\t\t\t\t&lt;projectType&gt;library&lt;\/projectType&gt;\r\n\t\t\t\t\t&lt;schemaVersion&gt;1.4&lt;\/schemaVersion&gt;\r\n\t\t\t\t\t&lt;includeBomSerialNumber&gt;true&lt;\/includeBomSerialNumber&gt;\r\n\t\t\t\t\t&lt;includeCompileScope&gt;true&lt;\/includeCompileScope&gt;\r\n\t\t\t\t\t&lt;includeProvidedScope&gt;true&lt;\/includeProvidedScope&gt;\r\n\t\t\t\t\t&lt;includeRuntimeScope&gt;true&lt;\/includeRuntimeScope&gt;\r\n\t\t\t\t\t&lt;includeSystemScope&gt;true&lt;\/includeSystemScope&gt;\r\n\t\t\t\t\t&lt;includeTestScope&gt;false&lt;\/includeTestScope&gt;\r\n\t\t\t\t\t&lt;includeLicenseText&gt;false&lt;\/includeLicenseText&gt;\r\n\t\t\t\t\t&lt;outputReactorProjects&gt;true&lt;\/outputReactorProjects&gt;\r\n\t\t\t\t\t&lt;outputFormat&gt;all&lt;\/outputFormat&gt;\r\n\t\t\t\t\t&lt;outputName&gt;bom&lt;\/outputName&gt;\r\n\t\t\t\t&lt;\/configuration&gt;\r\n\t\t\t&lt;\/plugin&gt;\r\n\t\t&lt;\/plugins&gt;<\/pre>\n<p>Hier eine Beispiel SBOM, viel Spa\u00df:<\/p>\n<pre class=\"minimize:true lang:xhtml decode:true \" >&lt;?xml version=\"1.0\" encoding=\"UTF-8\"?&gt;\r\n&lt;bom serialNumber=\"urn:uuid:8d1c1e35-ac1a-4545-9fc7-22fc6a1c256e\" version=\"1\" xmlns=\"http:\/\/cyclonedx.org\/schema\/bom\/1.4\"&gt;\r\n  &lt;metadata&gt;\r\n    &lt;timestamp&gt;2023-05-18T17:52:07Z&lt;\/timestamp&gt;\r\n    &lt;tools&gt;\r\n      &lt;tool&gt;\r\n        &lt;vendor&gt;OWASP Foundation&lt;\/vendor&gt;\r\n        &lt;name&gt;CycloneDX Maven plugin&lt;\/name&gt;\r\n        &lt;version&gt;2.7.9&lt;\/version&gt;\r\n        &lt;hashes&gt;\r\n          &lt;hash alg=\"MD5\"&gt;8e595cdb67f17e4b41e046456970591d&lt;\/hash&gt;\r\n          &lt;hash alg=\"SHA-1\"&gt;69e8ca804520d09ce4657e7235bae84d01cbffa6&lt;\/hash&gt;\r\n          &lt;hash alg=\"SHA-256\"&gt;aa09074fe5aa403c008cd4fc7ef8ce41cd244489337f16b3e91a3914158a4db8&lt;\/hash&gt;\r\n          &lt;hash alg=\"SHA-512\"&gt;1488a8112da8e675813d7585f57c5efb178aed32901118186ee12d0e4ae3d19c53774c7f860bf70d17d70f050119b69443a2637cf641675b4b5d9cdcdd69b89b&lt;\/hash&gt;\r\n          &lt;hash alg=\"SHA-384\"&gt;b097295dfbf10887abc6eec58d4d0822cde5a73d1f5c1cf183a57bf569016ad5ced9d34efae3e574d82bb62837540c6c&lt;\/hash&gt;\r\n          &lt;hash alg=\"SHA3-384\"&gt;289f9520bd73a2031276248a6ef8f0891c691062c2d1ea86a2bc9ea8db2c52377d92a53be9957179e71aee3deda26a8c&lt;\/hash&gt;\r\n          &lt;hash alg=\"SHA3-256\"&gt;32b50a7efe5d491a4039c0017eca3cf49d98b55fc66d06b3dd06209487323474&lt;\/hash&gt;\r\n          &lt;hash alg=\"SHA3-512\"&gt;1daf813da53e5d5cda4d0302ff3a5e388aa45d96ebe6dcbe240f35d33f14b1e6390f6bbe7f21f3ed8cf96ebd9f5516a08b18487b7339715109c81cebfc1563df&lt;\/hash&gt;\r\n        &lt;\/hashes&gt;\r\n      &lt;\/tool&gt;\r\n    &lt;\/tools&gt;\r\n    &lt;component type=\"library\" bom-ref=\"pkg:maven\/de.wenzlaff.twbibel\/de.wenzlaff.twbibel@0.1.1?type=jar\"&gt;\r\n      &lt;group&gt;de.wenzlaff.twbibel&lt;\/group&gt;\r\n      &lt;name&gt;de.wenzlaff.twbibel&lt;\/name&gt;\r\n      &lt;version&gt;0.1.1&lt;\/version&gt;\r\n      &lt;description&gt;Bible BEs&lt;\/description&gt;\r\n      &lt;licenses&gt;\r\n        &lt;license&gt;\r\n          &lt;id&gt;Apache-2.0&lt;\/id&gt;\r\n        &lt;\/license&gt;\r\n      &lt;\/licenses&gt;\r\n      &lt;purl&gt;pkg:maven\/de.wenzlaff.twbibel\/de.wenzlaff.twbibel@0.1.1?type=jar&lt;\/purl&gt;\r\n      &lt;externalReferences&gt;&lt;reference type=\"website\"&gt;&lt;url&gt;http:\/\/www.wenzlaff.info&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"distribution\"&gt;&lt;url&gt;https:\/\/oss.sonatype.org\/service\/local\/staging\/deploy\/maven2\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"vcs\"&gt;&lt;url&gt;https:\/\/gitlab.com\/IT-Berater\/twbibel&lt;\/url&gt;&lt;\/reference&gt;&lt;\/externalReferences&gt;\r\n    &lt;\/component&gt;\r\n    &lt;properties&gt;\r\n      &lt;property name=\"maven.goal\"&gt;makeAggregateBom&lt;\/property&gt;\r\n      &lt;property name=\"maven.scopes\"&gt;compile,provided,runtime,system&lt;\/property&gt;\r\n    &lt;\/properties&gt;\r\n  &lt;\/metadata&gt;\r\n  &lt;components&gt;\r\n    &lt;component type=\"library\" bom-ref=\"pkg:maven\/org.openjfx\/javafx-graphics@17.0.1?type=jar\"&gt;\r\n      &lt;group&gt;org.openjfx&lt;\/group&gt;\r\n      &lt;name&gt;javafx-graphics&lt;\/name&gt;\r\n      &lt;version&gt;17.0.1&lt;\/version&gt;\r\n      &lt;description&gt;OpenJFX JavaFX&lt;\/description&gt;\r\n      &lt;scope&gt;required&lt;\/scope&gt;\r\n      &lt;hashes&gt;\r\n        &lt;hash alg=\"MD5\"&gt;7545a300bfc844c796a9c293b396a968&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-1\"&gt;324fd0f6c9c55330fc64a44dde0887d9646e800a&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-256\"&gt;53d60cef64ab6a1549da4d0239c009f8ef8084b62ecd18c3bda782b4d6520a8f&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-512\"&gt;a366830966ba519d627d73be30799b24f1531b1afe15cbad976611825b4f322ecc566e26913fa74e7864d226524fff32f33e96c476f5f1786e93924724eaf4db&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-384\"&gt;d05fe8360cd031c9fc7742e2bb68f4050fd054164579b27497c35655ac7ead728a1bd50a61da9ae17af1c8ac3af0bda8&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-384\"&gt;6cd338d15a94f8f8025b9d7203527c0c6d6c6f8f82972e8c7553cb552a51219aaae9e66294a6b453833057fe0c1c2c2e&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-256\"&gt;aeca507caa11797d3d98a781e618501478eb45121d17909b010593bead9ea783&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-512\"&gt;c09d1c99287e87e773c1d3583d22aa7d3ed90a69e4533114bfd54ecfa824fc11b0172afb759f0186d8985df7b846edd84dbf410d8c83d30e5c60dfe50756afe7&lt;\/hash&gt;\r\n      &lt;\/hashes&gt;\r\n      &lt;licenses&gt;\r\n        &lt;license&gt;\r\n          &lt;id&gt;GPL-2.0-with-classpath-exception&lt;\/id&gt;\r\n        &lt;\/license&gt;\r\n      &lt;\/licenses&gt;\r\n      &lt;purl&gt;pkg:maven\/org.openjfx\/javafx-graphics@17.0.1?type=jar&lt;\/purl&gt;\r\n      &lt;externalReferences&gt;&lt;reference type=\"website\"&gt;&lt;url&gt;https:\/\/openjdk.java.net\/projects\/openjfx\/javafx-graphics\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"vcs\"&gt;&lt;url&gt;https:\/\/github.com\/openjdk\/jfx\/javafx-graphics&lt;\/url&gt;&lt;\/reference&gt;&lt;\/externalReferences&gt;\r\n    &lt;\/component&gt;\r\n    &lt;component type=\"library\" bom-ref=\"pkg:maven\/org.openjfx\/javafx-graphics@17.0.1?classifier=mac&amp;amp;type=jar\"&gt;\r\n      &lt;group&gt;org.openjfx&lt;\/group&gt;\r\n      &lt;name&gt;javafx-graphics&lt;\/name&gt;\r\n      &lt;version&gt;17.0.1&lt;\/version&gt;\r\n      &lt;description&gt;OpenJFX JavaFX&lt;\/description&gt;\r\n      &lt;scope&gt;required&lt;\/scope&gt;\r\n      &lt;hashes&gt;\r\n        &lt;hash alg=\"MD5\"&gt;15f69c53f8abd8ba682382ae02895392&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-1\"&gt;60505369f7528056d4d8c5ea080df5447bdb0264&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-256\"&gt;95f31f7e600af94ef9cc1356ad6c71ee94b1a96e399684fb7938c61fa1908ab8&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-512\"&gt;55c91d2001b16706bc6a77e4cd407bac4adcf6ea88b2e6db4437c2f93b758f2339285af50b29ca88228941068de458ca423e75d2a308ce2048809840fa14a220&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-384\"&gt;3ec7ada6b738c0402a9f300ce173e236ad8840585d17b966d2842ce508f5d6a771720f467c03ea08762e51c684c50b77&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-384\"&gt;abfb96f3de1cb500e8243a260cc3e747d03c060be599da90349a3d203322f15b2e1980a69f751e9de7fb68ac3833b060&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-256\"&gt;8b47999f0070e37fd5a7ed4f2a21ccd0125e34de29d004c62115b2f9aed7b2c4&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-512\"&gt;0008222b86330c03f1d9ce2c2a0310155d7d72e1ef7284efd32abad7e2b8bee4e248cc114f90f0c6ebdefa2b6b4ac12981976a0c5cd12d2eeb23dfcc0c141622&lt;\/hash&gt;\r\n      &lt;\/hashes&gt;\r\n      &lt;licenses&gt;\r\n        &lt;license&gt;\r\n          &lt;id&gt;GPL-2.0-with-classpath-exception&lt;\/id&gt;\r\n        &lt;\/license&gt;\r\n      &lt;\/licenses&gt;\r\n      &lt;purl&gt;pkg:maven\/org.openjfx\/javafx-graphics@17.0.1?classifier=mac&amp;amp;type=jar&lt;\/purl&gt;\r\n      &lt;externalReferences&gt;&lt;reference type=\"website\"&gt;&lt;url&gt;https:\/\/openjdk.java.net\/projects\/openjfx\/javafx-graphics\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"vcs\"&gt;&lt;url&gt;https:\/\/github.com\/openjdk\/jfx\/javafx-graphics&lt;\/url&gt;&lt;\/reference&gt;&lt;\/externalReferences&gt;\r\n    &lt;\/component&gt;\r\n    &lt;component type=\"library\" bom-ref=\"pkg:maven\/org.openjfx\/javafx-fxml@16-ea%2B5?type=jar\"&gt;\r\n      &lt;group&gt;org.openjfx&lt;\/group&gt;\r\n      &lt;name&gt;javafx-fxml&lt;\/name&gt;\r\n      &lt;version&gt;16-ea+5&lt;\/version&gt;\r\n      &lt;description&gt;OpenJFX JavaFX&lt;\/description&gt;\r\n      &lt;scope&gt;required&lt;\/scope&gt;\r\n      &lt;hashes&gt;\r\n        &lt;hash alg=\"MD5\"&gt;11033bbe9b654594c9bd7bb4ed6272e6&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-1\"&gt;750de81fb29ff82eb6dd35ad92871a683c4d8cfa&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-256\"&gt;c3dd869f7b0036c3d9ce358c5b576068b0e095ef15873e0e215042e866271206&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-512\"&gt;66cbd07c12c4d21c6fc4b2b2c9a66f54ef5c85ffc9f22fad54689bdb4df0563ff582c7f754cd0c4cba71dd0c2b2ebb1763fa4660dabd9ec0cc2ea7271014554b&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-384\"&gt;57b444cfede3b48b14b533f2f2c2b2cc19b2ca7cf2cc54d19bb5e265062173996c2d73a4fd74b4bc653a494adf64d8e4&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-384\"&gt;3b517f0616d1086236f84b2d7148abc9be8b64adb2cd1b36c48a1c568f315803051b1e19c8854dd3b2966c7090cb70d1&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-256\"&gt;2bff54cdf891bba7956f42aa7338194b80c5a86562d286e49769f2b68cf692fb&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-512\"&gt;4e5ea6a8ff10027fa16bcb99c5cd715c631d753a978026d5d1d4ce50571bf63e6c6d7eb03050bf07fac8c6c5dfec555223be9f3fe9f68d1665a456da4e1082c8&lt;\/hash&gt;\r\n      &lt;\/hashes&gt;\r\n      &lt;licenses&gt;\r\n        &lt;license&gt;\r\n          &lt;id&gt;GPL-2.0-with-classpath-exception&lt;\/id&gt;\r\n        &lt;\/license&gt;\r\n      &lt;\/licenses&gt;\r\n      &lt;purl&gt;pkg:maven\/org.openjfx\/javafx-fxml@16-ea%2B5?type=jar&lt;\/purl&gt;\r\n      &lt;externalReferences&gt;&lt;reference type=\"website\"&gt;&lt;url&gt;https:\/\/openjdk.java.net\/projects\/openjfx\/javafx-fxml\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"vcs\"&gt;&lt;url&gt;https:\/\/github.com\/openjdk\/jfx\/javafx-fxml&lt;\/url&gt;&lt;\/reference&gt;&lt;\/externalReferences&gt;\r\n    &lt;\/component&gt;\r\n    &lt;component type=\"library\" bom-ref=\"pkg:maven\/org.openjfx\/javafx-fxml@16-ea%2B5?classifier=mac&amp;amp;type=jar\"&gt;\r\n      &lt;group&gt;org.openjfx&lt;\/group&gt;\r\n      &lt;name&gt;javafx-fxml&lt;\/name&gt;\r\n      &lt;version&gt;16-ea+5&lt;\/version&gt;\r\n      &lt;description&gt;OpenJFX JavaFX&lt;\/description&gt;\r\n      &lt;scope&gt;required&lt;\/scope&gt;\r\n      &lt;hashes&gt;\r\n        &lt;hash alg=\"MD5\"&gt;ad8219af4809b18b80e9f0e13326a7f4&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-1\"&gt;49b4a39949045a4a783703e4c836547d78ff2308&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-256\"&gt;a932151babd4f2bdce00751180eb4cd8dcd7d55c8ecd4c01db106d619132be60&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-512\"&gt;f02c49908bb1a4a8d11928c2cf864b576f94f98ddb2ad14f85de33b29b1ddac12281a6d8d9a362cbb937a67d790cad0cedc36d472e94a648567423eaf55f6fe9&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-384\"&gt;1f06b2661ef7f1522c843927933fe8ea7e502ec5bce6ed4c5cc3c68718583d7b0cfa45500968ecd75085de38e38adf6c&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-384\"&gt;018af2810c6e2e6dc86522120823e904b9e085d1c3eaa4362ba83ee282b9daebce5a5b122d2f8ae93e32d4c6110ad297&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-256\"&gt;4dcb1b9f708fd9c49dd1a55f6163d336a3072e327b63edd323f041295bd2c919&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-512\"&gt;c02e2123dca3d94b7e572cce65af1ecbf0eb7429327121afa90cf2e23b06c8e540f42376415ff104416e29ef353b5a9ed6be7d1f548d968faf6af00a6161d73e&lt;\/hash&gt;\r\n      &lt;\/hashes&gt;\r\n      &lt;licenses&gt;\r\n        &lt;license&gt;\r\n          &lt;id&gt;GPL-2.0-with-classpath-exception&lt;\/id&gt;\r\n        &lt;\/license&gt;\r\n      &lt;\/licenses&gt;\r\n      &lt;purl&gt;pkg:maven\/org.openjfx\/javafx-fxml@16-ea%2B5?classifier=mac&amp;amp;type=jar&lt;\/purl&gt;\r\n      &lt;externalReferences&gt;&lt;reference type=\"website\"&gt;&lt;url&gt;https:\/\/openjdk.java.net\/projects\/openjfx\/javafx-fxml\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"vcs\"&gt;&lt;url&gt;https:\/\/github.com\/openjdk\/jfx\/javafx-fxml&lt;\/url&gt;&lt;\/reference&gt;&lt;\/externalReferences&gt;\r\n    &lt;\/component&gt;\r\n    &lt;component type=\"library\" bom-ref=\"pkg:maven\/org.openjfx\/javafx-controls@17.0.1?type=jar\"&gt;\r\n      &lt;group&gt;org.openjfx&lt;\/group&gt;\r\n      &lt;name&gt;javafx-controls&lt;\/name&gt;\r\n      &lt;version&gt;17.0.1&lt;\/version&gt;\r\n      &lt;description&gt;OpenJFX JavaFX&lt;\/description&gt;\r\n      &lt;scope&gt;required&lt;\/scope&gt;\r\n      &lt;hashes&gt;\r\n        &lt;hash alg=\"MD5\"&gt;69efe49db3f11131ea7d68b4d9b645b8&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-1\"&gt;4aa202089425f7b3bac4566e98da4b94ad10ee00&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-256\"&gt;51d698cac8627e221152b4c421900f73f4af5abcd517008e695e43e22c40ec33&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-512\"&gt;d7d683bb9ef96d60f7ccd0262f08b34b1b28fa95bf637d16698c1d4d5cefd7e1c43826417dc97d6779976a85dcd38a3bc99adcff7d1c79b44e5b6854ff722164&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-384\"&gt;2269332b47ac884147d9c6ad0e1c256437ead479de2a61a1dfb708dd6914cdcf72d8e45c1c71c7bd136fdb1db26b5c80&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-384\"&gt;c2b0b6fbeab58d6f6ca01d53b1bd40a9ffd8cd0fbd49fd5f157e3ec2603ca600ff0b6022c081baddd69fb47cfa049283&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-256\"&gt;a00a9855aa6837f7931fb60f51271ad8ab04d445fc6ad194181a6aa624dec49f&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-512\"&gt;351d4dc4abfe736d41fcae71e90dd252b3ea98f1c49c805254f6da369d35c9dd2eeecb519e3b0a97e1584a5868c854e2f673285f0fbfd437b77e9c70d24c26fd&lt;\/hash&gt;\r\n      &lt;\/hashes&gt;\r\n      &lt;licenses&gt;\r\n        &lt;license&gt;\r\n          &lt;id&gt;GPL-2.0-with-classpath-exception&lt;\/id&gt;\r\n        &lt;\/license&gt;\r\n      &lt;\/licenses&gt;\r\n      &lt;purl&gt;pkg:maven\/org.openjfx\/javafx-controls@17.0.1?type=jar&lt;\/purl&gt;\r\n      &lt;externalReferences&gt;&lt;reference type=\"website\"&gt;&lt;url&gt;https:\/\/openjdk.java.net\/projects\/openjfx\/javafx-controls\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"vcs\"&gt;&lt;url&gt;https:\/\/github.com\/openjdk\/jfx\/javafx-controls&lt;\/url&gt;&lt;\/reference&gt;&lt;\/externalReferences&gt;\r\n    &lt;\/component&gt;\r\n    &lt;component type=\"library\" bom-ref=\"pkg:maven\/org.openjfx\/javafx-controls@17.0.1?classifier=mac&amp;amp;type=jar\"&gt;\r\n      &lt;group&gt;org.openjfx&lt;\/group&gt;\r\n      &lt;name&gt;javafx-controls&lt;\/name&gt;\r\n      &lt;version&gt;17.0.1&lt;\/version&gt;\r\n      &lt;description&gt;OpenJFX JavaFX&lt;\/description&gt;\r\n      &lt;scope&gt;required&lt;\/scope&gt;\r\n      &lt;hashes&gt;\r\n        &lt;hash alg=\"MD5\"&gt;2d7449f7e25c42d43409e8d665d7f7c3&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-1\"&gt;9c4e3c7ee4fe3f2d71cb94811910695f43040dc5&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-256\"&gt;9bcaff9cb652f7d5e8c3ab36ea837c6d123ae93e43ee66767dc0f65f15563640&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-512\"&gt;b019fa6aa881272e0c294071e962b5462bd54f3b4f649ca95a599f900df0fb3a5a1e60923d730b9c9a98d9aea9fb7a7d2ad5f4f1e2f169c0956685aef53e7dd2&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-384\"&gt;071645e68313539caaba560bb9f581099826d185a3af2f61de2f672c279432cb22fb7d9bdee146f62a41da3e7087efbd&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-384\"&gt;0d16aeb35e7bb98a0d819ac226d8ca0b38588bd5627902b82dae6fd3dcebc29278f32714c49c20637988f6cf25bfed3a&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-256\"&gt;4f8e6cbf12e45a2ba38ab33019952c9d82a19c8dfed673a9b438df3eaee7fd30&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-512\"&gt;07cbc07c40189f6243e9680521289f7d9a0b474d50ade55896a2723c0c65494bc4f4fd0926b0746fa38b0b756e96db601691fa7f62475a7c6b455713cbb654ed&lt;\/hash&gt;\r\n      &lt;\/hashes&gt;\r\n      &lt;licenses&gt;\r\n        &lt;license&gt;\r\n          &lt;id&gt;GPL-2.0-with-classpath-exception&lt;\/id&gt;\r\n        &lt;\/license&gt;\r\n      &lt;\/licenses&gt;\r\n      &lt;purl&gt;pkg:maven\/org.openjfx\/javafx-controls@17.0.1?classifier=mac&amp;amp;type=jar&lt;\/purl&gt;\r\n      &lt;externalReferences&gt;&lt;reference type=\"website\"&gt;&lt;url&gt;https:\/\/openjdk.java.net\/projects\/openjfx\/javafx-controls\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"vcs\"&gt;&lt;url&gt;https:\/\/github.com\/openjdk\/jfx\/javafx-controls&lt;\/url&gt;&lt;\/reference&gt;&lt;\/externalReferences&gt;\r\n    &lt;\/component&gt;\r\n    &lt;component type=\"library\" bom-ref=\"pkg:maven\/org.openjfx\/javafx-base@17.0.1?type=jar\"&gt;\r\n      &lt;group&gt;org.openjfx&lt;\/group&gt;\r\n      &lt;name&gt;javafx-base&lt;\/name&gt;\r\n      &lt;version&gt;17.0.1&lt;\/version&gt;\r\n      &lt;description&gt;OpenJFX JavaFX&lt;\/description&gt;\r\n      &lt;scope&gt;required&lt;\/scope&gt;\r\n      &lt;hashes&gt;\r\n        &lt;hash alg=\"MD5\"&gt;481b4f438a0b0e5b9ffb432cde040e58&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-1\"&gt;2c53dcf0d89ff42a63b09d941cab75c5a052ef32&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-256\"&gt;045700bcabd5441a50964944f38babbee8fc2e8159179b8cb5e64d18274e3853&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-512\"&gt;9f6303ea590a5a78beac4f5558f2995f8312b20b5dcb44da1a4b07b74f4f67a4bf4bd39ed997f49a93eca459496c6952d8a196ad6cf32bc30acfee7797440b1c&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-384\"&gt;c77280bb6ce0238daa2a42a5f9ce7d04727ffe53d9bbb07359a1309dfdf011cfb4fffd322b7dd3f08385980c95e34eba&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-384\"&gt;521cb39f95cb766f5e68a394932bf0d0805d195d382453b0dee3c6c74116ade61c5b6f5c95ae4400a42e66776f2e832f&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-256\"&gt;a00a8c62a461838dbf0df3abdfa87882bd8a0ca9587c725b1d87d912bd173cff&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-512\"&gt;5a2230091a56e0e85869c09ceaeb14df8639ba49938010fe98b42d2263c2921d09e3eeecb9c06cf9256e5247ad26245b6c08da5f8e2921b0aea5677672f3377c&lt;\/hash&gt;\r\n      &lt;\/hashes&gt;\r\n      &lt;licenses&gt;\r\n        &lt;license&gt;\r\n          &lt;id&gt;GPL-2.0-with-classpath-exception&lt;\/id&gt;\r\n        &lt;\/license&gt;\r\n      &lt;\/licenses&gt;\r\n      &lt;purl&gt;pkg:maven\/org.openjfx\/javafx-base@17.0.1?type=jar&lt;\/purl&gt;\r\n      &lt;externalReferences&gt;&lt;reference type=\"website\"&gt;&lt;url&gt;https:\/\/openjdk.java.net\/projects\/openjfx\/javafx-base\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"vcs\"&gt;&lt;url&gt;https:\/\/github.com\/openjdk\/jfx\/javafx-base&lt;\/url&gt;&lt;\/reference&gt;&lt;\/externalReferences&gt;\r\n    &lt;\/component&gt;\r\n    &lt;component type=\"library\" bom-ref=\"pkg:maven\/org.openjfx\/javafx-base@17.0.1?classifier=mac&amp;amp;type=jar\"&gt;\r\n      &lt;group&gt;org.openjfx&lt;\/group&gt;\r\n      &lt;name&gt;javafx-base&lt;\/name&gt;\r\n      &lt;version&gt;17.0.1&lt;\/version&gt;\r\n      &lt;description&gt;OpenJFX JavaFX&lt;\/description&gt;\r\n      &lt;scope&gt;required&lt;\/scope&gt;\r\n      &lt;hashes&gt;\r\n        &lt;hash alg=\"MD5\"&gt;a7521cc0781a6ec5bbcfd30da3396187&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-1\"&gt;75cfa6f780ea3b3fd4ae336161e9e136ebb91ef2&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-256\"&gt;2a4f9e646dace35300abb19464f350691e7a00d883b24c6595832448a1cee0ef&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-512\"&gt;d6ca4560816e79793735f786a5f3ea0d80920d6a84dc17c7cfd02d2470e6d0436922f7fd023c448271e6cb805d1ca16bd39d4f25c41f14e4f708ed60e6516198&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-384\"&gt;0893c40a5cf5c663364ffdcccde7ed1d1908ac43d4cf2102b119ae1aa16709b9a708d36417c3e6328a594538ed8ff44b&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-384\"&gt;7ba9d349cf9f43a56366a54f13d8efaaca58ca74d1bf24c8c017056d6d7f0197cc200432fcbdc092f731360ad642ce0f&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-256\"&gt;d90f73d262a73f4e1225f1c0602db59c0e0ce5f7fd0b157ed15be6847d5ef80f&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-512\"&gt;cbbd379f63b34e7bc21073a64473e9bda0e667f903d3875d0b842f184532c0b6d0d0622116fbac520e3f822dc57774e94539b8ca3111e73d4f5aa7d35c49a7e8&lt;\/hash&gt;\r\n      &lt;\/hashes&gt;\r\n      &lt;licenses&gt;\r\n        &lt;license&gt;\r\n          &lt;id&gt;GPL-2.0-with-classpath-exception&lt;\/id&gt;\r\n        &lt;\/license&gt;\r\n      &lt;\/licenses&gt;\r\n      &lt;purl&gt;pkg:maven\/org.openjfx\/javafx-base@17.0.1?classifier=mac&amp;amp;type=jar&lt;\/purl&gt;\r\n      &lt;externalReferences&gt;&lt;reference type=\"website\"&gt;&lt;url&gt;https:\/\/openjdk.java.net\/projects\/openjfx\/javafx-base\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"vcs\"&gt;&lt;url&gt;https:\/\/github.com\/openjdk\/jfx\/javafx-base&lt;\/url&gt;&lt;\/reference&gt;&lt;\/externalReferences&gt;\r\n    &lt;\/component&gt;\r\n    &lt;component type=\"library\" bom-ref=\"pkg:maven\/org.apache.httpcomponents\/httpclient@4.5.13?type=jar\"&gt;\r\n      &lt;publisher&gt;The Apache Software Foundation&lt;\/publisher&gt;\r\n      &lt;group&gt;org.apache.httpcomponents&lt;\/group&gt;\r\n      &lt;name&gt;httpclient&lt;\/name&gt;\r\n      &lt;version&gt;4.5.13&lt;\/version&gt;\r\n      &lt;description&gt;Apache HttpComponents Client&lt;\/description&gt;\r\n      &lt;scope&gt;required&lt;\/scope&gt;\r\n      &lt;hashes&gt;\r\n        &lt;hash alg=\"MD5\"&gt;40d6b9075fbd28fa10292a45a0db9457&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-1\"&gt;e5f6cae5ca7ecaac1ec2827a9e2d65ae2869cada&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-256\"&gt;6fe9026a566c6a5001608cf3fc32196641f6c1e5e1986d1037ccdbd5f31ef743&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-512\"&gt;3567739186e551f84cad3e4b6b270c5b8b19aba297675a96bcdff3663ff7d20d188611d21f675fe5ff1bfd7d8ca31362070910d7b92ab1b699872a120aa6f089&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-384\"&gt;093ac3e2dde58e34aa70309c7305eb3c9b5be2509a9293f1672494da55479a86bd112e83326746dc7a32855472952b99&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-384\"&gt;cd6882e7868624164e460f2f3ea01466f863c0dcb902b031c656b57356f563be83b29530df41d88d634ed3d01fc9964d&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-256\"&gt;710b1d8d7dae0b8e4270756694ca9c83d64965f42d3b4170c609b14d47c2762c&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-512\"&gt;276fa6a6599dc89382d658115695cf4da6b0d39b34e9c349c17a5dbd64122eaee553bb9ed75c0378ec4a83be157c8aa39370662de3c9b8fd55ebc1dd608383e6&lt;\/hash&gt;\r\n      &lt;\/hashes&gt;\r\n      &lt;licenses&gt;\r\n        &lt;license&gt;\r\n          &lt;id&gt;Apache-2.0&lt;\/id&gt;\r\n        &lt;\/license&gt;\r\n      &lt;\/licenses&gt;\r\n      &lt;purl&gt;pkg:maven\/org.apache.httpcomponents\/httpclient@4.5.13?type=jar&lt;\/purl&gt;\r\n      &lt;externalReferences&gt;&lt;reference type=\"website\"&gt;&lt;url&gt;http:\/\/hc.apache.org\/httpcomponents-client&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"distribution\"&gt;&lt;url&gt;https:\/\/repository.apache.org\/service\/local\/staging\/deploy\/maven2&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"issue-tracker\"&gt;&lt;url&gt;http:\/\/issues.apache.org\/jira\/browse\/HTTPCLIENT&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"mailing-list\"&gt;&lt;url&gt;http:\/\/mail-archives.apache.org\/mod_mbox\/hc-httpclient-users\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"vcs\"&gt;&lt;url&gt;https:\/\/github.com\/apache\/httpcomponents-client\/tree\/4.5.13\/httpclient&lt;\/url&gt;&lt;\/reference&gt;&lt;\/externalReferences&gt;\r\n    &lt;\/component&gt;\r\n    &lt;component type=\"library\" bom-ref=\"pkg:maven\/org.apache.httpcomponents\/httpcore@4.4.13?type=jar\"&gt;\r\n      &lt;publisher&gt;The Apache Software Foundation&lt;\/publisher&gt;\r\n      &lt;group&gt;org.apache.httpcomponents&lt;\/group&gt;\r\n      &lt;name&gt;httpcore&lt;\/name&gt;\r\n      &lt;version&gt;4.4.13&lt;\/version&gt;\r\n      &lt;description&gt;Apache HttpComponents Core (blocking I\/O)&lt;\/description&gt;\r\n      &lt;scope&gt;required&lt;\/scope&gt;\r\n      &lt;hashes&gt;\r\n        &lt;hash alg=\"MD5\"&gt;e07a248f61c52776a2366c075dcd4963&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-1\"&gt;853b96d3afbb7bf8cc303fe27ee96836a10c1834&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-256\"&gt;e06e89d40943245fcfa39ec537cdbfce3762aecde8f9c597780d2b00c2b43424&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-512\"&gt;23430cde8b9bed33c91474ba49f1143284135df1b25fdcbc37bc3bb7e9549e77b3918eb40250093db652ae200367e87316129b23b4f6987e94939d60f467498d&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-384\"&gt;b776d57492478c162d428bdd3139be0fa6c3cf4503355c3a04710ca7bc3ee74d66627f49eb42814fd8f8364dbd17aa91&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-384\"&gt;f6f9e70b76717b705d040f0b33857f0dde89736f2e6d55ea56585235eb1b6d0ce4d5aa18c82050391ac968dcb5ec29e2&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-256\"&gt;721a9fc1bb353ddf3e438bed4306a3fa5b55ffafb474be5dc8715bd23d7a5afa&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-512\"&gt;c78f9d464e4b840e28266658512b1cab0ece1470bef2764deb2dc20ba69b73d526d92a19494ccb87b4408f9235c4294417f2e10ba709469f4bd62d017b9e3cbe&lt;\/hash&gt;\r\n      &lt;\/hashes&gt;\r\n      &lt;licenses&gt;\r\n        &lt;license&gt;\r\n          &lt;id&gt;Apache-2.0&lt;\/id&gt;\r\n        &lt;\/license&gt;\r\n      &lt;\/licenses&gt;\r\n      &lt;purl&gt;pkg:maven\/org.apache.httpcomponents\/httpcore@4.4.13?type=jar&lt;\/purl&gt;\r\n      &lt;externalReferences&gt;&lt;reference type=\"website\"&gt;&lt;url&gt;http:\/\/hc.apache.org\/httpcomponents-core-ga&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"distribution\"&gt;&lt;url&gt;https:\/\/repository.apache.org\/service\/local\/staging\/deploy\/maven2&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"issue-tracker\"&gt;&lt;url&gt;http:\/\/issues.apache.org\/jira\/browse\/HTTPCORE&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"mailing-list\"&gt;&lt;url&gt;http:\/\/mail-archives.apache.org\/mod_mbox\/hc-httpclient-users\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"vcs\"&gt;&lt;url&gt;https:\/\/github.com\/apache\/httpcomponents-core\/tree\/4.4.13\/httpcore&lt;\/url&gt;&lt;\/reference&gt;&lt;\/externalReferences&gt;\r\n    &lt;\/component&gt;\r\n    &lt;component type=\"library\" bom-ref=\"pkg:maven\/commons-logging\/commons-logging@1.2?type=jar\"&gt;\r\n      &lt;publisher&gt;The Apache Software Foundation&lt;\/publisher&gt;\r\n      &lt;group&gt;commons-logging&lt;\/group&gt;\r\n      &lt;name&gt;commons-logging&lt;\/name&gt;\r\n      &lt;version&gt;1.2&lt;\/version&gt;\r\n      &lt;description&gt;Apache Commons Logging is a thin adapter allowing configurable bridging to other,\r\n    well known logging systems.&lt;\/description&gt;\r\n      &lt;scope&gt;required&lt;\/scope&gt;\r\n      &lt;hashes&gt;\r\n        &lt;hash alg=\"MD5\"&gt;040b4b4d8eac886f6b4a2a3bd2f31b00&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-1\"&gt;4bfc12adfe4842bf07b657f0369c4cb522955686&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-256\"&gt;daddea1ea0be0f56978ab3006b8ac92834afeefbd9b7e4e6316fca57df0fa636&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-512\"&gt;ed00dbfabd9ae00efa26dd400983601d076fe36408b7d6520084b447e5d1fa527ce65bd6afdcb58506c3a808323d28e88f26cb99c6f5db9ff64f6525ecdfa557&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-384\"&gt;ac20720d7156131478205f1b454395abf84cfc8da2f163301af32f63bd3c4764bd26cb54ed53800f33193ae591f3ce9c&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-384\"&gt;628eb4407e95dca84da1a06b08a6d9b832a49de8472b1b217e8607f08efeeed18b996232d64dd07f03e78e0e3bb4b078&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-256\"&gt;9aab62deccf156ee6e324c925dfc30ecb53e8465802863a551901a461424e807&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-512\"&gt;3fd76857f6d20c03799537cc961c1c4ddf1c375c6c192fb982363e3b9397ba138b77f24ef38b4202f44e37586789c0320e4de18fdadd2772304fd14a9b26d552&lt;\/hash&gt;\r\n      &lt;\/hashes&gt;\r\n      &lt;licenses&gt;\r\n        &lt;license&gt;\r\n          &lt;id&gt;Apache-2.0&lt;\/id&gt;\r\n        &lt;\/license&gt;\r\n      &lt;\/licenses&gt;\r\n      &lt;purl&gt;pkg:maven\/commons-logging\/commons-logging@1.2?type=jar&lt;\/purl&gt;\r\n      &lt;externalReferences&gt;&lt;reference type=\"website\"&gt;&lt;url&gt;http:\/\/commons.apache.org\/proper\/commons-logging\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"build-system\"&gt;&lt;url&gt;https:\/\/continuum-ci.apache.org\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"distribution\"&gt;&lt;url&gt;https:\/\/repository.apache.org\/service\/local\/staging\/deploy\/maven2&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"issue-tracker\"&gt;&lt;url&gt;http:\/\/issues.apache.org\/jira\/browse\/LOGGING&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"mailing-list\"&gt;&lt;url&gt;http:\/\/mail-archives.apache.org\/mod_mbox\/commons-user\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"vcs\"&gt;&lt;url&gt;http:\/\/svn.apache.org\/repos\/asf\/commons\/proper\/logging\/trunk&lt;\/url&gt;&lt;\/reference&gt;&lt;\/externalReferences&gt;\r\n    &lt;\/component&gt;\r\n    &lt;component type=\"library\" bom-ref=\"pkg:maven\/org.apache.logging.log4j\/log4j-core@2.20.0?type=jar\"&gt;\r\n      &lt;publisher&gt;The Apache Software Foundation&lt;\/publisher&gt;\r\n      &lt;group&gt;org.apache.logging.log4j&lt;\/group&gt;\r\n      &lt;name&gt;log4j-core&lt;\/name&gt;\r\n      &lt;version&gt;2.20.0&lt;\/version&gt;\r\n      &lt;description&gt;The Apache Log4j Implementation&lt;\/description&gt;\r\n      &lt;scope&gt;required&lt;\/scope&gt;\r\n      &lt;hashes&gt;\r\n        &lt;hash alg=\"MD5\"&gt;20bd40d026d35a93fe710acb141e93da&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-1\"&gt;eb2a9a47b1396e00b5eee1264296729a70565cc0&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-256\"&gt;6137df848cdaed9f4d5076f75513c6c85da80b953f4e7acca38098b770763f55&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-512\"&gt;a7fe8fa2304c1b013513c1838013804cf601a7148dfef95642ea763c9550a6d844d9a1e528c9c21efc7ea830d13fbbb55e2db2c2eeb5542c4d9f00c127f211e4&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-384\"&gt;1d8b0349286118f102014706f02b7851f10ca0b1554bd7a2e1efdda76ccab6e0abd967490d06fca030f2a26289686275&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-384\"&gt;1448a9c78c339abc0768deaa54e4d680091a6e6539ba2589e09ae6f5988176fcef0ee16b0b574a37374eeac0b8c91616&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-256\"&gt;11a9f2311fbfcc334ff2ab26d04fd4e265b94c12f206c676ff1913e90ae4c916&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-512\"&gt;ed2bc1a05c856f7ad3ad71cbcb9d2bc9104d3a9badeadda0886616c1c99eb8442577e16bd8d85ca2437176e379a4307d43c3e34157165210460dfc7bf3ca3f9d&lt;\/hash&gt;\r\n      &lt;\/hashes&gt;\r\n      &lt;licenses&gt;\r\n        &lt;license&gt;\r\n          &lt;id&gt;Apache-2.0&lt;\/id&gt;\r\n        &lt;\/license&gt;\r\n      &lt;\/licenses&gt;\r\n      &lt;purl&gt;pkg:maven\/org.apache.logging.log4j\/log4j-core@2.20.0?type=jar&lt;\/purl&gt;\r\n      &lt;externalReferences&gt;&lt;reference type=\"website\"&gt;&lt;url&gt;https:\/\/logging.apache.org\/log4j\/2.x\/log4j-core\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"build-system\"&gt;&lt;url&gt;https:\/\/github.com\/apache\/logging-log4j2\/actions&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"distribution\"&gt;&lt;url&gt;https:\/\/logging.apache.org\/log4j\/2.x\/download.html&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"issue-tracker\"&gt;&lt;url&gt;https:\/\/github.com\/apache\/logging-log4j2\/issues&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"mailing-list\"&gt;&lt;url&gt;https:\/\/lists.apache.org\/list.html?log4j-user@logging.apache.org&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"vcs\"&gt;&lt;url&gt;https:\/\/github.com\/apache\/logging-log4j2\/log4j-core&lt;\/url&gt;&lt;\/reference&gt;&lt;\/externalReferences&gt;\r\n    &lt;\/component&gt;\r\n    &lt;component type=\"library\" bom-ref=\"pkg:maven\/org.apache.logging.log4j\/log4j-api@2.20.0?type=jar\"&gt;\r\n      &lt;publisher&gt;The Apache Software Foundation&lt;\/publisher&gt;\r\n      &lt;group&gt;org.apache.logging.log4j&lt;\/group&gt;\r\n      &lt;name&gt;log4j-api&lt;\/name&gt;\r\n      &lt;version&gt;2.20.0&lt;\/version&gt;\r\n      &lt;description&gt;The Apache Log4j API&lt;\/description&gt;\r\n      &lt;scope&gt;required&lt;\/scope&gt;\r\n      &lt;hashes&gt;\r\n        &lt;hash alg=\"MD5\"&gt;f9446464667f0139b839b5e9da37f5b9&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-1\"&gt;1fe6082e660daf07c689a89c94dc0f49c26b44bb&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-256\"&gt;2f43eea679ea66f14ca0f13fec2a8600ac124f5a5231dcb4df8393eddcb97550&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-512\"&gt;851016b38421d21864bb3073089c44000f941bfbaa9dc518db7bf7fb3c7f942bfb2c0c7b832e375e82b2f285379bd0935e42aa1833817daacb4fca2a6a9500bc&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-384\"&gt;12b05c61f49caab0b845e93967228a3bd3ab096c4ea1516cb7263f49963137a688a178ddebe790ccc3c0c73f2d4440fc&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-384\"&gt;87151e10c182a828d06fb5299361f01091f5ff066c3d8ba1fac0358d40c370a06ea46d9d93613499ebf94a855aef2f41&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-256\"&gt;2047730cb45c594da67d019cbd9f379e1d409a574deadfc9bc907461047f1fde&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-512\"&gt;5fde3529958bd5e9567f0dc6015c58621521641cfe0517eb1237413c750558415fdeb45cc1b4332c3d1f09938fc8fe327de86cc876ed52594c216d2c04c9d2d5&lt;\/hash&gt;\r\n      &lt;\/hashes&gt;\r\n      &lt;licenses&gt;\r\n        &lt;license&gt;\r\n          &lt;id&gt;Apache-2.0&lt;\/id&gt;\r\n        &lt;\/license&gt;\r\n      &lt;\/licenses&gt;\r\n      &lt;purl&gt;pkg:maven\/org.apache.logging.log4j\/log4j-api@2.20.0?type=jar&lt;\/purl&gt;\r\n      &lt;externalReferences&gt;&lt;reference type=\"website\"&gt;&lt;url&gt;https:\/\/logging.apache.org\/log4j\/2.x\/log4j-api\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"build-system\"&gt;&lt;url&gt;https:\/\/github.com\/apache\/logging-log4j2\/actions&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"distribution\"&gt;&lt;url&gt;https:\/\/logging.apache.org\/log4j\/2.x\/download.html&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"issue-tracker\"&gt;&lt;url&gt;https:\/\/github.com\/apache\/logging-log4j2\/issues&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"mailing-list\"&gt;&lt;url&gt;https:\/\/lists.apache.org\/list.html?log4j-user@logging.apache.org&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"vcs\"&gt;&lt;url&gt;https:\/\/github.com\/apache\/logging-log4j2\/log4j-api&lt;\/url&gt;&lt;\/reference&gt;&lt;\/externalReferences&gt;\r\n    &lt;\/component&gt;\r\n    &lt;component type=\"library\" bom-ref=\"pkg:maven\/org.slf4j\/slf4j-simple@2.0.0-alpha5?type=jar\"&gt;\r\n      &lt;publisher&gt;QOS.ch&lt;\/publisher&gt;\r\n      &lt;group&gt;org.slf4j&lt;\/group&gt;\r\n      &lt;name&gt;slf4j-simple&lt;\/name&gt;\r\n      &lt;version&gt;2.0.0-alpha5&lt;\/version&gt;\r\n      &lt;description&gt;SLF4J Simple binding&lt;\/description&gt;\r\n      &lt;scope&gt;required&lt;\/scope&gt;\r\n      &lt;hashes&gt;\r\n        &lt;hash alg=\"MD5\"&gt;38adc719300aa7c7c014e1080491d39a&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-1\"&gt;5a3906d6c39e2bc4e38782228b13f8da5eef7fb2&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-256\"&gt;d56dacb6baccb6695061fbc5fb5761f09b84e0760d20a4873a634bf2a51c5242&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-512\"&gt;907320c05ff54fe02c71cc041ba70a9f2d2483a3f1618b76a99dd9d03388fb98de31cc492156f719e048f03510e06a95697051e231bd7ebd04a0a7d925376b90&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-384\"&gt;de90c6f560e1cb157ee156bd4dca17af1f2e8a326f0151727501ec654c2d77486ff8391c5b6e4f8861b91dfd8844650e&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-384\"&gt;da0c34404aa65affcda1e71f386c8d337ab49374b761dda1c362a548f7633bd78b901fe742972bb9e8284b0a836753c9&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-256\"&gt;a443f45ae729c6b7442a0e70b91cc5225d0db160f0e55915d8851a295daef09c&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-512\"&gt;1e0a9f01265caec83cd6d43df9613dd3e83211e0fc2ed2993000ac93ae7336db410cc09bb2d4a34489021abf67857615489a5d9fdf5350e7a6647fad8ea9a50a&lt;\/hash&gt;\r\n      &lt;\/hashes&gt;\r\n      &lt;licenses&gt;\r\n        &lt;license&gt;\r\n          &lt;id&gt;MIT&lt;\/id&gt;\r\n          &lt;url&gt;https:\/\/opensource.org\/licenses\/MIT&lt;\/url&gt;\r\n        &lt;\/license&gt;\r\n      &lt;\/licenses&gt;\r\n      &lt;purl&gt;pkg:maven\/org.slf4j\/slf4j-simple@2.0.0-alpha5?type=jar&lt;\/purl&gt;\r\n      &lt;externalReferences&gt;&lt;reference type=\"website\"&gt;&lt;url&gt;http:\/\/www.slf4j.org&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"distribution\"&gt;&lt;url&gt;https:\/\/oss.sonatype.org\/service\/local\/staging\/deploy\/maven2\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"vcs\"&gt;&lt;url&gt;https:\/\/github.com\/qos-ch\/slf4j\/slf4j-simple&lt;\/url&gt;&lt;\/reference&gt;&lt;\/externalReferences&gt;\r\n    &lt;\/component&gt;\r\n    &lt;component type=\"library\" bom-ref=\"pkg:maven\/org.slf4j\/slf4j-api@2.0.0-alpha5?type=jar\"&gt;\r\n      &lt;publisher&gt;QOS.ch&lt;\/publisher&gt;\r\n      &lt;group&gt;org.slf4j&lt;\/group&gt;\r\n      &lt;name&gt;slf4j-api&lt;\/name&gt;\r\n      &lt;version&gt;2.0.0-alpha5&lt;\/version&gt;\r\n      &lt;description&gt;The slf4j API&lt;\/description&gt;\r\n      &lt;scope&gt;required&lt;\/scope&gt;\r\n      &lt;hashes&gt;\r\n        &lt;hash alg=\"MD5\"&gt;17f3fb533a070f0e3e61a1609b7da32a&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-1\"&gt;241721b0e0ef3cd6cf584b8f0e24d24ea80799ea&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-256\"&gt;299f935195950ec5441aaa332c7fccb758fbca59163c93c1b1627b5985f4fedb&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-512\"&gt;7a0a06175efccc3119d8e6e073dd5580cc32ab46875217680090231e53bfa3a9f7d963c44f7a8e5aeed1e8168ba11fdcba66aafa3123c95062aaf5f7e68e03ec&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-384\"&gt;409d08229fa689500d4194c27d3c62353ae8ceaef841da5b91cf9f627a8e8bf69d4edd8495b4b582f6e73f6e2a68c166&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-384\"&gt;82e6f8ea53aef20ed9d1bf5da33c9598d3d8533779737502b60d70f0a1e281f3878361d8a3cfbd13541140b0f66121a5&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-256\"&gt;4a54303e58fb8c0155365a07bd66ad66e91875d578186229c928f423f014f714&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-512\"&gt;44ab6763cb1d7ef3d54a57d858acfaae220150faf782cfe064e31979122fada826f05fc2f51d2af63f9dbc30eb2a784cc2b1b8c8a022b2720c84b676cf45ed5b&lt;\/hash&gt;\r\n      &lt;\/hashes&gt;\r\n      &lt;licenses&gt;\r\n        &lt;license&gt;\r\n          &lt;id&gt;MIT&lt;\/id&gt;\r\n          &lt;url&gt;https:\/\/opensource.org\/licenses\/MIT&lt;\/url&gt;\r\n        &lt;\/license&gt;\r\n      &lt;\/licenses&gt;\r\n      &lt;purl&gt;pkg:maven\/org.slf4j\/slf4j-api@2.0.0-alpha5?type=jar&lt;\/purl&gt;\r\n      &lt;externalReferences&gt;&lt;reference type=\"website\"&gt;&lt;url&gt;http:\/\/www.slf4j.org&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"distribution\"&gt;&lt;url&gt;https:\/\/oss.sonatype.org\/service\/local\/staging\/deploy\/maven2\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"vcs\"&gt;&lt;url&gt;https:\/\/github.com\/qos-ch\/slf4j\/slf4j-api&lt;\/url&gt;&lt;\/reference&gt;&lt;\/externalReferences&gt;\r\n    &lt;\/component&gt;\r\n    &lt;component type=\"library\" bom-ref=\"pkg:maven\/org.mnode.ical4j\/ical4j@3.0.4?type=jar\"&gt;\r\n      &lt;group&gt;org.mnode.ical4j&lt;\/group&gt;\r\n      &lt;name&gt;ical4j&lt;\/name&gt;\r\n      &lt;version&gt;3.0.4&lt;\/version&gt;\r\n      &lt;description&gt;A Java library for reading and writing iCalendar (*.ics) files&lt;\/description&gt;\r\n      &lt;scope&gt;required&lt;\/scope&gt;\r\n      &lt;hashes&gt;\r\n        &lt;hash alg=\"MD5\"&gt;a88534595acac0de514a0517df0e098e&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-1\"&gt;822c90df39a712b8d5aac4052a39871094b66f70&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-256\"&gt;9b05caa3cd03d5dd828b21fc00c41eb98dddc317d4d6a1818a1c795d8d09c48a&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-512\"&gt;3ebe70ac67a3acc2f613e4585daa1696117af633898186bdb242821734b43bda26922a2135d783e950eaf23f254cb356d757575255afec2fc491b5bed640ffe3&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-384\"&gt;c2effb780212f1c265679058b36883d233eadfec090a470be21bd7c63de13538ccbe4341fe3ede35487661f410ec7a97&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-384\"&gt;538b13a205dcf73d58cd22d65c0aa1691d4265f97f0f3189b39930e5b1d9d257297968bd5ee383d183a2e679dad3c3a7&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-256\"&gt;bdfd8ffeb4ec8a0b1f8e3e7c52bebadeb6c4967ce2b53cd748fd8c6035afe755&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-512\"&gt;88238d8488971a0b22e90472fe22a285a7a07cedaf9b1274e2711a7ac0074fcc7e02f60108be36aeaebdf71ec7e1f365df95004d17c4f38d9e28e238eb6030e3&lt;\/hash&gt;\r\n      &lt;\/hashes&gt;\r\n      &lt;licenses&gt;\r\n        &lt;license&gt;\r\n          &lt;name&gt;iCal4j - License&lt;\/name&gt;\r\n          &lt;url&gt;https:\/\/raw.githubusercontent.com\/ical4j\/ical4j\/master\/LICENSE&lt;\/url&gt;\r\n        &lt;\/license&gt;\r\n      &lt;\/licenses&gt;\r\n      &lt;purl&gt;pkg:maven\/org.mnode.ical4j\/ical4j@3.0.4?type=jar&lt;\/purl&gt;\r\n      &lt;externalReferences&gt;&lt;reference type=\"website\"&gt;&lt;url&gt;http:\/\/ical4j.github.io&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"vcs\"&gt;&lt;url&gt;https:\/\/github.com\/ical4j\/ical4j&lt;\/url&gt;&lt;\/reference&gt;&lt;\/externalReferences&gt;\r\n    &lt;\/component&gt;\r\n    &lt;component type=\"library\" bom-ref=\"pkg:maven\/org.apache.commons\/commons-lang3@3.6?type=jar\"&gt;\r\n      &lt;publisher&gt;The Apache Software Foundation&lt;\/publisher&gt;\r\n      &lt;group&gt;org.apache.commons&lt;\/group&gt;\r\n      &lt;name&gt;commons-lang3&lt;\/name&gt;\r\n      &lt;version&gt;3.6&lt;\/version&gt;\r\n      &lt;description&gt;Apache Commons Lang, a package of Java utility classes for the\r\n  classes that are in java.lang's hierarchy, or are considered to be so\r\n  standard as to justify existence in java.lang.&lt;\/description&gt;\r\n      &lt;scope&gt;required&lt;\/scope&gt;\r\n      &lt;hashes&gt;\r\n        &lt;hash alg=\"MD5\"&gt;5d18f68b5122fd398c118df53ab4cf55&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-1\"&gt;9d28a6b23650e8a7e9063c04588ace6cf7012c17&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-256\"&gt;89c27f03fff18d0b06e7afd7ef25e209766df95b6c1269d6c3ebbdea48d5f284&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-512\"&gt;88501994a338221464b2e87c83dd12b6572daf882cb760419edd66ca2805dbb09d96693c21144b00026e68919436af87534f719896bcd5e3f9a66cef12736675&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-384\"&gt;d4420dc812feb3ee261b144a29ad9cdd08c03840530134b3f5149a561c0cd8ead3838a66c5f6d5aacb8573188293193f&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-384\"&gt;d2254530c9f37c904a7c6e5484b5f8fe95f06b8ba75066ac0e96ef3fb6efebbdfa521dd65545dc4be56d4d4b324f2a1d&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-256\"&gt;ac16eab0dbd28ff2f1a26454be50492bb5681dc540399fda389c662ab0652d01&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-512\"&gt;713971e9ac9eab4163834e200c02ffd0fb69dbe29dca9374c3a7c19e4783476229dbec17e10d88a1273aeab0309cadd036e2ea6394498d3158b4e1ab99db031d&lt;\/hash&gt;\r\n      &lt;\/hashes&gt;\r\n      &lt;licenses&gt;\r\n        &lt;license&gt;\r\n          &lt;id&gt;Apache-2.0&lt;\/id&gt;\r\n        &lt;\/license&gt;\r\n      &lt;\/licenses&gt;\r\n      &lt;purl&gt;pkg:maven\/org.apache.commons\/commons-lang3@3.6?type=jar&lt;\/purl&gt;\r\n      &lt;externalReferences&gt;&lt;reference type=\"website\"&gt;&lt;url&gt;http:\/\/commons.apache.org\/proper\/commons-lang\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"build-system\"&gt;&lt;url&gt;https:\/\/builds.apache.org\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"distribution\"&gt;&lt;url&gt;https:\/\/repository.apache.org\/service\/local\/staging\/deploy\/maven2&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"issue-tracker\"&gt;&lt;url&gt;http:\/\/issues.apache.org\/jira\/browse\/LANG&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"mailing-list\"&gt;&lt;url&gt;http:\/\/mail-archives.apache.org\/mod_mbox\/commons-user\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"vcs\"&gt;&lt;url&gt;https:\/\/git-wip-us.apache.org\/repos\/asf?p=commons-lang.git&lt;\/url&gt;&lt;\/reference&gt;&lt;\/externalReferences&gt;\r\n    &lt;\/component&gt;\r\n    &lt;component type=\"library\" bom-ref=\"pkg:maven\/org.apache.commons\/commons-collections4@4.1?type=jar\"&gt;\r\n      &lt;publisher&gt;The Apache Software Foundation&lt;\/publisher&gt;\r\n      &lt;group&gt;org.apache.commons&lt;\/group&gt;\r\n      &lt;name&gt;commons-collections4&lt;\/name&gt;\r\n      &lt;version&gt;4.1&lt;\/version&gt;\r\n      &lt;description&gt;The Apache Commons Collections package contains types that extend and augment the Java Collections Framework.&lt;\/description&gt;\r\n      &lt;scope&gt;required&lt;\/scope&gt;\r\n      &lt;hashes&gt;\r\n        &lt;hash alg=\"MD5\"&gt;45af6a8e5b51d5945de6c7411e290bd1&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-1\"&gt;a4cf4688fe1c7e3a63aa636cc96d013af537768e&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-256\"&gt;b1fe8b5968b57d8465425357ed2d9dc695504518bed2df5b565c4b8e68c1c8a5&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-512\"&gt;1553751f9126b24f8c893b169df881052483ccf1586efeed4215b6ef013e115e001b96a09d348055df6d1be338a0fa1b14b28fedca3f1663273931a7d17e1363&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-384\"&gt;76724283c14e799f161e999cfe24a2444764a83027c2fc43099153c6586d704682eca31b045c3adcfd9440fa073af4da&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-384\"&gt;54c6fd77fd95fe1859438d5e550ae5f82f13b8ea4e789a4c9c1d0de943b6a16c142bf1f422dec9e075d3e5f9d052b27e&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-256\"&gt;874dea7fc249c98eafa0bed0801583cd84393b7ef4d1fcb3d0451a8d83335fc5&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-512\"&gt;a72d4f6987f253753e2f6b5e1367493e4261d935e5e84c9f487f48beaf05702dc0fd90050e830a9edcc56b3a075beb26a72741360eb7691208b73e3d771b675e&lt;\/hash&gt;\r\n      &lt;\/hashes&gt;\r\n      &lt;licenses&gt;\r\n        &lt;license&gt;\r\n          &lt;id&gt;Apache-2.0&lt;\/id&gt;\r\n        &lt;\/license&gt;\r\n      &lt;\/licenses&gt;\r\n      &lt;purl&gt;pkg:maven\/org.apache.commons\/commons-collections4@4.1?type=jar&lt;\/purl&gt;\r\n      &lt;externalReferences&gt;&lt;reference type=\"website\"&gt;&lt;url&gt;http:\/\/commons.apache.org\/proper\/commons-collections\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"build-system\"&gt;&lt;url&gt;https:\/\/continuum-ci.apache.org\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"distribution\"&gt;&lt;url&gt;https:\/\/repository.apache.org\/service\/local\/staging\/deploy\/maven2&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"issue-tracker\"&gt;&lt;url&gt;http:\/\/issues.apache.org\/jira\/browse\/COLLECTIONS&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"mailing-list\"&gt;&lt;url&gt;http:\/\/mail-archives.apache.org\/mod_mbox\/commons-user\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"vcs\"&gt;&lt;url&gt;http:\/\/svn.apache.org\/viewvc\/commons\/proper\/collections\/trunk&lt;\/url&gt;&lt;\/reference&gt;&lt;\/externalReferences&gt;\r\n    &lt;\/component&gt;\r\n    &lt;component type=\"library\" bom-ref=\"pkg:maven\/commons-cli\/commons-cli@1.2?type=jar\"&gt;\r\n      &lt;publisher&gt;The Apache Software Foundation&lt;\/publisher&gt;\r\n      &lt;group&gt;commons-cli&lt;\/group&gt;\r\n      &lt;name&gt;commons-cli&lt;\/name&gt;\r\n      &lt;version&gt;1.2&lt;\/version&gt;\r\n      &lt;description&gt;Commons CLI provides a simple API for presenting, processing and validating a command line interface.&lt;\/description&gt;\r\n      &lt;scope&gt;required&lt;\/scope&gt;\r\n      &lt;hashes&gt;\r\n        &lt;hash alg=\"MD5\"&gt;bfdcae1ff93f0c07d733f03bdce28c9e&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-1\"&gt;2bf96b7aa8b611c177d329452af1dc933e14501c&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-256\"&gt;e7cd8951956d349b568b7ccfd4f5b2529a8c113e67c32b028f52ffda371259d9&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-512\"&gt;0b8f4610d3a05a589026b1af605cf976f73e6fecb9b9cce9f572e5883ce0a78e8a9cfe48e06257bb68cb8eea080ffe84a2b0b73682036f85dbbb3c03cfdedfaa&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-384\"&gt;3e39c2926a3d022280dc6a706f0be11d073541500b641dfe485c7b054469a8a01902cbc8692e38ff976bc69fd974174f&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-384\"&gt;c22f48ca48d04a717549df9b083aba508af9bc87439a33edbfb05e9a3d458eb6b3ec5f0014242547ccb24eb59f2d7b8f&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-256\"&gt;006a8f27b555487fc21e99848344dfa671be826310aef75138cbb0e9be773b6b&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-512\"&gt;841bd6703e4fe9792736de93a5ea54821af0dc4f297ff96b3116067895650e3fb3721159dc6b7d34214e376b4d1f936414b21747562f2462b818c576cf0e73a6&lt;\/hash&gt;\r\n      &lt;\/hashes&gt;\r\n      &lt;licenses&gt;\r\n        &lt;license&gt;\r\n          &lt;id&gt;Apache-2.0&lt;\/id&gt;\r\n        &lt;\/license&gt;\r\n      &lt;\/licenses&gt;\r\n      &lt;purl&gt;pkg:maven\/commons-cli\/commons-cli@1.2?type=jar&lt;\/purl&gt;\r\n      &lt;externalReferences&gt;&lt;reference type=\"website\"&gt;&lt;url&gt;http:\/\/commons.apache.org\/cli\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"build-system\"&gt;&lt;url&gt;http:\/\/vmbuild.apache.org\/continuum\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"distribution\"&gt;&lt;url&gt;&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"issue-tracker\"&gt;&lt;url&gt;http:\/\/issues.apache.org\/jira\/browse\/CLI&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"mailing-list\"&gt;&lt;url&gt;http:\/\/mail-archives.apache.org\/mod_mbox\/commons-user\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"vcs\"&gt;&lt;url&gt;http:\/\/svn.apache.org\/viewvc\/commons\/proper\/cli\/branches\/cli-1.x\/&lt;\/url&gt;&lt;\/reference&gt;&lt;\/externalReferences&gt;\r\n    &lt;\/component&gt;\r\n    &lt;component type=\"library\" bom-ref=\"pkg:maven\/com.itextpdf\/itext7-core@7.2.2?type=pom\"&gt;\r\n      &lt;group&gt;com.itextpdf&lt;\/group&gt;\r\n      &lt;name&gt;itext7-core&lt;\/name&gt;\r\n      &lt;version&gt;7.2.2&lt;\/version&gt;\r\n      &lt;scope&gt;required&lt;\/scope&gt;\r\n      &lt;hashes&gt;\r\n        &lt;hash alg=\"MD5\"&gt;7de7c332191daab572adf25c3e5687ac&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-1\"&gt;ad7868eed753503a76eca2d55b45a36d43c661b2&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-256\"&gt;f4d9cd4684b13ad9dcbbde9d74bf55ab9824f9f6d813619e2f2e23d5e1b30e9a&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-512\"&gt;18df5cd3939a257ba62011362120cb09250e7ae8da1ef0254f0b687d0bc88c2fad704eb5df2766b753ff5d78aa76ffc8d82d10aac6b2f446b8a655acfabde158&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-384\"&gt;0265e332e9f500d1a263892d4a204a0625927b225bd8c3288f1fd4e69b4f89186a308a2ffc37f5c35cef0278aeaa6f8c&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-384\"&gt;62f265afd53af96cb4d4ee7a309ca3a4b2565b1eef31f5c8f80570a6c5ba1c4239b4d09a7c99eae41b955fdd399a6f40&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-256\"&gt;8f3047857fb4e3ec39b717812e495280a3d67e39e22577780736161e045f902e&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-512\"&gt;2a0cb33acd46c4b46278c3faaeb5d7c59043dea8765b2f02a550e69063b2acc502f7c0b121c59e343f59b0904fefca11c54c838a6af8895d9989d144c62af7b0&lt;\/hash&gt;\r\n      &lt;\/hashes&gt;\r\n      &lt;purl&gt;pkg:maven\/com.itextpdf\/itext7-core@7.2.2?type=pom&lt;\/purl&gt;\r\n    &lt;\/component&gt;\r\n    &lt;component type=\"library\" bom-ref=\"pkg:maven\/com.itextpdf\/barcodes@7.2.2?type=jar\"&gt;\r\n      &lt;publisher&gt;iText Group NV&lt;\/publisher&gt;\r\n      &lt;group&gt;com.itextpdf&lt;\/group&gt;\r\n      &lt;name&gt;barcodes&lt;\/name&gt;\r\n      &lt;version&gt;7.2.2&lt;\/version&gt;\r\n      &lt;description&gt;A Free Java-PDF library&lt;\/description&gt;\r\n      &lt;scope&gt;required&lt;\/scope&gt;\r\n      &lt;hashes&gt;\r\n        &lt;hash alg=\"MD5\"&gt;3dd4d9d277d89aef0d6591dc609d6a81&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-1\"&gt;c49ffbabe3d34100a2c981c3e5080d900963e63c&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-256\"&gt;728ee1e1ce6cb81cc0b85abd6c2f4c427ec177e4d85639bd07858fe004333899&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-512\"&gt;af69a28a68dbc4f98de7f3872c027cf482f80d43be5581b1dbe925feed2796ba558cef6126449a5a709b6adae7d9b5d033c8ee28dcb214de6f04e38c8d7944c7&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-384\"&gt;9460560ffc023623b75d27cf3ec42782391b425933e4528eedcc0ea21492640b01a57bde63a0271a9b43c89f22edb7b5&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-384\"&gt;6cd97670052ed94e03518239ef8eb31670bf9d72db5ebeb496d6e443c5f4f4b66b193a29ce04b924815895d809e04961&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-256\"&gt;fcd8ef982685c3223e6ebb3bea63da6ec321d2564a46db56506530ab75c179ee&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-512\"&gt;361ef5b657eccda591d0853388eed6ba23ef4c6e9ce82fc2e946b3d5e73fb314b9a7af3980dc8fe2e81aa08d8199776c8733af332f1e5b67997028fca9cc33dd&lt;\/hash&gt;\r\n      &lt;\/hashes&gt;\r\n      &lt;licenses&gt;\r\n        &lt;license&gt;\r\n          &lt;name&gt;GNU Affero General Public License v3&lt;\/name&gt;\r\n          &lt;url&gt;http:\/\/www.fsf.org\/licensing\/licenses\/agpl-3.0.html&lt;\/url&gt;\r\n        &lt;\/license&gt;\r\n      &lt;\/licenses&gt;\r\n      &lt;purl&gt;pkg:maven\/com.itextpdf\/barcodes@7.2.2?type=jar&lt;\/purl&gt;\r\n      &lt;externalReferences&gt;&lt;reference type=\"website\"&gt;&lt;url&gt;https:\/\/itextpdf.com\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"build-system\"&gt;&lt;url&gt;https:\/\/jenkins.itextsupport.com\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"issue-tracker\"&gt;&lt;url&gt;https:\/\/jira.itextsupport.com\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"mailing-list\"&gt;&lt;url&gt;https:\/\/stackoverflow.com\/questions\/tagged\/itext7&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"vcs\"&gt;&lt;url&gt;https:\/\/git.itextsupport.com\/projects\/I7J\/repos\/itextcore\/barcodes&lt;\/url&gt;&lt;\/reference&gt;&lt;\/externalReferences&gt;\r\n    &lt;\/component&gt;\r\n    &lt;component type=\"library\" bom-ref=\"pkg:maven\/com.itextpdf\/font-asian@7.2.2?type=jar\"&gt;\r\n      &lt;publisher&gt;iText Group NV&lt;\/publisher&gt;\r\n      &lt;group&gt;com.itextpdf&lt;\/group&gt;\r\n      &lt;name&gt;font-asian&lt;\/name&gt;\r\n      &lt;version&gt;7.2.2&lt;\/version&gt;\r\n      &lt;description&gt;iText Asian fonts for use in conjunction with iText 7, a free Java-PDF library&lt;\/description&gt;\r\n      &lt;scope&gt;required&lt;\/scope&gt;\r\n      &lt;hashes&gt;\r\n        &lt;hash alg=\"MD5\"&gt;636ba26afdd74d4085fe3907577c4cdc&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-1\"&gt;5c1c77a8399bd675585d5448ca806afb320bb03f&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-256\"&gt;cfa8ba8283e3607e8465cc6fe28229282330bc20adab337d5fd3bc6a5d1db094&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-512\"&gt;298ffceeed227524a46fe515f0878cf952b5e3bb44dd36ec34aad5dc2516e86bb46fc59bba79a157388ed94ddb7f74c460650c2b6f282d7b3d9b0a3c8281e931&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-384\"&gt;9b25b0d83320bd7da5cd04fa3eb7fabb367e082b224730a93fc9af2a35a91e8bcbefc902669ff41af40906948743c298&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-384\"&gt;7db64cc0c5adfb1dc2f5c45b33fbb9a76cf1a7053246aa889cd3b554b586e8fcd7690cead58e01ed582902f40bfbd6f8&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-256\"&gt;a9734684907ce6a06347a4c864eda2149162a738014f465b43d895dc363ec066&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-512\"&gt;e3ac0c4e2b5bc38b133131a6091db4e480145e82cc21cbba13f447eca85494ad8f27541f2189eb7ab8aaeb5d8162b31ec2e1d0b5edc2b95bcd24a46f0916d0fe&lt;\/hash&gt;\r\n      &lt;\/hashes&gt;\r\n      &lt;licenses&gt;\r\n        &lt;license&gt;\r\n          &lt;name&gt;Various licenses (see individual files)&lt;\/name&gt;\r\n        &lt;\/license&gt;\r\n      &lt;\/licenses&gt;\r\n      &lt;purl&gt;pkg:maven\/com.itextpdf\/font-asian@7.2.2?type=jar&lt;\/purl&gt;\r\n      &lt;externalReferences&gt;&lt;reference type=\"website\"&gt;&lt;url&gt;https:\/\/itextpdf.com\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"build-system\"&gt;&lt;url&gt;https:\/\/jenkins.itextsupport.com\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"issue-tracker\"&gt;&lt;url&gt;https:\/\/jira.itextsupport.com\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"mailing-list\"&gt;&lt;url&gt;https:\/\/stackoverflow.com\/questions\/tagged\/itext7&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"vcs\"&gt;&lt;url&gt;https:\/\/git.itextsupport.com\/projects\/I7J\/repos\/itextcore\/font-asian&lt;\/url&gt;&lt;\/reference&gt;&lt;\/externalReferences&gt;\r\n    &lt;\/component&gt;\r\n    &lt;component type=\"library\" bom-ref=\"pkg:maven\/com.itextpdf\/forms@7.2.2?type=jar\"&gt;\r\n      &lt;publisher&gt;iText Group NV&lt;\/publisher&gt;\r\n      &lt;group&gt;com.itextpdf&lt;\/group&gt;\r\n      &lt;name&gt;forms&lt;\/name&gt;\r\n      &lt;version&gt;7.2.2&lt;\/version&gt;\r\n      &lt;description&gt;A Free Java-PDF library&lt;\/description&gt;\r\n      &lt;scope&gt;required&lt;\/scope&gt;\r\n      &lt;hashes&gt;\r\n        &lt;hash alg=\"MD5\"&gt;8ec6b0f615c5e443620364b32ad58877&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-1\"&gt;50864f947e2dcc85649056fd580c79a664655f33&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-256\"&gt;48552f05fd64be580aa6d04ad51edb878b1f36a30c13f53a1ddf8d8b709cf893&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-512\"&gt;a0613549afeb9b45c17c2c9d6df5f4f69ff078c46648daa881c8d80a83bec27a30fccca143ed9ff466bd05e9472e620485c4e08117ca47e68fb5d00395f11e31&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-384\"&gt;a252e4e79f2d0ceb1dcc82fc71b9ff0bb54956a53eaeabe21a13032346b6fa940c67deaed2e16efdcc68fe29c276f292&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-384\"&gt;b94316833bc3d6918cb1682c81834d752b2ad6cb0fb0949464fe35caf240a47b7b76dca8e12595011d9486c86b40cd95&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-256\"&gt;67443a4a864458f2fb63dfaec0864b1c8f7cea87b996ebb4563e7d0de97b595b&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-512\"&gt;fbbd26a08a468a05aa92f3a4e5c8ed55781fcafc94b3cad9a0c9437983cb958d48b3e79addb0147ce3f8cac5ba520ed09da4bf2dc132809acc813148e6055141&lt;\/hash&gt;\r\n      &lt;\/hashes&gt;\r\n      &lt;licenses&gt;\r\n        &lt;license&gt;\r\n          &lt;name&gt;GNU Affero General Public License v3&lt;\/name&gt;\r\n          &lt;url&gt;http:\/\/www.fsf.org\/licensing\/licenses\/agpl-3.0.html&lt;\/url&gt;\r\n        &lt;\/license&gt;\r\n      &lt;\/licenses&gt;\r\n      &lt;purl&gt;pkg:maven\/com.itextpdf\/forms@7.2.2?type=jar&lt;\/purl&gt;\r\n      &lt;externalReferences&gt;&lt;reference type=\"website\"&gt;&lt;url&gt;https:\/\/itextpdf.com\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"build-system\"&gt;&lt;url&gt;https:\/\/jenkins.itextsupport.com\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"issue-tracker\"&gt;&lt;url&gt;https:\/\/jira.itextsupport.com\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"mailing-list\"&gt;&lt;url&gt;https:\/\/stackoverflow.com\/questions\/tagged\/itext7&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"vcs\"&gt;&lt;url&gt;https:\/\/git.itextsupport.com\/projects\/I7J\/repos\/itextcore\/forms&lt;\/url&gt;&lt;\/reference&gt;&lt;\/externalReferences&gt;\r\n    &lt;\/component&gt;\r\n    &lt;component type=\"library\" bom-ref=\"pkg:maven\/com.itextpdf\/hyph@7.2.2?type=jar\"&gt;\r\n      &lt;publisher&gt;iText Group NV&lt;\/publisher&gt;\r\n      &lt;group&gt;com.itextpdf&lt;\/group&gt;\r\n      &lt;name&gt;hyph&lt;\/name&gt;\r\n      &lt;version&gt;7.2.2&lt;\/version&gt;\r\n      &lt;description&gt;XML files that can be used for hyphenation&lt;\/description&gt;\r\n      &lt;scope&gt;required&lt;\/scope&gt;\r\n      &lt;hashes&gt;\r\n        &lt;hash alg=\"MD5\"&gt;91445e6a91ac58b464cae5ce52cca4fb&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-1\"&gt;5865942ed26bb3c48cff58e4331628dfa94bcf5a&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-256\"&gt;a4f48d140aad8a0197cfc11d7efa3edc2a5ec34984160d88a40f44a046a53636&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-512\"&gt;d51438d4861db96377d094bcbd92760fb4ce13e6f6cd66152913cdc48e6b5d6a8192a5bf80a71857c711234a3092f8bf0dffc7f8d77063ba1ff2cdcb77d207ae&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-384\"&gt;bdc3a842cb5a0aaaf10f9db83073d71cd93ada9741d4b229bfe2bb78e4fe5e504881486950a72aa752f43ecf76fa83cb&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-384\"&gt;92d0688cae51396468625d998306d027edc2781f4aed63e28371f82d43333fd4e02a7618e4aa96a41d5bd00e8cca7c4e&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-256\"&gt;75fc4c3f086ce7b2539812bed4be6e9f6dae44cda6a802f76aaf594f91d6aa85&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-512\"&gt;38085decc5497c38ea9fb3c2164cf8175a98736795d40bf12e1becb03b189710c9254d42be603af00b9f1ef540fde9c8eb9a77344cbfbe8b47a17e9d26a109e5&lt;\/hash&gt;\r\n      &lt;\/hashes&gt;\r\n      &lt;licenses&gt;\r\n        &lt;license&gt;\r\n          &lt;name&gt;Various licenses (see individual files)&lt;\/name&gt;\r\n        &lt;\/license&gt;\r\n      &lt;\/licenses&gt;\r\n      &lt;purl&gt;pkg:maven\/com.itextpdf\/hyph@7.2.2?type=jar&lt;\/purl&gt;\r\n      &lt;externalReferences&gt;&lt;reference type=\"website\"&gt;&lt;url&gt;https:\/\/itextpdf.com\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"build-system\"&gt;&lt;url&gt;https:\/\/jenkins.itextsupport.com\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"issue-tracker\"&gt;&lt;url&gt;https:\/\/jira.itextsupport.com\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"mailing-list\"&gt;&lt;url&gt;https:\/\/stackoverflow.com\/questions\/tagged\/itext7&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"vcs\"&gt;&lt;url&gt;https:\/\/git.itextsupport.com\/projects\/I7J\/repos\/itextcore\/hyph&lt;\/url&gt;&lt;\/reference&gt;&lt;\/externalReferences&gt;\r\n    &lt;\/component&gt;\r\n    &lt;component type=\"library\" bom-ref=\"pkg:maven\/com.itextpdf\/pdfa@7.2.2?type=jar\"&gt;\r\n      &lt;publisher&gt;iText Group NV&lt;\/publisher&gt;\r\n      &lt;group&gt;com.itextpdf&lt;\/group&gt;\r\n      &lt;name&gt;pdfa&lt;\/name&gt;\r\n      &lt;version&gt;7.2.2&lt;\/version&gt;\r\n      &lt;description&gt;A Free Java-PDF library&lt;\/description&gt;\r\n      &lt;scope&gt;required&lt;\/scope&gt;\r\n      &lt;hashes&gt;\r\n        &lt;hash alg=\"MD5\"&gt;0167db66d5cf9695ccf50a1e5559b5c1&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-1\"&gt;afff915b19274a35838a53b2867f9fbd7d73bcd0&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-256\"&gt;ebc185f88630fa6fec22a2a8e6c97db506bf8fc28c6fe357db0d39c87583cd65&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-512\"&gt;4ebcb3bb32cb325e73be8c4679a6818dc87329aa632f3a50dafa933ef5cbbd10c00659d5b8aff0fc63aaea157bda741c2bc57f1135d058ba6e473254d56eb55a&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-384\"&gt;7d9d0f91a5cb3a016164aea07f9af5aac37b5ea8d2c3928f0fae27b8490ee0f0ca79bb8c91ddc40e92077edecbfb78f0&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-384\"&gt;e53676e87cbcdec878fda6f147118f494cf21f4d20f967bf1b3d5e0ff6e71733629d967959e63cd37912f554729aab21&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-256\"&gt;df0ad54e27bd8d0a76e3e40541f533a131aa2b92061cc78202360866e562e719&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-512\"&gt;5ff48b54941ecc6a82b32085e2b4fb6704a20a534abddad1b42773593bf76a1a5e6023aae27e7d79f80ecb15ee61ac7d6b6f17be53a63e1d5ac33e3d22e887cd&lt;\/hash&gt;\r\n      &lt;\/hashes&gt;\r\n      &lt;licenses&gt;\r\n        &lt;license&gt;\r\n          &lt;name&gt;GNU Affero General Public License v3&lt;\/name&gt;\r\n          &lt;url&gt;http:\/\/www.fsf.org\/licensing\/licenses\/agpl-3.0.html&lt;\/url&gt;\r\n        &lt;\/license&gt;\r\n      &lt;\/licenses&gt;\r\n      &lt;purl&gt;pkg:maven\/com.itextpdf\/pdfa@7.2.2?type=jar&lt;\/purl&gt;\r\n      &lt;externalReferences&gt;&lt;reference type=\"website\"&gt;&lt;url&gt;https:\/\/itextpdf.com\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"build-system\"&gt;&lt;url&gt;https:\/\/jenkins.itextsupport.com\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"issue-tracker\"&gt;&lt;url&gt;https:\/\/jira.itextsupport.com\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"mailing-list\"&gt;&lt;url&gt;https:\/\/stackoverflow.com\/questions\/tagged\/itext7&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"vcs\"&gt;&lt;url&gt;https:\/\/git.itextsupport.com\/projects\/I7J\/repos\/itextcore\/pdfa&lt;\/url&gt;&lt;\/reference&gt;&lt;\/externalReferences&gt;\r\n    &lt;\/component&gt;\r\n    &lt;component type=\"library\" bom-ref=\"pkg:maven\/com.itextpdf\/sign@7.2.2?type=jar\"&gt;\r\n      &lt;publisher&gt;iText Group NV&lt;\/publisher&gt;\r\n      &lt;group&gt;com.itextpdf&lt;\/group&gt;\r\n      &lt;name&gt;sign&lt;\/name&gt;\r\n      &lt;version&gt;7.2.2&lt;\/version&gt;\r\n      &lt;description&gt;A Free Java-PDF library&lt;\/description&gt;\r\n      &lt;scope&gt;required&lt;\/scope&gt;\r\n      &lt;hashes&gt;\r\n        &lt;hash alg=\"MD5\"&gt;4114079a195bc56392e5b977b7f94816&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-1\"&gt;dfe222045ae956b7e9ef0882c68158861937e1bd&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-256\"&gt;6b923bde58208e66ddc02edddc03f29c9e8350d03703fd332f87d51ebb3e7433&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-512\"&gt;094286e9d5ebd3acdc80231581066b1d698c4610d78c823b81dd66940f73383313ce2dcdc9444630cdc0eff5a505d01737cd3c5eb810f40e3613c965062f1878&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-384\"&gt;48f4f75903f2b13776ea6881996f25c05ce80a7470c9bc4508540075f39d71bec7281ace3aa744f0b72606aeced96e85&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-384\"&gt;a64b804f754e92bb176b7095df97cee03303586191099f4462a6d721f189f56f03de5a520f4aa9dba90d974768e96939&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-256\"&gt;0e27d5e7580be0a2d831d621d7603f5215537d48fda39186d1c745c2083b8c44&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-512\"&gt;6b6d0e9b3f4af2aa4642237bf00c534cf96f6a5fef171b1dc1023ee4af85ad6614f639948ae2824b423d4dfae66169236edf3dad1ec13727eacff24568446828&lt;\/hash&gt;\r\n      &lt;\/hashes&gt;\r\n      &lt;licenses&gt;\r\n        &lt;license&gt;\r\n          &lt;name&gt;GNU Affero General Public License v3&lt;\/name&gt;\r\n          &lt;url&gt;http:\/\/www.fsf.org\/licensing\/licenses\/agpl-3.0.html&lt;\/url&gt;\r\n        &lt;\/license&gt;\r\n      &lt;\/licenses&gt;\r\n      &lt;purl&gt;pkg:maven\/com.itextpdf\/sign@7.2.2?type=jar&lt;\/purl&gt;\r\n      &lt;externalReferences&gt;&lt;reference type=\"website\"&gt;&lt;url&gt;https:\/\/itextpdf.com\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"build-system\"&gt;&lt;url&gt;https:\/\/jenkins.itextsupport.com\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"issue-tracker\"&gt;&lt;url&gt;https:\/\/jira.itextsupport.com\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"mailing-list\"&gt;&lt;url&gt;https:\/\/stackoverflow.com\/questions\/tagged\/itext7&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"vcs\"&gt;&lt;url&gt;https:\/\/git.itextsupport.com\/projects\/I7J\/repos\/itextcore\/sign&lt;\/url&gt;&lt;\/reference&gt;&lt;\/externalReferences&gt;\r\n    &lt;\/component&gt;\r\n    &lt;component type=\"library\" bom-ref=\"pkg:maven\/com.itextpdf\/styled-xml-parser@7.2.2?type=jar\"&gt;\r\n      &lt;publisher&gt;iText Group NV&lt;\/publisher&gt;\r\n      &lt;group&gt;com.itextpdf&lt;\/group&gt;\r\n      &lt;name&gt;styled-xml-parser&lt;\/name&gt;\r\n      &lt;version&gt;7.2.2&lt;\/version&gt;\r\n      &lt;description&gt;Styled XML parser is used by iText7 modules to parse HTML and XML&lt;\/description&gt;\r\n      &lt;scope&gt;required&lt;\/scope&gt;\r\n      &lt;hashes&gt;\r\n        &lt;hash alg=\"MD5\"&gt;0fc03234c107454322edf6e53dc9fd6c&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-1\"&gt;1ae9a60eda61adb5748c90771b883271dd8f952b&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-256\"&gt;04649d5cfc8690dee4cf3ec5a45c73a0ecee296a98f4be0a790db19c91e23960&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-512\"&gt;b982732639856cd620a77b613d77524391c3c4b454adc64a1eed37ea611f12d0a754f53fdd291fdfec9c193a80e8710ed8fbbb618098775a55a4375e39810f46&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-384\"&gt;22c37848050f23a02153b512db920c3e1730fd5c977e5545d66a231fcc4bddab9fd1687573c7f6e51b950cb04e8cad4b&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-384\"&gt;dee1c42f307cbce9127c0b6ab204a415a3bde8019eb141692a02d70fb10efb8b8605a662f67f1c74e071f87ff29e12b6&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-256\"&gt;33d6685fe5ee2624d673f8eb2afffa6796c6f059db5b5d90623f1b8ff437bcaf&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-512\"&gt;1d6f3cdfe589e1d0f80359ebefe250e0f13abafa0976e4a52338267c945ebb806c3efe4c351199841a02ed0c45ebabbed560892c6cf13bdd4897843aadb694d7&lt;\/hash&gt;\r\n      &lt;\/hashes&gt;\r\n      &lt;licenses&gt;\r\n        &lt;license&gt;\r\n          &lt;name&gt;GNU Affero General Public License v3&lt;\/name&gt;\r\n          &lt;url&gt;http:\/\/www.fsf.org\/licensing\/licenses\/agpl-3.0.html&lt;\/url&gt;\r\n        &lt;\/license&gt;\r\n      &lt;\/licenses&gt;\r\n      &lt;purl&gt;pkg:maven\/com.itextpdf\/styled-xml-parser@7.2.2?type=jar&lt;\/purl&gt;\r\n      &lt;externalReferences&gt;&lt;reference type=\"website\"&gt;&lt;url&gt;https:\/\/itextpdf.com\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"build-system\"&gt;&lt;url&gt;https:\/\/jenkins.itextsupport.com\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"issue-tracker\"&gt;&lt;url&gt;https:\/\/jira.itextsupport.com\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"mailing-list\"&gt;&lt;url&gt;https:\/\/stackoverflow.com\/questions\/tagged\/itext7&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"vcs\"&gt;&lt;url&gt;https:\/\/git.itextsupport.com\/projects\/I7J\/repos\/itextcore\/styled-xml-parser&lt;\/url&gt;&lt;\/reference&gt;&lt;\/externalReferences&gt;\r\n    &lt;\/component&gt;\r\n    &lt;component type=\"library\" bom-ref=\"pkg:maven\/com.itextpdf\/svg@7.2.2?type=jar\"&gt;\r\n      &lt;publisher&gt;iText Group NV&lt;\/publisher&gt;\r\n      &lt;group&gt;com.itextpdf&lt;\/group&gt;\r\n      &lt;name&gt;svg&lt;\/name&gt;\r\n      &lt;version&gt;7.2.2&lt;\/version&gt;\r\n      &lt;description&gt;svg is a module for iText7 that allows you to integrate SVG images in your PDF creation and manipulation process&lt;\/description&gt;\r\n      &lt;scope&gt;required&lt;\/scope&gt;\r\n      &lt;hashes&gt;\r\n        &lt;hash alg=\"MD5\"&gt;82fe6b897ce033f1a09778e65d261db0&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-1\"&gt;4bc5ae6dd793e937f7056c0007d1d749dab4c67a&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-256\"&gt;8bd2d146f7efc8c6ff9509749ceb6504c5664489a4e84c05852fac1cbd476d54&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-512\"&gt;802e0eb578571f79c742d126ff17945edb7501834a60a523901ff95bc695ece24ec57d7fc74cd1553f29c48de40c239d114419dcf28d755acb0f908caa4dcd3f&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-384\"&gt;c58bf0d8d42f295a33d1b743af7830135d1fc0f3c4aab6b57dc8b9646dd67af349085e2ed00b9368a26a75f68bcf432e&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-384\"&gt;b01086a0fc165e397dc27704748c72e8446f8f8c5e8592f90e9187f4d69be6ab708c8e0ee7ba5dd4e3f2e9adcbfdb1f5&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-256\"&gt;9994dce6d0bab71e18655dbacbbbce00a1d5610b5d87f4d42594e816e27ac875&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-512\"&gt;304d47d0927b4fd0be2932cf17d61b7664187e3ec4e08e7dc6f5b10c2a490f301df5a18583ba2a9a8eb02a4f237eee9cab89ada8bc4ad61e73d1e22e4fae699c&lt;\/hash&gt;\r\n      &lt;\/hashes&gt;\r\n      &lt;licenses&gt;\r\n        &lt;license&gt;\r\n          &lt;name&gt;GNU Affero General Public License v3&lt;\/name&gt;\r\n          &lt;url&gt;http:\/\/www.fsf.org\/licensing\/licenses\/agpl-3.0.html&lt;\/url&gt;\r\n        &lt;\/license&gt;\r\n      &lt;\/licenses&gt;\r\n      &lt;purl&gt;pkg:maven\/com.itextpdf\/svg@7.2.2?type=jar&lt;\/purl&gt;\r\n      &lt;externalReferences&gt;&lt;reference type=\"website\"&gt;&lt;url&gt;https:\/\/itextpdf.com\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"build-system\"&gt;&lt;url&gt;https:\/\/jenkins.itextsupport.com\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"issue-tracker\"&gt;&lt;url&gt;https:\/\/jira.itextsupport.com\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"mailing-list\"&gt;&lt;url&gt;https:\/\/stackoverflow.com\/questions\/tagged\/itext7&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"vcs\"&gt;&lt;url&gt;https:\/\/git.itextsupport.com\/projects\/I7J\/repos\/itextcore\/svg&lt;\/url&gt;&lt;\/reference&gt;&lt;\/externalReferences&gt;\r\n    &lt;\/component&gt;\r\n    &lt;component type=\"library\" bom-ref=\"pkg:maven\/com.itextpdf\/layout@7.2.2?type=jar\"&gt;\r\n      &lt;publisher&gt;iText Group NV&lt;\/publisher&gt;\r\n      &lt;group&gt;com.itextpdf&lt;\/group&gt;\r\n      &lt;name&gt;layout&lt;\/name&gt;\r\n      &lt;version&gt;7.2.2&lt;\/version&gt;\r\n      &lt;description&gt;A Free Java-PDF library&lt;\/description&gt;\r\n      &lt;scope&gt;required&lt;\/scope&gt;\r\n      &lt;hashes&gt;\r\n        &lt;hash alg=\"MD5\"&gt;1515a9584648f8eb35111c3d5c14e302&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-1\"&gt;c25f01cdf16bd8ddc1da5c2e042aaa033d780a00&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-256\"&gt;3ede1d839b0236ff607e51e4e77d2316c86aa6600e4bee84b22d5e699d875874&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-512\"&gt;da0f6f6331a7cc3adfb4f5a55c29446ba2788ac1b46607a12e70279a00cc09a8643c4bcc85d824a756cb80ab59ac38103cd7b8299db6eeec2eebce0d17ab2704&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-384\"&gt;b90d9b3f1bbcb0544f6e2fd38c87f63aaa7e5dffd9e653c1afb207cf9999174dfffa079a75883be4f9427cfb0fa06a98&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-384\"&gt;f839912347c963430cff9290a4739cec600a76adbe5bb147ecad9e134e1f388dd00949cce603097fecd98afd7d8a65e7&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-256\"&gt;ce8b98f1900cef1b296e44be5850c7f7783694fe64c2a58c98b2e7daa033c92e&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-512\"&gt;e7179bd12bb156f33d8cf8080f98df7148390ebd1c02a297a1d67b262a1b7397d23be54f427a1beff115adaba4f6d11aeca0b2f868bbc5a042e57d05acde8532&lt;\/hash&gt;\r\n      &lt;\/hashes&gt;\r\n      &lt;licenses&gt;\r\n        &lt;license&gt;\r\n          &lt;name&gt;GNU Affero General Public License v3&lt;\/name&gt;\r\n          &lt;url&gt;http:\/\/www.fsf.org\/licensing\/licenses\/agpl-3.0.html&lt;\/url&gt;\r\n        &lt;\/license&gt;\r\n      &lt;\/licenses&gt;\r\n      &lt;purl&gt;pkg:maven\/com.itextpdf\/layout@7.2.2?type=jar&lt;\/purl&gt;\r\n      &lt;externalReferences&gt;&lt;reference type=\"website\"&gt;&lt;url&gt;https:\/\/itextpdf.com\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"build-system\"&gt;&lt;url&gt;https:\/\/jenkins.itextsupport.com\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"issue-tracker\"&gt;&lt;url&gt;https:\/\/jira.itextsupport.com\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"mailing-list\"&gt;&lt;url&gt;https:\/\/stackoverflow.com\/questions\/tagged\/itext7&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"vcs\"&gt;&lt;url&gt;https:\/\/git.itextsupport.com\/projects\/I7J\/repos\/itextcore\/layout&lt;\/url&gt;&lt;\/reference&gt;&lt;\/externalReferences&gt;\r\n    &lt;\/component&gt;\r\n    &lt;component type=\"library\" bom-ref=\"pkg:maven\/com.itextpdf\/kernel@7.2.2?type=jar\"&gt;\r\n      &lt;publisher&gt;iText Group NV&lt;\/publisher&gt;\r\n      &lt;group&gt;com.itextpdf&lt;\/group&gt;\r\n      &lt;name&gt;kernel&lt;\/name&gt;\r\n      &lt;version&gt;7.2.2&lt;\/version&gt;\r\n      &lt;description&gt;A Free Java-PDF library&lt;\/description&gt;\r\n      &lt;scope&gt;required&lt;\/scope&gt;\r\n      &lt;hashes&gt;\r\n        &lt;hash alg=\"MD5\"&gt;9808df2241f1c061f10bc06abe5563ca&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-1\"&gt;39b29155bde729295254f0b7cc828810ba348c6a&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-256\"&gt;d8b0b5f2227fcbf35f501031777e53484d7b2ffeb30dff92894a62fe12800a27&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-512\"&gt;dc55e98a565d54bcd3c9e8dc6cce0ce5d58d86bb1185d7c726a9435dd931cfc43d2fe20caabd054eb2dafd016f77b8846c70cbdafd8cef569250206d75de6086&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-384\"&gt;59b9d04b037fb0e16056363efcb1a79966304072cc85d72bc407821e9723aa281f9954479c0f12a9988e1e5e0ab93c28&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-384\"&gt;d57d0c875b9084ef427c470a86c6aedb06413be30658197c357c57c0ec204a941ca28aab72536b03eabf30356741279d&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-256\"&gt;7d899745d909e892ee5a104acbbd1412fc75117a25760493bb56428de5979130&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-512\"&gt;a1d1f078eb03c399bce2d28bf9b1ca499d02151d6d84099fe0698165c999ae22fa798f33ca119af8211bebc02d5787ffd7a3bd3c4f6798c7945934e451570e23&lt;\/hash&gt;\r\n      &lt;\/hashes&gt;\r\n      &lt;licenses&gt;\r\n        &lt;license&gt;\r\n          &lt;name&gt;GNU Affero General Public License v3&lt;\/name&gt;\r\n          &lt;url&gt;http:\/\/www.fsf.org\/licensing\/licenses\/agpl-3.0.html&lt;\/url&gt;\r\n        &lt;\/license&gt;\r\n      &lt;\/licenses&gt;\r\n      &lt;purl&gt;pkg:maven\/com.itextpdf\/kernel@7.2.2?type=jar&lt;\/purl&gt;\r\n      &lt;externalReferences&gt;&lt;reference type=\"website\"&gt;&lt;url&gt;https:\/\/itextpdf.com\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"build-system\"&gt;&lt;url&gt;https:\/\/jenkins.itextsupport.com\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"issue-tracker\"&gt;&lt;url&gt;https:\/\/jira.itextsupport.com\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"mailing-list\"&gt;&lt;url&gt;https:\/\/stackoverflow.com\/questions\/tagged\/itext7&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"vcs\"&gt;&lt;url&gt;https:\/\/git.itextsupport.com\/projects\/I7J\/repos\/itextcore\/kernel&lt;\/url&gt;&lt;\/reference&gt;&lt;\/externalReferences&gt;\r\n    &lt;\/component&gt;\r\n    &lt;component type=\"library\" bom-ref=\"pkg:maven\/org.bouncycastle\/bcpkix-jdk15on@1.70?type=jar\"&gt;\r\n      &lt;group&gt;org.bouncycastle&lt;\/group&gt;\r\n      &lt;name&gt;bcpkix-jdk15on&lt;\/name&gt;\r\n      &lt;version&gt;1.70&lt;\/version&gt;\r\n      &lt;description&gt;The Bouncy Castle Java APIs for CMS, PKCS, EAC, TSP, CMP, CRMF, OCSP, and certificate generation. This jar contains APIs for JDK 1.5 and up. The APIs can be used in conjunction with a JCE\/JCA provider such as the one provided with the Bouncy Castle Cryptography APIs.&lt;\/description&gt;\r\n      &lt;scope&gt;required&lt;\/scope&gt;\r\n      &lt;hashes&gt;\r\n        &lt;hash alg=\"MD5\"&gt;2c383f50d41937eae4fd32c35d8668cd&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-1\"&gt;f81e5af49571a9d5a109a88f239a73ce87055417&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-256\"&gt;e5b9cb821df57f70b0593358e89c0e8d7266515da9d088af6c646f63d433c07c&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-512\"&gt;477001e9556cdbe7fe9eca0c35b3ce29cd6b4d9cd5e13d1f44e3da6433d56a18e23f3679603a23730d78a93bd401113b804562c8bacb1e745e7944127f7afa4c&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-384\"&gt;249614fa138e4b405ad067f69ee538269ade5a517d8f47b6d69bfc8180ae48c019570540a47314f3b64060a6bca20682&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-384\"&gt;13d1354f83de80b89fa91ffc44a14b0aeee418367ec7dde95aaecd70f6d219e4ed1bbf102e099cdfe64737c06dafc199&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-256\"&gt;afc8204fb76d0ec343ba436eaeac7834156ee976a1e0b2bafd0075812451046a&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-512\"&gt;b55bcc09c9f9c87332160ce068ca349502d628c34b156ebb30a99d94f87606d59ccc62f8ded4a927d57ed9553d274b34a8f9b5602a5eefad66958f9eddbffa28&lt;\/hash&gt;\r\n      &lt;\/hashes&gt;\r\n      &lt;licenses&gt;\r\n        &lt;license&gt;\r\n          &lt;name&gt;Bouncy Castle Licence&lt;\/name&gt;\r\n          &lt;url&gt;https:\/\/www.bouncycastle.org\/licence.html&lt;\/url&gt;\r\n        &lt;\/license&gt;\r\n      &lt;\/licenses&gt;\r\n      &lt;purl&gt;pkg:maven\/org.bouncycastle\/bcpkix-jdk15on@1.70?type=jar&lt;\/purl&gt;\r\n      &lt;externalReferences&gt;&lt;reference type=\"website\"&gt;&lt;url&gt;https:\/\/www.bouncycastle.org\/java.html&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"issue-tracker\"&gt;&lt;url&gt;https:\/\/github.com\/bcgit\/bc-java\/issues&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"vcs\"&gt;&lt;url&gt;https:\/\/github.com\/bcgit\/bc-java&lt;\/url&gt;&lt;\/reference&gt;&lt;\/externalReferences&gt;\r\n    &lt;\/component&gt;\r\n    &lt;component type=\"library\" bom-ref=\"pkg:maven\/org.bouncycastle\/bcutil-jdk15on@1.70?type=jar\"&gt;\r\n      &lt;group&gt;org.bouncycastle&lt;\/group&gt;\r\n      &lt;name&gt;bcutil-jdk15on&lt;\/name&gt;\r\n      &lt;version&gt;1.70&lt;\/version&gt;\r\n      &lt;description&gt;The Bouncy Castle Java APIs for ASN.1 extension and utility APIs used to support bcpkix and bctls. This jar contains APIs for JDK 1.5 and up.&lt;\/description&gt;\r\n      &lt;scope&gt;required&lt;\/scope&gt;\r\n      &lt;hashes&gt;\r\n        &lt;hash alg=\"MD5\"&gt;805173dfb0891331dbe69d0e53371af4&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-1\"&gt;54280e7195a7430d7911ded93fc01e07300b9526&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-256\"&gt;52dc5551b0257666526c5095424567fed7dc7b00d2b1ba7bd52298411112b1d0&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-512\"&gt;f65fc2af60be9b4a0cfa227cede3ba5ef994716dcd462a9935ef74535a32e67c56cff92e6af9d5168c7a866e5f7c9fd17797485b89eb020eda12f7018af0fca1&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-384\"&gt;46f32ed832f447e519beab6c553ffbab455376bdaed3554bc8c687b876776861afa02bd5ae226cdc0dc3f0c2ae28c9a4&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-384\"&gt;749aa3317618bc93fbdf12fb49f4c653f81321b4ee69d7807515f50234bf531539bd6eb5c3ed34955eeb60bdb56967dc&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-256\"&gt;2dc5b7a38918f9eed8e3652c0794d8bf3eb674d8b0f24f03c64edc2e2ac251eb&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-512\"&gt;0506c3a4cfad6c892568ffefb71b049ef7c943e5ab172ac8756cebcd53a7facee7c1472b18ed2211eb6f820dbfc6bd07da25dee62a5edc61dc6b333d42964fbc&lt;\/hash&gt;\r\n      &lt;\/hashes&gt;\r\n      &lt;licenses&gt;\r\n        &lt;license&gt;\r\n          &lt;name&gt;Bouncy Castle Licence&lt;\/name&gt;\r\n          &lt;url&gt;https:\/\/www.bouncycastle.org\/licence.html&lt;\/url&gt;\r\n        &lt;\/license&gt;\r\n      &lt;\/licenses&gt;\r\n      &lt;purl&gt;pkg:maven\/org.bouncycastle\/bcutil-jdk15on@1.70?type=jar&lt;\/purl&gt;\r\n      &lt;externalReferences&gt;&lt;reference type=\"website\"&gt;&lt;url&gt;https:\/\/www.bouncycastle.org\/java.html&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"issue-tracker\"&gt;&lt;url&gt;https:\/\/github.com\/bcgit\/bc-java\/issues&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"vcs\"&gt;&lt;url&gt;https:\/\/github.com\/bcgit\/bc-java&lt;\/url&gt;&lt;\/reference&gt;&lt;\/externalReferences&gt;\r\n    &lt;\/component&gt;\r\n    &lt;component type=\"library\" bom-ref=\"pkg:maven\/org.bouncycastle\/bcprov-jdk15on@1.70?type=jar\"&gt;\r\n      &lt;group&gt;org.bouncycastle&lt;\/group&gt;\r\n      &lt;name&gt;bcprov-jdk15on&lt;\/name&gt;\r\n      &lt;version&gt;1.70&lt;\/version&gt;\r\n      &lt;description&gt;The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.5 and up.&lt;\/description&gt;\r\n      &lt;scope&gt;required&lt;\/scope&gt;\r\n      &lt;hashes&gt;\r\n        &lt;hash alg=\"MD5\"&gt;1809d0449a6374279c01fdd3be26cd92&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-1\"&gt;4636a0d01f74acaf28082fb62b317f1080118371&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-256\"&gt;8f3c20e3e2d565d26f33e8d4857a37d0d7f8ac39b62a7026496fcab1bdac30d4&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-512\"&gt;7dccfc636ee4df1487615818cfa99c69941081df95e8ef1eaf4bca165594dff9547e3774fd70de3418abace77d2c45889f70bcd2e6823f8539f359e68eaf36d1&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-384\"&gt;a0b35d204cd962f1d246fa94b6e8b0fcee1a7c3f37b7e87cda742f2124a25b48794ce11a903ea8d12009c86227b6808d&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-384\"&gt;980d81d3d9906764bbf2ae9b3b364ea58628b485ce1dc3d06734e10495d79f2be2e7cc7df61ac88cd67c1104c7af9393&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-256\"&gt;10a3572e42d29f609721d795116e3e5d0f6f03efef84bb979ce72e26908d242b&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-512\"&gt;a0761cb6deeb86c94b96850c72c0a0eaf516ca849f4b8268f9f60c9ed2a6730e692c15098d47e617da294e931113c6cbcaddec8957c9f029fa595b5f14ff35ac&lt;\/hash&gt;\r\n      &lt;\/hashes&gt;\r\n      &lt;licenses&gt;\r\n        &lt;license&gt;\r\n          &lt;name&gt;Bouncy Castle Licence&lt;\/name&gt;\r\n          &lt;url&gt;https:\/\/www.bouncycastle.org\/licence.html&lt;\/url&gt;\r\n        &lt;\/license&gt;\r\n      &lt;\/licenses&gt;\r\n      &lt;purl&gt;pkg:maven\/org.bouncycastle\/bcprov-jdk15on@1.70?type=jar&lt;\/purl&gt;\r\n      &lt;externalReferences&gt;&lt;reference type=\"website\"&gt;&lt;url&gt;https:\/\/www.bouncycastle.org\/java.html&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"issue-tracker\"&gt;&lt;url&gt;https:\/\/github.com\/bcgit\/bc-java\/issues&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"vcs\"&gt;&lt;url&gt;https:\/\/github.com\/bcgit\/bc-java&lt;\/url&gt;&lt;\/reference&gt;&lt;\/externalReferences&gt;\r\n    &lt;\/component&gt;\r\n    &lt;component type=\"library\" bom-ref=\"pkg:maven\/com.itextpdf\/io@7.2.2?type=jar\"&gt;\r\n      &lt;publisher&gt;iText Group NV&lt;\/publisher&gt;\r\n      &lt;group&gt;com.itextpdf&lt;\/group&gt;\r\n      &lt;name&gt;io&lt;\/name&gt;\r\n      &lt;version&gt;7.2.2&lt;\/version&gt;\r\n      &lt;description&gt;A Free Java-PDF library&lt;\/description&gt;\r\n      &lt;scope&gt;required&lt;\/scope&gt;\r\n      &lt;hashes&gt;\r\n        &lt;hash alg=\"MD5\"&gt;af0d5d79e49c556f4144183d35bcf9ac&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-1\"&gt;ab280225933bd4724114509acfca08cb0215d19a&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-256\"&gt;412b7f1628b5388951de125318579b241418a17c1b4ad612d0144c020a5c509b&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-512\"&gt;5e3df3dd84274b073768f4eb0d125624764183f51bc34dfae6f12b196f431170d0896996d6ada29da148749747281303699a70bc936d2222dc967ef37377bc45&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-384\"&gt;fbda6e3452bd37d7d9646ef5b5d09536ff4b9ed6dd5b27084fb37cde8a1c32626c5dbcb8be25bd34185277b8f2074dd0&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-384\"&gt;17542c1c2d0314599b5e74055cdb68ba802f1f8bd86fbda2fbf2124e55492b43c82f37781ebb7dc59a5828f69ced7a31&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-256\"&gt;d76b0b85e5b0a30030e2e66549730a8332482f82c72ff0d04c3288eb740088d2&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-512\"&gt;5473f1d95908d569f876e670b49bb5d979c0fb9a61f1f503f60d65ba4d8f4e34820e5703934d25eb16a6d83ad27ca06059a335cfb4dea81aa03209a0b3c31d2e&lt;\/hash&gt;\r\n      &lt;\/hashes&gt;\r\n      &lt;licenses&gt;\r\n        &lt;license&gt;\r\n          &lt;name&gt;GNU Affero General Public License v3&lt;\/name&gt;\r\n          &lt;url&gt;http:\/\/www.fsf.org\/licensing\/licenses\/agpl-3.0.html&lt;\/url&gt;\r\n        &lt;\/license&gt;\r\n      &lt;\/licenses&gt;\r\n      &lt;purl&gt;pkg:maven\/com.itextpdf\/io@7.2.2?type=jar&lt;\/purl&gt;\r\n      &lt;externalReferences&gt;&lt;reference type=\"website\"&gt;&lt;url&gt;https:\/\/itextpdf.com\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"build-system\"&gt;&lt;url&gt;https:\/\/jenkins.itextsupport.com\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"issue-tracker\"&gt;&lt;url&gt;https:\/\/jira.itextsupport.com\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"mailing-list\"&gt;&lt;url&gt;https:\/\/stackoverflow.com\/questions\/tagged\/itext7&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"vcs\"&gt;&lt;url&gt;https:\/\/git.itextsupport.com\/projects\/I7J\/repos\/itextcore\/io&lt;\/url&gt;&lt;\/reference&gt;&lt;\/externalReferences&gt;\r\n    &lt;\/component&gt;\r\n    &lt;component type=\"library\" bom-ref=\"pkg:maven\/com.itextpdf\/commons@7.2.2?type=jar\"&gt;\r\n      &lt;publisher&gt;iText Group NV&lt;\/publisher&gt;\r\n      &lt;group&gt;com.itextpdf&lt;\/group&gt;\r\n      &lt;name&gt;commons&lt;\/name&gt;\r\n      &lt;version&gt;7.2.2&lt;\/version&gt;\r\n      &lt;description&gt;A Free Java-PDF library&lt;\/description&gt;\r\n      &lt;scope&gt;required&lt;\/scope&gt;\r\n      &lt;hashes&gt;\r\n        &lt;hash alg=\"MD5\"&gt;ab9952d9cb8a35270fc46c8d3327f360&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-1\"&gt;b6f6c03afe61ca09fce222b5e2bbe4613e9a0fd4&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-256\"&gt;4982d939d0aefcdffd2f593500e7d6e9e3a5faf432cb4869951fca3809cea7ac&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-512\"&gt;07f37faed9a9865729ceb6f7543b64ee91100717fd4a9a396adc3194a221670a0a56929f4394d066211906da910d8197f95b62496e110ede2fe84010b594e53f&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-384\"&gt;3c72ee93d50eefe2f7b98c976ae6ec45c9017b60ae6511e990487ce7699773858aab2713bc3461368281bb853d2195d2&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-384\"&gt;93d29a8a7dffed4a406eda15e2b97717225ea265d50877309b6822b005faf94cba53351d96b6a252374cdda355feea8c&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-256\"&gt;8d60b5bcef56636b95c2f87ba9998958425e2ab614d8d8184cfa25ab441fd5aa&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-512\"&gt;345515ddbf1f36f3cccb10957c524d529cdf5e5bd566bd1020ebc65579cc6b7869a6f9efecd663f2e02a0d239cc4b8ca64e40252be681451ca763b5c168f9fdc&lt;\/hash&gt;\r\n      &lt;\/hashes&gt;\r\n      &lt;licenses&gt;\r\n        &lt;license&gt;\r\n          &lt;name&gt;GNU Affero General Public License v3&lt;\/name&gt;\r\n          &lt;url&gt;http:\/\/www.fsf.org\/licensing\/licenses\/agpl-3.0.html&lt;\/url&gt;\r\n        &lt;\/license&gt;\r\n      &lt;\/licenses&gt;\r\n      &lt;purl&gt;pkg:maven\/com.itextpdf\/commons@7.2.2?type=jar&lt;\/purl&gt;\r\n      &lt;externalReferences&gt;&lt;reference type=\"website\"&gt;&lt;url&gt;https:\/\/itextpdf.com\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"build-system\"&gt;&lt;url&gt;https:\/\/jenkins.itextsupport.com\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"issue-tracker\"&gt;&lt;url&gt;https:\/\/jira.itextsupport.com\/&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"mailing-list\"&gt;&lt;url&gt;https:\/\/stackoverflow.com\/questions\/tagged\/itext7&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"vcs\"&gt;&lt;url&gt;https:\/\/git.itextsupport.com\/projects\/I7J\/repos\/itextcore\/commons&lt;\/url&gt;&lt;\/reference&gt;&lt;\/externalReferences&gt;\r\n    &lt;\/component&gt;\r\n    &lt;component type=\"library\" bom-ref=\"pkg:maven\/info.picocli\/picocli@4.6.1?type=jar\"&gt;\r\n      &lt;group&gt;info.picocli&lt;\/group&gt;\r\n      &lt;name&gt;picocli&lt;\/name&gt;\r\n      &lt;version&gt;4.6.1&lt;\/version&gt;\r\n      &lt;description&gt;Java command line parser with both an annotations API and a programmatic API. Usage help with ANSI styles and colors. Autocomplete. Nested subcommands. Easily included as source to avoid adding a dependency.&lt;\/description&gt;\r\n      &lt;scope&gt;required&lt;\/scope&gt;\r\n      &lt;hashes&gt;\r\n        &lt;hash alg=\"MD5\"&gt;f09461a45f8d0591e6625bc4ecba5ced&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-1\"&gt;49a67ee4b4d9722fa60f3f9ffaffa72861c32966&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-256\"&gt;2a6e03310db149f8a11eb058aa78e775c229ef816333c9687379762d22833ad6&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-512\"&gt;96ac6f7246444370b6d8d394f904ad818363759819275a14b8fc5d26398ad8db8984092c2d3de7ad91325a158bd7d74a6665a1fd4183afa6a872abbfcdbc9177&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA-384\"&gt;39b9a9defc500ab665f3779a1d93f3fb565910fe545f1a10fc4955c512d7585bb11667c0f9f7b7ef52642f771f868454&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-384\"&gt;6b3aa01915963c4df64de644fb80099f89b0ee1f1ee7e6e66f9b96bc24c58c58833dc722d57c616b2698c477d1e51d6c&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-256\"&gt;49f9d4983ba32a94a5b8ecf55ada85e3cacdbfb333c2c97c143f6306f2e39e44&lt;\/hash&gt;\r\n        &lt;hash alg=\"SHA3-512\"&gt;7c4ed578d560ee7e31881397b9be492db3ebdb8fd17b05adc4860daabf06540cc40da7006129a8f91156c87d3d599b6ec417a60d9610e677d0c2a31d77e01a36&lt;\/hash&gt;\r\n      &lt;\/hashes&gt;\r\n      &lt;licenses&gt;\r\n        &lt;license&gt;\r\n          &lt;id&gt;Apache-2.0&lt;\/id&gt;\r\n        &lt;\/license&gt;\r\n      &lt;\/licenses&gt;\r\n      &lt;purl&gt;pkg:maven\/info.picocli\/picocli@4.6.1?type=jar&lt;\/purl&gt;\r\n      &lt;externalReferences&gt;&lt;reference type=\"website\"&gt;&lt;url&gt;http:\/\/picocli.info&lt;\/url&gt;&lt;\/reference&gt;&lt;reference type=\"vcs\"&gt;&lt;url&gt;https:\/\/github.com\/remkop\/picocli\/tree\/master&lt;\/url&gt;&lt;\/reference&gt;&lt;\/externalReferences&gt;\r\n    &lt;\/component&gt;\r\n  &lt;\/components&gt;\r\n  &lt;dependencies&gt;\r\n    &lt;dependency ref=\"pkg:maven\/de.wenzlaff.twbibel\/de.wenzlaff.twbibel@0.1.1?type=jar\"&gt;\r\n      &lt;dependency ref=\"pkg:maven\/org.openjfx\/javafx-graphics@17.0.1?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/org.openjfx\/javafx-fxml@16-ea%2B5?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/org.openjfx\/javafx-controls@17.0.1?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/org.openjfx\/javafx-base@17.0.1?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/org.apache.httpcomponents\/httpclient@4.5.13?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/org.apache.logging.log4j\/log4j-core@2.20.0?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/org.apache.logging.log4j\/log4j-api@2.20.0?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/org.slf4j\/slf4j-simple@2.0.0-alpha5?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/org.mnode.ical4j\/ical4j@3.0.4?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/commons-cli\/commons-cli@1.2?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/com.itextpdf\/itext7-core@7.2.2?type=pom\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/com.itextpdf\/layout@7.2.2?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/com.itextpdf\/kernel@7.2.2?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/com.itextpdf\/io@7.2.2?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/info.picocli\/picocli@4.6.1?type=jar\"\/&gt;\r\n    &lt;\/dependency&gt;\r\n    &lt;dependency ref=\"pkg:maven\/org.openjfx\/javafx-graphics@17.0.1?type=jar\"&gt;\r\n      &lt;dependency ref=\"pkg:maven\/org.openjfx\/javafx-graphics@17.0.1?classifier=mac&amp;amp;type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/org.openjfx\/javafx-base@17.0.1?type=jar\"\/&gt;\r\n    &lt;\/dependency&gt;\r\n    &lt;dependency ref=\"pkg:maven\/org.openjfx\/javafx-graphics@17.0.1?classifier=mac&amp;amp;type=jar\"\/&gt;\r\n    &lt;dependency ref=\"pkg:maven\/org.openjfx\/javafx-base@17.0.1?type=jar\"&gt;\r\n      &lt;dependency ref=\"pkg:maven\/org.openjfx\/javafx-base@17.0.1?classifier=mac&amp;amp;type=jar\"\/&gt;\r\n    &lt;\/dependency&gt;\r\n    &lt;dependency ref=\"pkg:maven\/org.openjfx\/javafx-base@17.0.1?classifier=mac&amp;amp;type=jar\"\/&gt;\r\n    &lt;dependency ref=\"pkg:maven\/org.openjfx\/javafx-fxml@16-ea%2B5?type=jar\"&gt;\r\n      &lt;dependency ref=\"pkg:maven\/org.openjfx\/javafx-fxml@16-ea%2B5?classifier=mac&amp;amp;type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/org.openjfx\/javafx-controls@17.0.1?type=jar\"\/&gt;\r\n    &lt;\/dependency&gt;\r\n    &lt;dependency ref=\"pkg:maven\/org.openjfx\/javafx-fxml@16-ea%2B5?classifier=mac&amp;amp;type=jar\"\/&gt;\r\n    &lt;dependency ref=\"pkg:maven\/org.openjfx\/javafx-controls@17.0.1?type=jar\"&gt;\r\n      &lt;dependency ref=\"pkg:maven\/org.openjfx\/javafx-controls@17.0.1?classifier=mac&amp;amp;type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/org.openjfx\/javafx-graphics@17.0.1?type=jar\"\/&gt;\r\n    &lt;\/dependency&gt;\r\n    &lt;dependency ref=\"pkg:maven\/org.openjfx\/javafx-controls@17.0.1?classifier=mac&amp;amp;type=jar\"\/&gt;\r\n    &lt;dependency ref=\"pkg:maven\/org.apache.httpcomponents\/httpclient@4.5.13?type=jar\"&gt;\r\n      &lt;dependency ref=\"pkg:maven\/org.apache.httpcomponents\/httpcore@4.4.13?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/commons-logging\/commons-logging@1.2?type=jar\"\/&gt;\r\n    &lt;\/dependency&gt;\r\n    &lt;dependency ref=\"pkg:maven\/org.apache.httpcomponents\/httpcore@4.4.13?type=jar\"\/&gt;\r\n    &lt;dependency ref=\"pkg:maven\/commons-logging\/commons-logging@1.2?type=jar\"\/&gt;\r\n    &lt;dependency ref=\"pkg:maven\/org.apache.logging.log4j\/log4j-core@2.20.0?type=jar\"&gt;\r\n      &lt;dependency ref=\"pkg:maven\/org.apache.logging.log4j\/log4j-api@2.20.0?type=jar\"\/&gt;\r\n    &lt;\/dependency&gt;\r\n    &lt;dependency ref=\"pkg:maven\/org.apache.logging.log4j\/log4j-api@2.20.0?type=jar\"\/&gt;\r\n    &lt;dependency ref=\"pkg:maven\/org.slf4j\/slf4j-simple@2.0.0-alpha5?type=jar\"&gt;\r\n      &lt;dependency ref=\"pkg:maven\/org.slf4j\/slf4j-api@2.0.0-alpha5?type=jar\"\/&gt;\r\n    &lt;\/dependency&gt;\r\n    &lt;dependency ref=\"pkg:maven\/org.slf4j\/slf4j-api@2.0.0-alpha5?type=jar\"\/&gt;\r\n    &lt;dependency ref=\"pkg:maven\/org.mnode.ical4j\/ical4j@3.0.4?type=jar\"&gt;\r\n      &lt;dependency ref=\"pkg:maven\/org.apache.commons\/commons-lang3@3.6?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/org.apache.commons\/commons-collections4@4.1?type=jar\"\/&gt;\r\n    &lt;\/dependency&gt;\r\n    &lt;dependency ref=\"pkg:maven\/org.apache.commons\/commons-lang3@3.6?type=jar\"\/&gt;\r\n    &lt;dependency ref=\"pkg:maven\/org.apache.commons\/commons-collections4@4.1?type=jar\"\/&gt;\r\n    &lt;dependency ref=\"pkg:maven\/commons-cli\/commons-cli@1.2?type=jar\"\/&gt;\r\n    &lt;dependency ref=\"pkg:maven\/com.itextpdf\/itext7-core@7.2.2?type=pom\"&gt;\r\n      &lt;dependency ref=\"pkg:maven\/com.itextpdf\/barcodes@7.2.2?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/com.itextpdf\/font-asian@7.2.2?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/com.itextpdf\/forms@7.2.2?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/com.itextpdf\/hyph@7.2.2?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/com.itextpdf\/io@7.2.2?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/com.itextpdf\/kernel@7.2.2?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/com.itextpdf\/layout@7.2.2?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/com.itextpdf\/pdfa@7.2.2?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/com.itextpdf\/sign@7.2.2?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/com.itextpdf\/styled-xml-parser@7.2.2?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/com.itextpdf\/svg@7.2.2?type=jar\"\/&gt;\r\n    &lt;\/dependency&gt;\r\n    &lt;dependency ref=\"pkg:maven\/com.itextpdf\/barcodes@7.2.2?type=jar\"&gt;\r\n      &lt;dependency ref=\"pkg:maven\/com.itextpdf\/kernel@7.2.2?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/org.slf4j\/slf4j-api@2.0.0-alpha5?type=jar\"\/&gt;\r\n    &lt;\/dependency&gt;\r\n    &lt;dependency ref=\"pkg:maven\/com.itextpdf\/kernel@7.2.2?type=jar\"&gt;\r\n      &lt;dependency ref=\"pkg:maven\/com.itextpdf\/io@7.2.2?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/org.bouncycastle\/bcpkix-jdk15on@1.70?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/org.bouncycastle\/bcprov-jdk15on@1.70?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/org.slf4j\/slf4j-api@2.0.0-alpha5?type=jar\"\/&gt;\r\n    &lt;\/dependency&gt;\r\n    &lt;dependency ref=\"pkg:maven\/com.itextpdf\/io@7.2.2?type=jar\"&gt;\r\n      &lt;dependency ref=\"pkg:maven\/com.itextpdf\/commons@7.2.2?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/org.slf4j\/slf4j-api@2.0.0-alpha5?type=jar\"\/&gt;\r\n    &lt;\/dependency&gt;\r\n    &lt;dependency ref=\"pkg:maven\/com.itextpdf\/commons@7.2.2?type=jar\"&gt;\r\n      &lt;dependency ref=\"pkg:maven\/org.slf4j\/slf4j-api@2.0.0-alpha5?type=jar\"\/&gt;\r\n    &lt;\/dependency&gt;\r\n    &lt;dependency ref=\"pkg:maven\/org.bouncycastle\/bcpkix-jdk15on@1.70?type=jar\"&gt;\r\n      &lt;dependency ref=\"pkg:maven\/org.bouncycastle\/bcprov-jdk15on@1.70?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/org.bouncycastle\/bcutil-jdk15on@1.70?type=jar\"\/&gt;\r\n    &lt;\/dependency&gt;\r\n    &lt;dependency ref=\"pkg:maven\/org.bouncycastle\/bcprov-jdk15on@1.70?type=jar\"\/&gt;\r\n    &lt;dependency ref=\"pkg:maven\/org.bouncycastle\/bcutil-jdk15on@1.70?type=jar\"&gt;\r\n      &lt;dependency ref=\"pkg:maven\/org.bouncycastle\/bcprov-jdk15on@1.70?type=jar\"\/&gt;\r\n    &lt;\/dependency&gt;\r\n    &lt;dependency ref=\"pkg:maven\/com.itextpdf\/font-asian@7.2.2?type=jar\"&gt;\r\n      &lt;dependency ref=\"pkg:maven\/org.slf4j\/slf4j-api@2.0.0-alpha5?type=jar\"\/&gt;\r\n    &lt;\/dependency&gt;\r\n    &lt;dependency ref=\"pkg:maven\/com.itextpdf\/forms@7.2.2?type=jar\"&gt;\r\n      &lt;dependency ref=\"pkg:maven\/com.itextpdf\/kernel@7.2.2?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/com.itextpdf\/layout@7.2.2?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/org.slf4j\/slf4j-api@2.0.0-alpha5?type=jar\"\/&gt;\r\n    &lt;\/dependency&gt;\r\n    &lt;dependency ref=\"pkg:maven\/com.itextpdf\/layout@7.2.2?type=jar\"&gt;\r\n      &lt;dependency ref=\"pkg:maven\/com.itextpdf\/kernel@7.2.2?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/org.slf4j\/slf4j-api@2.0.0-alpha5?type=jar\"\/&gt;\r\n    &lt;\/dependency&gt;\r\n    &lt;dependency ref=\"pkg:maven\/com.itextpdf\/hyph@7.2.2?type=jar\"&gt;\r\n      &lt;dependency ref=\"pkg:maven\/org.slf4j\/slf4j-api@2.0.0-alpha5?type=jar\"\/&gt;\r\n    &lt;\/dependency&gt;\r\n    &lt;dependency ref=\"pkg:maven\/com.itextpdf\/pdfa@7.2.2?type=jar\"&gt;\r\n      &lt;dependency ref=\"pkg:maven\/com.itextpdf\/kernel@7.2.2?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/org.slf4j\/slf4j-api@2.0.0-alpha5?type=jar\"\/&gt;\r\n    &lt;\/dependency&gt;\r\n    &lt;dependency ref=\"pkg:maven\/com.itextpdf\/sign@7.2.2?type=jar\"&gt;\r\n      &lt;dependency ref=\"pkg:maven\/com.itextpdf\/forms@7.2.2?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/com.itextpdf\/kernel@7.2.2?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/com.itextpdf\/layout@7.2.2?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/com.itextpdf\/pdfa@7.2.2?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/org.slf4j\/slf4j-api@2.0.0-alpha5?type=jar\"\/&gt;\r\n    &lt;\/dependency&gt;\r\n    &lt;dependency ref=\"pkg:maven\/com.itextpdf\/styled-xml-parser@7.2.2?type=jar\"&gt;\r\n      &lt;dependency ref=\"pkg:maven\/com.itextpdf\/io@7.2.2?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/com.itextpdf\/kernel@7.2.2?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/com.itextpdf\/layout@7.2.2?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/org.slf4j\/slf4j-api@2.0.0-alpha5?type=jar\"\/&gt;\r\n    &lt;\/dependency&gt;\r\n    &lt;dependency ref=\"pkg:maven\/com.itextpdf\/svg@7.2.2?type=jar\"&gt;\r\n      &lt;dependency ref=\"pkg:maven\/com.itextpdf\/layout@7.2.2?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/com.itextpdf\/styled-xml-parser@7.2.2?type=jar\"\/&gt;\r\n      &lt;dependency ref=\"pkg:maven\/org.slf4j\/slf4j-api@2.0.0-alpha5?type=jar\"\/&gt;\r\n    &lt;\/dependency&gt;\r\n    &lt;dependency ref=\"pkg:maven\/info.picocli\/picocli@4.6.1?type=jar\"\/&gt;\r\n  &lt;\/dependencies&gt;\r\n&lt;\/bom&gt;<\/pre>\n","protected":false},"excerpt":{"rendered":"<p>In einer zunehmend vernetzten und digitalisierten Welt sind Softwarekomponenten und -anwendungen allgegenw\u00e4rtig. Unternehmen verlassen sich auf komplexe Softwarel\u00f6sungen, um ihre Gesch\u00e4ftsprozesse zu unterst\u00fctzen und innovative Produkte und Dienstleistungen anzubieten. Angesichts der wachsenden Bedrohungen durch Sicherheitsl\u00fccken und Compliance-Anforderungen wird die Transparenz \u00fcber die verwendeten Softwarekomponenten immer wichtiger. Hier kommt die Software Bill of Materials (SBOM) ins &hellip; <\/p>\n<p class=\"link-more\"><a href=\"http:\/\/blog.wenzlaff.de\/?p=20202\" class=\"more-link\"><span class=\"screen-reader-text\">\u201eSoftware Bill of Materials (SBOM) mit CycloneDX Maven Plugin leicht erzeugen\u201c <\/span>weiterlesen<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[220,3161,5,3163,79,1319],"tags":[5417,5276,5415,2178,66,2099,5416,5275,102],"class_list":["post-20202","post","type-post","status-publish","format-standard","hentry","category-anleitung","category-build","category-java","category-maven","category-programmierung","category-sicherheit-2","tag-bill-of-material","tag-bom","tag-cyclonedx","tag-java","tag-maven","tag-mvn","tag-pom","tag-sbom","tag-xml"],"_links":{"self":[{"href":"http:\/\/blog.wenzlaff.de\/index.php?rest_route=\/wp\/v2\/posts\/20202","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/blog.wenzlaff.de\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/blog.wenzlaff.de\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/blog.wenzlaff.de\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/blog.wenzlaff.de\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=20202"}],"version-history":[{"count":0,"href":"http:\/\/blog.wenzlaff.de\/index.php?rest_route=\/wp\/v2\/posts\/20202\/revisions"}],"wp:attachment":[{"href":"http:\/\/blog.wenzlaff.de\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=20202"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/blog.wenzlaff.de\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=20202"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/blog.wenzlaff.de\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=20202"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}