{
  "spec_version": "1.0.0",
  "build": {
    "variant": "non-fips",
    "derivation": "kms-server-non-fips-static-openssl",
    "output_path": "/nix/store/7a5iq7kimj4v1mnarxg03wg2diywrwdm-cosmian-kms-server-5.20.0",
    "timestamp": "2026-04-03T12:33:10Z",
    "generator": {
      "tool": "sbomnix",
      "version": "v1.7.4"
    }
  },
  "component_count": 5,
  "vulnerability_count": 26,
  "notes": [
    "OpenSSL is statically linked in the binary",
    "All dependencies are from Nix store with pinned versions",
    "SBOM reflects the exact Nix build output (derivation closure)"
  ]
}
