{
  "spec_version": "1.0.0",
  "build": {
    "variant": "non-fips",
    "derivation": "kms-server-non-fips-static-openssl",
    "output_path": "/nix/store/0srb3s1pg0p85w6gb9s5h4nn16f1ljcx-cosmian-kms-server-5.23.0",
    "timestamp": "2026-06-15T12:57:54Z",
    "generator": {
      "tool": "sbomnix",
      "version": "v1.7.4"
    }
  },
  "component_count": 5,
  "vulnerability_count": 38,
  "notes": [
    "OpenSSL is statically linked in the binary",
    "All dependencies are from Nix store with pinned versions",
    "SBOM reflects the exact Nix build output (derivation closure)"
  ]
}
