{"@context":"https://spdx.org/rdf/3.0.1/spdx-context.jsonld","@graph":[{"type":"CreationInfo","@id":"_:CreationInfo0","created":"2011-04-05T23:00:00Z","createdBy":["http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/agent/OpenEmbedded"],"createdUsing":["http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/tool/oe-spdx-creator_1_0"],"specVersion":"3.0.1"},{"type":"CreationInfo","@id":"_:CreationInfo1","created":"2025-04-09T11:13:34Z","createdBy":["http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/agent/OpenEmbedded"],"createdUsing":["http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/tool/oe-spdx-creator_1_0"],"specVersion":"3.0.1"},{"type":"Organization","spdxId":"http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/agent/OpenEmbedded","creationInfo":"_:CreationInfo0","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias"}],"name":"OpenEmbedded"},{"type":"Tool","spdxId":"http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/tool/oe-spdx-creator_1_0","creationInfo":"_:CreationInfo0","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias"}],"name":"oe-spdx-creator 1.0"},{"type":"SpdxDocument","spdxId":"http://spdx.org/spdxdocs/coreutils-31f3ba4d-00f2-59bc-9d87-40a89376a138/cf19239f93e37670249b75ba6e6023070e36ab2da287bc8515af53dea247f9d5/document/package-coreutils-locale-id","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/doc/coreutils/package-coreutils-locale-id/coreutils/UNIHASH/document/package-coreutils-locale-id","https://rdf.openembedded.org/spdx/3.0/link-name":"dbdf1a9588b83d55cf66fdbad8ae12760894eb2c9369ac3c909cffbc4fa57a4a"}],"name":"package-coreutils-locale-id","profileConformance":["build","core","security","simpleLicensing","software"],"rootElement":["http://spdx.org/spdxdocs/coreutils-31f3ba4d-00f2-59bc-9d87-40a89376a138/cf19239f93e37670249b75ba6e6023070e36ab2da287bc8515af53dea247f9d5/package/coreutils-locale-id"]},{"type":"software_Package","spdxId":"http://spdx.org/spdxdocs/coreutils-31f3ba4d-00f2-59bc-9d87-40a89376a138/cf19239f93e37670249b75ba6e6023070e36ab2da287bc8515af53dea247f9d5/package/coreutils-locale-id","creationInfo":"_:CreationInfo1","description":"The GNU Core Utilities provide the basic file, shell and text manipulation utilities. These are the core utilities which are expected to exist on every system.  This package contains language translation files for the id locale.","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/dbdf1a9588b83d55cf66fdbad8ae12760894eb2c9369ac3c909cffbc4fa57a4a/coreutils/UNIHASH/package/coreutils-locale-id"}],"externalIdentifier":[{"type":"ExternalIdentifier","externalIdentifierType":"cpe23","identifier":"cpe:2.3:*:*:coreutils:9.7:*:*:*:*:*:*:*"}],"name":"coreutils-locale-id","summary":"The basic file, shell and text manipulation utilities - id translations","software_primaryPurpose":"install","software_homePage":"http://www.gnu.org/software/coreutils/","software_packageVersion":"9.7"},{"type":"software_File","spdxId":"http://spdx.org/spdxdocs/coreutils-31f3ba4d-00f2-59bc-9d87-40a89376a138/cf19239f93e37670249b75ba6e6023070e36ab2da287bc8515af53dea247f9d5/package/coreutils-locale-id/file/1","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/dbdf1a9588b83d55cf66fdbad8ae12760894eb2c9369ac3c909cffbc4fa57a4a/coreutils/UNIHASH/package/coreutils-locale-id/file/1"}],"name":"usr/share/locale/id/LC_MESSAGES/coreutils.mo","verifiedUsing":[{"type":"Hash","algorithm":"sha256","hashValue":"bc759b159a3e0cf39d7aa1fb8ad8e60bde234456200a2dc50fd0ea9153b15554"}]},{"type":"Relationship","spdxId":"http://spdx.org/spdxdocs/coreutils-31f3ba4d-00f2-59bc-9d87-40a89376a138/cf19239f93e37670249b75ba6e6023070e36ab2da287bc8515af53dea247f9d5/relationship/4acd9b8f0c00a1f9ad4a16f6f657c12c","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/dbdf1a9588b83d55cf66fdbad8ae12760894eb2c9369ac3c909cffbc4fa57a4a/coreutils/UNIHASH/relationship/4acd9b8f0c00a1f9ad4a16f6f657c12c"}],"from":"http://spdx.org/spdxdocs/coreutils-31f3ba4d-00f2-59bc-9d87-40a89376a138/cf19239f93e37670249b75ba6e6023070e36ab2da287bc8515af53dea247f9d5/package/coreutils-locale-id","relationshipType":"hasAssociatedVulnerability","to":["http://spdxdocs.org/openembedded-alias/by-doc-hash/5e08f180a9050a2bdcba5c46367dd20e5ae76615586b60a960441bd50660f0ca/coreutils/UNIHASH/vulnerability/CVE-2016-2781","http://spdxdocs.org/openembedded-alias/by-doc-hash/5e08f180a9050a2bdcba5c46367dd20e5ae76615586b60a960441bd50660f0ca/coreutils/UNIHASH/vulnerability/CVE-2025-5278"]},{"type":"LifecycleScopedRelationship","spdxId":"http://spdx.org/spdxdocs/coreutils-31f3ba4d-00f2-59bc-9d87-40a89376a138/cf19239f93e37670249b75ba6e6023070e36ab2da287bc8515af53dea247f9d5/relationship/5051615a6f039326ca364f8826ad7981","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/dbdf1a9588b83d55cf66fdbad8ae12760894eb2c9369ac3c909cffbc4fa57a4a/coreutils/UNIHASH/relationship/5051615a6f039326ca364f8826ad7981"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/5e08f180a9050a2bdcba5c46367dd20e5ae76615586b60a960441bd50660f0ca/coreutils/UNIHASH/build/recipe","relationshipType":"hasOutput","to":["http://spdx.org/spdxdocs/coreutils-31f3ba4d-00f2-59bc-9d87-40a89376a138/cf19239f93e37670249b75ba6e6023070e36ab2da287bc8515af53dea247f9d5/package/coreutils-locale-id"],"scope":"build"},{"type":"Relationship","spdxId":"http://spdx.org/spdxdocs/coreutils-31f3ba4d-00f2-59bc-9d87-40a89376a138/cf19239f93e37670249b75ba6e6023070e36ab2da287bc8515af53dea247f9d5/relationship/df7bdfc46efb9cb87332c5056154d542","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/dbdf1a9588b83d55cf66fdbad8ae12760894eb2c9369ac3c909cffbc4fa57a4a/coreutils/UNIHASH/relationship/df7bdfc46efb9cb87332c5056154d542"}],"from":"http://spdx.org/spdxdocs/coreutils-31f3ba4d-00f2-59bc-9d87-40a89376a138/cf19239f93e37670249b75ba6e6023070e36ab2da287bc8515af53dea247f9d5/package/coreutils-locale-id","relationshipType":"contains","to":["http://spdx.org/spdxdocs/coreutils-31f3ba4d-00f2-59bc-9d87-40a89376a138/cf19239f93e37670249b75ba6e6023070e36ab2da287bc8515af53dea247f9d5/package/coreutils-locale-id/file/1"]},{"type":"Relationship","spdxId":"http://spdx.org/spdxdocs/coreutils-31f3ba4d-00f2-59bc-9d87-40a89376a138/cf19239f93e37670249b75ba6e6023070e36ab2da287bc8515af53dea247f9d5/relationship/ea2dfa884513d3f042351fb1660e7701","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/dbdf1a9588b83d55cf66fdbad8ae12760894eb2c9369ac3c909cffbc4fa57a4a/coreutils/UNIHASH/relationship/ea2dfa884513d3f042351fb1660e7701"}],"from":"http://spdx.org/spdxdocs/coreutils-31f3ba4d-00f2-59bc-9d87-40a89376a138/cf19239f93e37670249b75ba6e6023070e36ab2da287bc8515af53dea247f9d5/package/coreutils-locale-id","relationshipType":"hasDeclaredLicense","to":["http://spdxdocs.org/openembedded-alias/by-doc-hash/5e08f180a9050a2bdcba5c46367dd20e5ae76615586b60a960441bd50660f0ca/coreutils/UNIHASH/license/3_27_0/GPL-3_0-or-later"]},{"type":"security_VexFixedVulnAssessmentRelationship","spdxId":"http://spdx.org/spdxdocs/coreutils-31f3ba4d-00f2-59bc-9d87-40a89376a138/cf19239f93e37670249b75ba6e6023070e36ab2da287bc8515af53dea247f9d5/vex-fixed/cc50d47be093b1860dc3aa59fa3f0532","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/dbdf1a9588b83d55cf66fdbad8ae12760894eb2c9369ac3c909cffbc4fa57a4a/coreutils/UNIHASH/vex-fixed/cc50d47be093b1860dc3aa59fa3f0532"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/5e08f180a9050a2bdcba5c46367dd20e5ae76615586b60a960441bd50660f0ca/coreutils/UNIHASH/vulnerability/CVE-2025-5278","relationshipType":"fixedIn","to":["http://spdx.org/spdxdocs/coreutils-31f3ba4d-00f2-59bc-9d87-40a89376a138/cf19239f93e37670249b75ba6e6023070e36ab2da287bc8515af53dea247f9d5/package/coreutils-locale-id"],"security_vexVersion":"1.0.0"},{"type":"security_VexNotAffectedVulnAssessmentRelationship","spdxId":"http://spdx.org/spdxdocs/coreutils-31f3ba4d-00f2-59bc-9d87-40a89376a138/cf19239f93e37670249b75ba6e6023070e36ab2da287bc8515af53dea247f9d5/vex-not-affected/c163e69117cafd8587b259cd94a6b4f3","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/dbdf1a9588b83d55cf66fdbad8ae12760894eb2c9369ac3c909cffbc4fa57a4a/coreutils/UNIHASH/vex-not-affected/c163e69117cafd8587b259cd94a6b4f3"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/5e08f180a9050a2bdcba5c46367dd20e5ae76615586b60a960441bd50660f0ca/coreutils/UNIHASH/vulnerability/CVE-2016-2781","relationshipType":"doesNotAffect","to":["http://spdx.org/spdxdocs/coreutils-31f3ba4d-00f2-59bc-9d87-40a89376a138/cf19239f93e37670249b75ba6e6023070e36ab2da287bc8515af53dea247f9d5/package/coreutils-locale-id"],"security_vexVersion":"1.0.0","security_impactStatement":"runcon is not really a sandbox command, use `runcon ... setsid ...` to avoid this particular issue."}]}