{"@context":"https://spdx.org/rdf/3.0.1/spdx-context.jsonld","@graph":[{"type":"CreationInfo","@id":"_:CreationInfo0","created":"2011-04-05T23:00:00Z","createdBy":["http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/agent/OpenEmbedded"],"createdUsing":["http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/tool/oe-spdx-creator_1_0"],"specVersion":"3.0.1"},{"type":"CreationInfo","@id":"_:CreationInfo1","created":"2025-09-08T14:35:34Z","createdBy":["http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/agent/OpenEmbedded"],"createdUsing":["http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/tool/oe-spdx-creator_1_0"],"specVersion":"3.0.1"},{"type":"Organization","spdxId":"http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/agent/OpenEmbedded","creationInfo":"_:CreationInfo0","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias"}],"name":"OpenEmbedded"},{"type":"Tool","spdxId":"http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/tool/oe-spdx-creator_1_0","creationInfo":"_:CreationInfo0","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias"}],"name":"oe-spdx-creator 1.0"},{"type":"SpdxDocument","spdxId":"http://spdx.org/spdxdocs/libxml2-09ad8067-76cb-5fbb-84be-43f2d1ab3e49/2e3d81bba8d5aa42e86defbb2677d6f7596da6bc4bfa1850f8489cb7093ddab3/document/package-libxml2","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/doc/libxml2/package-libxml2/libxml2/UNIHASH/document/package-libxml2","https://rdf.openembedded.org/spdx/3.0/link-name":"ff2a1cbba6daac7acabe689be5a06487fbf58b93fc48ef87378fffedc23bf5bd"}],"name":"package-libxml2","profileConformance":["build","core","security","simpleLicensing","software"],"rootElement":["http://spdx.org/spdxdocs/libxml2-09ad8067-76cb-5fbb-84be-43f2d1ab3e49/2e3d81bba8d5aa42e86defbb2677d6f7596da6bc4bfa1850f8489cb7093ddab3/package/libxml2"]},{"type":"software_Package","spdxId":"http://spdx.org/spdxdocs/libxml2-09ad8067-76cb-5fbb-84be-43f2d1ab3e49/2e3d81bba8d5aa42e86defbb2677d6f7596da6bc4bfa1850f8489cb7093ddab3/package/libxml2","creationInfo":"_:CreationInfo1","description":"The XML Parser Library allows for manipulation of XML files.  Libxml2 exports Push and Pull type parser interfaces for both XML and HTML.  It can do DTD validation at parse time, on a parsed document instance or with an arbitrary DTD.  Libxml2 includes complete XPath, XPointer and Xinclude implementations.  It also has a SAX like interface, which is designed to be compatible with Expat.","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/ff2a1cbba6daac7acabe689be5a06487fbf58b93fc48ef87378fffedc23bf5bd/libxml2/UNIHASH/package/libxml2"}],"externalIdentifier":[{"type":"ExternalIdentifier","externalIdentifierType":"cpe23","identifier":"cpe:2.3:*:*:libxml2:2.14.6:*:*:*:*:*:*:*"}],"name":"libxml2","summary":"XML C Parser Library and Toolkit","software_primaryPurpose":"install","software_homePage":"https://gitlab.gnome.org/GNOME/libxml2","software_packageVersion":"2.14.6"},{"type":"software_File","spdxId":"http://spdx.org/spdxdocs/libxml2-09ad8067-76cb-5fbb-84be-43f2d1ab3e49/2e3d81bba8d5aa42e86defbb2677d6f7596da6bc4bfa1850f8489cb7093ddab3/package/libxml2/file/1","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/ff2a1cbba6daac7acabe689be5a06487fbf58b93fc48ef87378fffedc23bf5bd/libxml2/UNIHASH/package/libxml2/file/1"}],"name":"usr/lib/libxml2.so.16.0.6","verifiedUsing":[{"type":"Hash","algorithm":"sha256","hashValue":"b2fa8db4bb5d3e407d053a88742e467aae0f8c9a2aeab6cd9286247349aed3db"}]},{"type":"LifecycleScopedRelationship","spdxId":"http://spdx.org/spdxdocs/libxml2-09ad8067-76cb-5fbb-84be-43f2d1ab3e49/2e3d81bba8d5aa42e86defbb2677d6f7596da6bc4bfa1850f8489cb7093ddab3/relationship/10ef45707a48e9d47246b9a46fd259c6","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/ff2a1cbba6daac7acabe689be5a06487fbf58b93fc48ef87378fffedc23bf5bd/libxml2/UNIHASH/relationship/10ef45707a48e9d47246b9a46fd259c6"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/1950f1452318655ff08369bc7691e6c8ac74d4e8314914482b75234163c8d172/libxml2/UNIHASH/build/recipe","relationshipType":"hasOutput","to":["http://spdx.org/spdxdocs/libxml2-09ad8067-76cb-5fbb-84be-43f2d1ab3e49/2e3d81bba8d5aa42e86defbb2677d6f7596da6bc4bfa1850f8489cb7093ddab3/package/libxml2"],"scope":"build"},{"type":"Relationship","spdxId":"http://spdx.org/spdxdocs/libxml2-09ad8067-76cb-5fbb-84be-43f2d1ab3e49/2e3d81bba8d5aa42e86defbb2677d6f7596da6bc4bfa1850f8489cb7093ddab3/relationship/29c95146c14da8d466a83db9465ce07b","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/ff2a1cbba6daac7acabe689be5a06487fbf58b93fc48ef87378fffedc23bf5bd/libxml2/UNIHASH/relationship/29c95146c14da8d466a83db9465ce07b"}],"from":"http://spdx.org/spdxdocs/libxml2-09ad8067-76cb-5fbb-84be-43f2d1ab3e49/2e3d81bba8d5aa42e86defbb2677d6f7596da6bc4bfa1850f8489cb7093ddab3/package/libxml2","relationshipType":"hasAssociatedVulnerability","to":["http://spdxdocs.org/openembedded-alias/by-doc-hash/1950f1452318655ff08369bc7691e6c8ac74d4e8314914482b75234163c8d172/libxml2/UNIHASH/vulnerability/CVE-2025-6021","http://spdxdocs.org/openembedded-alias/by-doc-hash/1950f1452318655ff08369bc7691e6c8ac74d4e8314914482b75234163c8d172/libxml2/UNIHASH/vulnerability/CVE-2026-0989","http://spdxdocs.org/openembedded-alias/by-doc-hash/1950f1452318655ff08369bc7691e6c8ac74d4e8314914482b75234163c8d172/libxml2/UNIHASH/vulnerability/CVE-2026-0990","http://spdxdocs.org/openembedded-alias/by-doc-hash/1950f1452318655ff08369bc7691e6c8ac74d4e8314914482b75234163c8d172/libxml2/UNIHASH/vulnerability/CVE-2026-0992"]},{"type":"Relationship","spdxId":"http://spdx.org/spdxdocs/libxml2-09ad8067-76cb-5fbb-84be-43f2d1ab3e49/2e3d81bba8d5aa42e86defbb2677d6f7596da6bc4bfa1850f8489cb7093ddab3/relationship/6e2f0fec356ff6acadf2eb36e2e7399c","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/ff2a1cbba6daac7acabe689be5a06487fbf58b93fc48ef87378fffedc23bf5bd/libxml2/UNIHASH/relationship/6e2f0fec356ff6acadf2eb36e2e7399c"}],"from":"http://spdx.org/spdxdocs/libxml2-09ad8067-76cb-5fbb-84be-43f2d1ab3e49/2e3d81bba8d5aa42e86defbb2677d6f7596da6bc4bfa1850f8489cb7093ddab3/package/libxml2","relationshipType":"contains","to":["http://spdx.org/spdxdocs/libxml2-09ad8067-76cb-5fbb-84be-43f2d1ab3e49/2e3d81bba8d5aa42e86defbb2677d6f7596da6bc4bfa1850f8489cb7093ddab3/package/libxml2/file/1"]},{"type":"Relationship","spdxId":"http://spdx.org/spdxdocs/libxml2-09ad8067-76cb-5fbb-84be-43f2d1ab3e49/2e3d81bba8d5aa42e86defbb2677d6f7596da6bc4bfa1850f8489cb7093ddab3/relationship/e01f739be86d6956ceb164c148ac9b43","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/ff2a1cbba6daac7acabe689be5a06487fbf58b93fc48ef87378fffedc23bf5bd/libxml2/UNIHASH/relationship/e01f739be86d6956ceb164c148ac9b43"}],"from":"http://spdx.org/spdxdocs/libxml2-09ad8067-76cb-5fbb-84be-43f2d1ab3e49/2e3d81bba8d5aa42e86defbb2677d6f7596da6bc4bfa1850f8489cb7093ddab3/package/libxml2","relationshipType":"hasDeclaredLicense","to":["http://spdxdocs.org/openembedded-alias/by-doc-hash/1950f1452318655ff08369bc7691e6c8ac74d4e8314914482b75234163c8d172/libxml2/UNIHASH/license/3_27_0/MIT"]},{"type":"security_VexFixedVulnAssessmentRelationship","spdxId":"http://spdx.org/spdxdocs/libxml2-09ad8067-76cb-5fbb-84be-43f2d1ab3e49/2e3d81bba8d5aa42e86defbb2677d6f7596da6bc4bfa1850f8489cb7093ddab3/vex-fixed/0eae773b608de1f5c83772f9d023e4cd","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/ff2a1cbba6daac7acabe689be5a06487fbf58b93fc48ef87378fffedc23bf5bd/libxml2/UNIHASH/vex-fixed/0eae773b608de1f5c83772f9d023e4cd"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/1950f1452318655ff08369bc7691e6c8ac74d4e8314914482b75234163c8d172/libxml2/UNIHASH/vulnerability/CVE-2025-6021","relationshipType":"fixedIn","to":["http://spdx.org/spdxdocs/libxml2-09ad8067-76cb-5fbb-84be-43f2d1ab3e49/2e3d81bba8d5aa42e86defbb2677d6f7596da6bc4bfa1850f8489cb7093ddab3/package/libxml2"],"security_vexVersion":"1.0.0"},{"type":"security_VexFixedVulnAssessmentRelationship","spdxId":"http://spdx.org/spdxdocs/libxml2-09ad8067-76cb-5fbb-84be-43f2d1ab3e49/2e3d81bba8d5aa42e86defbb2677d6f7596da6bc4bfa1850f8489cb7093ddab3/vex-fixed/5f57b832d7192d4e72ceead6488783f9","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/ff2a1cbba6daac7acabe689be5a06487fbf58b93fc48ef87378fffedc23bf5bd/libxml2/UNIHASH/vex-fixed/5f57b832d7192d4e72ceead6488783f9"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/1950f1452318655ff08369bc7691e6c8ac74d4e8314914482b75234163c8d172/libxml2/UNIHASH/vulnerability/CVE-2026-0989","relationshipType":"fixedIn","to":["http://spdx.org/spdxdocs/libxml2-09ad8067-76cb-5fbb-84be-43f2d1ab3e49/2e3d81bba8d5aa42e86defbb2677d6f7596da6bc4bfa1850f8489cb7093ddab3/package/libxml2"],"security_vexVersion":"1.0.0"},{"type":"security_VexFixedVulnAssessmentRelationship","spdxId":"http://spdx.org/spdxdocs/libxml2-09ad8067-76cb-5fbb-84be-43f2d1ab3e49/2e3d81bba8d5aa42e86defbb2677d6f7596da6bc4bfa1850f8489cb7093ddab3/vex-fixed/b80bcd67d51d678480b73f24f448701c","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/ff2a1cbba6daac7acabe689be5a06487fbf58b93fc48ef87378fffedc23bf5bd/libxml2/UNIHASH/vex-fixed/b80bcd67d51d678480b73f24f448701c"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/1950f1452318655ff08369bc7691e6c8ac74d4e8314914482b75234163c8d172/libxml2/UNIHASH/vulnerability/CVE-2026-0992","relationshipType":"fixedIn","to":["http://spdx.org/spdxdocs/libxml2-09ad8067-76cb-5fbb-84be-43f2d1ab3e49/2e3d81bba8d5aa42e86defbb2677d6f7596da6bc4bfa1850f8489cb7093ddab3/package/libxml2"],"security_vexVersion":"1.0.0"},{"type":"security_VexFixedVulnAssessmentRelationship","spdxId":"http://spdx.org/spdxdocs/libxml2-09ad8067-76cb-5fbb-84be-43f2d1ab3e49/2e3d81bba8d5aa42e86defbb2677d6f7596da6bc4bfa1850f8489cb7093ddab3/vex-fixed/fedff1c64cb8152fa9dfda60db6d560b","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/ff2a1cbba6daac7acabe689be5a06487fbf58b93fc48ef87378fffedc23bf5bd/libxml2/UNIHASH/vex-fixed/fedff1c64cb8152fa9dfda60db6d560b"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/1950f1452318655ff08369bc7691e6c8ac74d4e8314914482b75234163c8d172/libxml2/UNIHASH/vulnerability/CVE-2026-0990","relationshipType":"fixedIn","to":["http://spdx.org/spdxdocs/libxml2-09ad8067-76cb-5fbb-84be-43f2d1ab3e49/2e3d81bba8d5aa42e86defbb2677d6f7596da6bc4bfa1850f8489cb7093ddab3/package/libxml2"],"security_vexVersion":"1.0.0"}]}