← Trust Center
CycloneDX 1.5 · Auto-generated on every build

Software Bill of Materials

A complete, machine-readable inventory of every third-party component shipped with the AutoCops marketing website. Generated on every production build via @cyclonedx/cyclonedx-npm. Available as both an interactive view (below) and a raw CycloneDX JSON download.

Format

CycloneDX 1.5

Components

177

Generated

11 Apr 2026, 7:07 am

BOM serial

29baa781…

Raw download

Get the complete CycloneDX 1.5 JSON for ingestion into your security tooling, vulnerability scanner, or procurement-review process.

Suitable for Dependency-Track, Snyk, Grype, GitHub Advisory ingestion, and any tool that consumes CycloneDX 1.5 JSON.

↓ Download sbom.json

License distribution

MIT ×158Apache-2.0 ×6ISC ×4BSD-3-Clause ×3LGPL-3.0-or-later ×2CC-BY-4.0 ×1BSD-2-Clause ×1MPL-2.0 ×1

All components (177)

Every third-party dependency

Sorted alphabetically. Each row links to the package on the npm registry. The PURL (Package URL) is the canonical identifier used by SBOM tooling for matching against vulnerability databases.

#NameVersionLicensePURL
1acorn8.16.0MITpkg:npm/acorn@8.16.0
2acorn-jsx5.3.2MITpkg:npm/acorn-jsx@5.3.2
3argparse1.0.10MITpkg:npm/argparse@1.0.10
4astring1.9.0MITpkg:npm/astring@1.9.0
5bail2.0.2MITpkg:npm/bail@2.0.2
6baseline-browser-mapping2.10.17Apache-2.0pkg:npm/baseline-browser-mapping@2.10.17
7caniuse-lite1.0.30001787CC-BY-4.0pkg:npm/caniuse-lite@1.0.30001787
8ccount2.0.1MITpkg:npm/ccount@2.0.1
9character-entities2.0.2MITpkg:npm/character-entities@2.0.2
10character-entities-html42.1.0MITpkg:npm/character-entities-html4@2.1.0
11character-entities-legacy3.0.0MITpkg:npm/character-entities-legacy@3.0.0
12character-reference-invalid2.0.1MITpkg:npm/character-reference-invalid@2.0.1
13client-only0.0.1MITpkg:npm/client-only@0.0.1
14code-frame7.29.0MITpkg:npm/%40babel/code-frame@7.29.0
15collapse-white-space2.1.0MITpkg:npm/collapse-white-space@2.1.0
16colour1.1.0MITpkg:npm/%40img/colour@1.1.0
17comma-separated-tokens2.0.3MITpkg:npm/comma-separated-tokens@2.0.3
18csstype3.2.3MITpkg:npm/csstype@3.2.3
19debug4.1.13MITpkg:npm/%40types/debug@4.1.13
20debug4.4.3MITpkg:npm/debug@4.4.3
21decode-named-character-reference1.3.0MITpkg:npm/decode-named-character-reference@1.3.0
22dequal2.0.3MITpkg:npm/dequal@2.0.3
23detect-libc2.1.2Apache-2.0pkg:npm/detect-libc@2.1.2
24devlop1.1.0MITpkg:npm/devlop@1.1.0
25env16.2.3MITpkg:npm/%40next/env@16.2.3
26esast-util-from-estree2.0.0MITpkg:npm/esast-util-from-estree@2.0.0
27esast-util-from-js2.0.1MITpkg:npm/esast-util-from-js@2.0.1
28escape-string-regexp5.0.0MITpkg:npm/escape-string-regexp@5.0.0
29esprima4.0.1BSD-2-Clausepkg:npm/esprima@4.0.1
30estree1.0.8MITpkg:npm/%40types/estree@1.0.8
31estree-jsx1.0.5MITpkg:npm/%40types/estree-jsx@1.0.5
32estree-util-attach-comments3.0.0MITpkg:npm/estree-util-attach-comments@3.0.0
33estree-util-build-jsx3.0.1MITpkg:npm/estree-util-build-jsx@3.0.1
34estree-util-is-identifier-name3.0.0MITpkg:npm/estree-util-is-identifier-name@3.0.0
35estree-util-scope1.0.0MITpkg:npm/estree-util-scope@1.0.0
36estree-util-to-js2.0.0MITpkg:npm/estree-util-to-js@2.0.0
37estree-util-visit2.0.0MITpkg:npm/estree-util-visit@2.0.0
38estree-walker3.0.3MITpkg:npm/estree-walker@3.0.3
39extend3.0.2MITpkg:npm/extend@3.0.2
40extend-shallow2.0.1MITpkg:npm/extend-shallow@2.0.1
41gray-matter4.0.3MITpkg:npm/gray-matter@4.0.3
42hast3.0.4MITpkg:npm/%40types/hast@3.0.4
43hast-util-to-estree3.1.3MITpkg:npm/hast-util-to-estree@3.1.3
44hast-util-to-jsx-runtime2.3.6MITpkg:npm/hast-util-to-jsx-runtime@2.3.6
45hast-util-whitespace3.0.0MITpkg:npm/hast-util-whitespace@3.0.0
46helper-validator-identifier7.28.5MITpkg:npm/%40babel/helper-validator-identifier@7.28.…
47helpers0.5.15Apache-2.0pkg:npm/%40swc/helpers@0.5.15
48inline-style-parser0.2.7MITpkg:npm/inline-style-parser@0.2.7
49is-alphabetical2.0.1MITpkg:npm/is-alphabetical@2.0.1
50is-alphanumerical2.0.1MITpkg:npm/is-alphanumerical@2.0.1
51is-decimal2.0.1MITpkg:npm/is-decimal@2.0.1
52is-extendable0.1.1MITpkg:npm/is-extendable@0.1.1
53is-hexadecimal2.0.1MITpkg:npm/is-hexadecimal@2.0.1
54is-plain-obj4.1.0MITpkg:npm/is-plain-obj@4.1.0
55js-tokens4.0.0MITpkg:npm/js-tokens@4.0.0
56js-yaml3.14.2MITpkg:npm/js-yaml@3.14.2
57kind-of6.0.3MITpkg:npm/kind-of@6.0.3
58loader3.1.1MITpkg:npm/%40mdx-js/loader@3.1.1
59longest-streak3.1.0MITpkg:npm/longest-streak@3.1.0
60markdown-extensions2.0.0MITpkg:npm/markdown-extensions@2.0.0
61markdown-table3.0.4MITpkg:npm/markdown-table@3.0.4
62mdast4.0.4MITpkg:npm/%40types/mdast@4.0.4
63mdast-util-find-and-replace3.0.2MITpkg:npm/mdast-util-find-and-replace@3.0.2
64mdast-util-from-markdown2.0.3MITpkg:npm/mdast-util-from-markdown@2.0.3
65mdast-util-gfm3.1.0MITpkg:npm/mdast-util-gfm@3.1.0
66mdast-util-gfm-autolink-literal2.0.1MITpkg:npm/mdast-util-gfm-autolink-literal@2.0.1
67mdast-util-gfm-footnote2.1.0MITpkg:npm/mdast-util-gfm-footnote@2.1.0
68mdast-util-gfm-strikethrough2.0.0MITpkg:npm/mdast-util-gfm-strikethrough@2.0.0
69mdast-util-gfm-table2.0.0MITpkg:npm/mdast-util-gfm-table@2.0.0
70mdast-util-gfm-task-list-item2.0.0MITpkg:npm/mdast-util-gfm-task-list-item@2.0.0
71mdast-util-mdx3.0.0MITpkg:npm/mdast-util-mdx@3.0.0
72mdast-util-mdx-expression2.0.1MITpkg:npm/mdast-util-mdx-expression@2.0.1
73mdast-util-mdx-jsx3.2.0MITpkg:npm/mdast-util-mdx-jsx@3.2.0
74mdast-util-mdxjs-esm2.0.1MITpkg:npm/mdast-util-mdxjs-esm@2.0.1
75mdast-util-phrasing4.1.0MITpkg:npm/mdast-util-phrasing@4.1.0
76mdast-util-to-hast13.2.1MITpkg:npm/mdast-util-to-hast@13.2.1
77mdast-util-to-markdown2.1.2MITpkg:npm/mdast-util-to-markdown@2.1.2
78mdast-util-to-string4.0.0MITpkg:npm/mdast-util-to-string@4.0.0
79mdx16.2.3MITpkg:npm/%40next/mdx@16.2.3
80mdx2.0.13MITpkg:npm/%40types/mdx@2.0.13
81mdx3.1.1MITpkg:npm/%40mdx-js/mdx@3.1.1
82micromark4.0.2MITpkg:npm/micromark@4.0.2
83micromark-core-commonmark2.0.3MITpkg:npm/micromark-core-commonmark@2.0.3
84micromark-extension-gfm3.0.0MITpkg:npm/micromark-extension-gfm@3.0.0
85micromark-extension-gfm-autolink-literal2.1.0MITpkg:npm/micromark-extension-gfm-autolink-literal@2…
86micromark-extension-gfm-footnote2.1.0MITpkg:npm/micromark-extension-gfm-footnote@2.1.0
87micromark-extension-gfm-strikethrough2.1.0MITpkg:npm/micromark-extension-gfm-strikethrough@2.1.…
88micromark-extension-gfm-table2.1.1MITpkg:npm/micromark-extension-gfm-table@2.1.1
89micromark-extension-gfm-tagfilter2.0.0MITpkg:npm/micromark-extension-gfm-tagfilter@2.0.0
90micromark-extension-gfm-task-list-item2.1.0MITpkg:npm/micromark-extension-gfm-task-list-item@2.1…
91micromark-extension-mdx-expression3.0.1MITpkg:npm/micromark-extension-mdx-expression@3.0.1
92micromark-extension-mdx-jsx3.0.2MITpkg:npm/micromark-extension-mdx-jsx@3.0.2
93micromark-extension-mdx-md2.0.0MITpkg:npm/micromark-extension-mdx-md@2.0.0
94micromark-extension-mdxjs3.0.0MITpkg:npm/micromark-extension-mdxjs@3.0.0
95micromark-extension-mdxjs-esm3.0.0MITpkg:npm/micromark-extension-mdxjs-esm@3.0.0
96micromark-factory-destination2.0.1MITpkg:npm/micromark-factory-destination@2.0.1
97micromark-factory-label2.0.1MITpkg:npm/micromark-factory-label@2.0.1
98micromark-factory-mdx-expression2.0.3MITpkg:npm/micromark-factory-mdx-expression@2.0.3
99micromark-factory-space2.0.1MITpkg:npm/micromark-factory-space@2.0.1
100micromark-factory-title2.0.1MITpkg:npm/micromark-factory-title@2.0.1
101micromark-factory-whitespace2.0.1MITpkg:npm/micromark-factory-whitespace@2.0.1
102micromark-util-character2.1.1MITpkg:npm/micromark-util-character@2.1.1
103micromark-util-chunked2.0.1MITpkg:npm/micromark-util-chunked@2.0.1
104micromark-util-classify-character2.0.1MITpkg:npm/micromark-util-classify-character@2.0.1
105micromark-util-combine-extensions2.0.1MITpkg:npm/micromark-util-combine-extensions@2.0.1
106micromark-util-decode-numeric-character-reference2.0.2MITpkg:npm/micromark-util-decode-numeric-character-re…
107micromark-util-decode-string2.0.1MITpkg:npm/micromark-util-decode-string@2.0.1
108micromark-util-encode2.0.1MITpkg:npm/micromark-util-encode@2.0.1
109micromark-util-events-to-acorn2.0.3MITpkg:npm/micromark-util-events-to-acorn@2.0.3
110micromark-util-html-tag-name2.0.1MITpkg:npm/micromark-util-html-tag-name@2.0.1
111micromark-util-normalize-identifier2.0.1MITpkg:npm/micromark-util-normalize-identifier@2.0.1
112micromark-util-resolve-all2.0.1MITpkg:npm/micromark-util-resolve-all@2.0.1
113micromark-util-sanitize-uri2.0.1MITpkg:npm/micromark-util-sanitize-uri@2.0.1
114micromark-util-subtokenize2.1.0MITpkg:npm/micromark-util-subtokenize@2.1.0
115micromark-util-symbol2.0.1MITpkg:npm/micromark-util-symbol@2.0.1
116micromark-util-types2.0.2MITpkg:npm/micromark-util-types@2.0.2
117ms2.1.0MITpkg:npm/%40types/ms@2.1.0
118ms2.1.3MITpkg:npm/ms@2.1.3
119nanoid3.3.11MITpkg:npm/nanoid@3.3.11
120next16.2.3MITpkg:npm/next@16.2.3
121next-mdx-remote6.0.0MPL-2.0pkg:npm/next-mdx-remote@6.0.0
122parse-entities4.0.2MITpkg:npm/parse-entities@4.0.2
123picocolors1.1.1ISCpkg:npm/picocolors@1.1.1
124property-information7.1.0MITpkg:npm/property-information@7.1.0
125react3.1.1MITpkg:npm/%40mdx-js/react@3.1.1
126react19.2.4MITpkg:npm/react@19.2.4
127react19.2.14MITpkg:npm/%40types/react@19.2.14
128react-dom19.2.4MITpkg:npm/react-dom@19.2.4
129reading-time1.5.0MITpkg:npm/reading-time@1.5.0
130recma-build-jsx1.0.0MITpkg:npm/recma-build-jsx@1.0.0
131recma-jsx1.0.1MITpkg:npm/recma-jsx@1.0.1
132recma-parse1.0.0MITpkg:npm/recma-parse@1.0.0
133recma-stringify1.0.0MITpkg:npm/recma-stringify@1.0.0
134rehype-recma1.0.0MITpkg:npm/rehype-recma@1.0.0
135remark-gfm4.0.1MITpkg:npm/remark-gfm@4.0.1
136remark-mdx3.1.1MITpkg:npm/remark-mdx@3.1.1
137remark-parse11.0.0MITpkg:npm/remark-parse@11.0.0
138remark-rehype11.1.2MITpkg:npm/remark-rehype@11.1.2
139remark-stringify11.0.0MITpkg:npm/remark-stringify@11.0.0
140runtime1.9.2MITpkg:npm/%40emnapi/runtime@1.9.2
141scheduler0.27.0MITpkg:npm/scheduler@0.27.0
142section-matter1.0.0MITpkg:npm/section-matter@1.0.0
143semver7.7.4ISCpkg:npm/semver@7.7.4
144sharp0.34.5Apache-2.0pkg:npm/sharp@0.34.5
145sharp-libvips-linux-x641.2.4LGPL-3.0-or-laterpkg:npm/%40img/sharp-libvips-linux-x64@1.2.4
146sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-laterpkg:npm/%40img/sharp-libvips-linuxmusl-x64@1.2.4
147sharp-linux-x640.34.5Apache-2.0pkg:npm/%40img/sharp-linux-x64@0.34.5
148sharp-linuxmusl-x640.34.5Apache-2.0pkg:npm/%40img/sharp-linuxmusl-x64@0.34.5
149source-map0.7.6BSD-3-Clausepkg:npm/source-map@0.7.6
150source-map-js1.2.1BSD-3-Clausepkg:npm/source-map-js@1.2.1
151space-separated-tokens2.0.2MITpkg:npm/space-separated-tokens@2.0.2
152sprintf-js1.0.3BSD-3-Clausepkg:npm/sprintf-js@1.0.3
153stringify-entities4.0.4MITpkg:npm/stringify-entities@4.0.4
154strip-bom-string1.0.0MITpkg:npm/strip-bom-string@1.0.0
155structured-clone1.3.0ISCpkg:npm/%40ungap/structured-clone@1.3.0
156style-to-js1.1.21MITpkg:npm/style-to-js@1.1.21
157style-to-object1.0.14MITpkg:npm/style-to-object@1.0.14
158styled-jsx5.1.6MITpkg:npm/styled-jsx@5.1.6
159swc-linux-x64-gnu16.2.3MITpkg:npm/%40next/swc-linux-x64-gnu@16.2.3
160swc-linux-x64-musl16.2.3MITpkg:npm/%40next/swc-linux-x64-musl@16.2.3
161trim-lines3.0.1MITpkg:npm/trim-lines@3.0.1
162trough2.2.0MITpkg:npm/trough@2.2.0
163tslib2.8.10BSDpkg:npm/tslib@2.8.1
164unified11.0.5MITpkg:npm/unified@11.0.5
165unist3.0.3MITpkg:npm/%40types/unist@3.0.3
166unist-util-is6.0.1MITpkg:npm/unist-util-is@6.0.1
167unist-util-position5.0.0MITpkg:npm/unist-util-position@5.0.0
168unist-util-position-from-estree2.0.0MITpkg:npm/unist-util-position-from-estree@2.0.0
169unist-util-remove4.0.0MITpkg:npm/unist-util-remove@4.0.0
170unist-util-stringify-position4.0.0MITpkg:npm/unist-util-stringify-position@4.0.0
171unist-util-visit5.1.0MITpkg:npm/unist-util-visit@5.1.0
172unist-util-visit-parents6.0.2MITpkg:npm/unist-util-visit-parents@6.0.2
173vfile6.0.3MITpkg:npm/vfile@6.0.3
174vfile-matter5.0.1MITpkg:npm/vfile-matter@5.0.1
175vfile-message4.0.3MITpkg:npm/vfile-message@4.0.3
176yaml2.8.3ISCpkg:npm/yaml@2.8.3
177zwitch2.0.4MITpkg:npm/zwitch@2.0.4

Connected SBOMs

Application + API SBOMs

This page shows the SBOM for the marketing website only. The AutoCops React application and FastAPI backend each ship with their own SBOMs, accessible to authenticated customers from inside the application's Trust Center. Customers on enterprise plans can request all three SBOMs as a single CycloneDX bundle for procurement reviews.

Website SBOM (this page) · publicReact app SBOM · authenticated onlyAPI SBOM · authenticated only

How this is generated: We run @cyclonedx/cyclonedx-npm as part of the production npm run build pipeline. The output is committed to website/public/sbom.json on every release. The SBOM you see here is byte-identical to the one ingested by our internal vulnerability tracking and is the same file we share with enterprise security reviewers.

Supply chain security: We use npm audit in CI to gate any high-or-critical vulnerability from reaching production. npm-ecosystem advisories are checked on every build. The current audit status is 0 known vulnerabilities.