{
 "arch": "amd64",
 "findings": [
  {
   "affects": [
    "filippo.io/edwards25519"
   ],
   "cvss": 1.7,
   "distro_severity": "low",
   "fix_state": "fixed",
   "fixed_in": [
    "1.1.1"
   ],
   "id": "GHSA-fw7p-63qq-7hpr",
   "severity": "low",
   "title": "filippo.io/edwards25519 MultiScalarMult produces invalid results or undefined behavior if receiver is not the identity",
   "url": "https://github.com/advisories/GHSA-fw7p-63qq-7hpr"
  },
  {
   "affects": [
    "golang.org/x/crypto"
   ],
   "cvss": null,
   "distro_severity": "unknown",
   "fix_state": "unknown",
   "fixed_in": [],
   "id": "GO-2026-5932",
   "severity": "unknown",
   "title": "The golang.org/x/crypto/openpgp package is unsafe by design, has numerous known security issues, is not maintained, and should not be used.",
   "url": "https://go.dev/issue/44226"
  }
 ],
 "findings_changed_at": "2026-08-21T22:08:39Z",
 "image": "age",
 "inputs": {
  "sbom_sha256": "0be57534e570418d47da6632c3722aeeb498fb3b12e8e4e8c57fe8b9c14ca19f"
 },
 "platform_digest": "sha256:386ca25702492ca5ca0f9e23c4f0eb79a2b2e91e40d94a7971731ed06ba776d6",
 "project": "age",
 "receipt_sha256": "e81b25e45e4a8f3b2f0e308be24bd30d63e90f42d0c1b181bb18282b564d9d51",
 "scanner": "grype",
 "severity_counts": {
  "critical": 0,
  "high": 0,
  "low": 1,
  "medium": 0,
  "unknown": 1
 },
 "suppressed": [],
 "version": "1.3.1",
 "vex_applied": [
  "age-1.3.1-amd64.vex.json",
  "age-1.3.1-amd64.ubuntu-vex.json"
 ]
}
