Document Information
Machine-readable SBOM artifacts (
sbom.cdx.json and sbom-data.json) are attached to each GitHub release. Download the SBOM matching your installed version. These files are consumable by Dependency-Track, Snyk, FOSSA, Nessus, and other SBOM-aware tools.Compliance Coverage
This SBOM is structured to satisfy the following frameworks:For a detailed analysis of dependency provenance, supply chain risk assessment, and architectural constraints, see the companion Dependency Narrative.
Summary
License Inventory
License Elections
The following packages are dual-licensed. Provisionr elects the permissive license for distribution.Direct Dependencies
These packages are explicitly declared in the application’scomposer.json.
Transitive Dependencies
Framework Core (Required at Runtime)
These packages are required bylaravel-zero/framework or laravel/framework and are exercised at runtime.
Framework Transitive (Not Invoked by Application Code)
These packages are present in the dependency tree becauselaravel/framework is installed as a monolith via Composer’s replace mechanism. They are never called by Provisionr Workspace CLI application code.