Skip to main content

Document Information

Machine-readable SBOM artifacts (sbom.cdx.json and sbom-data.json) are attached to each GitHub release. Download the SBOM matching your installed version. These files are consumable by Dependency-Track, Snyk, FOSSA, Nessus, and other SBOM-aware tools.

Compliance Coverage

This SBOM is structured to satisfy the following frameworks:
For a detailed analysis of dependency provenance, supply chain risk assessment, and architectural constraints, see the companion Dependency Narrative.

Summary

License Inventory

License Elections

The following packages are dual-licensed. Provisionr elects the permissive license for distribution.

Direct Dependencies

These packages are explicitly declared in the application’s composer.json.
illuminate/http, illuminate/log, and illuminate/validation are declared as direct dependencies but are resolved by Composer via laravel/framework’s replace directive. See the Dependency Narrative for a full explanation of this resolution mechanism and its implications.

Transitive Dependencies

Framework Core (Required at Runtime)

These packages are required by laravel-zero/framework or laravel/framework and are exercised at runtime.

Framework Transitive (Not Invoked by Application Code)

These packages are present in the dependency tree because laravel/framework is installed as a monolith via Composer’s replace mechanism. They are never called by Provisionr Workspace CLI application code.

PSR Interfaces

Standard PHP-FIG interface contracts. Minimal code, no runtime behavior.

Symfony Contracts and Polyfills

Other Transitive

Vulnerability Disclosure

Provisionr monitors dependencies for known vulnerabilities using automated scanning integrated into our CI/CD pipeline. If you discover a vulnerability in any dependency listed here, please report it to [email protected]. See responsible disclosure to learn more.