<?xml version="1.0" encoding="UTF-8"?>
<bom serialNumber="urn:uuid:e56882e1-7dc1-33b1-bca9-a3be9cc2d42f" version="1" xmlns="http://cyclonedx.org/schema/bom/1.6">
  <metadata>
    <lifecycles>
      <lifecycle>
        <phase>build</phase>
      </lifecycle>
    </lifecycles>
    <tools>
      <components>
        <component type="library">
          <author>OWASP Foundation</author>
          <group>org.cyclonedx</group>
          <name>cyclonedx-maven-plugin</name>
          <version>2.9.1</version>
          <description>CycloneDX Maven plugin</description>
          <hashes>
            <hash alg="MD5">9c7a565cf28cce58557d0c621c5ea4b1</hash>
            <hash alg="SHA-1">be882d5a22050bfa9d19090b1420c188617d0e1c</hash>
            <hash alg="SHA-256">698e0f37184a5b28c245c4065fd036dfce253b52f82fbb7113d81d36326cc249</hash>
            <hash alg="SHA-512">c0f0b11026858166f872a2eb54719492e5cecaa0bc9cd6b30b3ecb4a174eed220f4a1b5829d18d6734128e778d3cb3db7ffed177c92866133129cb29081814a0</hash>
            <hash alg="SHA-384">d80964707dfe5caca8c70521d5066f57589304c0a657e6fbc7c0614ea0fc7b3b3dbe7778361eee0f54ba111e9cb0ffcb</hash>
            <hash alg="SHA3-384">80bc3a275d9514bc457461ff52a72add8c7ecbbc01d8912efce57139016c544ee776981851be0a58fa977ab4221f703f</hash>
            <hash alg="SHA3-256">142317d6f245390f4fd2d0c100b16281b8dfc5c0c2cff86943bdcc97039cb699</hash>
            <hash alg="SHA3-512">af0fb9137c90b65d1a07f72e4d51ae509956cdb8800f35c961b037cdda1fe4a14ce3b496cef71ba85f1621affcfe29cd42704ae4191ff0b090a9602087c8997b</hash>
          </hashes>
        </component>
      </components>
    </tools>
    <component type="library" bom-ref="pkg:maven/org.apache.spark/spark-hive-thriftserver_2.13@4.1.2?type=jar">
      <publisher>Apache Software Foundation</publisher>
      <group>org.apache.spark</group>
      <name>spark-hive-thriftserver_2.13</name>
      <version>4.1.2</version>
      <description>The Apache Software Foundation provides support for the Apache community of open-source software projects.
    The Apache projects are characterized by a collaborative, consensus based development process, an open and
    pragmatic software license, and a desire to create high quality software that leads the way in its field.
    We consider ourselves not simply a group of projects sharing a server, but rather a community of developers
    and users.</description>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.spark/spark-hive-thriftserver_2.13@4.1.2?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://spark.apache.org/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://issues.apache.org/jira/browse/SPARK</url>
        </reference>
        <reference type="mailing-list">
          <url>dev-subscribe@spark.apache.org</url>
        </reference>
        <reference type="vcs">
          <url>scm:git:git@github.com:apache/spark.git/sql/spark-hive-thriftserver_2.13</url>
        </reference>
      </externalReferences>
    </component>
    <properties>
      <property name="maven.goal">makeBom</property>
      <property name="maven.scopes">compile,provided,runtime,system</property>
      <property name="cdx:reproducible">enabled</property>
    </properties>
  </metadata>
  <components>
    <component type="library" bom-ref="pkg:maven/org.apache.spark/spark-hive_2.13@4.1.2?type=jar">
      <publisher>Apache Software Foundation</publisher>
      <group>org.apache.spark</group>
      <name>spark-hive_2.13</name>
      <version>4.1.2</version>
      <description>The Apache Software Foundation provides support for the Apache community of open-source software projects.
    The Apache projects are characterized by a collaborative, consensus based development process, an open and
    pragmatic software license, and a desire to create high quality software that leads the way in its field.
    We consider ourselves not simply a group of projects sharing a server, but rather a community of developers
    and users.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">7ce65069c8f946c815ab121f16c3de32</hash>
        <hash alg="SHA-1">d48bd1c4af33966106f4df5b7ebd14c36dbd23fd</hash>
        <hash alg="SHA-256">654a2a21b5d26dd258520e0b948956d293c50d8bd12bc7c3a12c0d6a03568048</hash>
        <hash alg="SHA-512">19ccf2cb8a4095a25a84800fffe2c84887cae878edfd8bda3fa1d2c78699dc2a700be80df95c59c756ea3393fb5d9e83db52b176bdcfd4c45c504e7d4346f4bb</hash>
        <hash alg="SHA-384">ccc845f0759683e1590d2ba4ca6339abfa39ed95736cc9b2872231aac910852123f9297780410630a4481bfcf1f9efbc</hash>
        <hash alg="SHA3-384">82d17dab7647cf1e874e00c9b5cc0f8840af1f6f11bbf4f7df47ece10c022e769b4f95bb1cd46977e239ab2ce6f7beb0</hash>
        <hash alg="SHA3-256">2d091007a5d19d48e657702af5d20e376b1c7debc499291c28cadf3eb330f367</hash>
        <hash alg="SHA3-512">be657264e490fd6114b8d5d849f79cfcc3eed740766e778ad139f7a390a40c896b13abf04cd6a821f3c17223a58fe347eebfec4014437b778a42568328be4f3e</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.spark/spark-hive_2.13@4.1.2?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://spark.apache.org/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://issues.apache.org/jira/browse/SPARK</url>
        </reference>
        <reference type="mailing-list">
          <url>dev-subscribe@spark.apache.org</url>
        </reference>
        <reference type="vcs">
          <url>scm:git:git@github.com:apache/spark.git/sql/spark-hive_2.13</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.spark/spark-core_2.13@4.1.2?type=jar">
      <publisher>Apache Software Foundation</publisher>
      <group>org.apache.spark</group>
      <name>spark-core_2.13</name>
      <version>4.1.2</version>
      <description>The Apache Software Foundation provides support for the Apache community of open-source software projects.
    The Apache projects are characterized by a collaborative, consensus based development process, an open and
    pragmatic software license, and a desire to create high quality software that leads the way in its field.
    We consider ourselves not simply a group of projects sharing a server, but rather a community of developers
    and users.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">bfb9b8e69ac051c9406dd5480ec97636</hash>
        <hash alg="SHA-1">a4487ffdfdfa42fc05a404ed2ec3a634007848d4</hash>
        <hash alg="SHA-256">19cea8a7759431a276b7e4d0837f21472a72f01806739957ad85bfd686db7abb</hash>
        <hash alg="SHA-512">4fa470d3cc29b1ae0de5eb4cab43861187f1e44978712afa6cf2258a809213668b9eb11252ead2f0a3f08ae65a599d3cf3250e1d9f177b52799a78726af7a0d6</hash>
        <hash alg="SHA-384">e7b7a8b78e75cd69f7468549ff693ed25200044285b3532945e28aa74028efa6c16191f403db82dc3f3574bf1360ddeb</hash>
        <hash alg="SHA3-384">18d8956ba3561ef0ed758d759626c78b0262d526b830ee566ddeb58134cb075fac3ed9d6ebe1ad69c613e644bafb03ad</hash>
        <hash alg="SHA3-256">1d138e878ef5d129ab1c100557e3b2c649a533ed1393e371fbba447faa004242</hash>
        <hash alg="SHA3-512">b68a6d6f13119e18dc71051e99ef22aeaeab5c5078fdce398f4ccc269f05c9603ee8b08b0e67eff4fd27390718e99bbfa1208600a5a4e2545d968dff018b6198</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.spark/spark-core_2.13@4.1.2?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://spark.apache.org/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://issues.apache.org/jira/browse/SPARK</url>
        </reference>
        <reference type="mailing-list">
          <url>dev-subscribe@spark.apache.org</url>
        </reference>
        <reference type="vcs">
          <url>scm:git:git@github.com:apache/spark.git/sql/spark-core_2.13</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/commons-lang/commons-lang@2.6?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>commons-lang</group>
      <name>commons-lang</name>
      <version>2.6</version>
      <description>Commons Lang, a package of Java utility classes for the
        classes that are in java.lang's hierarchy, or are considered to be so
        standard as to justify existence in java.lang.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">4d5c1693079575b362edf41500630bbd</hash>
        <hash alg="SHA-1">0ce1edb914c94ebc388f086c6827e8bdeec71ac2</hash>
        <hash alg="SHA-256">50f11b09f877c294d56f24463f47d28f929cf5044f648661c0f0cfbae9a2f49c</hash>
        <hash alg="SHA-512">4a5a3dbe4941c645e2cca068cca5c1882cfe988b02e7cd981d1e51784900767d1deab0e0e0566f559c9fcabb4a180e436d5bb948902d4f4106f37360466afb42</hash>
        <hash alg="SHA-384">9725bc421adc1dbcd6f937eca0f3075d186a2b353ece4cef66b0fe81bb8d3f7d7641c43e86d657ef526c719f0c2a8c90</hash>
        <hash alg="SHA3-384">4bc4eaaf2580ded6d552b96ae5261c936de95f69a1d137c47279c51bf2aa1406ae44f69ccc94486267b8441e53c4bd74</hash>
        <hash alg="SHA3-256">b68d49ef037d428ea0c3e67a7a20f3d68a134bef30a1639ec08d28886b9f5629</hash>
        <hash alg="SHA3-512">2e9ffc0608827cffc0b48b7a0f35d371c66586c99fea2910f7c2a237c7c57d9ae4d65de7c8e018362c2e4f963c2f70a9196cebf35457f1dd0cea6c65c256f673</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/commons-lang/commons-lang@2.6?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://commons.apache.org/lang/</url>
        </reference>
        <reference type="build-system">
          <url>http://vmbuild.apache.org/continuum/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>http://issues.apache.org/jira/browse/LANG</url>
        </reference>
        <reference type="mailing-list">
          <url>http://mail-archives.apache.org/mod_mbox/commons-user/</url>
        </reference>
        <reference type="vcs">
          <url>http://svn.apache.org/viewvc/commons/proper/lang/branches/LANG_2_X</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.spark/spark-sql_2.13@4.1.2?type=jar">
      <publisher>Apache Software Foundation</publisher>
      <group>org.apache.spark</group>
      <name>spark-sql_2.13</name>
      <version>4.1.2</version>
      <description>The Apache Software Foundation provides support for the Apache community of open-source software projects.
    The Apache projects are characterized by a collaborative, consensus based development process, an open and
    pragmatic software license, and a desire to create high quality software that leads the way in its field.
    We consider ourselves not simply a group of projects sharing a server, but rather a community of developers
    and users.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">4b75c046d554941330663b187f7f422e</hash>
        <hash alg="SHA-1">03390b5c817480b8560bfd60db960dfd35e83b8b</hash>
        <hash alg="SHA-256">2c97d6ba8539d10784ad05b5cb4f7361467322aef2d2e84eb4f87231001792eb</hash>
        <hash alg="SHA-512">b9e58dedf07f6c2f8b5f2166659a2c49798d634fd1e8d7a86207a379c80b5989b7be653bdb85245c4d81479dc2a326e7da2f39f07dca80fa862b203627eb9be9</hash>
        <hash alg="SHA-384">ea726e82e14984056ba09c60690e73626a86cce16658bd1f36838af0566f95537414413e5e6fcde46d7df8a21b58ba38</hash>
        <hash alg="SHA3-384">18469263bd6b0c5d87c1db1078a35686473e25e43467379ec9db8e97413c4e2afcd7827d13397d95da6cd61ee767d434</hash>
        <hash alg="SHA3-256">58586720f547f79932adffcc4b6f0a560b5047be9f1c72ad62aca3dc279de932</hash>
        <hash alg="SHA3-512">b753f56a7a0cdf7a71186d3df5a336d5895c57ab9bdd27bbc63f149d716b43c674db7f759ba2479e0bf9514f514be49467046eeed0266f8201708df774dfff04</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.spark/spark-sql_2.13@4.1.2?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://spark.apache.org/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://issues.apache.org/jira/browse/SPARK</url>
        </reference>
        <reference type="mailing-list">
          <url>dev-subscribe@spark.apache.org</url>
        </reference>
        <reference type="vcs">
          <url>scm:git:git@github.com:apache/spark.git/sql/spark-sql_2.13</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.spark/spark-pipelines_2.13@4.1.2?type=jar">
      <publisher>Apache Software Foundation</publisher>
      <group>org.apache.spark</group>
      <name>spark-pipelines_2.13</name>
      <version>4.1.2</version>
      <description>The Apache Software Foundation provides support for the Apache community of open-source software projects.
    The Apache projects are characterized by a collaborative, consensus based development process, an open and
    pragmatic software license, and a desire to create high quality software that leads the way in its field.
    We consider ourselves not simply a group of projects sharing a server, but rather a community of developers
    and users.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">3fb1fa00eb9679181efca643587cdfe3</hash>
        <hash alg="SHA-1">6be7feb89ec09c5c361e671b7fbde798efe8197f</hash>
        <hash alg="SHA-256">cbadf737b2e84cb5ac8cce02c2b32ca6b939d3fffaec9f7a68d2de80a6e77746</hash>
        <hash alg="SHA-512">569fd228a8ecf1df22751a2d504cd0b72be94d1fa2f76069ca168a0b113a958d248d28610ea618d9482d31cd34d4e467c8b7cb4de69b5be60d688960e5965075</hash>
        <hash alg="SHA-384">30bd36b068e68a49f32c12b284fb5b9df2913966565340bdaab84e5c3a936bdcfb0a072760310b636ab6bdb519d33cb0</hash>
        <hash alg="SHA3-384">10cf75bcbcb6b49072c7397e8a9a0d997f3aadf33e095f9976cbc477228a3e6f4ea989f468272a8899b20ada23599f9c</hash>
        <hash alg="SHA3-256">28457f0b4d174aecb1e99f236a11d41a7a0e330cf3a64de5866a7fe2f5d1a056</hash>
        <hash alg="SHA3-512">bcfd5037eca3b39a89982ca5543d3733bba4192dd4cf606237329a706457e8ad5853e18f31ce9d09f073d8d66c290c5e5b174772b5d84232208e7f89e0f88dd4</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.spark/spark-pipelines_2.13@4.1.2?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://spark.apache.org/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://issues.apache.org/jira/browse/SPARK</url>
        </reference>
        <reference type="mailing-list">
          <url>dev-subscribe@spark.apache.org</url>
        </reference>
        <reference type="vcs">
          <url>scm:git:git@github.com:apache/spark.git/sql/spark-pipelines_2.13</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.hive/hive-common@2.3.10?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.hive</group>
      <name>hive-common</name>
      <version>2.3.10</version>
      <description>The Apache Software Foundation provides support for the Apache community of open-source software projects.
    The Apache projects are characterized by a collaborative, consensus based development process, an open and
    pragmatic software license, and a desire to create high quality software that leads the way in its field.
    We consider ourselves not simply a group of projects sharing a server, but rather a community of developers
    and users.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">8af37a73b588e0d6b8b230ed2087dee4</hash>
        <hash alg="SHA-1">735c4766eca38057e5a5321712d405166530c0d3</hash>
        <hash alg="SHA-256">b6a26be6eaf7ead173edfb2a654f72bdbf5fd1d5bb5ab99144a21a2205593831</hash>
        <hash alg="SHA-512">52f471ce5052566c1b05fb936e37e0ad57bf5fb7a2f6bccbfc676e294f8caf9c8d772c6874d389b0ec13ab96e7b787a7835d94ebdc23e9977c944811cdf2ee31</hash>
        <hash alg="SHA-384">94dd84a32c7969ec2569e9a0fe3741a70145ac86fa17af9ee269bcde2cf000ce4a744b4164ac68d6bc1796b50c2807df</hash>
        <hash alg="SHA3-384">f0b13077fd9857f82f417f919163db67576f1118761d1f326795e6995a2ad92a60d4caf30761883a8941bdcf51e25bae</hash>
        <hash alg="SHA3-256">d79e24500304dbbb5ba395370408efdfa73af751ee3a97d2f005be42f67bba09</hash>
        <hash alg="SHA3-512">d3ddd5cc8027423149c0df5939294cf83e986590857975d5682aa1cb63410bbe3ebef3a12a25c833bb0bbd429560755e0e152132e87eaa2adcebd89bcf215cb1</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.hive/hive-common@2.3.10?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://hive.apache.org/hive-common</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="mailing-list">
          <url>http://mail-archives.apache.org/mod_mbox/www-announce/</url>
        </reference>
        <reference type="vcs">
          <url>http://svn.apache.org/viewvc/maven/pom/tags/apache-14/hive/hive-common</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/com.tdunning/json@1.8?type=jar">
      <group>com.tdunning</group>
      <name>json</name>
      <version>1.8</version>
      <description>A clean-room Apache-licensed implementation of simple JSON processing</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">a89b66cf37063d0ee4f401193eb0ca2d</hash>
        <hash alg="SHA-1">fa57d5adf557b226738cd42e6c093dd0a76c5fd4</hash>
        <hash alg="SHA-256">e0b487de3ccd3d1c288976677835e49880799c35507059039a18fa4ae1e7c59a</hash>
        <hash alg="SHA-512">558e9780bcea2d0e077cc4c8d07eccd5d821361e0d9298bdfc30fc4b4472c5e5bec2aebae5ec677f9fa2047f3f356c6a41588d73eabd7ff45cd6bb37156f58fc</hash>
        <hash alg="SHA-384">b7b0cfb7092ff5d32fb84a981c5f8a4b41e271057c3558dfa49cec23c91645311cae46758f31fb74d0d7a98d78d128b8</hash>
        <hash alg="SHA3-384">8a7f21ac35a224ae2dcc0e72c84bf4ff6217c27116f188a738004fcfd9d9c562276029d858adb9105cd6b66e8fb54397</hash>
        <hash alg="SHA3-256">30f5d79dba15d3893fb1056c08879467cbe7fbc3e59812eb56917baff0f2fd38</hash>
        <hash alg="SHA3-512">2eaf229ec5ace316b72c0ecf03968b782871c82ee351bc8e65449adcea305b5be4b12495296974063ecfe12cc456e3c49cb9f0aa090e0bb309b9b7d9a1e00386</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/com.tdunning/json@1.8?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/tdunning/open-json</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/tdunning/open-json</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/com.github.joshelser/dropwizard-metrics-hadoop-metrics2-reporter@0.1.2?type=jar">
      <group>com.github.joshelser</group>
      <name>dropwizard-metrics-hadoop-metrics2-reporter</name>
      <version>0.1.2</version>
      <description>A reporter for Dropwizard Metrics which announces measurements using Hadoop Metrics2.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">7c59244206bb5ed013cbd52b4c84d94d</hash>
        <hash alg="SHA-1">ff3520ab6e48718e2d79e47f6cf2bd7b50180b84</hash>
        <hash alg="SHA-256">a22d6889790fa98d5f85de6e25f7dc89946b26964742e6deb9f91681946fa03a</hash>
        <hash alg="SHA-512">f3ce33c36b41a727f4fe34644f5fa9980ff178fa9761030d6545e561f90940d4d7041b3342d155ac90f2f2f85e4bc668a7bdc5af4fcd593d37fd66db6d8ec8dc</hash>
        <hash alg="SHA-384">37423aca07f575a0d29140bb672f4c2ac8b80e1ce603142180aa8a74f29df6812c53472ac55f52b6934e92eccec20a61</hash>
        <hash alg="SHA3-384">aa4eaefeee878634054f649d417a32210558eb7ee098acc88f213df45ae6a9e3ecb6f83675bf7605bce2f047264f4f1b</hash>
        <hash alg="SHA3-256">34bf655212c3ca1ca9e15f579e9b7c4a4ce18c90ebd8932f3bc3452653a0eaae</hash>
        <hash alg="SHA3-512">93ed266ebe65ae88eb3e9ac8e62a00b281a9622767d1a2dca3521ee8729b699fe8c9b2939d1c535990318efee3d410e3be0d8b6adf89f1d32b8b079bcc66c61a</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/com.github.joshelser/dropwizard-metrics-hadoop-metrics2-reporter@0.1.2?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/joshelser/dropwizard-hadoop-metrics2</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/joshelser/dropwizard-hadoop-metrics2/issues</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/joshelser/dropwizard-hadoop-metrics2</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.hive/hive-exec@2.3.10?classifier=core&amp;type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.hive</group>
      <name>hive-exec</name>
      <version>2.3.10</version>
      <description>The Apache Software Foundation provides support for the Apache community of open-source software projects.
    The Apache projects are characterized by a collaborative, consensus based development process, an open and
    pragmatic software license, and a desire to create high quality software that leads the way in its field.
    We consider ourselves not simply a group of projects sharing a server, but rather a community of developers
    and users.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">a7ff5b04d8cbc0977f5ac4d8bcee74d5</hash>
        <hash alg="SHA-1">8b83a1d6f1916ff118e5030f3b670fd3a86dfc4a</hash>
        <hash alg="SHA-256">1699ff817dd73db685ff112f109ec7ae380e0a6fa1a204166e55f66268fcd801</hash>
        <hash alg="SHA-512">f1403fa70bab012df11868c66b3caab0040cd830b3a86c90324d934d543a7c1131065f0437e6e8adadd875f2e778031174b1573f4570cdeb979ec8acec43fddf</hash>
        <hash alg="SHA-384">263c1e344559cbf4c7c8dbffe0e8eca78331a68e466c72e065006be4704223ad844e44eaa5e97e32c2010de5929980a1</hash>
        <hash alg="SHA3-384">3c623f56b955462b22303cd5e676315d10458a59209da64741a28af660b96cf0474d8a2590aa3fdc01b1fcbff2db5149</hash>
        <hash alg="SHA3-256">0261b2bb85057d3d985b3b0aacdc38d9349445819032dadbf07ad5a34cbeaa26</hash>
        <hash alg="SHA3-512">8d021fc74610002b978b97eec7e2447b4e484cb61ae28b1b4da30836ca98aab3cf325eff3682683655cf2bdf58f493aaff26630fa0c38c95646a20aa70bb97da</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.hive/hive-exec@2.3.10?classifier=core&amp;type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://hive.apache.org/hive-exec</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="mailing-list">
          <url>http://mail-archives.apache.org/mod_mbox/www-announce/</url>
        </reference>
        <reference type="vcs">
          <url>http://svn.apache.org/viewvc/maven/pom/tags/apache-14/hive/hive-exec</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.antlr/antlr-runtime@3.5.2?type=jar">
      <publisher>ANTLR</publisher>
      <group>org.antlr</group>
      <name>antlr-runtime</name>
      <version>3.5.2</version>
      <description>A framework for constructing recognizers, compilers, and translators from grammatical descriptions containing Java, C#, C++, or Python actions.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">1fbbae2cb72530207c20b797bdabd029</hash>
        <hash alg="SHA-1">cd9cd41361c155f3af0f653009dcecb08d8b4afd</hash>
        <hash alg="SHA-256">ce3fc8ecb10f39e9a3cddcbb2ce350d272d9cd3d0b1e18e6fe73c3b9389c8734</hash>
        <hash alg="SHA-512">71adb4a78a23e4106e9f09c92a7e0c1d975ad314a49f4a06472e22a2ec09c83fc02c6b684a20055b46ae69fcc119b155b7109ef56e170579c9a462c8839bae52</hash>
        <hash alg="SHA-384">e56770e380da87eda373e1f0fa7da0fd031b3e310e70b581d8a7eeffa80192f7cdccd073e45f277610ca1e161662db62</hash>
        <hash alg="SHA3-384">856d53937937c945025382711f9a28b66510ba5fa98ba928cedfa0314cc333d2a570c84d12e3dc877fc11b9e5b5902be</hash>
        <hash alg="SHA3-256">52d6cd070ca8a0dc5bfe4dbc2e7f6c095e32d3c83c5030bbc160dcc5eb47457d</hash>
        <hash alg="SHA3-512">d9da25347d24b7ccb0f840cec91f7ca7262b61969351f87b3c6ef7fbc202104d45250ae3920d2dd430a9db20c457529b1adcf9c7e3bc068b1f03793123a88646</hash>
      </hashes>
      <licenses>
        <license>
          <name>BSD licence</name>
          <url>http://antlr.org/license.html</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.antlr/antlr-runtime@3.5.2?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://www.antlr.org</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/antlr/antlr3/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://groups.google.com/forum/?fromgroups#!forum/antlr-discussion</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/antlr/antlr3/tree/master/antlr-runtime</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.antlr/ST4@4.0.4?type=jar">
      <group>org.antlr</group>
      <name>ST4</name>
      <version>4.0.4</version>
      <description>StringTemplate is a java template engine for generating source code,
web pages, emails, or any other formatted text output.

StringTemplate is particularly good at multi-targeted code generators,
multiple site skins, and internationalization/localization. 

It evolved over years of effort developing jGuru.com. 

StringTemplate also generates the stringtemplate website: http://www.stringtemplate.org
and powers the ANTLR v3 code generator. Its distinguishing characteristic 
is that unlike other engines, it strictly enforces model-view separation.

Strict separation makes websites and code generators more flexible
and maintainable; it also provides an excellent defense against malicious
template authors.

There are currently about 600 StringTemplate source downloads a month.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">06856c607f242639cd52ef2b4c63ebc9</hash>
        <hash alg="SHA-1">467a2aa12be6d0f0f68c70eecf6714ab733027ac</hash>
        <hash alg="SHA-256">17cc49dc535a0fbe58c3a8634e774572bed31eb73415e9ce9d2703b977bf356f</hash>
        <hash alg="SHA-512">b3ebd65ab7c425b7346bc528d5e45983e28126928946caadc39ca9f84be62ddffcf81a428c33f36de874e671cf09b5fea13270bb1dd52176dbe12f8e1e5a402c</hash>
        <hash alg="SHA-384">8b92ececea4875a1a2272925c7a06ace23f8f995f85c31bc84b53700a179d01f450505524fa84b86e71e3d2ae518879c</hash>
        <hash alg="SHA3-384">13cd835c1f038510c22793d4d3964561947b572e72cafa75ac6a82b3f78ca1e05bf812e479c1f9294952516d3fab243f</hash>
        <hash alg="SHA3-256">694a44933f779af3f8d1a59d49a50628a0c67f33afac6fdb30bfcce80cdc11bd</hash>
        <hash alg="SHA3-512">5aa52dea153e2d39e38f5c1f8ba584ef2a77572d7a9b64e60a4534074da91c53af3767edcea650e30a394d2634410dcf5565f0c1d3448490fe8afa9e43a56703</hash>
      </hashes>
      <licenses>
        <license>
          <name>BSD licence</name>
          <url>http://antlr.org/license.html</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.antlr/ST4@4.0.4?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://www.stringtemplate.org</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>http://fisheye2.cenqua.com/browse/stringtemplate</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.ivy/ivy@2.5.3?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.ivy</group>
      <name>ivy</name>
      <version>2.5.3</version>
      <description>The Apache Software Foundation provides support for the Apache community of open-source software projects.
    The Apache projects are characterized by a collaborative, consensus based development process, an open and
    pragmatic software license, and a desire to create high quality software that leads the way in its field.
    We consider ourselves not simply a group of projects sharing a server, but rather a community of developers
    and users.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">b4d09f19aa90390308e50ddbc49f9227</hash>
        <hash alg="SHA-1">163b4d6b330cd4590a05f3e97a6eb8bf5b54665e</hash>
        <hash alg="SHA-256">9502aa5aabf0b1484924a13ef4b5d24f121f7f91aab6768f11cc9d0906c0803b</hash>
        <hash alg="SHA-512">be291ddf612703fd3657a72820199430d053a8e06f7631e78477b428ba343631bc36b16bde8c25df544b64b420be84568d3898921f8db63fe676fb590586355b</hash>
        <hash alg="SHA-384">2d4b27645c4cf77d8814f45845ef3e6a40208823b13fca106b1f8564d17bfb65d6972dd58fec3829a12e0f23690d2313</hash>
        <hash alg="SHA3-384">696dfa4292c3eed1e24c4c3b5665af86cc184842fed676cbff3f5776f78884a578c0cbff5d3ee92cbbf8d4c063cee475</hash>
        <hash alg="SHA3-256">61397f02e250a2f9a66854753ed390e026218a4499da0a4a17d37893e9ad5b64</hash>
        <hash alg="SHA3-512">101d885a3e85f7241787c65a4e2c1aba10af74a9267d6d05b94e7037ce7dc9c39e1c1bdc1d61ebbb97d3ffed89078d49cfdcf74fea2d3ee1da2baf0ace463abc</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.ivy/ivy@2.5.3?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://ant.apache.org/ivy/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://issues.apache.org/jira/browse/IVY</url>
        </reference>
        <reference type="mailing-list">
          <url>https://mail-archives.apache.org/mod_mbox/ant-dev</url>
        </reference>
        <reference type="vcs">
          <url>https://svn.apache.org/repos/asf/ant/ivy/core/trunk</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/com.google.code.gson/gson@2.11.0?type=jar">
      <group>com.google.code.gson</group>
      <name>gson</name>
      <version>2.11.0</version>
      <description>Gson JSON library</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">0c69b9199d3a4e6c34dc03619ff7feee</hash>
        <hash alg="SHA-1">527175ca6d81050b53bdd4c457a6d6e017626b0e</hash>
        <hash alg="SHA-256">57928d6e5a6edeb2abd3770a8f95ba44dce45f3b23b7a9dc2b309c581552a78b</hash>
        <hash alg="SHA-512">b8c91426a8275b42ea5c55b104308ffbe656ae3354bc661f62173352e53a4818a009e4dd82bc6cf518c77fda5a4d2eab0d3ad832581a8f0d87966ef04e6c025a</hash>
        <hash alg="SHA-384">8720df1ca6f2258a71b7f2307e2b49f0ad2379bc93e93be6a6c619e52b95dbe5a080a49149e8708ce1890e97b47b9bbf</hash>
        <hash alg="SHA3-384">e3e268c6f8c75f018c7c8160fba7fe373242d45a2313b5c7823f3f75fcc04bbf93cb43c08ba2998b01b8a3c685d77280</hash>
        <hash alg="SHA3-256">aa4162683be07c5de9c962e88301054ea42a9bed2257a5e4e650545624a2c094</hash>
        <hash alg="SHA3-512">31730c961b8920673ac3e973a16272752a46df479bfc0ce4dfb6dd324e32d34e5006247d6b5508b8fdc785ba5ffb42534ea3fa2d7094191febcac60654230e24</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/com.google.code.gson/gson@2.11.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/google/gson</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/google/gson/issues</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/google/gson/</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/stax/stax-api@1.0.1?type=jar">
      <group>stax</group>
      <name>stax-api</name>
      <version>1.0.1</version>
      <description>StAX API is the standard java XML processing API defined by JSR-173</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">7d436a53c64490bee564c576babb36b4</hash>
        <hash alg="SHA-1">49c100caf72d658aca8e58bd74a4ba90fa2b0d70</hash>
        <hash alg="SHA-256">d1968436fc216c901fb9b82c7e878b50fd1d30091676da95b2edd3a9c0ccf92e</hash>
        <hash alg="SHA-512">43c24e8dbffa9b932492c8ccf2b91926b2ba3d1d34b5a9671c689bd24d4c220b996708a9667521641d1abbf29404b653755b6f6f3dc0ad0671f5c09db332ea06</hash>
        <hash alg="SHA-384">2e6c232d3012064dc17e10c2e5b281728a6771eb0d74868e730caf60fe6f96fdd6145759fbbf9d1aa2e07eb1f49764d6</hash>
        <hash alg="SHA3-384">03ebb8db88d04b7308570c1058aadfb6a81d3d6725b1dd13a049ea984ed1df42d3e0f8163e1229752228cada978fb462</hash>
        <hash alg="SHA3-256">8173e3e3a0db17b3dbb80c017268858ecda57c819e5b58dbe202bd8087664bb1</hash>
        <hash alg="SHA3-512">e9a7c234dfeff5d4cabd034a536f31ad5a141e30b0ad2438cf5856dd6c36eeb16c69b8bc1ba3ee6bba91f69cd3cbd450953249f2f0eee0a9a22d49637b575f4d</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/stax/stax-api@1.0.1?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://stax.codehaus.org/</url>
        </reference>
        <reference type="issue-tracker">
          <url>http://jira.codehaus.org/browse/STAX</url>
        </reference>
        <reference type="mailing-list">
          <url>http://groups.yahoo.com/group/stax_builders/</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.hive/hive-metastore@2.3.10?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.hive</group>
      <name>hive-metastore</name>
      <version>2.3.10</version>
      <description>The Apache Software Foundation provides support for the Apache community of open-source software projects.
    The Apache projects are characterized by a collaborative, consensus based development process, an open and
    pragmatic software license, and a desire to create high quality software that leads the way in its field.
    We consider ourselves not simply a group of projects sharing a server, but rather a community of developers
    and users.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">f1282f3596208d9d45f39ac42c35c224</hash>
        <hash alg="SHA-1">309f3c5509a9aba9b88559d215f6a00a92f6ac21</hash>
        <hash alg="SHA-256">20786e707c40793b5e23688c61dc1959b3c828a821945712a530983cb7ea6c24</hash>
        <hash alg="SHA-512">ed4d4df6db0ab96b4bbf793cb2e75351ed1c9b1cb5562212f1c52a9b8e57f3e2b0c536868a5207a6243f05270b75506a563a930d115b78b3cd5ebd6c5be0ec45</hash>
        <hash alg="SHA-384">3c79c248cd778231205457507f0cafb4fccda6ef4e81fb86739f151c5e4ef7704f1b899694b5c95d6415edaa05a5c9b0</hash>
        <hash alg="SHA3-384">9c66ffdd531061e8142bb4d5be5fa561f2acb273ad42d360bbbb1526780426bbca71ca46f5180c25da96bfa288a37267</hash>
        <hash alg="SHA3-256">e84fe91129190453d9ef27734d290182348b7f9d93a7ac46cd1eef67954e8c44</hash>
        <hash alg="SHA3-512">c0d2059054626d9aa8d9696dfb102472d06b25217658e4aba4252821079790a4cbe27caccf3fcd568166378cd1d6ea7b6555f2ae13e3e4b39d54ac7c42a7861c</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.hive/hive-metastore@2.3.10?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://hive.apache.org/hive-metastore</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="mailing-list">
          <url>http://mail-archives.apache.org/mod_mbox/www-announce/</url>
        </reference>
        <reference type="vcs">
          <url>http://svn.apache.org/viewvc/maven/pom/tags/apache-14/hive/hive-metastore</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/javolution/javolution@5.5.1?type=jar">
      <publisher>Javolution</publisher>
      <group>javolution</group>
      <name>javolution</name>
      <version>5.5.1</version>
      <description>Javolution - Java Solution for Real-Time and Embedded Systems.
        This project uses template classes to generates java code for various versions
        of the Java run-time (e.g. J2ME, 1.4, GCJ, 1.5). The default maven compilation
        builds OSGI bundle for Java 1.5+ (parameterized classes).
        For others targets the ant script should be used directly (e.g. "ant j2me").</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">1b7257da4690bada3cac7293985f8588</hash>
        <hash alg="SHA-1">3fcba819cdb7861728405963ddc4b2755ab182e5</hash>
        <hash alg="SHA-256">6de167427fb5ad34fe533cb36a8b3427fa6052a2b99781874396ed5cca9f8ed1</hash>
        <hash alg="SHA-512">847f503a9cb1ea6076be51c8f81325916ba78c25c54651e03c5db88162a12e0203922679f8ac52b68d35be331f5d842017c482519c149bd6198e327f8f8c1fb8</hash>
        <hash alg="SHA-384">10f431e0c1acbdd383e7e693d2f6d8dcc6c8e5fd0a864dfbce3a81e5f69d224f22f5463db53022b8048add18e3dc659c</hash>
        <hash alg="SHA3-384">47baf48250b24dd6af7eea7137f43050712c38153b22ea7fecccea11ef310542c0277cecce2c290a469a8323832214a3</hash>
        <hash alg="SHA3-256">817e9c89519e079716641d49737fa301f17c1c844b90bbb31f65010e172defa3</hash>
        <hash alg="SHA3-512">490432649a293da6327647c2944d9b04859e91c485aa58dcf836cbff7735cf91930efc000b70ebdf2e20e67353169b59cd1d215f56b2c744929d2351b2826178</hash>
      </hashes>
      <licenses>
        <license>
          <id>BSD-3-Clause</id>
        </license>
      </licenses>
      <purl>pkg:maven/javolution/javolution@5.5.1?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://javolution.org</url>
        </reference>
        <reference type="distribution-intake">
          <url>java-net:/maven2-repository/trunk/repository/</url>
        </reference>
        <reference type="issue-tracker">
          <url>http://kenai.com/jira/browse/JAVOLUTION</url>
        </reference>
        <reference type="vcs">
          <url>https://kenai.com/svn/javolution~svn-repository/trunk</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/com.zaxxer/HikariCP@2.5.1?type=jar">
      <publisher>Zaxxer.com</publisher>
      <group>com.zaxxer</group>
      <name>HikariCP</name>
      <version>2.5.1</version>
      <description>Ultimate JDBC Connection Pool</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">4fd401dee8e525cbb8403476381e34cd</hash>
        <hash alg="SHA-1">b896b711e2d98fedf403de590559a123b5fbf1a6</hash>
        <hash alg="SHA-256">3cf7bc5258414b77613e8d8ef0ce63b3ae1c53a441fd95b9ea335ec051c652b2</hash>
        <hash alg="SHA-512">4a3137acfff20e17fb20bc582ed238d0305daef88f45d898c2b1c169343bece7970a4535d558333bacb24ddf52a4a90ccd6a7c49ffbefd31e0611bd86dc15cfc</hash>
        <hash alg="SHA-384">4254051930ab34c016fbe438065d368c288352f626fa2b0f0855b9deac6d70406eba16cc3e63fddfc93facad597bdac2</hash>
        <hash alg="SHA3-384">d35fa8945146febdbf1755fd3dfc141b55e8112a15de187d001492f6cb2e6844fb27f55355036bf23c3eaa296a13e6cd</hash>
        <hash alg="SHA3-256">b525d63c9dde15798c0101c9fd81077208e7cb1076aa7d206e2c3caf0f9205a9</hash>
        <hash alg="SHA3-512">c029f4e72c7b481bc666423dd496d1d19be1b1b6f8857c412a0ddb251531f4dd213ecee2f4182ad6c7f2249cdecafdcf0fe1d32ee4f580ab345facba56cc4c78</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/com.zaxxer/HikariCP@2.5.1?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/brettwooldridge/HikariCP</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.datanucleus/datanucleus-api-jdo@4.2.4?type=jar">
      <group>org.datanucleus</group>
      <name>datanucleus-api-jdo</name>
      <version>4.2.4</version>
      <description>Plugin providing DataNucleus implementation of the JDO API.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">f54789e11168bdfa5063d5241573ff21</hash>
        <hash alg="SHA-1">7e2c71f7eb9b40b660d009c3ea1b55fb71694bca</hash>
        <hash alg="SHA-256">f30f1f09658329190811468e58a622f069d97a7284d67a88b8d01c809ab3d1f3</hash>
        <hash alg="SHA-512">948027e5d289b8e9718fb0c552a60b8c9f3d1db42bdeae3e45f42701bd5bb23d5cccceedd98f958a09e2ff32b6a16a80dd11b397738521f8cb37f1af6c748384</hash>
        <hash alg="SHA-384">c577425c7c1451c7eaf96203ef7cfdcb3373ac72eab3193df37e317dd54e28d45a047a332d2bff1c395d391f992510f0</hash>
        <hash alg="SHA3-384">2fe3a5677cf33c9d426c835a0b9de182fe3d7aea97fb3b44c25239f6f5f5cd50868c033e78ad878cb09e45d349ca9333</hash>
        <hash alg="SHA3-256">042ef26d000a314786518cc714c453192799370119886209c692562c41ef9a68</hash>
        <hash alg="SHA3-512">39298aa3b780c14548ad7cdce93056987017d65664ef60d5c4203f255a65bd9894abbd32021e7e42ec0f2e9108c10150544b8af9e46bbf2382be0c27ad73ffd3</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.datanucleus/datanucleus-api-jdo@4.2.4?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://www.datanucleus.org/#/datanucleus-api-jdo</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/datanucleus/datanucleus-api-jdo</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.datanucleus/datanucleus-rdbms@4.1.19?type=jar">
      <group>org.datanucleus</group>
      <name>datanucleus-rdbms</name>
      <version>4.1.19</version>
      <description>Plugin for DataNucleus providing persistence to RDBMS datastores.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">7d1ad32dea1b7f5bf2d6c04e83a7bb17</hash>
        <hash alg="SHA-1">923fa411f49cca5dbb6221140b1ae89c90b3a3fd</hash>
        <hash alg="SHA-256">a189e10fb48dc0fa550721ee2206a1df8a2fd68d213149bf68793976b0ade687</hash>
        <hash alg="SHA-512">33288f43d5d3c6cc5d86079f784fcc6c12761480628e8f276f24ebed74f1844d2fb8175de11c29b4e8e5acc105e64f968f24a6df0ba0b5ea7f1d6c474c57a5e6</hash>
        <hash alg="SHA-384">33d88a62fae54d975579667a584c3784621e7489cf69e3d6f25432691c7ac48915ec8a7b10f91523d3230ecb23662694</hash>
        <hash alg="SHA3-384">45d456d4a62a7687301df25a7825bd54351c165ee6b2380991db876ce6eda8e3be00fea2aae95d87f18f815f365b3386</hash>
        <hash alg="SHA3-256">39f1fcfc21292f91471be93caa2821a6b1d3c5491dd91cc4853f9a4752caf487</hash>
        <hash alg="SHA3-512">f9dbec4558a3747e1c9310c5b5a0194caa6495a11527b9820785808c6609ba8b2c7d5ff9bff8d25ddd026ea65cfc27ca18ee27dc768738012c15f1f38e531ba8</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.datanucleus/datanucleus-rdbms@4.1.19?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://www.datanucleus.org/#/datanucleus-rdbms</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/datanucleus/datanucleus-rdbms</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/commons-pool/commons-pool@1.5.4?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>commons-pool</group>
      <name>commons-pool</name>
      <version>1.5.4</version>
      <description>Commons Object Pooling Library</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">80e9d1cbd70542f4f293793d109679a9</hash>
        <hash alg="SHA-1">75b6e20c596ed2945a259cea26d7fadd298398e6</hash>
        <hash alg="SHA-256">22095672ac3ad6503e42ec6d4cbc330cd1318040223f6c5d9605473b6d2aa0fd</hash>
        <hash alg="SHA-512">bb5a66d7da8f389660fb369c1a6e77296f39239cca1d69ca1b7c80e8e81c38a9d25debefb702a2eaac987e83885898ca0c95c6387d8440e548653d6bdae686a6</hash>
        <hash alg="SHA-384">6767d16144c5e86926f71f5ff24c4dd25f8d1aef47264502367cb7cfe63abaf9f914aba0de9fe998af4b510b85e76bf4</hash>
        <hash alg="SHA3-384">78c61e9ef304cd6184fe54519a675142f18b7baf3b3c4494a465ff5ba592996684367e3a3d7c91989db3c11207b4a022</hash>
        <hash alg="SHA3-256">faa40c2e730a63130868c95f41ad146d11011350b179cfbba6a0f45f066f6569</hash>
        <hash alg="SHA3-512">34e37f2f810cb75f7b5c1282e4adce88917014985a3c293fb2cfd18c4f76399cfd46d048e543c814203aa47b2d4ebfcf6950272a63c3ba6b79ba42261207e813</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/commons-pool/commons-pool@1.5.4?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://commons.apache.org/pool/</url>
        </reference>
        <reference type="build-system">
          <url>http://vmbuild.apache.org/continuum/</url>
        </reference>
        <reference type="issue-tracker">
          <url>http://issues.apache.org/jira/browse/POOL</url>
        </reference>
        <reference type="mailing-list">
          <url>http://mail-archives.apache.org/mod_mbox/commons-user/</url>
        </reference>
        <reference type="vcs">
          <url>http://svn.apache.org/viewvc/commons/proper/pool/trunk</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/commons-dbcp/commons-dbcp@1.4?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>commons-dbcp</group>
      <name>commons-dbcp</name>
      <version>1.4</version>
      <description>Commons Database Connection Pooling</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">b004158fab904f37f5831860898b3cd9</hash>
        <hash alg="SHA-1">30be73c965cc990b153a100aaaaafcf239f82d39</hash>
        <hash alg="SHA-256">a6e2d83551d0e5b59aa942359f3010d35e79365e6552ad3dbaa6776e4851e4f6</hash>
        <hash alg="SHA-512">c0512b255c4a7242634b820c78c397296fc9388deceb4dec199775341598f0c87b21164425a97dfdeadfad9f3c80e1d4dab735d32b1362377820a4204b4e5a78</hash>
        <hash alg="SHA-384">c28b64ac524706ba21a94657e334c9b9ea83738db222d6761290b1e2ea3caea267b63f54dd0044d4cd77d9f13e6c42b1</hash>
        <hash alg="SHA3-384">a0e87dbe19989dba04e58c21a4f43097cb9ef7207df1c4ed7592d133eb80a2596833e1708e39e820b1ea134f1403dcd8</hash>
        <hash alg="SHA3-256">f0b43fde5c8487f6bd9ece425bfbed73b9caa08c6853bf9442803f2714e6719b</hash>
        <hash alg="SHA3-512">20bbc73c349f66a607fd00e7e9a58859dbe8b8ef61fe43f86f2747ead24cb04a83ccfa8c34cab5fa2a4be9a1d0d234eabf81132ab49344c2aae6a42cc0cf82b0</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/commons-dbcp/commons-dbcp@1.4?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://commons.apache.org/dbcp/</url>
        </reference>
        <reference type="build-system">
          <url>http://vmbuild.apache.org/continuum/</url>
        </reference>
        <reference type="issue-tracker">
          <url>http://issues.apache.org/jira/browse/DBCP</url>
        </reference>
        <reference type="mailing-list">
          <url>http://mail-archives.apache.org/mod_mbox/commons-user/</url>
        </reference>
        <reference type="vcs">
          <url>http://svn.apache.org/viewvc/commons/proper/dbcp/trunk</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/javax.jdo/jdo-api@3.0.1?type=jar">
      <publisher>Apache Software Foundation</publisher>
      <group>javax.jdo</group>
      <name>jdo-api</name>
      <version>3.0.1</version>
      <description>The Java Data Objects (JDO) API is a standard interface-based Java model abstraction of persistence, developed as Java Specification Request 243 under the auspices of the Java Community Process.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">978ae9726514457b8cfe8a3ba1c17ca5</hash>
        <hash alg="SHA-1">058e7a538e020b73871e232eeb064835fd98a492</hash>
        <hash alg="SHA-256">2a2e63d44a4d7fe267650d08431218648adee14f725df3896d09db3084d7a2f2</hash>
        <hash alg="SHA-512">0cda5bbbbe791e91d4b8a8ca2e27a18f661c9c27324107cda69c346f12181e520a29a52048fcd0f31db0a7d60409de4c509689f793d5c56061b81c1087dbf428</hash>
        <hash alg="SHA-384">6ea573adcac7e5d2b6f676d783578079538f10f0de59d2699ef3a4ada0baf70c0d77ee8fdd5dc88a1bc0956e7cf7ae67</hash>
        <hash alg="SHA3-384">6098235b1088eab8fc0b8933de921721dcbd6f9897fd6549606cde231c6401e8713a58ba6ba6c646f1df16333f6f6b7b</hash>
        <hash alg="SHA3-256">c9748422837f1858368fb323e5b7bfd85e13e2b0b4d4460716b85a9ad9e2fa9d</hash>
        <hash alg="SHA3-512">bb71b22949e1137cf9c1d9562eee654e53bd859ded160fdafd3b4c1df9298eee4eef3c9d644bacd01ee8db4d0c7e1e63c1e97144a8896db7f9d87091216c39ca</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/javax.jdo/jdo-api@3.0.1?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://db.apache.org/jdo</url>
        </reference>
        <reference type="mailing-list">
          <url>http://mail-archives.apache.org/mod_mbox/db-jdo-user/</url>
        </reference>
        <reference type="vcs">
          <url>http://svn.apache.org/viewcvs.cgi/db/jdo</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/javax.transaction/jta@1.1?type=jar">
      <group>javax.transaction</group>
      <name>jta</name>
      <version>1.1</version>
      <description>The javax.transaction package. It is appropriate for inclusion in a classpath, and may be added to a Java 2 installation.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">82a10ce714f411b28f13850059de09ee</hash>
        <hash alg="SHA-1">2ca09f0b36ca7d71b762e14ea2ff09d5eac57558</hash>
        <hash alg="SHA-256">b8ec163b4a47bad16f9a0b7d03c3210c6b0a29216d768031073ac20817c0ba50</hash>
        <hash alg="SHA-512">fa9a5ab51f97e2cd63b5c1cb1775b63b1edc0197aedbcc0e8ab3116dfe27d47365865d24eefaf19b648554b60f1a1ece13e3192d157c319344a97ad551c628c4</hash>
        <hash alg="SHA-384">5119a3fdd809a087087c6491df078247ee50769529d793e5722b18270cf7399b5fc218763e2331c66ebd47fc0825ee79</hash>
        <hash alg="SHA3-384">e9384696ec5a9d50e7ec60144aec0b80d9b8fd9c95997b3548a0e8db4b7d96cf39f19e06ecaf298f78cb7152fc63623e</hash>
        <hash alg="SHA3-256">4c8506405cd570cb97d1d7aa211614cd7ade35df85c6168d9c82b38b730d4438</hash>
        <hash alg="SHA3-512">b90c7bc07e120db674b03f0fbd75f0a7bde6d9483883ca9359273e2d4ee6cfe73642dc79e7fec5c256ea7be0fe3a4b9365799cc99c29caa35b9c0dcc78fc9b2a</hash>
      </hashes>
      <purl>pkg:maven/javax.transaction/jta@1.1?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://java.sun.com/products/jta</url>
        </reference>
        <reference type="distribution">
          <url>http://java.sun.com/products/jta</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.datanucleus/javax.jdo@3.2.0-m3?type=jar">
      <group>org.datanucleus</group>
      <name>javax.jdo</name>
      <version>3.2.0-m3</version>
      <description>The Java Data Objects API (JDO) : a standard interface-based Java model abstraction of persistence, developed by the JCP.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">53e1eac14fa3a58cf0054f03373af8f4</hash>
        <hash alg="SHA-1">c911b22710a8f77541a966615033b4ab943fd6f3</hash>
        <hash alg="SHA-256">b0e338881376e4588f7564ae2dcc91737148e7c950873f6b0b899cbf0feef80b</hash>
        <hash alg="SHA-512">7e4959c1ed0e96af512a3bb058d25b1e284a76bae12063f3f179a24a6397acde2341a96d994bcb5f6c0e655fc4908e519c068a35bbb69e7010f09dac68d0047c</hash>
        <hash alg="SHA-384">fbe7e534591f03b5a538fc30dfea213e2a6e7bd86b8a45d778b312f859c745936bf45b0177a32d8b127506104f9c1c8e</hash>
        <hash alg="SHA3-384">5f38259adc32fa39fe62089b6b5c907fe3afffce67cbf5d3a2198ac2395aa19c815aa243c0cdbf3cac58ce972acaeced</hash>
        <hash alg="SHA3-256">37a039c9009e8098384292481f3032911def912a7c8e9271cc92489b0b158651</hash>
        <hash alg="SHA3-512">5b96d544c4f5e7fb62b72d909606fd316085dd10768619d1640a867cea51a995f4ad6f237ead69787163a4f4ea32f93ea2f73afde639256e614d89ec77e8142c</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.datanucleus/javax.jdo@3.2.0-m3?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://www.datanucleus.org/#/javax.jdo</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/datanucleus/javax.jdo</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/javax.transaction/transaction-api@1.1?type=jar">
      <group>javax.transaction</group>
      <name>transaction-api</name>
      <version>1.1</version>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">82a10ce714f411b28f13850059de09ee</hash>
        <hash alg="SHA-1">2ca09f0b36ca7d71b762e14ea2ff09d5eac57558</hash>
        <hash alg="SHA-256">b8ec163b4a47bad16f9a0b7d03c3210c6b0a29216d768031073ac20817c0ba50</hash>
        <hash alg="SHA-512">fa9a5ab51f97e2cd63b5c1cb1775b63b1edc0197aedbcc0e8ab3116dfe27d47365865d24eefaf19b648554b60f1a1ece13e3192d157c319344a97ad551c628c4</hash>
        <hash alg="SHA-384">5119a3fdd809a087087c6491df078247ee50769529d793e5722b18270cf7399b5fc218763e2331c66ebd47fc0825ee79</hash>
        <hash alg="SHA3-384">e9384696ec5a9d50e7ec60144aec0b80d9b8fd9c95997b3548a0e8db4b7d96cf39f19e06ecaf298f78cb7152fc63623e</hash>
        <hash alg="SHA3-256">4c8506405cd570cb97d1d7aa211614cd7ade35df85c6168d9c82b38b730d4438</hash>
        <hash alg="SHA3-512">b90c7bc07e120db674b03f0fbd75f0a7bde6d9483883ca9359273e2d4ee6cfe73642dc79e7fec5c256ea7be0fe3a4b9365799cc99c29caa35b9c0dcc78fc9b2a</hash>
      </hashes>
      <purl>pkg:maven/javax.transaction/transaction-api@1.1?type=jar</purl>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.hive/hive-serde@2.3.10?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.hive</group>
      <name>hive-serde</name>
      <version>2.3.10</version>
      <description>The Apache Software Foundation provides support for the Apache community of open-source software projects.
    The Apache projects are characterized by a collaborative, consensus based development process, an open and
    pragmatic software license, and a desire to create high quality software that leads the way in its field.
    We consider ourselves not simply a group of projects sharing a server, but rather a community of developers
    and users.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">a9b46c1dbbcdeffa27474556d50b46a6</hash>
        <hash alg="SHA-1">643c3ea10b3c5ba7f01659944a7c15998d580ac4</hash>
        <hash alg="SHA-256">d29877f0a83fbee1d43495520e6b186f157d3a0999b12a2a8b21840be6230206</hash>
        <hash alg="SHA-512">1469bdb00edb064b213575816f41255cf457929527704faa883355721344d718f22756c05dc4b891947bfc42cf9cd352d73663eef63c0b8458f5aea4d6e081ed</hash>
        <hash alg="SHA-384">0438a7f121c384fb7c40cd8770335a146c48a4b9f349436221a22603a70bb4352b285da243dfc285f209e135f5bcbb93</hash>
        <hash alg="SHA3-384">016e9a55feec2449324d8111a6c3fd3266da5713d6e40460aad39ad2ca10a18405fa2398d9755cb44c80725eaac0b284</hash>
        <hash alg="SHA3-256">09ae01409bedc768e5c1b19146ff6a8c42f487d70f992699a8de035237156637</hash>
        <hash alg="SHA3-512">57b1c6836bdbcbd10653f67c2ebccf6c02506a04a784960f0db0f21bb99e0ed0d73eb4643ab140161e0899b6538a560b8416c74737fc655a0fdd4faaf0cbab5e</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.hive/hive-serde@2.3.10?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://hive.apache.org/hive-serde</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="mailing-list">
          <url>http://mail-archives.apache.org/mod_mbox/www-announce/</url>
        </reference>
        <reference type="vcs">
          <url>http://svn.apache.org/viewvc/maven/pom/tags/apache-14/hive/hive-serde</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/net.sf.opencsv/opencsv@2.3?type=jar">
      <group>net.sf.opencsv</group>
      <name>opencsv</name>
      <version>2.3</version>
      <description>A simple library for reading and writing CSV in Java</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">9eebabaa007dc329845e5ab3c12b4e6b</hash>
        <hash alg="SHA-1">c23708cdb9e80a144db433e23344a788a1fd6599</hash>
        <hash alg="SHA-256">dc0ba5bff6140dc92339973026a0ecbddc2a3b01bdd46ed9d16becc2f6d78de6</hash>
        <hash alg="SHA-512">0c385519e65f09c84785988dbe29966b41d74fa1a35f27053d150fc69a5b3d07b20e351aaf9ce50005df9a7123c0520473208520a05e58090255b82e7ac0b27a</hash>
        <hash alg="SHA-384">9863406442dda7cb9e763f34ed68aeb9bbb5b36edb9ec1818d0bd47874c8cecc480d41cb6b9d7bf3117f2e7fd6e0d556</hash>
        <hash alg="SHA3-384">d56c6fe1cf95f0dc1662eb42d9fbc83c34574c0e7e350ad0db78a05052f4870671dfcba7ab2806adf1736e9bbcba7548</hash>
        <hash alg="SHA3-256">750674eabd8da524fba1b02dd079c5295b97bfdaca55f6615fe159af56d64fc2</hash>
        <hash alg="SHA3-512">036fd4be2f266d749a0f92ceb777938364143cd4e7f2b4c2154dc7e077a8b17f90b1175a728e2cc6440fb7a6141aa24295f99fefaddf439097a1943660e54727</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/net.sf.opencsv/opencsv@2.3?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://opencsv.sf.net</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="issue-tracker">
          <url>http://sourceforge.net/tracker/?group_id=148905</url>
        </reference>
        <reference type="vcs">
          <url>http://opencsv.svn.sourceforge.net/viewvc/opencsv/</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.hive/hive-shims@2.3.10?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.hive</group>
      <name>hive-shims</name>
      <version>2.3.10</version>
      <description>The Apache Software Foundation provides support for the Apache community of open-source software projects.
    The Apache projects are characterized by a collaborative, consensus based development process, an open and
    pragmatic software license, and a desire to create high quality software that leads the way in its field.
    We consider ourselves not simply a group of projects sharing a server, but rather a community of developers
    and users.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">c45f01892b6152bba2ba6d9a366c2a2c</hash>
        <hash alg="SHA-1">9999e778a62dc8e9f66921fa4475077aff977f19</hash>
        <hash alg="SHA-256">bafd52d8fc0a9c02c18f9771dc82d6ebc270e1331c31c668e2c4c02fc4bf1bfd</hash>
        <hash alg="SHA-512">735cd90c92c783b22728584ace9e47020dffb0b7db57225e66667a48eddcfa43645e48cb2f3b4e70c965a7b44316ac1e71674bf6ceda01fcc41b345505bd363f</hash>
        <hash alg="SHA-384">526ec31ec7ab66debab537e5dad06a17a30138169be60acc69b73f7cd4349f5b1a1ffe040ef91ec8da9530eb67dedd57</hash>
        <hash alg="SHA3-384">be75f9fcc3d553ed15cd805bed50139372dc031ec926f768c7644b9bc9131d5cc7315f34eec51e1b2e8f368692debc6b</hash>
        <hash alg="SHA3-256">f01e989cf96698af11b88c07cb076a88d865568848255eb49ffd85425c99b83b</hash>
        <hash alg="SHA3-512">10b3ae0bb10a0d902be0607e16cea17d56cacd4296d940b3ec3acaf4fd8b8a6600a107cf799487a3a7534a96b1373250e52be13e13f0cb3d0f40e910d2bbfc4c</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.hive/hive-shims@2.3.10?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://hive.apache.org/hive-shims</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="mailing-list">
          <url>http://mail-archives.apache.org/mod_mbox/www-announce/</url>
        </reference>
        <reference type="vcs">
          <url>http://svn.apache.org/viewvc/maven/pom/tags/apache-14/hive/hive-shims</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.hive.shims/hive-shims-common@2.3.10?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.hive.shims</group>
      <name>hive-shims-common</name>
      <version>2.3.10</version>
      <description>The Apache Software Foundation provides support for the Apache community of open-source software projects.
    The Apache projects are characterized by a collaborative, consensus based development process, an open and
    pragmatic software license, and a desire to create high quality software that leads the way in its field.
    We consider ourselves not simply a group of projects sharing a server, but rather a community of developers
    and users.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">2bfe73bb0a7d948631f3d2959764d935</hash>
        <hash alg="SHA-1">6c5b37c98532a449aed0316c740721d6be0f99dd</hash>
        <hash alg="SHA-256">03e7dbde1aec45904b04f46910cbbadee800d5d88403fa646bb67ca0557d93d1</hash>
        <hash alg="SHA-512">de2fdd8c785591fe64af2b6891033d62cdd3304c1e3cc35ec0d6606cd613c4fc9b13f1ea18cba08c507da93d65135f3cc7f40b4ecbc907b4d02c14d8eac003af</hash>
        <hash alg="SHA-384">8d9dce8e77595c8a04f57ec8675bf887ea688dedb704bb51394c0098a8acfb38352f3178c8d4aa9b0d753e5357463c0d</hash>
        <hash alg="SHA3-384">b28979866b6466be0c4da6d8e0e3662ff337a489febae00dbcd90b02178478e1b153e2e0b97c23cb2922f4130bc05ae3</hash>
        <hash alg="SHA3-256">8612f29b31c49f6385586b8ea26d0cb1ab051a748c90024c87172f8c27d207ea</hash>
        <hash alg="SHA3-512">c6c16ee2deee058efdca69d6d6584e882ee9495611333e77eeb30d6698133818d4a772d6a941f3988a3d3ca0dbdc7ab2e53740b8600cb7c99e82256580f3aff5</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.hive.shims/hive-shims-common@2.3.10?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://hive.apache.org/hive-shims-common</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="mailing-list">
          <url>http://mail-archives.apache.org/mod_mbox/www-announce/</url>
        </reference>
        <reference type="vcs">
          <url>http://svn.apache.org/viewvc/maven/pom/tags/apache-14/hive/hive-shims-common</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.hive.shims/hive-shims-0.23@2.3.10?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.hive.shims</group>
      <name>hive-shims-0.23</name>
      <version>2.3.10</version>
      <description>The Apache Software Foundation provides support for the Apache community of open-source software projects.
    The Apache projects are characterized by a collaborative, consensus based development process, an open and
    pragmatic software license, and a desire to create high quality software that leads the way in its field.
    We consider ourselves not simply a group of projects sharing a server, but rather a community of developers
    and users.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">de104b0eee2e15b11156e7bcbfe269f7</hash>
        <hash alg="SHA-1">501b46df8e2fc79db6990246346aa1d12a6039a8</hash>
        <hash alg="SHA-256">1eb002e63c6c165fa65b5b6b43d26fda5b8f04c3ac8e13d5a3625ba6bc79cd44</hash>
        <hash alg="SHA-512">61ab9330d203ba100cd87494ee8bc594e439892e252f02e3422b9c14dacc2d6fee2448c8b97ca3ffc02168b81134a727b41884c3bfacc8a2f7b1e19043db2a67</hash>
        <hash alg="SHA-384">5b0202758738316ae4c117f11318f9fad273feacf7321341dc8e76312663f62327ae91ca057f9f8988a8e8264fdede27</hash>
        <hash alg="SHA3-384">d47ea9d7ec0d22058c11aca4a64e3d1a7475293f5ac7215183c2b43f7a1048526e7a8d25fa3f257d807412d0ccf2539a</hash>
        <hash alg="SHA3-256">9b5a5c0a073054084764782c4961b168c109937632db2e797747c7c2e6023267</hash>
        <hash alg="SHA3-512">18481bdba8267eb6af3d131e9954cdc2ef18bb0bf3b69fd573192d44ead414c983a61095e4026df668cfc27164b7861de572ccea4eaffcf5827fcbbed84ef40d</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.hive.shims/hive-shims-0.23@2.3.10?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://hive.apache.org/hive-shims-0.23</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="mailing-list">
          <url>http://mail-archives.apache.org/mod_mbox/www-announce/</url>
        </reference>
        <reference type="vcs">
          <url>http://svn.apache.org/viewvc/maven/pom/tags/apache-14/hive/hive-shims-0.23</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.hive.shims/hive-shims-scheduler@2.3.10?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.hive.shims</group>
      <name>hive-shims-scheduler</name>
      <version>2.3.10</version>
      <description>The Apache Software Foundation provides support for the Apache community of open-source software projects.
    The Apache projects are characterized by a collaborative, consensus based development process, an open and
    pragmatic software license, and a desire to create high quality software that leads the way in its field.
    We consider ourselves not simply a group of projects sharing a server, but rather a community of developers
    and users.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">562afa9cb44dfbda371eb45dc7d49bb1</hash>
        <hash alg="SHA-1">029f0dd9c3505892a01280b409e9c1a22c796692</hash>
        <hash alg="SHA-256">cdb5f8866ae54b125fe88748cc7ffcd065de4603529b9ca1a756c8c550b2ade2</hash>
        <hash alg="SHA-512">ad01ae1e20ec94650b9c4855b8c82a9d9b1b27f6075ee6289ecdbcf9bd1e00ed26587749177d3e6215d1ca3743b095a60b9d4b91a7bc168114a462122194aef0</hash>
        <hash alg="SHA-384">e5f4e6abde5c676bf8e398bc5e0b48acec1a740dcdbf1fab66a691c9016aa517afd79ebca8d35031b38b2405d02594ff</hash>
        <hash alg="SHA3-384">7d3cb8fb407ace6b4cd25b8a692d6de9b9e2510b1fac9c8a0f883ef729ebd8f9963791df51b42282cadec35d6e4323e1</hash>
        <hash alg="SHA3-256">8e509fb369da3a6b49b27f89784406c8df4f79c758e5839f82312499851aadc2</hash>
        <hash alg="SHA3-512">1cf861d11867a682032677f4cfdd5ee7310847044c0593d2cb6cd7a6b8c10ce4d3ecbf3ab3d840a751bde798b10095f38bc65f08100eee8e55264485b2251d15</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.hive.shims/hive-shims-scheduler@2.3.10?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://hive.apache.org/hive-shims-scheduler</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="mailing-list">
          <url>http://mail-archives.apache.org/mod_mbox/www-announce/</url>
        </reference>
        <reference type="vcs">
          <url>http://svn.apache.org/viewvc/maven/pom/tags/apache-14/hive/hive-shims-scheduler</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.avro/avro@1.12.1?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.avro</group>
      <name>avro</name>
      <version>1.12.1</version>
      <description>Avro core components</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">83a5127156dbc59c024d8e76302161e7</hash>
        <hash alg="SHA-1">1c6294ac1d67ce396f51827c87ba2e01de304500</hash>
        <hash alg="SHA-256">72600f057bfbe2efe35fa55433e7756d45667dc938934be38a6e2be368aca237</hash>
        <hash alg="SHA-512">1d3ea16d6f374724728660f02fbbb20a42a6f380404cce092d3ab6c143e4e3b8ae9353040ba409af21b06e4a1a1456098020509bed6c12aa9ab6974d52ea8c5f</hash>
        <hash alg="SHA-384">fbe691d8500a239ba2a4370235f66fd4e53895489181258ecee2a45fa5dc5cfaf191b5973d702f96e17284f96562675c</hash>
        <hash alg="SHA3-384">2a945cd2245ee74ecba3760b2767abe6b105b4557cc3ab97298dcae75044cd2fa077705b48371ee9ba580c9112ff942c</hash>
        <hash alg="SHA3-256">1d2f7bbd2ed2e57097bbe760f4c392ea46de7870547170c43b12ddcfa731140b</hash>
        <hash alg="SHA3-512">c163eca320d4e66751b2e08bc06f1a659059c009e3f98074da2404d4e58994fbaf4ccadb14f3631bf6fdd270c711e4f320a7f83f519f6269afe89b1eb425adc4</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.avro/avro@1.12.1?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://avro.apache.org</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://issues.apache.org/jira/browse/AVRO</url>
        </reference>
        <reference type="mailing-list">
          <url>https://mail-archives.apache.org/mod_mbox/avro-dev/</url>
        </reference>
        <reference type="vcs">
          <url>scm:git:https://github.com/apache/avro/avro-parent/avro</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.2?type=jar">
      <publisher>FasterXML</publisher>
      <group>com.fasterxml.jackson.core</group>
      <name>jackson-core</name>
      <version>2.21.2</version>
      <description>Core Jackson processing abstractions (aka Streaming API), implementation for JSON</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">b62c1031b5f38fc58158fc0c559980cb</hash>
        <hash alg="SHA-1">7d11eac823392f28d8ee7bda77eaadfccbab83e5</hash>
        <hash alg="SHA-256">12e8655b100267b44d0f14d01b1f5082a5105e616174dc4307be1a761e92407b</hash>
        <hash alg="SHA-512">31a16a40b2e1a1a9467a66c93884c034527fb5af641a79bd6a563d4c3aaa0cfc8d8250f930d13c7fd70c18db579940ec54a49538c5a2e0fb9780c575808000ff</hash>
        <hash alg="SHA-384">cff72535be10b86fac89af4fd8eb0a7d89b0385712bff36cca6b94ad014acd9c2480bc3bc87b25b8621ccdf17cf8ae1f</hash>
        <hash alg="SHA3-384">1a7cd7206198350f0810989bc1448bb262099b14f3fc746d70651a3cf20a35948cc545326c07852dec25871605c862a3</hash>
        <hash alg="SHA3-256">7550f1f3812a13530bcb61db040d8b57415447395a62503dad6664e7dc62acc7</hash>
        <hash alg="SHA3-512">94e8097f45134c4e30e84cba9a4bd10dcec3e69ac3a9e289278be8f4005befe6efe33dec7bf4c349c3cd65928c8a1aaa0ffdfa689e60ca240393634eb384ed6e</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.2?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/FasterXML/jackson-core</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://central.sonatype.com/api/v1/publisher</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/FasterXML/jackson-core/issues</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/FasterXML/jackson-core</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.avro/avro-mapred@1.12.1?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.avro</group>
      <name>avro-mapred</name>
      <version>1.12.1</version>
      <description>An org.apache.hadoop.mapred compatible API for using Avro Serialization in Hadoop</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">b0c73d6865e55786bc12904b3aee64a9</hash>
        <hash alg="SHA-1">4b11d31fdc87f6240b573cb2a68fe6dead007650</hash>
        <hash alg="SHA-256">85a6526b599b29f75a6200dbfd504149eeb188a7d7a19476d61862e42e612dee</hash>
        <hash alg="SHA-512">809eb35239bd1b3a72680c04c303559124405e13101a9caf61bde6cad4f9faee380613595c2d48d91af01754c632f6c45819ab57f678c6f170f78b653abbd6ce</hash>
        <hash alg="SHA-384">57ab91db232826ac044501d58655fa9c4cf9fcb07b618db0c1448e6874de6ae19ab3a39484b71dfc80f827cccacf3380</hash>
        <hash alg="SHA3-384">3bb5469f675e995befcdddb6a8113603b9ade2cca2c99d6b0a6b2e017ea98dc32e3b7b074305b86c5c4af8353e0402be</hash>
        <hash alg="SHA3-256">70c45fe6934c1454513dd443f8269a95c19d089e5a0cca1d8b23900eaf59765f</hash>
        <hash alg="SHA3-512">b8f969d5672ac5954d50fe5644c6ce0620004d3b2e169a62672a5915c8d6cdc4081704e257906f334281fac944a4f7e5546002e634b2c9ff4019e6e51ff85148</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.avro/avro-mapred@1.12.1?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://avro.apache.org/avro-mapred</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://issues.apache.org/jira/browse/AVRO</url>
        </reference>
        <reference type="mailing-list">
          <url>https://mail-archives.apache.org/mod_mbox/avro-dev/</url>
        </reference>
        <reference type="vcs">
          <url>scm:git:https://github.com/apache/avro/avro-parent/avro-mapred</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.avro/avro-ipc@1.12.1?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.avro</group>
      <name>avro-ipc</name>
      <version>1.12.1</version>
      <description>Avro inter-process communication components</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">4e5307ba8b1b384046f39e3eac0ba730</hash>
        <hash alg="SHA-1">010891b0d5aca1bacfaea1486350439941a72e80</hash>
        <hash alg="SHA-256">9f8c1921f055238fe22da2f806b838fec2b375c3408c6c768ae1238f50e27624</hash>
        <hash alg="SHA-512">12e9bb213579d2c48e0638cbf50c22327667057780d0d205ab7378da7734cbeefadf866030e0766c76cb9b3b998a5f2557acc1ae268a039b16cd292ec1a12c65</hash>
        <hash alg="SHA-384">6bf51783290104e34580725112b7afd7fd80fc3202345cf7dc26c14c049336d9d2916c6708bed54045c468a2fab2e0e4</hash>
        <hash alg="SHA3-384">4ad9b0e2cc39b7462932a95994161fea66d36d0fbd448a6618dbc942b9b6298ea60d13382b942f7261c7ebbe7dbe20be</hash>
        <hash alg="SHA3-256">84380a55d3c231debfb92a325213841c330da458e262714c934a53bc8b6143c3</hash>
        <hash alg="SHA3-512">42cae39eb06e08aee4cff2633e93e9e90b903015225133578c87cec6782d2eb8a0f468822c3c0886165a5236a35738721dacfdbe4ce9581ad20594a49987c7b9</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.avro/avro-ipc@1.12.1?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://avro.apache.org</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://issues.apache.org/jira/browse/AVRO</url>
        </reference>
        <reference type="mailing-list">
          <url>https://mail-archives.apache.org/mod_mbox/avro-dev/</url>
        </reference>
        <reference type="vcs">
          <url>scm:git:https://github.com/apache/avro/avro-parent/avro-ipc</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.tukaani/xz@1.10?type=jar">
      <group>org.tukaani</group>
      <name>xz</name>
      <version>1.10</version>
      <description>XZ data compression</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">56e3fd256e5423a74393bd5eaa5302bb</hash>
        <hash alg="SHA-1">1be8166f89e035a56c6bfc67dbc423996fe577e2</hash>
        <hash alg="SHA-256">95c63c1a55b22dd6453890a419cc1a640f790bbf7d8ae82db1e30aefefb08888</hash>
        <hash alg="SHA-512">af234bb2a5d42b355ea020c5b687268f0336e393eae69a05251677151d1e85b1e34999d5a6be6451e0b047e3cf13341dc227a5483553766252b0ea66025a44f9</hash>
        <hash alg="SHA-384">b078b623faac3600d11bf905fd3e800439b101bf11096834305c04e015aae0096765bbd20e61bacae83eadd7e3a9e2af</hash>
        <hash alg="SHA3-384">c51f9a76a9d9972526c8acf1d0e3eebe77557ea00aba2296bf4eee2cd47e11c98fcec5343c2507c83dc2e2ff6c73a40f</hash>
        <hash alg="SHA3-256">e211a91b89c5198152dd602caf00f3433462004859e885d5dfb4f00ca6b2633e</hash>
        <hash alg="SHA3-512">baa9fff0a0c0e1409bc2b5cf1b024397aef8a189a11b648bc0d4eea0b4827a30a78865b2db7ad99b0143e370de2a854efc3b95ca61fa770ab46c12e68aff2754</hash>
      </hashes>
      <licenses>
        <license>
          <id>0BSD</id>
          <url>http://landley.net/toybox/license.html</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.tukaani/xz@1.10?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://tukaani.org/xz/java.html</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/tukaani-project/xz-java</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.httpcomponents/httpclient@4.5.14?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.httpcomponents</group>
      <name>httpclient</name>
      <version>4.5.14</version>
      <description>Apache HttpComponents Client</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">2cb357c4b763f47e58af6cad47df6ba3</hash>
        <hash alg="SHA-1">1194890e6f56ec29177673f2f12d0b8e627dec98</hash>
        <hash alg="SHA-256">c8bc7e1c51a6d4ce72f40d2ebbabf1c4b68bfe76e732104b04381b493478e9d6</hash>
        <hash alg="SHA-512">a084ef30fb0a2a25397d8fab439fe68f67e294bf53153e2e1355b8df92886d40fe6abe35dc84f014245f7158e92641bcbd98019b4fbbd9e5a0db495b160b4ced</hash>
        <hash alg="SHA-384">c8ccaa1fa8ba7c421413e3c30375bd9c31284e837c476fd831e18043ad4187e92166f49554123108891241bed674b95d</hash>
        <hash alg="SHA3-384">9a17dfcf12b2af3a9b006ec369f9bc78ba322348bf1a01146e0d4f3fec2bed6cbe8b2193fac5b4d5a0c3036c06477510</hash>
        <hash alg="SHA3-256">48f0a61b691e22dec9d6db8e0b58be4ca17a42a2846c82f0875de21f72bb0faa</hash>
        <hash alg="SHA3-512">4ad2c9adc761b7e813330f0dcad3f9978702896c7d0cbf81f60a472d550e320b1527be425ba597c8c9352d587e32e1d46ceb4c73e99c70a6190df4c699a7c2a9</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.httpcomponents/httpclient@4.5.14?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://hc.apache.org/httpcomponents-client-ga</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>http://issues.apache.org/jira/browse/HTTPCLIENT</url>
        </reference>
        <reference type="mailing-list">
          <url>http://mail-archives.apache.org/mod_mbox/hc-httpclient-users/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/apache/httpcomponents-client/tree/4.5.14/httpclient</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/commons-codec/commons-codec@1.19.0?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>commons-codec</group>
      <name>commons-codec</name>
      <version>1.19.0</version>
      <description>The Apache Commons Codec component contains encoders and decoders for
     formats such as Base16, Base32, Base64, digest, and Hexadecimal. In addition to these
     widely used encoders and decoders, the codec package also maintains a
     collection of phonetic encoding utilities.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">e46fa78c69544eb6239c4e8447e72544</hash>
        <hash alg="SHA-1">8c0dbe3ae883fceda9b50a6c76e745e548073388</hash>
        <hash alg="SHA-256">5c3881e4f556855e9c532927ee0c9dfde94cc66760d5805c031a59887070af5f</hash>
        <hash alg="SHA-512">d98a7a1cfcc08aa9cce4f7778e3f37ecb99da7b1da01944e5fa8faf06fbf9f969f2efb0b416832f419d53085250f711c071f1dac9fa0968483c37034198367fb</hash>
        <hash alg="SHA-384">f0edec3cd84b2320e6930380d3fe13335d33f041470d27fb93789db0c696ec01dda21b471f0015bf70bffffcbfdb67c0</hash>
        <hash alg="SHA3-384">ce771ef9f0df326a34ab37e70f710801bb18d545aca0ee492db62770db323ab8a0b5082123ca4826f3d3182748537cfc</hash>
        <hash alg="SHA3-256">8296db95bb2fac86a0eb68e61e9730084f4272ad6a4a4327a5259c631840e98e</hash>
        <hash alg="SHA3-512">05da2f8674a257c5d8a1137cadbda71d2635f22237450bf2cbc980380a56905247bea38049c8cd80e60077be2be73b1eae6b466c228e4277763a54979cf856fb</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/commons-codec/commons-codec@1.19.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://commons.apache.org/proper/commons-codec/</url>
        </reference>
        <reference type="build-system">
          <url>https://github.com/apache/commons-cli/actions</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://issues.apache.org/jira/browse/CODEC</url>
        </reference>
        <reference type="mailing-list">
          <url>https://mail-archives.apache.org/mod_mbox/commons-user/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/apache/commons-codec</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/joda-time/joda-time@2.14.0?type=jar">
      <publisher>Joda.org</publisher>
      <group>joda-time</group>
      <name>joda-time</name>
      <version>2.14.0</version>
      <description>Date and time library to replace JDK date handling</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">ce5d368699f16abb55616b6b9fcb34dd</hash>
        <hash alg="SHA-1">1fa665c1ce64a2c8c94f63fc5c1ee7bd742d2022</hash>
        <hash alg="SHA-256">1e2da6f9eb65f20a25d9a3186831ed2b3fb14f7a48e1ef8206135ee58cb143d3</hash>
        <hash alg="SHA-512">af0a707cb15a273d0169908d518b0bebc5f79aa07a442d9a77b117feaab2916b3729862642d2b465a3ec569540304a622758aac566c0af84123f151d4ebf1f5a</hash>
        <hash alg="SHA-384">2aba3754964f4d470bf3f7188aebc7ddda98f8981f46c5989f1bc3007ceed3a5ce008f5b50450d11e67b1c7bb4eba5b2</hash>
        <hash alg="SHA3-384">c9f59bda7a238f67401d525d0be6db455d4539bcb5d793319d4161c9aded59cd9851bf03977eb21d13b9a120805b9966</hash>
        <hash alg="SHA3-256">cc6863e7c8b47dda46731053f8df85387dd961b4f690c6212a910d6e07962324</hash>
        <hash alg="SHA3-512">59bea4e54b6a967f35a22b26584db889aa5f23a649270ac0cd7af4b713ebe9e68a55d92c27cc64a196ba76bd493eacb280d8bfe7951a32fd3a3cfce534eba8aa</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/joda-time/joda-time@2.14.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://www.joda.org/joda-time/</url>
        </reference>
        <reference type="distribution">
          <url>https://oss.sonatype.org/content/repositories/joda-releases</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/JodaOrg/joda-time/issues/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/JodaOrg/joda-time</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/com.google.code.findbugs/jsr305@3.0.0?type=jar">
      <group>com.google.code.findbugs</group>
      <name>jsr305</name>
      <version>3.0.0</version>
      <description>JSR305 Annotations for Findbugs</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">195d5db8981fbec5fa18d5df9fad95ed</hash>
        <hash alg="SHA-1">5871fb60dc68d67da54a663c3fd636a10a532948</hash>
        <hash alg="SHA-256">bec0b24dcb23f9670172724826584802b80ae6cbdaba03bdebdef9327b962f6a</hash>
        <hash alg="SHA-512">399510f759fb48255c6298f3545c9b644372fbc9d7245e80e6b51f49da0ac9275d104092c537ac047d5a1312c7d191dee8d655ca8d760b59ce1452bf4370a6e0</hash>
        <hash alg="SHA-384">a7fa7a0b69f41518fdb70e847148e17d0909fb657cee127308fb6cd14f913c63c82608aeae3955f10b48d358a8addfee</hash>
        <hash alg="SHA3-384">e55c3626a26119f465822e95c33266304bd87755e5e5865833dc10f4e2c1105c6c3ddc9efd889b1e43b346663627745b</hash>
        <hash alg="SHA3-256">dbd709e4edb2fe0ebd9b0d993e35f9fbf8bdb21cce13139bc6986c829c03aed6</hash>
        <hash alg="SHA3-512">a7cd693c969c8f9f6417030e987a4dda020c6a35d2b4174935baacf91619fc239fdf15a0af9a64d05855c872600c9744ee2755ad705b6d59fe099deea1e439bd</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/com.google.code.findbugs/jsr305@3.0.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://findbugs.sourceforge.net/</url>
        </reference>
        <reference type="vcs">
          <url>https://code.google.com/p/findbugs/</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.datanucleus/datanucleus-core@4.1.17?type=jar">
      <group>org.datanucleus</group>
      <name>datanucleus-core</name>
      <version>4.1.17</version>
      <description>DataNucleus Core provides the primary components of a heterogenous Java persistence solution. 
        It supports persistence API's being layered on top of the core functionality.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">56845c7af1890cde68d67c39f2d0e1d3</hash>
        <hash alg="SHA-1">c03898d49b506b60849fe1db39d04ab27fa15422</hash>
        <hash alg="SHA-256">adb64b5ec1837821e289fc82b04c13f6b5a2f1c68a24628bcec6a7c43b5f5bca</hash>
        <hash alg="SHA-512">b9b8bb43cdc876432793a85f50c0711661dc6aae563e18d4fd15be3495c3cec64f50d1c779ddd6cb46b6adbacdf8e2c51b322022146dcfcfdb1cfec45187ba93</hash>
        <hash alg="SHA-384">4341bf82943ead7348c5e6ff18c66f388418ecc52b857a6374a07a1f684deebd24538035af98086a525e7bedd09fe8c7</hash>
        <hash alg="SHA3-384">ce87ea04fe78e26e73d6fff8c5d69474f4a59cba7d99963472705b285d81c7aa80ac45c7c32e9806b4796f24da2ad9d1</hash>
        <hash alg="SHA3-256">2893ee7c991decf052fb5045c8a4da32d7a3caa7cadcbd64189e03bfa9a4421c</hash>
        <hash alg="SHA3-512">aa5dd716ca769a7311f29b4cb12b0a22faf170c732c86bc91d58205c567c2edd3a4137b00bb5f886feb458c05e9ab341c2e577908d524364815c7ae19ec19b29</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.datanucleus/datanucleus-core@4.1.17?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://www.datanucleus.org/#/datanucleus-core</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/datanucleus/datanucleus-core</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.hadoop/hadoop-client-runtime@3.4.2?type=jar">
      <publisher>Apache Software Foundation</publisher>
      <group>org.apache.hadoop</group>
      <name>hadoop-client-runtime</name>
      <version>3.4.2</version>
      <description>Apache Hadoop Client</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">c33df39ac18480f6efb9ba2646ad3f4f</hash>
        <hash alg="SHA-1">3e9508f154ac9f085f3f0400c696175dce771d2d</hash>
        <hash alg="SHA-256">18d071c7f72f8a946677b398a57af9c7afa2dd41a81023c310f99373fec200b3</hash>
        <hash alg="SHA-512">60b148db4e051a6c3841ae727f1d50b8db80526ad91d62c0352613d9dcb514dc84cc3733e030e8672563cfec4952ae3462eef33000fb8b37f3c047ecba8e93a1</hash>
        <hash alg="SHA-384">1eea7af9a0eb9a88e155005abae4ad8e53a3485b010a8f4969af4018e8ef7b6941d17d5821007e89682192cbeeb81b49</hash>
        <hash alg="SHA3-384">b3906796e68559410d9a5c8651cb8d7c3e67e82bf2b336360441ae588e1f70ad3773833a1c144c62eddb77b4a2779e30</hash>
        <hash alg="SHA3-256">6d2b14f6d862b529219d36d68018853be768de231efc9b3b0050102bbcacc012</hash>
        <hash alg="SHA3-512">4d4d34125b5f4b43853322cc142750e9e6893e9f710ffdea81fbc03d24290a91b888708cec2de5a67c50f330986b07cebc74808ecfa76f29e63ebf7444dae7b6</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.hadoop/hadoop-client-runtime@3.4.2?type=jar</purl>
      <externalReferences>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.thrift/libthrift@0.16.0?type=jar">
      <group>org.apache.thrift</group>
      <name>libthrift</name>
      <version>0.16.0</version>
      <description>Thrift is a software framework for scalable cross-language services development.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">19226bcfae19557ec080e098f87a1340</hash>
        <hash alg="SHA-1">995b1788bf9d954a77a24db5619a065ed1a455e9</hash>
        <hash alg="SHA-256">b311ad08f7dc5ba90139910ec8619460914a4a2952f738603f1d7803ffdbe0a8</hash>
        <hash alg="SHA-512">25e69530ea2883d39c7bbcd01f374d679eec9d7a05007fa5304802f38089f7910e027c608166fe576057a77759f39f669759abf3089b8940296c502974c43e30</hash>
        <hash alg="SHA-384">e3061ff167d812f2bcb36d585c57fe0ff320e397fa40229ce7185b4f5eb2204ba2b53f65297da4bdfdacc2f5f7e05ffc</hash>
        <hash alg="SHA3-384">97176f98c4c564655dc23adaed7adf530957d11db3b4d0d51e7cbc9b2a449d49e8982630be1160bdc50ce49bc60e25ee</hash>
        <hash alg="SHA3-256">e3f9cf17b93543b625fb66f77aba86e61ff03549336315bd0db8a62651f65a9d</hash>
        <hash alg="SHA3-512">68cc31068454f6024cb60a3c36a4e36f10f47a25ab6d3ff79968c027a4fb2f9946399e9d4b00c89a113ce5a7ac7aefb673732bf85018228e240157df866e868b</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.thrift/libthrift@0.16.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://thrift.apache.org</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/apache/thrift</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.thrift/libfb303@0.9.3?type=jar">
      <group>org.apache.thrift</group>
      <name>libfb303</name>
      <version>0.9.3</version>
      <description>Thrift is a software framework for scalable cross-language services development.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">5e1c646346ecf2750a1b8b6cb2aa1c4f</hash>
        <hash alg="SHA-1">5d1abb695642e88558f4e7e0d32aa1925a1fd0b7</hash>
        <hash alg="SHA-256">23fc397a42181b17bb7d0fada2213735ed8db38cfbf038d12b9c00ea7419e11b</hash>
        <hash alg="SHA-512">e30ddf2b4651d08bfcf980f98263fa95cc0a37fb722a2972811c9f9437dbfba4ab20d81e142a991501a3c5409e2651c43b936321f85f1e5e9ab5ad55ca3d6a82</hash>
        <hash alg="SHA-384">f8650670a386fb6234e7ec70a8cbc12d257506359997e1b14de6833d94364ce003f7113606bfa88840586e9153b8e524</hash>
        <hash alg="SHA3-384">9f5725bbadfb5f9e9bf75c0c82ef29e9012cb51374515cbf93dd685f2d036218fd14cde5a2cf60d174484743be416c60</hash>
        <hash alg="SHA3-256">dc019eb62ac43f097f74e9cf7bfc6b14e63cc204ffd6c785d34898b0aef265ca</hash>
        <hash alg="SHA3-512">107ad6197a7802ecc98b4929faffd1e8e00944bf2a08dc98afb4c25742c37c6bd26f76e4d3cf0cce44b71bafdc02d1353409170809136ac94ce728cb9315ad61</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.thrift/libfb303@0.9.3?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://thrift.apache.org</url>
        </reference>
        <reference type="vcs">
          <url>https://git-wip-us.apache.org/repos/asf?p=thrift.git</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.derby/derby@10.16.1.1?type=jar">
      <publisher>Apache Software Foundation</publisher>
      <group>org.apache.derby</group>
      <name>derby</name>
      <version>10.16.1.1</version>
      <description>Contains the core Apache Derby database engine, which also includes the embedded JDBC driver.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">d9c38ece80f4ec0756f54b06716a3dd6</hash>
        <hash alg="SHA-1">f9ca2054b3e33ec3f3f19df4a7490352d82de54a</hash>
        <hash alg="SHA-256">ede804cb04e871d7c52d2414e952ab939f9ef243abb7bd0ce7dbeb6e1e28bd0b</hash>
        <hash alg="SHA-512">2e645944b029d7acaf26afd1d490ef6b599206062ec36a2a052e84b591bf84738145ace70bd1371642273659b61a6b17fb40ea64a516db70580c56ff7abd837a</hash>
        <hash alg="SHA-384">63c8a9d6da604f1abff1bcf47bc926907bbf42c71f9318791c0b05897cd3397a624e4d445f049d0d0868c20aef6fd469</hash>
        <hash alg="SHA3-384">89fe693d57b5e9069b7f4fc090d37ac12d740559edbc57e702bab1ef2f14ffdb6345c7a2c8e79fe4470f5e85aed67c9a</hash>
        <hash alg="SHA3-256">1ad1c2cfb09004e76b11da0a32519e5104f99c7bd6b959ae1b8d8a9dc1dfd777</hash>
        <hash alg="SHA3-512">82d0e7ffebf6777fb9cf4ceffa151454c51281b7fb22dc4291711ff37d7784fb110b0e0bfb304ab45773a569a9901902bdefe678b5ce7d5ee7a7d538d0d32693</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.derby/derby@10.16.1.1?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://db.apache.org/derby/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://issues.apache.org/jira/browse/DERBY</url>
        </reference>
        <reference type="mailing-list">
          <url>http://mail-archives.apache.org/mod_mbox/db-derby-user/</url>
        </reference>
        <reference type="vcs">
          <url>http://svn.apache.org/viewcvs.cgi/db/derby/code/trunk/?root=Apache-SVN/derby</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.derby/derbyshared@10.16.1.1?type=jar">
      <publisher>Apache Software Foundation</publisher>
      <group>org.apache.derby</group>
      <name>derbyshared</name>
      <version>10.16.1.1</version>
      <description>The code which is shared across all Derby configurations.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">e423cba3150f195debaf7ff0d307ecf6</hash>
        <hash alg="SHA-1">77a3ec6b9791c7c29c76148c5d56fc1f3f12d638</hash>
        <hash alg="SHA-256">27d4be683a45f6c15940167277ce39bb7e26b9f6dc0bc05efbcf813cac5d2b8f</hash>
        <hash alg="SHA-512">df8f739037bdead36c80a3f8129b26bd24c4b45a7cda2cd440edbbb66d5f53a93fe4c9dd088a54feb9c0e6b1924e3609984869bc432cb869bdc858616cf5d678</hash>
        <hash alg="SHA-384">1d8a7a49943936cfcf8a6b222a16923fd1ae27110bc602beb5e7f6ddb07e41d7a9b76b39354eb873b95692d248d806f4</hash>
        <hash alg="SHA3-384">111190ba9f80a0f8f82a23fe25de2b5efe283be990d47e36df941eee65fd00a5d10556e00d77351f9c98312a6027251a</hash>
        <hash alg="SHA3-256">89cd89bfa88773a0fcf0f94d8ffd06aaf20d2fa93c420d058e899f4744cfa0c6</hash>
        <hash alg="SHA3-512">46d308b54695fe40b4b372dc5648255884aa7e411042a907c06fd4dbfe8ae6e75cd9642071a1e92e9fb8410c5fe4092fde4229b2325e953ce27f6bd97addef51</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.derby/derbyshared@10.16.1.1?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://db.apache.org/derby/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://issues.apache.org/jira/browse/DERBY</url>
        </reference>
        <reference type="mailing-list">
          <url>http://mail-archives.apache.org/mod_mbox/db-derby-user/</url>
        </reference>
        <reference type="vcs">
          <url>http://svn.apache.org/viewcvs.cgi/db/derby/code/trunk/?root=Apache-SVN/derbyshared</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.derby/derbytools@10.16.1.1?type=jar">
      <publisher>Apache Software Foundation</publisher>
      <group>org.apache.derby</group>
      <name>derbytools</name>
      <version>10.16.1.1</version>
      <description>Contains Apache Derby tools like ij, sysinfo, and dblook.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">25b138905deb681ff167a5a04d29c3c6</hash>
        <hash alg="SHA-1">32a5335f9087022cd8ca5c85f35f8c844b1360a9</hash>
        <hash alg="SHA-256">db052f92508e966ee8b0c5c9eca84cb11cbf0b0d78e608dc89340d4bb6c07314</hash>
        <hash alg="SHA-512">f1dc4aac64cd31c20d09f62aa81920216a15850d344126d57683bc4dd498396d74d5ceacf0838c4a4a5e52988fa25e1dd345810c91ddaf065f217cbffa35ceee</hash>
        <hash alg="SHA-384">00158eb14cf22d675fcf6cc82585a6f62a08b671ec7f83cba503e1e59d15719fdfc6024369e37930cc18b9b4ac5f0efe</hash>
        <hash alg="SHA3-384">00341133c17a2af1fd6ba5343b37bf6da718732c5de770c93307458483d3fa16581cc46831ccc451cdcea737508a1e90</hash>
        <hash alg="SHA3-256">e31dd4eb55d91673d1089ea0db4b2d68378a2858655f6a2f205fdbc667ff3e9e</hash>
        <hash alg="SHA3-512">384d8364389505b9830cb37a5c312ba02e6d5bb9070df0fc58a01ce6a3bd4ff3d084756f56590a8ef4d65eb044f4cde2ce07d28d63e3d4c35783e60580ffa08e</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.derby/derbytools@10.16.1.1?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://db.apache.org/derby/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://issues.apache.org/jira/browse/DERBY</url>
        </reference>
        <reference type="mailing-list">
          <url>http://mail-archives.apache.org/mod_mbox/db-derby-user/</url>
        </reference>
        <reference type="vcs">
          <url>http://svn.apache.org/viewcvs.cgi/db/derby/code/trunk/?root=Apache-SVN/derbytools</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/com.twitter/chill_2.13@0.10.0?type=jar">
      <publisher>com.twitter</publisher>
      <group>com.twitter</group>
      <name>chill_2.13</name>
      <version>0.10.0</version>
      <description>chill</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">a18d9c6269d2c7259ae324fef89c9ca2</hash>
        <hash alg="SHA-1">764f2844ce1c7033869e069dc7cfe3f9682d175f</hash>
        <hash alg="SHA-256">b6507cab344bf8a86bf8bd3987cef15a35c096570eb31893f760d4754de4d8b1</hash>
        <hash alg="SHA-512">4268042407f091073cdf3930187cedcf89436ebe8efd2bb9c0c12115bd4cd79cd28bef875b3196cc52a27f091a7faec0e5585eac364914bd7935c0bd28785bda</hash>
        <hash alg="SHA-384">7e8bc767010f8ca60e1c031a403127bd109078d73e8672957d63c250071b46d5f9d7f40a3476c002de7cdf7014609bce</hash>
        <hash alg="SHA3-384">ae6b434c8ef981afcc0ad9e37b9c414d861c51bd327b2b9a5859917899bc2862c0b14a9269ed6cbbcb37d903382ded24</hash>
        <hash alg="SHA3-256">cbb9400ddbd0538522a5770f6c0845462d028773674b803d1263dca322d4ebaa</hash>
        <hash alg="SHA3-512">3b2a84843bb55777dc3c94e586d5a2550ab1dab1b8d0b2d37a38d8e84c0fc1732271f7bc6126a14d99da130b9f4f95719419d475e887b66056ff8117e9cf59cd</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/com.twitter/chill_2.13@0.10.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/twitter/chill</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/twitter/chill</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/com.twitter/chill-java@0.10.0?type=jar">
      <publisher>com.twitter</publisher>
      <group>com.twitter</group>
      <name>chill-java</name>
      <version>0.10.0</version>
      <description>chill-java</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">3c0e9cbbb2016364333f2cea3922ae97</hash>
        <hash alg="SHA-1">0fd2eb52afd9ab4337c9e51823f41ad8916e6976</hash>
        <hash alg="SHA-256">52afd3c1256d6f89293ba616c0c9ebf11191bb9e8159cd0c1cfdc99e5e0c5ffe</hash>
        <hash alg="SHA-512">48ae455095f0a9ff7ed9b84c9b9bf339c14f6599703b7a34a473ea9c457b0ae700f793d6bf00d1af5e0eb307c9a68d2a10309faea77aaf2245afded08420cb8d</hash>
        <hash alg="SHA-384">7641e1570bd40b064e17c98c656b8b80680b36d2678973c53ea0557fb212d9ce535eda748cb7234813d953ef90e2cb8d</hash>
        <hash alg="SHA3-384">faf3cd7194a5ac06f9890d5a0cedd4645195dfa8de96d79245aeae7638915ce22495abb39ca82af6f604600fe15b2869</hash>
        <hash alg="SHA3-256">486eb481050b3da17ec5b3cf51c8c5cbcf8a972b27261dd34693977644873dae</hash>
        <hash alg="SHA3-512">2d4e782d6a2db53be3e36c9c5861b46a23320c15149d3ba2907575ae3de7372324e56fba30143d0c86f0132b49bedc5290704266b172a08d8747ab27346bcde9</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/com.twitter/chill-java@0.10.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/twitter/chill</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/twitter/chill</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/com.esotericsoftware/kryo-shaded@4.0.3?type=jar">
      <group>com.esotericsoftware</group>
      <name>kryo-shaded</name>
      <version>4.0.3</version>
      <description>Fast, efficient Java serialization. This contains the shaded reflectasm jar to prevent conflicts with other versions of asm.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">cffa6fce5594dd99374882abd33890e9</hash>
        <hash alg="SHA-1">8fa9a4ad14fae2217b2f1efd51cb35dde2ee4e06</hash>
        <hash alg="SHA-256">cb32b28ba586a96260d7d5016ffe7a2132c300644ddb68d78545ff31849c367d</hash>
        <hash alg="SHA-512">dc2357a7a6d91b7601deb553c24aa5e60e2d2802a9baf08e9eee2b5c1f7947f8d3a613efd54de7011f9ece55aa24d7a845942afa9002f8fa759b25e97c30e6a3</hash>
        <hash alg="SHA-384">5078519b214b387230addf3e8c63affe91e35eba1d54cdffe9048edaa65de885dd424951e022f24b0bb3c533fb5908dc</hash>
        <hash alg="SHA3-384">0db794168fa3f5567cb9262eebf0b699ab1f3b64fca0bf17946d8a5ffef0ed1ecdac9ffedb608ca24edf0ea4edc01085</hash>
        <hash alg="SHA3-256">9996c0dd2bb57010c60570009a6c91c503601c827df51a1efadcb3a4e3db1aef</hash>
        <hash alg="SHA3-512">d3e14f8f4661f12607b413321c5cd996f561a84545b41b569876dec63deff63f83261164ba2fb3a965579a4da82bc3dd4403e9974136ae3e798ec640605e1a7f</hash>
      </hashes>
      <licenses>
        <license>
          <id>BSD-3-Clause</id>
        </license>
      </licenses>
      <purl>pkg:maven/com.esotericsoftware/kryo-shaded@4.0.3?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/EsotericSoftware/kryo/kryo-shaded</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/EsotericSoftware/kryo/kryo-shaded</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/com.esotericsoftware/minlog@1.3.0?type=jar">
      <group>com.esotericsoftware</group>
      <name>minlog</name>
      <version>1.3.0</version>
      <description>Minimal overhead Java logging</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">5ab0ee168b90e0ad7010b159e603d304</hash>
        <hash alg="SHA-1">ff07b5f1b01d2f92bb00a337f9a94873712f0827</hash>
        <hash alg="SHA-256">f7b399d3a5478a4f3e0d98bd1c9f47766119c66414bc33aa0f6cde0066f24cc2</hash>
        <hash alg="SHA-512">ca319c94b7fd8a275dcc3c5102fc01d73071ac77f5e14b4fc5b6547f96574a4fff0e8cb7b0b0d5006e71faa00575a91defdbfc92a94d9d38dd65520d4ab52000</hash>
        <hash alg="SHA-384">3f9b5b7fd91332ad64d235024d486e24b00760e714713153a61f10e6867bc3e5b617a7bf0bed889a01f0cdb435415d6a</hash>
        <hash alg="SHA3-384">53f87e7d1c0615c0d443cf8f1dc2d83cbe8c72ba18061a68ec4d8dea8020a21aed04fec338e7eb2d566acac1f7f267b0</hash>
        <hash alg="SHA3-256">5eb8dd240a7196fc28a6c312148513f6c3d4af48abb46e1744bd730f479b0dd0</hash>
        <hash alg="SHA3-512">7573361d0b824f2db4fc9d06aab133021a2e07b5f32be296781eb105b3f6002314520fea1f2c856d0e4a0522ea5ff6a5cb046f1a832f2d772999cd17e36d7bd4</hash>
      </hashes>
      <licenses>
        <license>
          <id>BSD-3-Clause</id>
        </license>
      </licenses>
      <purl>pkg:maven/com.esotericsoftware/minlog@1.3.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/EsotericSoftware/minlog</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/EsotericSoftware/minlog</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.objenesis/objenesis@3.4?type=jar">
      <publisher>Joe Walnes, Henri Tremblay, Leonardo Mesquita</publisher>
      <group>org.objenesis</group>
      <name>objenesis</name>
      <version>3.4</version>
      <description>A library for instantiating Java objects</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">51242320cb2bb25a3f36e2e21fa87de0</hash>
        <hash alg="SHA-1">675cbe121a68019235d27f6c34b4f0ac30e07418</hash>
        <hash alg="SHA-256">95488102feaf2e2858adf6b299353677dac6c15294006f8ed1c5556f8e3cd251</hash>
        <hash alg="SHA-512">951a01075a5462cc989b8d8fb1b7089848eb825ee4e563bab139f121f5f515fbb5cf2ac607a5528cbd3929e610910113346956a4448fa39bf41fd8147e5eac6f</hash>
        <hash alg="SHA-384">8865ca08b684b72d9dcb620f01974022d864e8e5e0e4b469287bf4720536ee51735f29c7f05da563c967e1e2f1c52589</hash>
        <hash alg="SHA3-384">730526cb3490fdb1770264395afdc3782fd3397617582dde8bc2807512672f624e2f5b2206d9f615524b92ccdfba191a</hash>
        <hash alg="SHA3-256">f22667e2f7f0f86b48015d3995e3edbec9e81929c6860e9af1063c629a114ae2</hash>
        <hash alg="SHA3-512">465202eb4e341003b66a38a36d676656d17adf66267dc87cfbc6bcd6ee6fd3914423160e01c38d3f505c7f358674dd9e9f08dd7df73196f04e56cae01d4fe91e</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.objenesis/objenesis@3.4?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://objenesis.org/objenesis</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/easymock/objenesis/objenesis</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.hadoop/hadoop-client-api@3.4.2?type=jar">
      <publisher>Apache Software Foundation</publisher>
      <group>org.apache.hadoop</group>
      <name>hadoop-client-api</name>
      <version>3.4.2</version>
      <description>Apache Hadoop Client</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">395d85c50b012df5837e047a5b036a3b</hash>
        <hash alg="SHA-1">d49afafdccb52bddde866ea0f341e6b31edc97fe</hash>
        <hash alg="SHA-256">607c0299f4df33013bd0a0f37c8cf255c635bbaddd247b8fec68c210cc17d19f</hash>
        <hash alg="SHA-512">7d99150a74eac17fe0b868ef67a13d3b75d117cb00d5f4905b161805af31279a81780db195cb514d33972087bf89ee21ab076446401000637eeeb9afb5e153a4</hash>
        <hash alg="SHA-384">921a9c9ed929d94e527d8f9c790bde840b017fa89d65407fbdb6c02388aaff23111f0e8732d2446c63bbeb2a3c7c144d</hash>
        <hash alg="SHA3-384">8a2ca3901d839e86405f239e7e12f605d5a9ae8cf72e4f899b636d70d563dc9abccacedee413d92e63ea3e07d455844f</hash>
        <hash alg="SHA3-256">0ecc50e182f35be95138d9e47c431b40b93dcc721010dae740aa26fb51c4ca95</hash>
        <hash alg="SHA3-512">7d5af9d89d98e194df49466a9ddf100ee2199cbadaf1ce85e529ba870a2295651e2c192b125c80306a751af88454d82c619def3ce9b109838666fe74025193db</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.hadoop/hadoop-client-api@3.4.2?type=jar</purl>
      <externalReferences>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.spark/spark-launcher_2.13@4.1.2?type=jar">
      <publisher>Apache Software Foundation</publisher>
      <group>org.apache.spark</group>
      <name>spark-launcher_2.13</name>
      <version>4.1.2</version>
      <description>The Apache Software Foundation provides support for the Apache community of open-source software projects.
    The Apache projects are characterized by a collaborative, consensus based development process, an open and
    pragmatic software license, and a desire to create high quality software that leads the way in its field.
    We consider ourselves not simply a group of projects sharing a server, but rather a community of developers
    and users.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">b6c6afebd60ec0a3ff515913e7949253</hash>
        <hash alg="SHA-1">aee08e8565c087b36cd13ec3f4b52b65c510b024</hash>
        <hash alg="SHA-256">ba2225b8c045a3f1feb3e74acdcbc2a999de8279d3cefb2b5963c67d92d11de5</hash>
        <hash alg="SHA-512">92601340fc88668fd69d2e2493fb456f575702c937f7d0f15bfabbbf599c14ea89fec968ed41fd5cae6119ac4a3e1584285ce764b480745e5fdb2983f55be153</hash>
        <hash alg="SHA-384">17c329fcc5c00c254960760b611ba503ad58cd315a40268596875e8a00eed64e285067e7abcb0558c308868644d85435</hash>
        <hash alg="SHA3-384">23790b818dd3078b9ce5a629547d1376ef914beb49f32300519efe48daf20f78cc018b6c356efb3a17b5a8e247b43dbd</hash>
        <hash alg="SHA3-256">acd284508d25afd3e8fae7b69e5ffe94b82adbedfd7dfec994f0bc8d3483a6a8</hash>
        <hash alg="SHA3-512">6ce87c4cfc4d3d7b2f737b855a2e5b02f2941e15383efff11354f0c5e483a6a7a1faeb163cdfd02f277449ec0fa477c8bcd24c7c4703aca77c4def70f230f5c7</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.spark/spark-launcher_2.13@4.1.2?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://spark.apache.org/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://issues.apache.org/jira/browse/SPARK</url>
        </reference>
        <reference type="mailing-list">
          <url>dev-subscribe@spark.apache.org</url>
        </reference>
        <reference type="vcs">
          <url>scm:git:git@github.com:apache/spark.git/spark-launcher_2.13</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.spark/spark-kvstore_2.13@4.1.2?type=jar">
      <publisher>Apache Software Foundation</publisher>
      <group>org.apache.spark</group>
      <name>spark-kvstore_2.13</name>
      <version>4.1.2</version>
      <description>The Apache Software Foundation provides support for the Apache community of open-source software projects.
    The Apache projects are characterized by a collaborative, consensus based development process, an open and
    pragmatic software license, and a desire to create high quality software that leads the way in its field.
    We consider ourselves not simply a group of projects sharing a server, but rather a community of developers
    and users.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">4df86d6245549dc32ec42d8e7502833c</hash>
        <hash alg="SHA-1">72dc81d5c1388281aab7e40c176d29fd4442af45</hash>
        <hash alg="SHA-256">eed551ba425dcda9fd57306cbcc0807300e8a9ab3c4345845521b0e5dc2b9cda</hash>
        <hash alg="SHA-512">6c13f51f0f663a5fb92ad639b062fed9608d995483e31d8575046258e495732b0d8bce4f53cb43e081fb75263574d65447aef126d282fdf9957d8f2a47de03b9</hash>
        <hash alg="SHA-384">264e1662234798019379d6691f31c2877dfa2d8c5a0d48f278d8baaafd2a3f272e4253adfc63c828e7db72c03ac943d5</hash>
        <hash alg="SHA3-384">f1342eff9c09f903d7c56a6b083506056e583cd3b54354d4d65d6bab32303126088ce472efd04c4fccf42779ca638d0c</hash>
        <hash alg="SHA3-256">413e6365fe780824c9c4e80f5d857c1f1371f1e2b70787c947f579dcecdaf0fc</hash>
        <hash alg="SHA3-512">416043ae9cf905303f6d5e4670d596d5d7e7d62b86092795bc4fbe98859381132dbce2f256ec993cc37d8f7a402d22181d1539a031feec40e6a42ca2b9da9497</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.spark/spark-kvstore_2.13@4.1.2?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://spark.apache.org/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://issues.apache.org/jira/browse/SPARK</url>
        </reference>
        <reference type="mailing-list">
          <url>dev-subscribe@spark.apache.org</url>
        </reference>
        <reference type="vcs">
          <url>scm:git:git@github.com:apache/spark.git/common/spark-kvstore_2.13</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.fusesource.leveldbjni/leveldbjni-all@1.8?type=jar">
      <publisher>FuseSource, Corp.</publisher>
      <group>org.fusesource.leveldbjni</group>
      <name>leveldbjni-all</name>
      <version>1.8</version>
      <description>An uber jar which contains all the leveldbjni platform libraries and dependencies</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">6944e9bc03c7938868e53c96726ae914</hash>
        <hash alg="SHA-1">707350a2eeb1fa2ed77a32ddb3893ed308e941db</hash>
        <hash alg="SHA-256">c297213b0e6f9392305952753f3099a4c02e70b3656266fe01867e7b6c160ffe</hash>
        <hash alg="SHA-512">2e9f806af5d89c00e345b4516ffd325893a07f30c87274fa5b8ce314aad021633750b665d8c338fbf5adc79a527e19caf96d0b12af57e56fb8d3d8f7fd845a96</hash>
        <hash alg="SHA-384">f10d7ce88da5a9fada67fcbf6fc02939346e67428ee5dd7b000f884d8046131391ee1ece83885d3de60532d1227a66f2</hash>
        <hash alg="SHA3-384">b5919e94b576b4c30017e16f0b1a983aed10ba755bda341cd3f6056b56e0d024c1c63aa9892aab3be166c8a70fc94e47</hash>
        <hash alg="SHA3-256">5a8e38c0619923426a8a37733a9249986e6b9b389ebe2fe04b9235e045fea406</hash>
        <hash alg="SHA3-512">136aed54a48e86ec78e99ff19fc40de5dacfe9f0d9975e5e5c19024b68e35cdf88f82587d09d1f4e32db6ddb96fe7cd663bf1e01098e8366547a6a1620f938fc</hash>
      </hashes>
      <licenses>
        <license>
          <id>BSD-3-Clause</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.fusesource.leveldbjni/leveldbjni-all@1.8?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://leveldbjni.fusesource.org/leveldbjni-all</url>
        </reference>
        <reference type="distribution-intake">
          <url>http://repo.fusesource.com/nexus/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/fusesource/leveldbjni/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>leveldbjni-dev-subscribe@fusesource.org</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/fusesource/leveldbjni/leveldbjni-all</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/com.fasterxml.jackson.core/jackson-annotations@2.21?type=jar">
      <publisher>FasterXML</publisher>
      <group>com.fasterxml.jackson.core</group>
      <name>jackson-annotations</name>
      <version>2.21</version>
      <description>Core annotations used for value types, used by Jackson data binding package.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">e0d0c3e7300954f73e43c67d933aaea4</hash>
        <hash alg="SHA-1">b1bc1868bf02dc0bd6c7836257a036a331005309</hash>
        <hash alg="SHA-256">53ca085f4a150f703f49e1aabd935bd03b43e1ea3d55d135438292af22cef56b</hash>
        <hash alg="SHA-512">d832a99867acc2d5afb2596da760c50e6a6b54c1bbc8e6c4186f267a16e1d55c7a916ef8b034ad6b277c41e3342b91dcdc2e3dcea8bdccfe89e7c147894591be</hash>
        <hash alg="SHA-384">30b15d68f8da6f6c26aa9f6c95d09152b6c1a8092cd976cf600d63d1751509a73865f937e0ad97d8d55bf20f6a749b44</hash>
        <hash alg="SHA3-384">5205b51f6ed689cf31b58b98a61ca9e17a439c15d669dcb408ec4d430e77ac9ac57d39d5ca1f9973e8d184f6dd57ec4f</hash>
        <hash alg="SHA3-256">d6782d188a72b2bb96e4b595343e783012b3f98c30f7b9950244c21739334509</hash>
        <hash alg="SHA3-512">b648f1e9ffe818227d53fbde409e61858ac22d3f78705eaf08065587ed512c9b33b0f5e2222356bfb33fb2973bb5a3184e31d2a7099f8fc8d2fd23eb4612a4bf</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/com.fasterxml.jackson.core/jackson-annotations@2.21?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/FasterXML/jackson</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://central.sonatype.com/api/v1/publisher</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/FasterXML/jackson-annotations/issues</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/FasterXML/jackson-annotations</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.spark/spark-network-common_2.13@4.1.2?type=jar">
      <publisher>Apache Software Foundation</publisher>
      <group>org.apache.spark</group>
      <name>spark-network-common_2.13</name>
      <version>4.1.2</version>
      <description>The Apache Software Foundation provides support for the Apache community of open-source software projects.
    The Apache projects are characterized by a collaborative, consensus based development process, an open and
    pragmatic software license, and a desire to create high quality software that leads the way in its field.
    We consider ourselves not simply a group of projects sharing a server, but rather a community of developers
    and users.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">2c7b7873d4035aad25ed702f0f8d90a3</hash>
        <hash alg="SHA-1">0487bfd05b8de19fd31062608eb67dafd342b6e6</hash>
        <hash alg="SHA-256">301abbc7a6f15d38d8da98e45776fe22260d68949ffc8ce47daba7d45fae60b4</hash>
        <hash alg="SHA-512">0881656b233631bc111f5cf11aa22f382ebc7772dff73988601524930b2572c8f4084955eda5895ae38589d7b186db9cbb0eba285d620de325d52a49f468b114</hash>
        <hash alg="SHA-384">836ad76f0552e44d9d2b5187851802409af70973344b090536d78900f861eeacf426b09f36eccc99b21b9a25bbc400d2</hash>
        <hash alg="SHA3-384">7fbc8735e39be21848024a1b68137891697d807be19e91cac083f5647ee5303a9296d4f815899c2ba075595e103561a0</hash>
        <hash alg="SHA3-256">7ea1e204db8759438b95c178617eaffc6ecc2d56f6a90f860a034a877f017221</hash>
        <hash alg="SHA3-512">feb98a7bfa813e710d00ba11545cba228b2ad55d3de344705a0ad3fab972d959364e1dc27292f45b834a702468d679116725a6df5f7748955d2c01bba328a84f</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.spark/spark-network-common_2.13@4.1.2?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://spark.apache.org/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://issues.apache.org/jira/browse/SPARK</url>
        </reference>
        <reference type="mailing-list">
          <url>dev-subscribe@spark.apache.org</url>
        </reference>
        <reference type="vcs">
          <url>scm:git:git@github.com:apache/spark.git/common/spark-network-common_2.13</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-tcnative-boringssl-static@2.0.74.Final?classifier=linux-x86_64&amp;type=jar">
      <group>io.netty</group>
      <name>netty-tcnative-boringssl-static</name>
      <version>2.0.74.Final</version>
      <description>A Mavenized fork of Tomcat Native which incorporates various patches. This artifact is statically linked
    to BoringSSL and Apache APR.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">7d65e56d019c541ff8ebf83a6183c7f1</hash>
        <hash alg="SHA-1">93842fa9aa86fcce00114b07823dc6c7a351171c</hash>
        <hash alg="SHA-256">39ac6b1eb4ffc18d5fe9412cc6253a8954bafc8e3ca10109bc370490f73a3673</hash>
        <hash alg="SHA-512">367126a6b45db6bc61786e68d0ee7f6e2d5fbaf02dc722c5e7806dd23fc2170381bb4cf086641adaaa3b0d8cb42d67c51cc649870cffca2def448661bae57f81</hash>
        <hash alg="SHA-384">e297da34fefe67a622c3808735e0814c5596a5c6552e9347949bad2a8ad2fe1963d6d384a64d5c5da7a8e6900d5de26c</hash>
        <hash alg="SHA3-384">23e88d539ea149d690281fdd6948ab5cdc89867059d8f09a2c33d6ecefc73404aa282941576ae491ec82f7ad231d4cf5</hash>
        <hash alg="SHA3-256">759e6371aaed77198461e122522d2445253fe43d8356a759db3d04b7b463c527</hash>
        <hash alg="SHA3-512">5c954643b0d02480d144c567216075413a31f802599312264a049e94e84d91929c3e23c952b34efc7906b89d2912dc9ef5494020597c7f2e967197f3218135aa</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-tcnative-boringssl-static@2.0.74.Final?classifier=linux-x86_64&amp;type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/netty/netty-tcnative/netty-tcnative-boringssl-static/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty-tcnative/netty-tcnative-boringssl-static</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-tcnative-classes@2.0.74.Final?type=jar">
      <publisher>The Netty Project</publisher>
      <group>io.netty</group>
      <name>netty-tcnative-classes</name>
      <version>2.0.74.Final</version>
      <description>A Mavenized fork of Tomcat Native which incorporates various patches. This artifact is dynamically linked
    to OpenSSL and Apache APR.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">d08736a30c50e4348174a542ed3cc446</hash>
        <hash alg="SHA-1">c3b2e6ac13230849355f7ecaaeb12668a22e9c0a</hash>
        <hash alg="SHA-256">194874cf723794dd409fd1e728cd91ffbcff0584d73b4d8a1ad0d69d04acf9b3</hash>
        <hash alg="SHA-512">078a110dbf2097cb0d644de8c4582b624e2dfd4bd647dd2fa3c0b8e52badc85749e241d4a0957880533d44cef2a74ec68d6c2fab542b264f8656736cf72b065c</hash>
        <hash alg="SHA-384">b8c449c80ad22f7c9c407233547e2348936e48c783d3a35f9680e8d452ab6f629fc18ca56f4c75d8e0140742f5d2730b</hash>
        <hash alg="SHA3-384">b8b1f61bfa5e8fdfdce7aba019429e8569e3d33586db49ebfde94dbd1e96a7567f9fe908b591d3b44776739219766211</hash>
        <hash alg="SHA3-256">c7a13c535e5b7c20fb0f6d19ce048f0918ad0a4ffd033b3285a06e25b4710bd7</hash>
        <hash alg="SHA3-512">1132db86922954b9d40ebb0afb50b704568f8359e578e3795c85a3aba95e0116f9a67faabcf97f27e4243c41ba3a6d767cfede3bccfad5477182afbc1d19b184</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-tcnative-classes@2.0.74.Final?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/netty/netty-tcnative/netty-tcnative-classes/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty-tcnative/netty-tcnative-classes</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-tcnative-boringssl-static@2.0.74.Final?classifier=windows-x86_64&amp;type=jar">
      <group>io.netty</group>
      <name>netty-tcnative-boringssl-static</name>
      <version>2.0.74.Final</version>
      <description>A Mavenized fork of Tomcat Native which incorporates various patches. This artifact is statically linked
    to BoringSSL and Apache APR.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">41bdefaa9d8cd667b7b70a316fa43b65</hash>
        <hash alg="SHA-1">870d88a49456573702fba172c1ff639564ceab64</hash>
        <hash alg="SHA-256">5458b4b502763d49cd2e16c434312687178afac9c164cabf75c4a8bcecf7ac50</hash>
        <hash alg="SHA-512">55d0037aa73ae8e69f42877a491d8b487775ccd104a67bf785354270f61bda17872510837ecd3cd1a80d0f09d3d6c885c0a48a443f4e56dc29e90e37e84fbcb5</hash>
        <hash alg="SHA-384">09126f81b76036717a66a8e9e29cd61126f660b9fdbc30d9fb1403cfd388d304e18c26438e37c708ea5e30adcc2c1d13</hash>
        <hash alg="SHA3-384">03b22c4567166dd60cf33038816397d1d733f14ee8abaeda8649335c30e9cd378cec0986599100b887067a252015d957</hash>
        <hash alg="SHA3-256">ba94ebae2e6a105374827d91248d49de4da326cd6405e709a580f6acacf49779</hash>
        <hash alg="SHA3-512">1706911008b1b4264d353dfff082591eaa374d18aaa92a9def9452b7495ac1c4f07a66d4b2454a4ad5fb9495bc90ec45d00bac2eb27906459d208b7aee104050</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-tcnative-boringssl-static@2.0.74.Final?classifier=windows-x86_64&amp;type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/netty/netty-tcnative/netty-tcnative-boringssl-static/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty-tcnative/netty-tcnative-boringssl-static</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-tcnative-boringssl-static@2.0.74.Final?classifier=linux-aarch_64&amp;type=jar">
      <group>io.netty</group>
      <name>netty-tcnative-boringssl-static</name>
      <version>2.0.74.Final</version>
      <description>A Mavenized fork of Tomcat Native which incorporates various patches. This artifact is statically linked
    to BoringSSL and Apache APR.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">3026d98527f2269181ce3da715933e7a</hash>
        <hash alg="SHA-1">acb684cdf024656714a43bb5df350eed7cabae9c</hash>
        <hash alg="SHA-256">11dfee82cfcb5c4f596271fe1d56a70fe77b4034e54162d0bd211623b540857f</hash>
        <hash alg="SHA-512">9ce785026902c0d460b8a7e6a0aed050f2471bee17e13d58e4da812b156feaf6bea417b9ea42e5eb1129866a392700debf9010d286d3676478e83ad60a9a078a</hash>
        <hash alg="SHA-384">63507bffa85a3ef549ae0ae7c16a6a9cc38a5395656a511c7a1e6dbb8fe00502a1dce1cde0cec1af44b9c6f29be99c86</hash>
        <hash alg="SHA3-384">8da81b94a253100e228d440d377bc293bea771075e696c112e7a30b50a5acaaac2515a9a121441f7c885e96e43e229b9</hash>
        <hash alg="SHA3-256">af5c32c68b355aaec78a1d27e86fe300d066726b8a2ac99c00e40236ad74bbbd</hash>
        <hash alg="SHA3-512">5103952feab3fc4a9ea5d1447ead78b8ec115c07825912b9006be9fc44cf92e329c414fdf48bef75349550e526cd1f25c290f6462b7b6eeb75ae41b80a61e7e3</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-tcnative-boringssl-static@2.0.74.Final?classifier=linux-aarch_64&amp;type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/netty/netty-tcnative/netty-tcnative-boringssl-static/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty-tcnative/netty-tcnative-boringssl-static</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-tcnative-boringssl-static@2.0.74.Final?classifier=osx-aarch_64&amp;type=jar">
      <group>io.netty</group>
      <name>netty-tcnative-boringssl-static</name>
      <version>2.0.74.Final</version>
      <description>A Mavenized fork of Tomcat Native which incorporates various patches. This artifact is statically linked
    to BoringSSL and Apache APR.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">2f48f3d78e62ad3394c66c2da9d1513d</hash>
        <hash alg="SHA-1">75407946806094f97eb51fb41bb8eeed95c1cb16</hash>
        <hash alg="SHA-256">eef3fc7cdc5e2dc8c5cb50bae11443052bf1ee2f6e8b64378565746d1529f05e</hash>
        <hash alg="SHA-512">82d1fde3e754acb4f48540b6e429f1f661bcca86804cd17c4a31719bb9fb588ed5d463060e42dc047c2b00f53df17ed4f2b11e7f7d77974b923cba7a6e30938e</hash>
        <hash alg="SHA-384">438217631b75b005fae5b35345c9e11e692514ed686435e9e0fcdeb47179a492e68761561c4dcaadfa0f3a0a28027128</hash>
        <hash alg="SHA3-384">a250382cfaf0ae0790c415ddde2f96bf54bbf41567d313399bf852e9440734c8d0a31309c945451f0b71af87366f6b58</hash>
        <hash alg="SHA3-256">741db40bb31bd3c54a2597e5fe87b754a5cc15bd9ad53522453c29ecb7846520</hash>
        <hash alg="SHA3-512">4554ebe6124219cae33763424e2876a1b53d967508c127c05580654301abc77c11cf6f8ee42ea2e522a6f15b9db2ddefd8f13a6ba87f552ba04d8ca70bab56f5</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-tcnative-boringssl-static@2.0.74.Final?classifier=osx-aarch_64&amp;type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/netty/netty-tcnative/netty-tcnative-boringssl-static/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty-tcnative/netty-tcnative-boringssl-static</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-tcnative-boringssl-static@2.0.74.Final?classifier=osx-x86_64&amp;type=jar">
      <group>io.netty</group>
      <name>netty-tcnative-boringssl-static</name>
      <version>2.0.74.Final</version>
      <description>A Mavenized fork of Tomcat Native which incorporates various patches. This artifact is statically linked
    to BoringSSL and Apache APR.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">ca4bed341a1d9e6cb3cb1ec94ee309dc</hash>
        <hash alg="SHA-1">8ec60e25b054d42cfacfce918e7ef94a750d3dfa</hash>
        <hash alg="SHA-256">e3beaa3ebdb136569528c59aa826d771efadc0ac9db484c6c0e457fa5efd0f07</hash>
        <hash alg="SHA-512">22c96cd680010a0ab6a83228a042a9f0ffbbd06914e64ddd7adfa3a511602fff6ee55c23359031c5bb3575543332486a507330dd8bf277785d57d359d6b5d4df</hash>
        <hash alg="SHA-384">d8a09b9f3815fc1ba1854d2d5448a9f2bf50754d6ac43a81b9e705f5ea05d867441322af99d8a5b1b1f27741f915dfb2</hash>
        <hash alg="SHA3-384">2f0d26b4cccb11d9aeab8b31aff29f9affebbcd7d50ce18147c02c04276e5503e6f195e5392847338eb538c99257ccdc</hash>
        <hash alg="SHA3-256">f8de5248bbf8c19878290d8d0d833c3571897c51aac96218ef4bb44df0fed254</hash>
        <hash alg="SHA3-512">e9128a51c471f0cdf0f88d8e06d02e5ed8e06d1c8002ebbe441f6f5b6e4151d44470879b20b076c9aeb19a8eaf80cab983df6d5856fa50f0eac71d7e42593444</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-tcnative-boringssl-static@2.0.74.Final?classifier=osx-x86_64&amp;type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/netty/netty-tcnative/netty-tcnative-boringssl-static/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty-tcnative/netty-tcnative-boringssl-static</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/com.google.crypto.tink/tink@1.16.0?type=jar">
      <group>com.google.crypto.tink</group>
      <name>tink</name>
      <version>1.16.0</version>
      <description>Tink is a small cryptographic library that provides a safe, simple, agile and fast way to accomplish some common cryptographic tasks.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">9fad84f8ba4dddf00bd54dfb84a911cf</hash>
        <hash alg="SHA-1">883213082b39103b6093fa4e9880353494df9f85</hash>
        <hash alg="SHA-256">7f5e380dde874cd44613952f374723da1f8636526c6a574945bceb0e65571d0a</hash>
        <hash alg="SHA-512">77977867d8e3978fa00e1857c4a856d50484d424a1d5b6d55ab78c8fb4fa2888708a358c8c9112d790f101602fb68aa2089221fc0c5e4b44ac6816bb84fb4406</hash>
        <hash alg="SHA-384">c6c864f0535f22abecc2bcb7879baded4d08d0401939056598e06a64f47fa8549e3c04c05bffb830818552ab62096bdb</hash>
        <hash alg="SHA3-384">5084d35650cf3f328398fbd7011049a36831103ace327eb81b823d3879634d2e9ea6476c3564d4037ce5d025cbe56c77</hash>
        <hash alg="SHA3-256">f39cf4bb79729d756d79fa48a6c66331b66c638489753e6287d1e181f9d0004b</hash>
        <hash alg="SHA3-512">27f36cddae6f965cc5b61db84a3d2062bdebd578e1e4e0ceace3d6a560071c05e6a784c0ef106acc25890dcf1e070f943a3287432cbed34d7c94c18edf167137</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/com.google.crypto.tink/tink@1.16.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://github.com/tink-crypto/tink-java</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/tink-crypto/tink-java/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://groups.google.com/group/tink-users</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/tink-crypto/tink-java.git</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.spark/spark-common-utils-java_2.13@4.1.2?type=jar">
      <publisher>Apache Software Foundation</publisher>
      <group>org.apache.spark</group>
      <name>spark-common-utils-java_2.13</name>
      <version>4.1.2</version>
      <description>The Apache Software Foundation provides support for the Apache community of open-source software projects.
    The Apache projects are characterized by a collaborative, consensus based development process, an open and
    pragmatic software license, and a desire to create high quality software that leads the way in its field.
    We consider ourselves not simply a group of projects sharing a server, but rather a community of developers
    and users.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">2e0cbfe859ef90b63c185069225456f6</hash>
        <hash alg="SHA-1">9bbd74d4287a8b31588c19852516d52afbd52b8f</hash>
        <hash alg="SHA-256">243f52e5aaa84ba8335f0a457547da285d1b419642ceb2ac8bc5abdc3464d2c8</hash>
        <hash alg="SHA-512">3bcc7bd4d7d05de788bcab0d2cb8eabae802962f0a699a7fe3a3aa2671490eceebb0d77a89127f768ea2ccbb6a2746757a0e68db6b73357c55b12a351c8a0c99</hash>
        <hash alg="SHA-384">c37e502ff6122fcb78ddbc24ee96179ec30e9916c28a9fd1c5c787ba33f21dbd1be3def153c5f339183a25573d1749fa</hash>
        <hash alg="SHA3-384">0f8f48811d599cb988af8005f92af986e1a518295975f674d340178ca1f09256f30f4c572c739274f10874139040e46f</hash>
        <hash alg="SHA3-256">c536a85e24e9a7bff362113b598d1039aa032c887c5e1ae0b3170c6b2d3d9685</hash>
        <hash alg="SHA3-512">273a063a9c1d9dbea5be241dc1ce139bb7c63c6324c3e92c799629a84a4b50c78c2cc6615031037d6a800fff4c8833b9dcb4b8aa53469580e1127538f25aa2db</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.spark/spark-common-utils-java_2.13@4.1.2?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://spark.apache.org/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://issues.apache.org/jira/browse/SPARK</url>
        </reference>
        <reference type="mailing-list">
          <url>dev-subscribe@spark.apache.org</url>
        </reference>
        <reference type="vcs">
          <url>scm:git:git@github.com:apache/spark.git/common/spark-common-utils-java_2.13</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.spark/spark-network-shuffle_2.13@4.1.2?type=jar">
      <publisher>Apache Software Foundation</publisher>
      <group>org.apache.spark</group>
      <name>spark-network-shuffle_2.13</name>
      <version>4.1.2</version>
      <description>The Apache Software Foundation provides support for the Apache community of open-source software projects.
    The Apache projects are characterized by a collaborative, consensus based development process, an open and
    pragmatic software license, and a desire to create high quality software that leads the way in its field.
    We consider ourselves not simply a group of projects sharing a server, but rather a community of developers
    and users.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">ee8ee2210be98a57d39e9c27dfcfe0f2</hash>
        <hash alg="SHA-1">fe2d47767b50f0ecd15019b325ae54872faab7f2</hash>
        <hash alg="SHA-256">d221db20019945d5695e7e39e63d6feaa62acce1b1c0d7ed82539ea37b20b6d8</hash>
        <hash alg="SHA-512">7a7d110b1c696288ca856deeca5340c522e9ffda3354b6ca7e1caa3e0ba1d8fe5102252d606f267aeb6df47371c3725c4b2c91104bbca2d839063d1c6bfe4332</hash>
        <hash alg="SHA-384">adf3a97b9e917ec4c7ceaefb0095af0aca12865a02431e3675b7e91c5a864a656e4580fab766c9176e2439009f0ecfa4</hash>
        <hash alg="SHA3-384">baa043a2eb586718e9485f16bbda5776a77b9225650b9402cc3e37e2882ffdb2aff4f6a73bb9b57f0039c19db4ff5871</hash>
        <hash alg="SHA3-256">cfef204cf2c6a61b97a0209fa10a3d3763a94b82b7bf25538875bd6ed8cff4bd</hash>
        <hash alg="SHA3-512">7a11f3dc2264b1f9174943b9ab53bedb661f53f4fc9ee47379744ba9a9a168f40fb871c18576d0c56b13f9499c6c1fff1997d258f700effceff6e41c4b46d708</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.spark/spark-network-shuffle_2.13@4.1.2?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://spark.apache.org/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://issues.apache.org/jira/browse/SPARK</url>
        </reference>
        <reference type="mailing-list">
          <url>dev-subscribe@spark.apache.org</url>
        </reference>
        <reference type="vcs">
          <url>scm:git:git@github.com:apache/spark.git/common/spark-network-shuffle_2.13</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.spark/spark-unsafe_2.13@4.1.2?type=jar">
      <publisher>Apache Software Foundation</publisher>
      <group>org.apache.spark</group>
      <name>spark-unsafe_2.13</name>
      <version>4.1.2</version>
      <description>The Apache Software Foundation provides support for the Apache community of open-source software projects.
    The Apache projects are characterized by a collaborative, consensus based development process, an open and
    pragmatic software license, and a desire to create high quality software that leads the way in its field.
    We consider ourselves not simply a group of projects sharing a server, but rather a community of developers
    and users.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">4286b50a39c8cef6d3e09043491dc943</hash>
        <hash alg="SHA-1">f4fe1ccba3a2e6a2e3ee151644ddcfdd86e7724d</hash>
        <hash alg="SHA-256">7069a4aeef2c841268813f5de7baf062a84d0eaeda220d5924cdfc0d47b9a99d</hash>
        <hash alg="SHA-512">ba77878906ceba352105f3a813f71a27260a5d230bfaed87274bccc6e2989b107a2441b6d52c33f22e2c095550d03dfa31f0fb84b6fdcc0c335cc938ecd9fb5c</hash>
        <hash alg="SHA-384">cc5b5316148130c9d073c52d05332e9522ea64b1bc0ca4cc0a60056d2d80e2cdc5f166dee41d48dcc8a4b12beec20393</hash>
        <hash alg="SHA3-384">e8686d81b7a9a3b6bec5c988260e69fc689f38589b66e747c170512ea5b431b2f8f992be958b8769a108af392f41be08</hash>
        <hash alg="SHA3-256">bb64b481890d451be39a5eea6721bef3fe5ca7859b0fd60dfba03c3f525cca3c</hash>
        <hash alg="SHA3-512">8323b95ab707003dff7165e0282dd3f165d4787cb51beb422238f9c9fb6180ddd9ca01f308d9bf680178adbf001cba1c2625a74dc91ce69e11c9d72c5ab4e3be</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.spark/spark-unsafe_2.13@4.1.2?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://spark.apache.org/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://issues.apache.org/jira/browse/SPARK</url>
        </reference>
        <reference type="mailing-list">
          <url>dev-subscribe@spark.apache.org</url>
        </reference>
        <reference type="vcs">
          <url>scm:git:git@github.com:apache/spark.git/common/spark-unsafe_2.13</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.spark/spark-common-utils_2.13@4.1.2?type=jar">
      <publisher>Apache Software Foundation</publisher>
      <group>org.apache.spark</group>
      <name>spark-common-utils_2.13</name>
      <version>4.1.2</version>
      <description>The Apache Software Foundation provides support for the Apache community of open-source software projects.
    The Apache projects are characterized by a collaborative, consensus based development process, an open and
    pragmatic software license, and a desire to create high quality software that leads the way in its field.
    We consider ourselves not simply a group of projects sharing a server, but rather a community of developers
    and users.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">b675f43d73702e94882f2aab5b727af1</hash>
        <hash alg="SHA-1">fd1a54a55044f40a75858a8369f4f3ccbfefb621</hash>
        <hash alg="SHA-256">6c117b478cac4b617290ebda7e5ee372b63ddbf63ff3fa8da87810c2d8b0c613</hash>
        <hash alg="SHA-512">72e619376d984346056b7991beb2f93043b0d64d4f852d8acf7142cf148666d67e111daf9af8b8c015f9bfb662c155062d783165cc9a40271d6230d733f05761</hash>
        <hash alg="SHA-384">71c3d0b895c7f97c933957a6b3249e8eeb9618da9d2e712f819496ef5f58dbabd479dd61ac1a2110f6289b8244c0a561</hash>
        <hash alg="SHA3-384">217a369a863e563869c022851ad5e18543c6d7c383a80e4c8a1752b3381f726ba140a1474f4c9dfd0e4ed2554008f9f6</hash>
        <hash alg="SHA3-256">942f72a9a54b56d9ad83edd39bdce053fd8410f4af21273d0b21a25780a972c7</hash>
        <hash alg="SHA3-512">70107e73d6bc6c3fa7bf4bbba3dbb8658af3c04761a41340f52ae520f1698467360e126c6a92bf2b956f89061d9d7d4f1283b262ad6f907d6b67c0969a326505</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.spark/spark-common-utils_2.13@4.1.2?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://spark.apache.org/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://issues.apache.org/jira/browse/SPARK</url>
        </reference>
        <reference type="mailing-list">
          <url>dev-subscribe@spark.apache.org</url>
        </reference>
        <reference type="vcs">
          <url>scm:git:git@github.com:apache/spark.git/common/spark-common-utils_2.13</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/oro/oro@2.0.8?type=jar">
      <group>oro</group>
      <name>oro</name>
      <version>2.0.8</version>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">42e940d5d2d822f4dc04c65053e630ab</hash>
        <hash alg="SHA-1">5592374f834645c4ae250f4c9fbb314c9369d698</hash>
        <hash alg="SHA-256">e00ccdad5df7eb43fdee44232ef64602bf63807c2d133a7be83ba09fd49af26e</hash>
        <hash alg="SHA-512">9a98e493c4d771322b1331ec05ab0e363a83d8ac2af8018d96a44df2bf5bfc97d33ebe6f6f93e46ab10bf1536f0c29e9d9569318ed49bc18b4e96b1a8b476d37</hash>
        <hash alg="SHA-384">f542e92b7a86bcb20cc21f0c4b29778428944391344ca11df432f9ce36a96ce8e8f65da67e450e52c0e8ba441d2a7332</hash>
        <hash alg="SHA3-384">e483eec12e463136ea4163a280dc17d62e48f5d49f0f0ad2ab672c4c5366b1f4e5fd460e880caaa4b39666106ac98ca1</hash>
        <hash alg="SHA3-256">e558c00adc56713dc57cebed64b966e3ca0d8f096056d8843fa8bb11c7c96017</hash>
        <hash alg="SHA3-512">f6e02d2cd83014e4a4d5ca0f24b189ec944c3b1e306c5eb04fac7e148b47ad2432256ef6b05292cf6d34a31c72420637702cc0fff4b38edcfae21bc0ffda98aa</hash>
      </hashes>
      <purl>pkg:maven/oro/oro@2.0.8?type=jar</purl>
    </component>
    <component type="library" bom-ref="pkg:maven/org.slf4j/jul-to-slf4j@2.0.17?type=jar">
      <publisher>QOS.ch</publisher>
      <group>org.slf4j</group>
      <name>jul-to-slf4j</name>
      <version>2.0.17</version>
      <description>JUL to SLF4J bridge</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">a42936c56611e4794c42908fb3d3a647</hash>
        <hash alg="SHA-1">524cb6ccc2b68a57604750e1ab8b13b5a786a6aa</hash>
        <hash alg="SHA-256">a7afcd23b9cfd1475e55c94f943b808c5922035e7e2c2a5c65a487a4106bc538</hash>
        <hash alg="SHA-512">623426fb3a0a34c88b1fce686cbfaa8d17bf013f3583886dc94273bf2f767492044b48db6557988d764f0450129c9d496dd3c10ad548099879d80e3945f2f636</hash>
        <hash alg="SHA-384">fe66fb82c6f9dca6f8fb1d61e1fc6f4d8bc9b616cf89aa5b54fab933e1a55506a2400e8e9b1c92cb2787ac69731103f4</hash>
        <hash alg="SHA3-384">6f537049a039795f0f4c0653d2ab959fe0bfeae53f629148773db1a819b2308e16ef6e3f9d49a5741e9adf0ce5c34eda</hash>
        <hash alg="SHA3-256">f25e1333214a362f95ef31c8465f6d89b4bb7399638f4c4ad53a6d9f0ecbd649</hash>
        <hash alg="SHA3-512">a831c814c1064b39ead500e542de1decfe302688936b93c9aa781938bb0ae884907137ea34f18f99436f24fb9ddbbcecaf32df543c691d6311671f7e8b81dbc7</hash>
      </hashes>
      <licenses>
        <license>
          <id>MIT</id>
          <url>https://opensource.org/license/mit/</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.slf4j/jul-to-slf4j@2.0.17?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://www.slf4j.org</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/qos-ch/slf4j/slf4j-parent/jul-to-slf4j</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.slf4j/jcl-over-slf4j@2.0.17?type=jar">
      <publisher>QOS.ch</publisher>
      <group>org.slf4j</group>
      <name>jcl-over-slf4j</name>
      <version>2.0.17</version>
      <description>JCL 1.2 implemented over SLF4J</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">4fcd46ca51e55b9fd9b0db34474927e0</hash>
        <hash alg="SHA-1">76ea503eb688f06556a9ba69995d7eab63e34531</hash>
        <hash alg="SHA-256">affd06771589ebfe454bb11315a4f466ecaa135b95f3e7939534cf1d2fd7064c</hash>
        <hash alg="SHA-512">7efb2771bad2e643b0e814cd78ab4f9af3ea166643700776618c397e9755ca11f4b7c00030562a619932c9d2ec5114fd253ece3abbc3db2f1a064431d8990733</hash>
        <hash alg="SHA-384">96fd8b2732de79c40e5e6613e324d2845dc6e19bf31bc7f3e9fa6730fa527cd16579ba9eb7915481faae1e9a32dc82fd</hash>
        <hash alg="SHA3-384">252a3e6847dafd84955a71724d71641b5c6508bcbbc1f2457fdb18994b61f6d78b08cbd40d5c430743950e351ec79835</hash>
        <hash alg="SHA3-256">4c066cec2c40de9b5743f43d99b629d60de937718f69ffd837bbe5902682ee92</hash>
        <hash alg="SHA3-512">3334a1fff0751378abe8e010ca9716a85a15a90450265699c32886d2e8f9ff63df89237667a262350d860dbfb2f20fffff14e9a094f0bd2acf990dd543c2b86f</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.slf4j/jcl-over-slf4j@2.0.17?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://www.slf4j.org</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/qos-ch/slf4j/slf4j-parent/jcl-over-slf4j</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.logging.log4j/log4j-slf4j2-impl@2.24.3?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.logging.log4j</group>
      <name>log4j-slf4j2-impl</name>
      <version>2.24.3</version>
      <description>SLF4J 2 provider (binding) for the Apache Log4j API.
    It forwards SLF4J 2 calls to the Log4j API.
    This effectively allows using Log4j as an implementation of SLF4J 2.
    (Refer to the `log4j-to-slf4j` artifact for forwarding the Log4j API to SLF4J.)</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">0ec2df0e6ab3e63e2d7b043bd0478c3f</hash>
        <hash alg="SHA-1">c3bda2dc612bfc780ad06c5acf5e0ffd55b770e5</hash>
        <hash alg="SHA-256">cdaac22e40ec30c4096e1ebe8c454c8826c0d1c378d7db5d7b3ad166354b0bd3</hash>
        <hash alg="SHA-512">c837d1724dc85479ec0eabfd8adef32d5bc3e9ba94c058eac6904894c9d3dff4f85762287159b0ae9f1e314e64861414de36a0d6e314e2d3b7aef8bedbd37b2b</hash>
        <hash alg="SHA-384">9c4eb0ae56d844b202546868a8eec8529647d7b38967234ed79a794cc4b8740bf3264a2958d5db7111de588efd2dfc37</hash>
        <hash alg="SHA3-384">246549536ddbbd348a1f37d497f9f7c684b53311008ee3cec2705e86e35afa274774be4f0da966923ed32f77a3e9f4e5</hash>
        <hash alg="SHA3-256">213a0e3d560934abdfa725581e5b7f49155e95328ad67be9f49afa6275592370</hash>
        <hash alg="SHA3-512">81706150cf1a117569e4bdd8061964be4bf3042cdabd7bc24b5f524d212d4fca69c6952a8bafa41f973858ba9161a6bc89bb46880243c727b5f70a44b6b77a51</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.logging.log4j/log4j-slf4j2-impl@2.24.3?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://logging.apache.org/log4j/2.x/log4j/log4j-slf4j2-impl/</url>
        </reference>
        <reference type="build-system">
          <url>https://github.com/apache/logging-log4j2/actions</url>
        </reference>
        <reference type="distribution">
          <url>https://logging.apache.org/download.html</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/apache/logging-log4j2/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://lists.apache.org/list.html?log4j-user@logging.apache.org</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/apache/logging-log4j2</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.logging.log4j/log4j-api@2.24.3?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.logging.log4j</group>
      <name>log4j-api</name>
      <version>2.24.3</version>
      <description>The logging API of the Log4j project.
    Library and application code can log through this API.
    It contains a simple built-in implementation (`SimpleLogger`) for trivial use cases.
    Production applications are recommended to use Log4j API in combination with a fully-fledged implementation, such as Log4j Core.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">d89516699543c5c21be87ee1760695f3</hash>
        <hash alg="SHA-1">b02c125db8b6d295adf72ae6e71af5d83bce2370</hash>
        <hash alg="SHA-256">5b4a0a0cd0e751ded431c162442bdbdd53328d1f8bb2bae5fc1bbeee0f66d80f</hash>
        <hash alg="SHA-512">d936ac37b3d7ca2e4370ef122629c5ceb0bef60a6c08a3bd8bb278204dbed84bb888aaa307c58e80e4e9d645b73792433f52adcccd30378fbac99b1d271042f7</hash>
        <hash alg="SHA-384">d376ab3673186a1a39ea8b3d3c8359bb16dbb3f5d3782c182a112ab19b61d7730434c6d0f631d43d6daae66005d1df4e</hash>
        <hash alg="SHA3-384">7ee1b17a329d90bf648d05defced8d79f7bfbca66cc7e90aa2e1b2d7622697d535969e50d1a03460447eda2fa008f86c</hash>
        <hash alg="SHA3-256">5d2ad18a3352c3d7269ecb8d52d6a5ac8bf0d0d937e4809f5023a45d0f8f50f3</hash>
        <hash alg="SHA3-512">7e964e6425a1198e2568a9e8c326f730b7d139f71e8d3b1b440aa90860f136f443e5ebd62aa022c1c7834e23995ed0992f68dfb1760140d469b85fed84815ae1</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.logging.log4j/log4j-api@2.24.3?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://logging.apache.org/log4j/2.x/log4j/log4j-api/</url>
        </reference>
        <reference type="build-system">
          <url>https://github.com/apache/logging-log4j2/actions</url>
        </reference>
        <reference type="distribution">
          <url>https://logging.apache.org/download.html</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/apache/logging-log4j2/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://lists.apache.org/list.html?log4j-user@logging.apache.org</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/apache/logging-log4j2</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.logging.log4j/log4j-core@2.24.3?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.logging.log4j</group>
      <name>log4j-core</name>
      <version>2.24.3</version>
      <description>A versatile, industrial-grade, and reference implementation of the Log4j API.
    It bundles a rich set of components to assist various use cases:
    Appenders targeting files, network sockets, databases, SMTP servers;
    Layouts that can render CSV, HTML, JSON, Syslog, etc. formatted outputs;
    Filters that can be configured using log event rates, regular expressions, scripts, time, etc.
    It contains several extension points to introduce custom components, if needed.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">3f52ab7782fdd1349bd872b5dcf48bed</hash>
        <hash alg="SHA-1">7f6a261243ca767c7f38fd4b542bcde626c8894e</hash>
        <hash alg="SHA-256">7eb4084596ae25bd3c61698e48e8d0ab65a9260758884ed5cbb9c6e55c44a56a</hash>
        <hash alg="SHA-512">61332e92ea6ef6656994105a675eb8de85ec859f07cde9da5ef16a22cbf2e0d7695348e04e066dd1a1ff0146ec03a8884974319d4f71155db9c9ab0d073197ef</hash>
        <hash alg="SHA-384">fd3cd2ea5cdc84698b46833cbcdb10e3c1e507a2cba0293b487f45efa7f12f52bce9e2c0a96b0f1632e2ff2549ac2eb2</hash>
        <hash alg="SHA3-384">852c87ea21b50676f338fa423d203fa52845bb201b994afd963bbc8100ecc0f987136a21bf6a6bbd9ab13ee008de9822</hash>
        <hash alg="SHA3-256">fc5b8e9367369772309a23b9ba1c2384be7ace8f6dd6ce6a9c37c322b86e4f1b</hash>
        <hash alg="SHA3-512">c1de50e5cfa5a415ad97cff532d3d3df825ff97ee2c41ac11e50cbca86e37577b9d929e6675c2336008893686db1cdebe878234f15d0e4afc1309eea3f32020b</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.logging.log4j/log4j-core@2.24.3?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://logging.apache.org/log4j/2.x/log4j/log4j-core/</url>
        </reference>
        <reference type="build-system">
          <url>https://github.com/apache/logging-log4j2/actions</url>
        </reference>
        <reference type="distribution">
          <url>https://logging.apache.org/download.html</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/apache/logging-log4j2/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://lists.apache.org/list.html?log4j-user@logging.apache.org</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/apache/logging-log4j2</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.logging.log4j/log4j-1.2-api@2.24.3?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.logging.log4j</group>
      <name>log4j-1.2-api</name>
      <version>2.24.3</version>
      <description>The Apache Log4j 1.x Compatibility API</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">b2486768ef6049ed7c015622702bf99c</hash>
        <hash alg="SHA-1">880d64cfe147369dae43e7816b608fae2096abd0</hash>
        <hash alg="SHA-256">d541ebd1316f53374991e836ad52f32c11bf465cb6672d397f0444814528ef8b</hash>
        <hash alg="SHA-512">e486a46291842cf60410aa79b7051cd7ea9b14003ca06e8f9fb480729275d0c5b031d917c7a5716d3f80c0fb86a1d77123363200e11c4a330ba30b3479d2d780</hash>
        <hash alg="SHA-384">ce99785db26b5ef2bfdcd95e3c2a513a7b6901cb28bf8bdcbadba0642d941f57ffeacbf536954b0a81c9cfa28246611b</hash>
        <hash alg="SHA3-384">2e156eaaa832f43eb49fa2ae52d99599dafc1d51dd433ae3a004b9b48506fbb6f5a131b2e9ea05ef39160d29d0e6a830</hash>
        <hash alg="SHA3-256">638588e9577734a335e9cac2db690b54854fdf91717b12a5925cff07f9069321</hash>
        <hash alg="SHA3-512">183ab2706cfa270ceff91d58c2cc0f6d09051ffe06a867feddd5e7aca26341c63ce6f5334153ac80dc09f0721ed5ce623206101b3147f32d988afe7a00d46838</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.logging.log4j/log4j-1.2-api@2.24.3?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://logging.apache.org/log4j/2.x/log4j/log4j-1.2-api/</url>
        </reference>
        <reference type="build-system">
          <url>https://github.com/apache/logging-log4j2/actions</url>
        </reference>
        <reference type="distribution">
          <url>https://logging.apache.org/download.html</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/apache/logging-log4j2/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://lists.apache.org/list.html?log4j-user@logging.apache.org</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/apache/logging-log4j2</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.logging.log4j/log4j-layout-template-json@2.24.3?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.logging.log4j</group>
      <name>log4j-layout-template-json</name>
      <version>2.24.3</version>
      <description>Apache Log4j Layout for producing JSON output that is structured according to a user-provided template.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">0e751dbc1813c14097e6f1ecdc77f14d</hash>
        <hash alg="SHA-1">bc0573ca981a2a243cd7a8c9b0562df8bf809d39</hash>
        <hash alg="SHA-256">53e89d35be783d0d47de319dcfeed5b2ea16b0b39929a302f2b7e681efaf18ec</hash>
        <hash alg="SHA-512">165adeb26a6b70219d3ff42cc8aaed77b1a530ebc9a9bdecea8f8cd6d22249963949b9b944449204c1e484360a121d9bfe3d729a570eb87618b1105fba13f7eb</hash>
        <hash alg="SHA-384">22fabb0d4892463b59980a23b60789ad0628eeb6147adbef73ff0d6ffe2db2d458b50c87b5f779cdb298c31465120f58</hash>
        <hash alg="SHA3-384">c0ba5cd02e215f474c621412ceb612413ccb7ce0d232a1a3c99970391dc4ad8cc232070a2a1ba52d33cead1ccfe44591</hash>
        <hash alg="SHA3-256">afddbd8630c9bb75daf8b7655b657c38189cf6b791845dd1962822961356ee06</hash>
        <hash alg="SHA3-512">6f2d8ff863e70e8e048c371d024dda31f86be10497f0d56bb0b16f5aaff5207284bbb6b609a1109a8a27f33c6ca6b5d7b6ce7c836a5a2ba0099f57a9a77022ca</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.logging.log4j/log4j-layout-template-json@2.24.3?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://logging.apache.org/log4j/2.x/log4j/log4j-layout-template-json/</url>
        </reference>
        <reference type="build-system">
          <url>https://github.com/apache/logging-log4j2/actions</url>
        </reference>
        <reference type="distribution">
          <url>https://logging.apache.org/download.html</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/apache/logging-log4j2/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://lists.apache.org/list.html?log4j-user@logging.apache.org</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/apache/logging-log4j2</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.curator/curator-recipes@5.9.0?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.curator</group>
      <name>curator-recipes</name>
      <version>5.9.0</version>
      <description>All of the recipes listed on the ZooKeeper recipes doc (except two phase commit).</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">9ea89241ab838ab140f9791bdcff39c7</hash>
        <hash alg="SHA-1">4ddd58155916ce7a26073087ce4c1a58c8397eff</hash>
        <hash alg="SHA-256">2b384c256a8a30dfdff11763ec0fd56b6346e001afcb0c5ea972d5d0db1698bc</hash>
        <hash alg="SHA-512">0b782fae0f589be9c7a4a090c58ef7b768d71131801259d99bfa41764c3d7836bbd76d4deb948524061c82e459ee3e2eb460fc2d31786f09bcfb20cdc919d821</hash>
        <hash alg="SHA-384">f3408c11f9144cea2751bf1234fd479bc962d124c1f41c04e29a520be5fbb5a1a7eac18fbdf15ce41d30767788f7c46c</hash>
        <hash alg="SHA3-384">00cc3cce426338d749259f9f6103b44499d0a427856abe1d92f7ea24d210b2e2203c2a1e1794f583ed2e53803edb6195</hash>
        <hash alg="SHA3-256">48caaf532f5643d73beaf406142524732f563f4a5d79367482015ad9a20acae9</hash>
        <hash alg="SHA3-512">bd75efae49fe04c982ccc656b4859ebb56265cb63d725d36c0b7c45e014359ad496cb9f680c90e0254cb37f55ae090d6a15a528ef8ad8a7be9dcdbf6f3823e0b</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.curator/curator-recipes@5.9.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://curator.apache.org/curator-recipes</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://issues.apache.org/jira/browse/CURATOR</url>
        </reference>
        <reference type="mailing-list">
          <url>https://mail-archives.apache.org/mod_mbox/curator-user/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/apache/curator.git/curator-recipes</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.curator/curator-framework@5.9.0?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.curator</group>
      <name>curator-framework</name>
      <version>5.9.0</version>
      <description>High-level API that greatly simplifies using ZooKeeper.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">f963f74d5307c8929c7e23c1560bd3bb</hash>
        <hash alg="SHA-1">fe8d516d75dc00a49a7a37764d7fb9b2ea8a1129</hash>
        <hash alg="SHA-256">f8588d71d4b2d0b15ef5f911ceaac387563070cc328b91025047131d0c05733e</hash>
        <hash alg="SHA-512">37302ce738d5e4a52b4c4af83a737477140afb28c742e62e2c45066f1b8b3dfc685888f58909be513013613dd9dd613a57f5293c84bdace9af89cf918354f3a2</hash>
        <hash alg="SHA-384">558c4bf3cc0e7483a4e98486cfadbafc2380b9395f7ae7b9e3e36e95513ed4f3eb856d4a993be7dd8ef00d848c905e9f</hash>
        <hash alg="SHA3-384">8f876b731e1b1cd284c8f2d1cb5283a6efe236dcb5e775cba8904817e0bc006d8c62092faa3188f07c3a2dfdd4c70a1e</hash>
        <hash alg="SHA3-256">25ee66ca8a742187380bac8b7401edfab0ef93c342eee2d7b2329099475b33e4</hash>
        <hash alg="SHA3-512">fda329c2f4f09dcecfe032126073516cbf87b3087af6d19bb222730ec8b221ddc788edd8deeb607c9cef460a69ec54e6ca04aca75e7734b448665c5029c41eca</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.curator/curator-framework@5.9.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://curator.apache.org/curator-framework</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://issues.apache.org/jira/browse/CURATOR</url>
        </reference>
        <reference type="mailing-list">
          <url>https://mail-archives.apache.org/mod_mbox/curator-user/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/apache/curator.git/curator-framework</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.curator/curator-client@5.9.0?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.curator</group>
      <name>curator-client</name>
      <version>5.9.0</version>
      <description>Low-level API</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">6594b51bc88c6bbd3e6a94ee6e678e11</hash>
        <hash alg="SHA-1">220a0d2f5af16f1df2388741f7640d206f56e60c</hash>
        <hash alg="SHA-256">9b1d65fa1940f77199ed097a8e586534efd1e9311227939a46a0e467a5f7991a</hash>
        <hash alg="SHA-512">0fe75c92f2301a2eeb2d7735a7923caef12ea99df58aab1f8fef8d014d8a56a19d75794628b55a3cd822a23fc1dde353a5bab99e6b08787418f466065c327868</hash>
        <hash alg="SHA-384">3c6f0c675b4dae3033c9771f00a7b114437f3d7b57d7059f33531f773003ba2da5f9245ac28ad7e4cf53152c94889eb0</hash>
        <hash alg="SHA3-384">7f09c0d9960f93096010aa6f04661d0505b98a3a5c817d6902b665baf511b2ab574fdbf9409cfbd6e0af97c8a7a3913d</hash>
        <hash alg="SHA3-256">c957f5b5b064c591dddd28e7cfdcc36aaf75fb9b226d7ffecc58606c190dbd26</hash>
        <hash alg="SHA3-512">e0505185626c6b44a1b9546ecc14cb55dbc3841e2c8a520bad88ad454b3ecc28a94e5bfa71bd7b823c8965efb5373a331d6bd832e7587001dca145038c702d4b</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.curator/curator-client@5.9.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://curator.apache.org/curator-client</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://issues.apache.org/jira/browse/CURATOR</url>
        </reference>
        <reference type="mailing-list">
          <url>https://mail-archives.apache.org/mod_mbox/curator-user/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/apache/curator.git/curator-client</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.zookeeper/zookeeper@3.9.4?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.zookeeper</group>
      <name>zookeeper</name>
      <version>3.9.4</version>
      <description>ZooKeeper server</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">dd2faa7f0d08377a43e96b90c80484e6</hash>
        <hash alg="SHA-1">5ab49d76fcac9a33c255b0585bc1fc92e24166db</hash>
        <hash alg="SHA-256">7bb3bb38bbddbc71424c59a7a0b170a1b2147313a84c972225ab0568dab513bf</hash>
        <hash alg="SHA-512">3720eb34ed1f40b56a1dd5c3fd19d684dbad479738cd09ed1f680616d52d49022966bd278855b1928a697b2ddca2356ffab2ef3ad78888e1f5b264cbfa17c157</hash>
        <hash alg="SHA-384">4bf2698ea6aa7d3af2dd02f96918b7e07ff24239638d188dcad2a6a8f2dd87955e6c292980d5bb96e3c8bb474144910a</hash>
        <hash alg="SHA3-384">dfda120ee3e97c832517384c4b98d8b85227ef286c917906cdc0ce1ed88d8bbb1dfa3e8f322de31fba7b98a559d0bf84</hash>
        <hash alg="SHA3-256">5654dfe37d7383cb21af65d2c1f5cf165c955d2ff4a1a13e8023a5c6fdb2b243</hash>
        <hash alg="SHA3-512">dc7851118a9ea43792708a3a7b7d13e08a226790b41f4d1257c14062884e679b3c3fbd6afeb960252df2b01c4875fd1233a467e1584414b1e08c70592d07520c</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.zookeeper/zookeeper@3.9.4?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://zookeeper.apache.org/zookeeper</url>
        </reference>
        <reference type="build-system">
          <url>https://ci-hadoop.apache.org/view/ZooKeeper/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>http://issues.apache.org/jira/browse/ZOOKEEPER</url>
        </reference>
        <reference type="mailing-list">
          <url>http://mail-archives.apache.org/mod_mbox/zookeeper-user/</url>
        </reference>
        <reference type="vcs">
          <url>https://gitbox.apache.org/repos/asf/zookeeper.git/zookeeper</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.zookeeper/zookeeper-jute@3.9.4?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.zookeeper</group>
      <name>zookeeper-jute</name>
      <version>3.9.4</version>
      <description>ZooKeeper jute</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">5a7bd22933314609f54e316392ecf6e4</hash>
        <hash alg="SHA-1">db554b1c2b284a95274626126d9e1acb0e21ae4a</hash>
        <hash alg="SHA-256">bd9750935add09b6cb920f7bcf0fa7b9a8165c45cdafd8ee1fc6808c46ec9094</hash>
        <hash alg="SHA-512">97eeabeb6c5dab44e4566f81574b73901504eb814f80e6f60211404b984459a2f2d60ebebf08f85934bf30463f714f004e89ad68ab450a51c8ecbc6e3eac9ef2</hash>
        <hash alg="SHA-384">5b4991e0610cc74eec31377ac9e5c4c4bf4025c5c1f32591812089e586607c08b5699f82390380381c1f0fc1b51c62e4</hash>
        <hash alg="SHA3-384">263a8d044b7b1775a70b97abe9f3393230ccd34c04bf60ef8e27c3c3e73002d56e7e0c218ff515dac0a6303eca65f409</hash>
        <hash alg="SHA3-256">f0131cfb9cf9e290508741b774265018caa455a0394576fd63432bdb1bc73167</hash>
        <hash alg="SHA3-512">46fec30dd45afb9599e9e444befb0fe393ea09f2c53660b455fc676e4172da442ab09e1f8a2e1e9270a76105cd9dbe715e3808f648b0ea43feb618100ac7eb87</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.zookeeper/zookeeper-jute@3.9.4?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://zookeeper.apache.org/zookeeper-jute</url>
        </reference>
        <reference type="build-system">
          <url>https://ci-hadoop.apache.org/view/ZooKeeper/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>http://issues.apache.org/jira/browse/ZOOKEEPER</url>
        </reference>
        <reference type="mailing-list">
          <url>http://mail-archives.apache.org/mod_mbox/zookeeper-user/</url>
        </reference>
        <reference type="vcs">
          <url>https://gitbox.apache.org/repos/asf/zookeeper.git/zookeeper-jute</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.yetus/audience-annotations@0.12.0?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.yetus</group>
      <name>audience-annotations</name>
      <version>0.12.0</version>
      <description>Annotations for defining API boundaries and tools for managing javadocs</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">76ba71bbe18c4724d96bec68bbe12ff1</hash>
        <hash alg="SHA-1">e0efa60318229590103e31c69ebdaae56d903644</hash>
        <hash alg="SHA-256">ffb101fc066360ff3c77457c927fd7967fb096a6ee9e046ab7071447d8208efc</hash>
        <hash alg="SHA-512">264a5251272ec55eca1fae5a8fb9336d1eca1ee3bfb586d1ebc382fcfd37077c21cbfa9e198daf4e1eebe9f6fa90487bec2f85bc1c55cf5666cbbfc4d18b1715</hash>
        <hash alg="SHA-384">f936d92b5c3b3c88428fc7452871e4df112935dd25356396d15deb73dd39790f45909a3d14f038e9f585cee79622ad47</hash>
        <hash alg="SHA3-384">67ca97a525d98c3dab9ffda40e11d6c683f6f4208ae4a5b28dbd3e2b8b37187dfdcd1d9b89222dc69e5b84ac212f4428</hash>
        <hash alg="SHA3-256">fd99b55afe40884b5f6cfd9ffbdcd07fa32833443dead288390ca8e737dd3337</hash>
        <hash alg="SHA3-512">4aaece7bdadc2c2d9660b16345218cfc68a2ea344374d0ffbcdcc3722ff6be5f06c92231ae68ec3884f1aa9b99956cb5135b4060c5457f463251f3767003ad20</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.yetus/audience-annotations@0.12.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://yetus.apache.org/audience-annotations</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://issues.apache.org/jira/browse/YETUS</url>
        </reference>
        <reference type="mailing-list">
          <url>https://mail-archives.apache.org/mod_mbox/yetus-dev/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/apache/yetus.git/audience-annotations</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.jsonwebtoken/jjwt-api@0.12.6?type=jar">
      <publisher>jsonwebtoken.io</publisher>
      <group>io.jsonwebtoken</group>
      <name>jjwt-api</name>
      <version>0.12.6</version>
      <description>JSON Web Token support for the JVM and Android</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">995d2066feaa206de5e880045c9407d4</hash>
        <hash alg="SHA-1">478886a888f6add04937baf0361144504a024967</hash>
        <hash alg="SHA-256">8fabe0be1dfad1c823dc43137453e017d2c83f376422c83e017d9dd1043e6984</hash>
        <hash alg="SHA-512">d9bb467b64398cf4c28492a23abfcd890c11e3b97a0b43edddef4ddfeec3c2ca38f57d5c2dc28add9b12c51c9740f5469c50023b02d90524f254c2fd6e9a5451</hash>
        <hash alg="SHA-384">064b3fcde340defa8f6f120ccd4771869136dad77db042774c19007bfb278250e2eeb036b903e222bd2c16258d003cef</hash>
        <hash alg="SHA3-384">24d5a4273e7dc7a82ff85325e4968d138db29b5658381869f6020a785a16e29f6b20f327704b3222f44a93a9a136d572</hash>
        <hash alg="SHA3-256">25d801f8651850c5061d940489d0e37f1e612e971031584cab0356248d14628e</hash>
        <hash alg="SHA3-512">51024b085470f6bc966714d7feb188a7068752e10d837c2ec03ea4acf49d60cfeb5cebcb628f0b060f1311a7b53d95f466d66b05ff92b7c1b8d43a8c9f04215d</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.jsonwebtoken/jjwt-api@0.12.6?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/jwtk/jjwt/jjwt-api</url>
        </reference>
        <reference type="build-system">
          <url>https://travis-ci.org/jwtk/jjwt</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/jwtk/jjwt/issues</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/jwtk/jjwt.git/jjwt-api</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.jsonwebtoken/jjwt-impl@0.12.6?type=jar">
      <publisher>jsonwebtoken.io</publisher>
      <group>io.jsonwebtoken</group>
      <name>jjwt-impl</name>
      <version>0.12.6</version>
      <description>JSON Web Token support for the JVM and Android</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">e96f699bad6353508953424e82e5de45</hash>
        <hash alg="SHA-1">ac23673a84b6089e0369fb8ab2c69edd91cd6eb0</hash>
        <hash alg="SHA-256">ad80ceda467ddab64f0e729257dd5f72f61487cc3b92e696270e620f0d88168f</hash>
        <hash alg="SHA-512">52aa6dfb38c9caba248010ca9f46a04e7fe3666251bb6ee892c048fab2c9de21a0d6849ea5f08a4dec902a256a6f60a326c04c0f8acc95257ce288344bbf7929</hash>
        <hash alg="SHA-384">b5ec2cd687bb08ad57c9ab39e168bee96294e5fba971b0f0558a1bc1dcb1b10b0a742d76fff7f28b9797d1060860a369</hash>
        <hash alg="SHA3-384">1e718a95ddd029874fba2171696a109b31cd0eadb81aa37bbc12b60cb9b004a22da870076caa97f2a39a1843fe26527e</hash>
        <hash alg="SHA3-256">62a019c591096e7745734e0a3080f8b671a5b7fe12af3946b64e81c7a0706588</hash>
        <hash alg="SHA3-512">ceedfcaf594b9b125857c25f8613538caeb307b391f75873f6236bd0e77822d4d703efd22cddcba4f041332f24c56eeb2f9b1ffb2cbd92f03078a61635b3707f</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.jsonwebtoken/jjwt-impl@0.12.6?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/jwtk/jjwt/jjwt-impl</url>
        </reference>
        <reference type="build-system">
          <url>https://travis-ci.org/jwtk/jjwt</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/jwtk/jjwt/issues</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/jwtk/jjwt.git/jjwt-impl</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.jsonwebtoken/jjwt-jackson@0.12.6?type=jar">
      <publisher>jsonwebtoken.io</publisher>
      <group>io.jsonwebtoken</group>
      <name>jjwt-jackson</name>
      <version>0.12.6</version>
      <description>JSON Web Token support for the JVM and Android</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">a6f99a3cc5d2c7fd820f2aad638ca401</hash>
        <hash alg="SHA-1">f141e0c1136ba17f2632858238a31ae05642dbf8</hash>
        <hash alg="SHA-256">8f8c293730fa0241a0f882b6128c3e5b2c07f3ff3e6391126ef71e73ecb24ea0</hash>
        <hash alg="SHA-512">a6aaf9982adcb2e75406c9949f76b228a33fa48843b7615a4cebcff92e62060e302f529f22c6a70347b6c4dffb85534c75da18d0f496959ce5534a38c7d6bfbd</hash>
        <hash alg="SHA-384">ed4931e93e9a1e1919aa1a9464025f32292160c2e515accf885d427236b2e27befa2334ca2d40cfd17ad60a45d32e163</hash>
        <hash alg="SHA3-384">a047a2ddbfca4ed7114d768083e1b9c762a0ebbcb5f9d59ebdb7fce3b5c320fdf8ae4b44502a9ff073bc77d67bdc3952</hash>
        <hash alg="SHA3-256">15ba5e12d0087685f4dcd1d8e16e5c4c83a1ec88bfb1645756cc92d5a5c04735</hash>
        <hash alg="SHA3-512">c8747c5043a57413da5c9335274925bd37cd81bfecf0bdc4aa3b6c5aa6626d3dbc00591d0375351bddd0f0a37741c0cf1e100dfe5180313bbcbddf6618c81826</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.jsonwebtoken/jjwt-jackson@0.12.6?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/jwtk/jjwt/jjwt-jackson</url>
        </reference>
        <reference type="build-system">
          <url>https://travis-ci.org/jwtk/jjwt</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/jwtk/jjwt/issues</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/jwtk/jjwt.git/jjwt-jackson</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.eclipse.jetty/jetty-plus@11.0.26?type=jar">
      <publisher>Webtide</publisher>
      <group>org.eclipse.jetty</group>
      <name>jetty-plus</name>
      <version>11.0.26</version>
      <description>Jetty JavaEE style services</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">dcf7c1c5ba5c49cdd8bfd647c6d834a2</hash>
        <hash alg="SHA-1">3d74dc6697eac4ca4938d25f3729cd2d01a1187c</hash>
        <hash alg="SHA-256">343a85b4a29d8068d1bc53095e52287af6065a83f6ef4eac1b15002e83fc263e</hash>
        <hash alg="SHA-512">8b808469b7333b29c3e6afa163e2e2f3d6e3638cbcb835fb1cb23a94660783865e474450affea0c827601fc62d666a769debfda1797d67719a8cd914008ffb67</hash>
        <hash alg="SHA-384">8621e948e83268361da01bebbc3a41fb68a3d08043b8daece05d4ac2217dd3071a484eeb58b1fd4dc67c9d96fad03eb5</hash>
        <hash alg="SHA3-384">11e233d393099b892ffdedc5632c50a2988f97b6228c996c253a816572c85c4aef3c7c38a11a59fe9ac580f445366b0d</hash>
        <hash alg="SHA3-256">258846f7afaa90c4c8d7890af5f93c2100d4ddd5c66399211602c368b85b244c</hash>
        <hash alg="SHA3-512">48e2a600963b3ed78ded2ddc8863280fa17f9ed7288db69e2facf9d3478725677402c1c0459348a8a79f749362f8ea02e108b07d92ba460831974e318396d119</hash>
      </hashes>
      <licenses>
        <license>
          <id>EPL-2.0</id>
        </license>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.eclipse.jetty/jetty-plus@11.0.26?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://jetty.org/jetty-plus</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repo.maven.apache.org/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/jetty/jetty.project/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://www.eclipse.org/lists/jetty-dev/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/jetty/jetty.project/jetty-plus</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/jakarta.transaction/jakarta.transaction-api@2.0.0?type=jar">
      <publisher>EE4J Community</publisher>
      <group>jakarta.transaction</group>
      <name>jakarta.transaction-api</name>
      <version>2.0.0</version>
      <description>Jakarta Transactions</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">8cddb47aba40b4bf3f9eb8bb5c0b3e06</hash>
        <hash alg="SHA-1">24a0525b4acfbca4086d2f1278be3a084fe1c67d</hash>
        <hash alg="SHA-256">21474b7ee0ad764c05d5ad0bc430e5e647cdeabc86cb587477a7eca5be6e584b</hash>
        <hash alg="SHA-512">88c76b2da7a8c725e64074e30d1fa5797e36e9cf5bf67280d10c92d99452db89e0325fcf5bbe20052a96d3f73299f0fea699c850493fe0a64cd0e10dc9ce11b7</hash>
        <hash alg="SHA-384">cdac48a45cb496e659a2d262e8e36e3b89dcb822de44e84c1ef0a13919870646aa995eed70515986cd1438a09cb0cd3d</hash>
        <hash alg="SHA3-384">01757bfb62766e984c82e697f682e052ae038419690aa42b3b05ae19a6e8cacebb259b577576f109f8a04ba60e63cfec</hash>
        <hash alg="SHA3-256">6349e4e76de2d9fbb6523235480a38322292a5f292f6c2ec2125b1803d8833be</hash>
        <hash alg="SHA3-512">6ab2efa244f09dc552f35f99abe3dd8111a7ddaf62b3268ad5cad9b23c6993691481c6bec6fffc79c7faca9293fac655a6d12a719030837ff9c9e7a7b2738ad9</hash>
      </hashes>
      <licenses>
        <license>
          <id>EPL-2.0</id>
        </license>
        <license>
          <id>GPL-2.0-with-classpath-exception</id>
        </license>
      </licenses>
      <purl>pkg:maven/jakarta.transaction/jakarta.transaction-api@2.0.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://projects.eclipse.org/projects/ee4j.jta</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://jakarta.oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/eclipse-ee4j/jta-api/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://dev.eclipse.org/mhonarc/lists/jta-dev/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/eclipse-ee4j/jta-api</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.eclipse.jetty/jetty-jndi@11.0.26?type=jar">
      <publisher>Webtide</publisher>
      <group>org.eclipse.jetty</group>
      <name>jetty-jndi</name>
      <version>11.0.26</version>
      <description>JNDI spi impl for java namespace.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">847e25f8071a2ff23ad38140f3ba2dc4</hash>
        <hash alg="SHA-1">72a049d8517b6cb8a92234d695be8046f56cf786</hash>
        <hash alg="SHA-256">9062ae130a896cf764914c355110b7b479fceb357d1371fd03e9011ecce689a5</hash>
        <hash alg="SHA-512">116e5df4e8bfd1fcb2fbaa075e01c9fa78cf3d8acd6a9a5782227c9845c22f5955cc0849b08f3db82bbda94b1f811f952b6ddc3addbd6a36303f222ebaf7dee0</hash>
        <hash alg="SHA-384">4f4edf1d25791430947f734f767f600c62bdf90452a9a866d13e2950a0af3f152b7cbe9298bfefb42e13203f34d7140c</hash>
        <hash alg="SHA3-384">f31a59468ad72d4fdc355619d2d1a5a7558809a299664f9f38f6beb7e680c8d41ffbf90bb34b0f08be73d74065da0b64</hash>
        <hash alg="SHA3-256">136e4f38504fcb57733fb40f1b94a221d87d60471c419643ea1da035e0421c5e</hash>
        <hash alg="SHA3-512">b349b8b9b7c7023dd0a883a9685dbbc248860dc83d44ea3664635129bd601e220e879c45d6da4bb31ddf78c173e1e99fec3cdb230f825947360d8b48e832a26c</hash>
      </hashes>
      <licenses>
        <license>
          <id>EPL-2.0</id>
        </license>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.eclipse.jetty/jetty-jndi@11.0.26?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://jetty.org/jetty-jndi</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repo.maven.apache.org/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/jetty/jetty.project/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://www.eclipse.org/lists/jetty-dev/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/jetty/jetty.project/jetty-jndi</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.eclipse.jetty/jetty-webapp@11.0.26?type=jar">
      <publisher>Webtide</publisher>
      <group>org.eclipse.jetty</group>
      <name>jetty-webapp</name>
      <version>11.0.26</version>
      <description>Jetty web application support</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">88f929b0cfd7dab52cbbb85ebb9af2f0</hash>
        <hash alg="SHA-1">00427240d0dbb73e7da66bcbfa52e50f12510c19</hash>
        <hash alg="SHA-256">fe45152f8b84be3563abafd6c0b995e13b9a685799adf8b2e57ac6401edaeed1</hash>
        <hash alg="SHA-512">4838c69d87caf2fbf9333629c6d7776a7a13059e485207e7054e62559206a9265583436824283068d7842717bf97a4ba08f99c455f933c208b95fc0cb3bf29b9</hash>
        <hash alg="SHA-384">2b27eb507da6ae24dcbbf39c7eb514f6fa0873f9a1e048edc5338cd5c3d86fc7989071935a7f8e7c7ee3a7f05621941f</hash>
        <hash alg="SHA3-384">b6f72b8af03cbe0236c7e44055599a7f6da3105e2102f26e46032683ccb42b6a6f7265c1827a747f87b47c467e20056c</hash>
        <hash alg="SHA3-256">1ae755a7dcaeb69d858de0213bc9def845c745b844c7424108c7df6a8c354c35</hash>
        <hash alg="SHA3-512">8cd61b01dfc2dd23fcfeb25158bf3af6b3070601b4603bd8f20d77a610c7b90e1e44b547957e4cc2e039621f7586a20f3596a96076a601af9486c227380eb995</hash>
      </hashes>
      <licenses>
        <license>
          <id>EPL-2.0</id>
        </license>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.eclipse.jetty/jetty-webapp@11.0.26?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://jetty.org/jetty-webapp</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repo.maven.apache.org/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/jetty/jetty.project/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://www.eclipse.org/lists/jetty-dev/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/jetty/jetty.project/jetty-webapp</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.eclipse.jetty/jetty-xml@11.0.26?type=jar">
      <publisher>Webtide</publisher>
      <group>org.eclipse.jetty</group>
      <name>jetty-xml</name>
      <version>11.0.26</version>
      <description>The jetty xml utilities.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">889271f3a3ab25fd91609c17f7fefe28</hash>
        <hash alg="SHA-1">77056b654507fc7f1d4c50a649265195b4284676</hash>
        <hash alg="SHA-256">16fa7061a52d6052f4e1ed64dd1d61601d210bddc9ed6dbde8621b0edb7beb1f</hash>
        <hash alg="SHA-512">d117113a9aad2c45f379dc0e1120ca974040e9a3228967ccbc105760986f57809e77e86f969fa62a55dd3f28a4c25c0ad295773133d143d3c0172591016042b8</hash>
        <hash alg="SHA-384">864db3559cd4424916c2520bfcb4b75c5db85128b1baf11945499af347cbb5ead4a6fcee709025dc3c969347450661e2</hash>
        <hash alg="SHA3-384">eda8b60e8f936e4a8743314966d9e00f7e59bc87fac411dd421f1a3619275445d42028aa469e7f592c0c185d67364e27</hash>
        <hash alg="SHA3-256">f6d45074e5c4c78ce470a4fe9d7773cdfb1cd6c5bd419ce5762c606201c0b09d</hash>
        <hash alg="SHA3-512">27ee464fa8e33cb752a95b8d6a48fc12a148a00d0718c39d2d0f067093bf4aa7d4250f7817d7a51851d52754453e44e82e79c713ae082bbf695745af5bbb504c</hash>
      </hashes>
      <licenses>
        <license>
          <id>EPL-2.0</id>
        </license>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.eclipse.jetty/jetty-xml@11.0.26?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://jetty.org/jetty-xml</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repo.maven.apache.org/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/jetty/jetty.project/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://www.eclipse.org/lists/jetty-dev/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/jetty/jetty.project/jetty-xml</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.eclipse.jetty/jetty-security@11.0.26?type=jar">
      <publisher>Webtide</publisher>
      <group>org.eclipse.jetty</group>
      <name>jetty-security</name>
      <version>11.0.26</version>
      <description>Jetty security infrastructure</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">a916df9c92ff6507e2b6cfd1c806e491</hash>
        <hash alg="SHA-1">998cc26af3ddafff3a65eb57dc14b597c3fb8cf8</hash>
        <hash alg="SHA-256">1f0a1b58304741f243e2f6ac694e6506b1e26bb079cfc2baaa3f2a6ed4bf2d9f</hash>
        <hash alg="SHA-512">4e39a16eb5fe216bb3e56f3d27348d52bf08c17701e1538323638f6670846c0258bd3f4b29f7ff6cda8c22e4062afce0a3b6cb67b117f8b260f145f201a307da</hash>
        <hash alg="SHA-384">46f5aca8067d4eee18be6614cda31bb6a03580c02d4f2e3f1a52af8f8fb151131e18400381a9382e75d3010fc07560dc</hash>
        <hash alg="SHA3-384">c113e76dafa52d6d6912974141bba9c0a2cf759c6fe33516d7b25d5e4f8805680047f844a3fa5287e4640534eb9a2dab</hash>
        <hash alg="SHA3-256">498a406e356aef620ffb004cf9a5282adc0b81424090d955a1b5d83a76adf027</hash>
        <hash alg="SHA3-512">998e201414022290b46071d50665180b89d3e863df897629e3a07cd837bdea5b26451674e8d196803f9580ca22770d6cfe9671254766681d56b26ac5d8838e41</hash>
      </hashes>
      <licenses>
        <license>
          <id>EPL-2.0</id>
        </license>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.eclipse.jetty/jetty-security@11.0.26?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://jetty.org/jetty-security</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repo.maven.apache.org/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/jetty/jetty.project/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://www.eclipse.org/lists/jetty-dev/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/jetty/jetty.project/jetty-security</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.eclipse.jetty/jetty-util@11.0.26?type=jar">
      <publisher>Webtide</publisher>
      <group>org.eclipse.jetty</group>
      <name>jetty-util</name>
      <version>11.0.26</version>
      <description>Utility classes for Jetty</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">324a57e928ea8947cf4d39dc05c0b372</hash>
        <hash alg="SHA-1">452deb24d06d79f8a54731952b7e3dd8377bcdbc</hash>
        <hash alg="SHA-256">1b61b875a6d40e8fd44cffb307bdb66f3459370a152a50a092a698c3737eeca9</hash>
        <hash alg="SHA-512">f66c29c55131d635928cf6a22082eacd6c226f9179d4a2003dd7be01e017f5f67e43f367847e2e33bea859dcdaad4db2f4bd291c63eb5d9d576dc55e8a5d7810</hash>
        <hash alg="SHA-384">03d587b78f13a76bed8f09957674e72a948511246175b598679e01a5494b3c1a850e206898d1bd68fae8bc5ca17ec579</hash>
        <hash alg="SHA3-384">b8ddc3a671d5552d3d02901ae13afc103f211cac6a36f3c862c86fb4d51ff6d807f9b92d4c29c85ce17ac23a434120b9</hash>
        <hash alg="SHA3-256">44a5ab163d699fc6b122e01dc8bd483cb539a7c7d68f26bdd60f0259d147e82b</hash>
        <hash alg="SHA3-512">5c19cb5adab5fe13ffad93ea722bf5d2809217e748c3db6158bae95f9d14a9dac35518b63480ab36f40bffd1a9cc0cb4ccceeef007dda8361b68e9cc4e793deb</hash>
      </hashes>
      <licenses>
        <license>
          <id>EPL-2.0</id>
        </license>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.eclipse.jetty/jetty-util@11.0.26?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://jetty.org/jetty-util</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repo.maven.apache.org/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/jetty/jetty.project/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://www.eclipse.org/lists/jetty-dev/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/jetty/jetty.project/jetty-util</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.eclipse.jetty/jetty-http@11.0.26?type=jar">
      <publisher>Webtide</publisher>
      <group>org.eclipse.jetty</group>
      <name>jetty-http</name>
      <version>11.0.26</version>
      <description>The Eclipse Jetty Project</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">2493b69799e38b95d03e6eb7f281df45</hash>
        <hash alg="SHA-1">6702b5714ff0b174bf6aa62ebbaa8fb5c34792ad</hash>
        <hash alg="SHA-256">de738c8cfd5701627b5373c42376453beb8276f989d75e5258e3b1ffe217e938</hash>
        <hash alg="SHA-512">4b8b3b0a77a5fe8102bbc9c4f31498576c54c79a429e84d5bfbd942828c44dc3b376291a82f0df72b5f28568a0cf454ac3b593e92df4e44da6aa5b8962478c4d</hash>
        <hash alg="SHA-384">2715f33c7ddf6ac5c18d7f63bdb9082f130b562fe16db64f1cb96b89165bd517a7aa9284b433150b6dbd34f8f1e38d98</hash>
        <hash alg="SHA3-384">647e03e2fdabebf097ed257c4175189047cc6f54f79cb208bc729dcb32404ede0b3f8694fb0a42254976c9ec69833a80</hash>
        <hash alg="SHA3-256">5c26bab514f0e2227876778c502faf0743d9bf9cebfa36149c80a682f7e9e39f</hash>
        <hash alg="SHA3-512">281cdf23996fec66941b8158fbc40c75132faa21ff0ca910a2a7ddfbab5562e197129077336f9940469ac16e569a6f5412fcbb697973ef102922470df8cc8df2</hash>
      </hashes>
      <licenses>
        <license>
          <id>EPL-2.0</id>
        </license>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.eclipse.jetty/jetty-http@11.0.26?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://jetty.org/jetty-http</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repo.maven.apache.org/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/jetty/jetty.project/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://www.eclipse.org/lists/jetty-dev/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/jetty/jetty.project/jetty-http</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.eclipse.jetty/jetty-proxy@11.0.26?type=jar">
      <publisher>Webtide</publisher>
      <group>org.eclipse.jetty</group>
      <name>jetty-proxy</name>
      <version>11.0.26</version>
      <description>Jetty Proxy</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">e8e9ce13e70a41b8f572180b9f295964</hash>
        <hash alg="SHA-1">acc1953d0375395d496257de473c7c640383fa35</hash>
        <hash alg="SHA-256">c5caa121f7a78574c25b33f65c82ed6f1ffbb7f683777653d1ebe4460d3f10da</hash>
        <hash alg="SHA-512">3fca03259a4e5154af0da5d00360527d903a3af9b75acf9703eac9ed67cf38c0d262f9be28b1ff47c5ce6c29bdf67ac6933e9aee238a12daab045bcd90320e89</hash>
        <hash alg="SHA-384">13a1bf818ef8f922ee5a2af0389d609123f259d2944dde456ebb82195e26e22f1403ad9b0b9450ff5ca5e67b819052c0</hash>
        <hash alg="SHA3-384">9f2767fb7bf66a7436f2bf9068a0522b387732a7280b529b974d493c0a5dec38532b349195c3f70683d408477a841f96</hash>
        <hash alg="SHA3-256">f46823b73c98118ac3dc04b2addc0f82798478c6ae1f84a45e78a3ace2a4c0b0</hash>
        <hash alg="SHA3-512">96c3602e95cb3844baea594fd0b135448119f43cd00e51aebc0026c1c471bea0ab3ee2b177b2c8ba9e70c01046181f108b07b70f746ba6ca2c3bdd2a4f680f93</hash>
      </hashes>
      <licenses>
        <license>
          <id>EPL-2.0</id>
        </license>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.eclipse.jetty/jetty-proxy@11.0.26?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://jetty.org/jetty-proxy</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repo.maven.apache.org/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/jetty/jetty.project/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://www.eclipse.org/lists/jetty-dev/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/jetty/jetty.project/jetty-proxy</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.eclipse.jetty/jetty-client@11.0.26?type=jar">
      <publisher>Webtide</publisher>
      <group>org.eclipse.jetty</group>
      <name>jetty-client</name>
      <version>11.0.26</version>
      <description>The Eclipse Jetty Project</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">144329f9d60177f25dd0962e8abae53b</hash>
        <hash alg="SHA-1">3ba93f5d166d5b49ee626283070b5304c22434ad</hash>
        <hash alg="SHA-256">77da3e1dbb0d0f288f8629d7ba2f71e80aebb8f218a5dcfa888278c7fa5e04fd</hash>
        <hash alg="SHA-512">e78de2beaac65c0dd3328012636447efa71857e80bfdac6e8c71001e5126cd4ac8b682ef956ae3044a3851c2daab379aa61cd26a58af137e7f01e33c459c97cb</hash>
        <hash alg="SHA-384">0742a0fa1d495e8772befca9b041bf4a92d5b7c1984ee63eb9bf516711036b95505336d96348dd41a4ed6a6d826873b8</hash>
        <hash alg="SHA3-384">695bedf82879250f73a678b9fc208520b6404ec529adbdfe752d5cc1f0554477c21b7418095b2dae628860029a6ef3ce</hash>
        <hash alg="SHA3-256">1a64505dd9ef55bc0d326f614027eeab68888f8e896fae946d5d30779fa6c233</hash>
        <hash alg="SHA3-512">edae03486cadd48f684dc4b98c0745a1862864950d22b8e91f4c4620947d8b34b8ea8c60cf785de6ea6e03b3a0a397a9fb66fe9a92bcfb143d6de3a16c22b862</hash>
      </hashes>
      <licenses>
        <license>
          <id>EPL-2.0</id>
        </license>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.eclipse.jetty/jetty-client@11.0.26?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://jetty.org/jetty-client</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repo.maven.apache.org/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/jetty/jetty.project/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://www.eclipse.org/lists/jetty-dev/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/jetty/jetty.project/jetty-client</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.eclipse.jetty/jetty-alpn-client@11.0.26?type=jar">
      <publisher>Webtide</publisher>
      <group>org.eclipse.jetty</group>
      <name>jetty-alpn-client</name>
      <version>11.0.26</version>
      <description>The Eclipse Jetty Project</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">01bf62969a45f81608f1232f41308157</hash>
        <hash alg="SHA-1">cfac480868305ce9b9176048d5f8d5abe3965c33</hash>
        <hash alg="SHA-256">00cae1113d6051aa15f3259c96def9064793756dc62c5f1ae2363b16c55b533f</hash>
        <hash alg="SHA-512">cc5e3e16203306a58f89831153d059f19d40aadd0bc483ebc22bc1c28faaac60665de62b0a0bc5b15e5f7369dee96a7de8e8aabaad2c4092145e27d6162ef75e</hash>
        <hash alg="SHA-384">6780750f936dc7675452ba3985e94de4ebc830f29c22683d090c3d53ecf3be22152dfee4f11a1d7daa2cfae3bd5bdd2b</hash>
        <hash alg="SHA3-384">f0338c61ba2d7069c1c31a87a45f30ac0b9fe733b56b4337759a5be484aec9e31d31ff74909e9c67cbe61c99f3828d7d</hash>
        <hash alg="SHA3-256">6c2e04aec8577e7bb9a56d2b59848e5f513cdf9841b1a11a466d2ab5f02dbbe6</hash>
        <hash alg="SHA3-512">bb9ab1b0c9e9ed80110be360bbdf852e556fa7cf6fd890dd88866e562e5baf5e1458f65a88d1ebc50ad1bf2a6430304b16c14900747e40cd8d3e4c1bca4e584f</hash>
      </hashes>
      <licenses>
        <license>
          <id>EPL-2.0</id>
        </license>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.eclipse.jetty/jetty-alpn-client@11.0.26?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://jetty.org/jetty-alpn-parent/jetty-alpn-client</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repo.maven.apache.org/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/jetty/jetty.project/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://www.eclipse.org/lists/jetty-dev/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/jetty/jetty.project/jetty-alpn-parent/jetty-alpn-client</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.eclipse.jetty/jetty-servlets@11.0.26?type=jar">
      <publisher>Webtide</publisher>
      <group>org.eclipse.jetty</group>
      <name>jetty-servlets</name>
      <version>11.0.26</version>
      <description>Utility Servlets from Jetty</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">1a935f013b5037ca905cb42b82ad9eb2</hash>
        <hash alg="SHA-1">65b0c8f59f5fa00f659958f44ceff13ba184df0c</hash>
        <hash alg="SHA-256">535c0b8ac57e5c1fbcdeb9c200dac5c01d38421034d4d7cffc948bb3ad6f6f09</hash>
        <hash alg="SHA-512">9f8eabc077285da018a8572eab040419a3a3359e23e642c27e998874f00b482531ee0ad471ea8afad1c19bd673b54c7d94d8e2de6532a1936766f27ae7548dcb</hash>
        <hash alg="SHA-384">80d736680b195510eadf12311ad07e68294435415b3dd6f1aea61020eaa5a15c4194ce6ded38464dafedc676697946f2</hash>
        <hash alg="SHA3-384">8aefe00cafa1a83fe9f093fa74b778d718ac2ecb09253d96965128f1dc0ed313aebcd6946abad700eddaeceb1a5b5a33</hash>
        <hash alg="SHA3-256">9483dd02ada4d1c6ae3f29885350b10ee1f8a2a4c6b970393853278f998d4635</hash>
        <hash alg="SHA3-512">789776755b164c891da3e2fa4b37ff61088a400d9ce935c051cf635f9910aeba812cbc49680d9c2e932fd027ce0851b55a1f9420fa45466956e51f17bdd7cd49</hash>
      </hashes>
      <licenses>
        <license>
          <id>EPL-2.0</id>
        </license>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.eclipse.jetty/jetty-servlets@11.0.26?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://jetty.org/jetty-servlets</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repo.maven.apache.org/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/jetty/jetty.project/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://www.eclipse.org/lists/jetty-dev/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/jetty/jetty.project/jetty-servlets</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/jakarta.servlet/jakarta.servlet-api@5.0.0?type=jar">
      <publisher>Eclipse Foundation</publisher>
      <group>jakarta.servlet</group>
      <name>jakarta.servlet-api</name>
      <version>5.0.0</version>
      <description>Eclipse Enterprise for Java (EE4J) is an open source initiative to create standard APIs,
        implementations of those APIs, and technology compatibility kits for Java runtimes
        that enable development, deployment, and management of server-side and cloud-native applications.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">b950da93e08cf6d5a2d73dc7a80f9403</hash>
        <hash alg="SHA-1">2e6b8ccde55522c879434ddec3714683ccae6867</hash>
        <hash alg="SHA-256">33d3a5bda82c7d2f1b898685faa954f1fc34f7b0ae5c2f6ccc6d051e8a10973b</hash>
        <hash alg="SHA-512">667578d33b939b606bc38322e5cd8d0be4eacedf86e13f34b6c7c9d8ec6ef719ac7b4d830eba2588a4ea5c924fe3772960e94a99642a039f1781421e7eacb1e6</hash>
        <hash alg="SHA-384">329e54722e5da97d1c8d049c4dd68b0d8e22f72b299c2dd4db7f1bd3b07de4cf891402904760dca4584e30193741b11b</hash>
        <hash alg="SHA3-384">4b41bfe405d59203409fe3a5a5d11f177eabe7cd0eb7994dfe1f907c67c93a766959f703dfee1ef9925d420d0dadf9a0</hash>
        <hash alg="SHA3-256">b73926ebe8f21e0d3f440f9e7f3a229fae7975b34afeaa5c42d4334cb1d86121</hash>
        <hash alg="SHA3-512">a85b76f03626ad4d02779d812190fb4b44fddf132dda92c0c908a7eb182f202b0f02f54eea500d92b3a5667d5288e03269530b63c7f72504f424d3dbf5f8c48e</hash>
      </hashes>
      <licenses>
        <license>
          <id>EPL-2.0</id>
        </license>
        <license>
          <id>GPL-2.0-with-classpath-exception</id>
        </license>
      </licenses>
      <purl>pkg:maven/jakarta.servlet/jakarta.servlet-api@5.0.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://projects.eclipse.org/projects/ee4j.servlet</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://jakarta.oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/eclipse-ee4j/servlet-api/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://dev.eclipse.org/mhonarc/lists/servlet-dev</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/eclipse-ee4j/servlet-api</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.commons/commons-compress@1.28.0?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.commons</group>
      <name>commons-compress</name>
      <version>1.28.0</version>
      <description>Apache Commons Compress defines an API for working with
compression and archive formats. These include bzip2, gzip, pack200,
LZMA, XZ, Snappy, traditional Unix Compress, DEFLATE, DEFLATE64, LZ4,
Brotli, Zstandard and ar, cpio, jar, tar, zip, dump, 7z, arj.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">f33efe616d561f8281ef7bf9f2576ad0</hash>
        <hash alg="SHA-1">e482f2c7a88dac3c497e96aa420b6a769f59c8d7</hash>
        <hash alg="SHA-256">e1522945218456f3649a39bc4afd70ce4bd466221519dba7d378f2141a4642ca</hash>
        <hash alg="SHA-512">f1f140f4f40ab3cf3265919db9dbb95a631a29aa784e305f291de4e68876bb711d9217d62d7937cddddd393982decdf71a608b4b3ab7f4e6375cf28af2893d7f</hash>
        <hash alg="SHA-384">afe6a8fc8e7486c4ecce95276bb1467763d7ff7d941c7bcff8661bbbd4bff442fd0899ff7a11bc540cda86818ee4a8f0</hash>
        <hash alg="SHA3-384">6afb636ad0805e522913cfd91c8293c485b7f4eff5e45dd3a17a716c3f4b8ab8969e9c00927559a5fb762cba1fdb3d3f</hash>
        <hash alg="SHA3-256">4420e0b462b5dcc45077e95e012a82a5ae17659e5abe8a685fa086dab6995298</hash>
        <hash alg="SHA3-512">23e37d13c8ee6c7369e407c29d1f9ee1bb44eca9f09a6f9742f6b4cf3d38dd7a0509fe0142536cd8087b68a76e71d819105af2c23f2aeed08acc58eb93cf7e61</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.commons/commons-compress@1.28.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://commons.apache.org/proper/commons-compress/</url>
        </reference>
        <reference type="build-system">
          <url>https://github.com/apache/commons-compress/actions</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://issues.apache.org/jira/browse/COMPRESS</url>
        </reference>
        <reference type="mailing-list">
          <url>https://mail-archives.apache.org/mod_mbox/commons-user/</url>
        </reference>
        <reference type="vcs">
          <url>https://gitbox.apache.org/repos/asf?p=commons-compress.git</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.commons/commons-lang3@3.19.0?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.commons</group>
      <name>commons-lang3</name>
      <version>3.19.0</version>
      <description>Apache Commons Lang, a package of Java utility classes for the
  classes that are in java.lang's hierarchy, or are considered to be so
  standard as to justify existence in java.lang.

  The code is tested using the latest revision of the JDK for supported
  LTS releases: 8, 11, 17 and 21 currently.
  See https://github.com/apache/commons-lang/blob/master/.github/workflows/maven.yml
  
  Please ensure your build environment is up-to-date and kindly report any build issues.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">2ac2db154e365d55d167ec1215125a3a</hash>
        <hash alg="SHA-1">d6524b169a6574cd253760c472d419b47bfd37e6</hash>
        <hash alg="SHA-256">32733ab4bc90b45b63eb72677d886961003fd4ed113e07b1028f9877cb2ac735</hash>
        <hash alg="SHA-512">24cf9bfc7c32736277d2a1e82a455d004ec7d4989e8d0dc2831c910a04b6ff8b30ca9c49ec25562cf0b7f1ffc27726e7510a54bb99e75a3be83ddf6030c37978</hash>
        <hash alg="SHA-384">90c567c8f42b58d0f3f24233260258e7e3bae1f8284ee33f9730e1cecc4fe2c98b7d6ebbba2a6598b50d444ddfa70722</hash>
        <hash alg="SHA3-384">397a7aafd4f66cdec80cf4682a72db0873b3fc6a3db3cdd7be747b24ae13804dfc290e2441a115d50b0add9ce76af2dd</hash>
        <hash alg="SHA3-256">4c0809e7ff0474603b0a1bcdf2f745cec9233ffdc6c652b077d93f2630d52f8b</hash>
        <hash alg="SHA3-512">25564027878618e00dc24ea5caf8365a9396c25597aaf4ea8a37997fd699dabdf4b6f9ce4c1c9f86abedb4afa26041ac234d238c63ffecc207ce2068a6271956</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.commons/commons-lang3@3.19.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://commons.apache.org/proper/commons-lang/</url>
        </reference>
        <reference type="build-system">
          <url>https://github.com/apache/commons-lang/actions</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://issues.apache.org/jira/browse/LANG</url>
        </reference>
        <reference type="mailing-list">
          <url>https://mail-archives.apache.org/mod_mbox/commons-user/</url>
        </reference>
        <reference type="vcs">
          <url>https://gitbox.apache.org/repos/asf/commons-lang.git</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.commons/commons-math3@3.6.1?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.commons</group>
      <name>commons-math3</name>
      <version>3.6.1</version>
      <description>The Apache Commons Math project is a library of lightweight, self-contained mathematics and statistics components addressing the most common practical problems not immediately available in the Java programming language or commons-lang.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">5b730d97e4e6368069de1983937c508e</hash>
        <hash alg="SHA-1">e4ba98f1d4b3c80ec46392f25e094a6a2e58fcbf</hash>
        <hash alg="SHA-256">1e56d7b058d28b65abd256b8458e3885b674c1d588fa43cd7d1cbb9c7ef2b308</hash>
        <hash alg="SHA-512">8bc2438b3b4d9a6be4a47a58410b2d4d0e56e05787ab24badab8cbc9075d61857e8d2f0bffedad33f18f8a356541d00f80a8597b5dedb995be8480d693d03226</hash>
        <hash alg="SHA-384">95d1186d9ca06a3ea2e6437ddec3a55698e2493d3e72f6f554746b74fa929892bd71a2ab501a4e7b1ce56b7cd64e7ab4</hash>
        <hash alg="SHA3-384">f85bb3e46a00fc4940a3be1331301302b0eb728e2d1fe2c1842d4761e5a0bc7a420c0c705ae60250ca1c7b03d3694b9e</hash>
        <hash alg="SHA3-256">919c15ae4b1aef2a58aa6ea4b700bc5562e78dbc382f3393169425ca91ad368c</hash>
        <hash alg="SHA3-512">dbe54d586c898cdbd7df6c31c131ca3525db17fcea5c7f5da8cbfe617e2afc667289290c76771ec5c9567a56fb2b177b0a31d67abcc656410c90287da4d88999</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.commons/commons-math3@3.6.1?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://commons.apache.org/proper/commons-math/</url>
        </reference>
        <reference type="build-system">
          <url>https://continuum-ci.apache.org/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>http://issues.apache.org/jira/browse/MATH</url>
        </reference>
        <reference type="mailing-list">
          <url>http://mail-archives.apache.org/mod_mbox/commons-user/</url>
        </reference>
        <reference type="vcs">
          <url>https://git-wip-us.apache.org/repos/asf?p=commons-math.git</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.commons/commons-text@1.14.0?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.commons</group>
      <name>commons-text</name>
      <version>1.14.0</version>
      <description>Apache Commons Text is a set of utility functions and reusable components for processing
    and manipulating text in a Java environment.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">54960a12a82d52df3d5548d6934d87b2</hash>
        <hash alg="SHA-1">adcb0d4c67eabc79682604b47eb852aaff21138a</hash>
        <hash alg="SHA-256">121fce2282910c8f0c3ba793a5436b31beb710423cbe2d574a3fb7a73c508e92</hash>
        <hash alg="SHA-512">4975879372241025bd0a47fe540ed7d0cd3e5eba474b12af67a8c6016be0fbb4f4a3a4a0064f4d2b6aebce67d88ee814da345a5ba3a6ee4f6293b3b4e7bbd065</hash>
        <hash alg="SHA-384">a038f1a8b58bb7ec17ba55238d3e40f5d9386dfb17870630a728b22741a9592819374e9abbbc6402a439eea4db5b739a</hash>
        <hash alg="SHA3-384">5325922bb72aa73d2d51cb3fb5592fc77097614fd3ab3ac77e3acdc0fe1dc8c18893cdd9a05768bb725fa40dd8c14527</hash>
        <hash alg="SHA3-256">31008266592ec8503bcc7f6b4e7125b0e377f57f3a697cdcb02ee7f20f84ddf1</hash>
        <hash alg="SHA3-512">385249425d8c6ab181039195a03c6337f393a1e1419527e9f072d695367bc0bd6546e752d1912df557bd8788329f7609aa1c63ce42eb135e2d27b6141ce9280f</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.commons/commons-text@1.14.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://commons.apache.org/proper/commons-text</url>
        </reference>
        <reference type="build-system">
          <url>https://github.com/apache/commons-text/actions</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://issues.apache.org/jira/browse/TEXT</url>
        </reference>
        <reference type="mailing-list">
          <url>https://mail-archives.apache.org/mod_mbox/commons-user/</url>
        </reference>
        <reference type="vcs">
          <url>https://gitbox.apache.org/repos/asf?p=commons-text.git</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/commons-io/commons-io@2.21.0?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>commons-io</group>
      <name>commons-io</name>
      <version>2.21.0</version>
      <description>The Apache Commons IO library contains utility classes, stream implementations, file filters,
file comparators, endian transformation classes, and much more.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">bc7e020873f086ede85f97bd9f013215</hash>
        <hash alg="SHA-1">52a6f68fe5afe335cde95461dd5c3412f04996f7</hash>
        <hash alg="SHA-256">7d643a2afea8b058b762aa6fb90e5b256f6c729739f8b3784c3370ddc609e88d</hash>
        <hash alg="SHA-512">7ac1aa4d834cd7cdecaee223a64c63d481810c73dfdb5109f402234a05cadf754e414cead99072f5140d4f7042ee084161935fb28129a631d908d989c5bbac5d</hash>
        <hash alg="SHA-384">97c07e5c4f62484c98b6777f63ab032ee09eeb1c9ddae8332890126df9c665afb9cd554db02495171738720d23c53732</hash>
        <hash alg="SHA3-384">e3e44c9f4a5f4075fb62a438a84015fe2abf878e9793835a7816dc3c35141bb79fe96dfdc6bb5aef96b7c5bbbcf453c1</hash>
        <hash alg="SHA3-256">1f8f4ce25b7169452dabb10ce843b3246378ea55c1971acd2300e417747b3a68</hash>
        <hash alg="SHA3-512">175630adf10305aeb31d737f833021a25582ffe2ef66fda6e7f694598af9c68cebbd205ade469eca4faaf6b9d349244289e62179d9cf48d93427090e2c008cf8</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/commons-io/commons-io@2.21.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://commons.apache.org/proper/commons-io/</url>
        </reference>
        <reference type="build-system">
          <url>https://github.com/apache/commons-io/actions</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://issues.apache.org/jira/browse/IO</url>
        </reference>
        <reference type="mailing-list">
          <url>https://mail-archives.apache.org/mod_mbox/commons-user/</url>
        </reference>
        <reference type="vcs">
          <url>https://gitbox.apache.org/repos/asf?p=commons-io.git</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.commons/commons-collections4@4.5.0?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.commons</group>
      <name>commons-collections4</name>
      <version>4.5.0</version>
      <description>The Apache Commons Collections package contains types that extend and augment the Java Collections Framework.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">d564105594035b363b193d8ce3c18b98</hash>
        <hash alg="SHA-1">e5cf89f0c6e132fc970bd9a465fdcb8dbe94f75a</hash>
        <hash alg="SHA-256">00f93263c267be201b8ae521b44a7137271b16688435340bf629db1bac0a5845</hash>
        <hash alg="SHA-512">ee43c513ac9dcbd7dd23b5cbb4ea5f65a2e10cdfbb403d080b87e778b3b45062315522297c41eca514a9a946228ad7650f0a572d5b78effb8260dd8084131988</hash>
        <hash alg="SHA-384">73db8eb3e79569b3fa62aefdce413e6ea250b9853953cb75b9d5ce0f2f35b59b6e86ef708326a608ff20d95bdade8522</hash>
        <hash alg="SHA3-384">7a9c035fa846cdcebd4331eb86ed31a67595518299a8bee54597c1eb663aee63214553a561a510b929035266c2a4800b</hash>
        <hash alg="SHA3-256">614c41bfd8f9c6c1c1e5667c5be45587c3021b780937ad62f54d17051f425086</hash>
        <hash alg="SHA3-512">3cfd12ec2d03ed29b682123cedae422a4c6dc459034a7e0ab5f00ccd422cb9a2ec423a08b953119c426569b888157a6d80aa0e0c63debea50c5c54c481e2eff5</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.commons/commons-collections4@4.5.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://commons.apache.org/proper/commons-collections/</url>
        </reference>
        <reference type="build-system">
          <url>https://github.com/apache/commons-parent/actions</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://issues.apache.org/jira/browse/COLLECTIONS</url>
        </reference>
        <reference type="mailing-list">
          <url>https://mail-archives.apache.org/mod_mbox/commons-user/</url>
        </reference>
        <reference type="vcs">
          <url>https://gitbox.apache.org/repos/asf?p=commons-collections.git</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/com.ning/compress-lzf@1.1.2?type=jar">
      <publisher>FasterXML</publisher>
      <group>com.ning</group>
      <name>compress-lzf</name>
      <version>1.1.2</version>
      <description>Compression codec for LZF encoding for particularly encoding/decoding, with reasonable compression.
Compressor is basic Lempel-Ziv codec, without Huffman (deflate/gzip) or statistical post-encoding.
See "http://oldhome.schmorp.de/marc/liblzf.html" for more on original LZF package.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">f620dc5d92f58cfdb1c51895daf05f58</hash>
        <hash alg="SHA-1">d09d33ffa7bc1d987db92e5ebec926ff92b7cbdf</hash>
        <hash alg="SHA-256">a9a76c85a3cef3a22d4c0e8647a1449b638885f2ceb4d8c9f66df3c677cc228e</hash>
        <hash alg="SHA-512">ec119a239e5dc1a213ae06380cdaa1ab07049430485fd2e5651281ae53705feb4d5dd767ac87aca8e329adcd1e1325585d50b273738e6cb2b94b31c7156828b2</hash>
        <hash alg="SHA-384">f00e771ca4878a82ac6698fef4b8b17474fef2b3602ac850ec352a66d43cd798270a215313b17d98096e2f017eb7095a</hash>
        <hash alg="SHA3-384">2421eaa3ea9bb3aa1d2cedff792950ef197bf3759357e916dc37b27529fc7862aaacd02dc6dffea7819fcaf9ebc2c3c5</hash>
        <hash alg="SHA3-256">706e6da01e6e6c8c31d59f91039937941918269763a5a944fc620666e21b2e15</hash>
        <hash alg="SHA3-512">d3d6bb73de4a09c8f0956881f532167d01480f5359d035e42746e7d04757b9ab7752e9a1107c1aea5afd232f06e31b907dd856873b23a9b681744f32ab520609</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/com.ning/compress-lzf@1.1.2?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/ning/compress</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/ning/compress/issues</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/ning/compress</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.xerial.snappy/snappy-java@1.1.10.8?type=jar">
      <publisher>xerial.org</publisher>
      <group>org.xerial.snappy</group>
      <name>snappy-java</name>
      <version>1.1.10.8</version>
      <description>snappy-java: A fast compression/decompression library</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">a25bd213d1ca2f3c605c5f03050db070</hash>
        <hash alg="SHA-1">ccbaa2b5ea6a023a27c44daf2d6cdec0e138592d</hash>
        <hash alg="SHA-256">50485d06037fea3d6e40c968386feeca6338cc9872e25549593ff3eb352cefcc</hash>
        <hash alg="SHA-512">c7133f726f366b9f06df98d94b4dd7c91c7702c543e1a318055a886af5e625d8231b0a6728250596181bc20a6c4147855eeb02ed55c447fe13ff2156e29985a9</hash>
        <hash alg="SHA-384">aeb78b3f4c56ce769f5fda9cfabe00be77d21b93637f70601c28b16eef41405e1291001c3a6e45001b356543e33b664b</hash>
        <hash alg="SHA3-384">6137f6354b574d8decb579ad9147dd9463e3a9f62d1e929266bee1adc020f57382973d0a1abf9daeb2007bb32671fed8</hash>
        <hash alg="SHA3-256">f44a4a8cffe82ce6c99b401e9d822e71cdfc63c1b279b278282eda07243b2a94</hash>
        <hash alg="SHA3-512">655731ef3b20a2cec213138c170f7dc7182c2a09536d74c1d8a13224bb204dd706a35749bf99b51c4b945b75784a0a26c60931a158d27e1378ccd1c8ac7a0783</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.xerial.snappy/snappy-java@1.1.10.8?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/xerial/snappy-java</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/xerial/snappy-java</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.lz4/lz4-java@1.8.0?type=jar">
      <group>org.lz4</group>
      <name>lz4-java</name>
      <version>1.8.0</version>
      <description>Java ports and bindings of the LZ4 compression algorithm and the xxHash hashing algorithm</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">936a927700aa8fc3b75d21d7571171f6</hash>
        <hash alg="SHA-1">4b986a99445e49ea5fbf5d149c4b63f6ed6c6780</hash>
        <hash alg="SHA-256">d74a3334fb35195009b338a951f918203d6bbca3d1d359033dc33edd1cadc9ef</hash>
        <hash alg="SHA-512">98d59086a6021ca571d9c1d64b715e43044c730e1ac563f514c40cf44302615d30378b6d5cc69990446522de6260dc8e7b303e3990a3139dc326d058dfb6dbd9</hash>
        <hash alg="SHA-384">8e3f2acdbb41a00c4d9cc5f328e63fb626ac7c6c84e1bf9502e2fcc76a591b2b819b2d27b29925ff986b95c297b30e2c</hash>
        <hash alg="SHA3-384">ec0d6a00760d0a4ecba13a41785d6ae57a64552b1687eaa3e292b3054bb1348e49ab8a938197ff126f9218c6cb96ee1c</hash>
        <hash alg="SHA3-256">7be684c102891105f66d378b61ea1297a392c1618b5aebf7e0b281f55217c206</hash>
        <hash alg="SHA3-512">0b2294570ea2bfbb50ced21dfa4bad956467ca447e9ab2dd602a3478371bcd0e9f13d2dff74d06827a28882409612cdde00bd91267be05bd3510c68268bf3166</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.lz4/lz4-java@1.8.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/lz4/lz4-java</url>
        </reference>
        <reference type="vcs">
          <url>git://github.com/lz4/lz4-java.git</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/com.github.luben/zstd-jni@1.5.7-6?type=jar">
      <publisher>com.github.luben</publisher>
      <group>com.github.luben</group>
      <name>zstd-jni</name>
      <version>1.5.7-6</version>
      <description>JNI bindings for Zstd native library that provides fast and high compression lossless algorithm for Java and all JVM languages.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">47f279a106a9d6e40997522286e14545</hash>
        <hash alg="SHA-1">5ce34668f1ec629a343b9047f36c6cc4c0d3683a</hash>
        <hash alg="SHA-256">8d6feb1da335f3ab13c584c613e23c7b3c61b392e37956872057baf8f0ca1d6f</hash>
        <hash alg="SHA-512">70a2e2c4a3e3467cad0640955bea585fd263ad49fa7f00381321f0e26152af46c987f1b2ddfff66fff0d0035dfe23e633fc63091a8a4b08dcbac29b9b57a5ca1</hash>
        <hash alg="SHA-384">6974dccb4dfe78fd0f819fc9cec6d37963ad2bc18adbf639daef939ea9378f03e3cb8910ba490210123877bb1b05960c</hash>
        <hash alg="SHA3-384">b60fb9fef35eecfe600888bd69400c47299d03398e3784b2856e406ab8d3fb52fb7da188cf440e84844e3728a46ab88e</hash>
        <hash alg="SHA3-256">f0d3ef618aa167daa9da9cef404bee2bd383c7743365b2f1c54c4955f3456479</hash>
        <hash alg="SHA3-512">cbce7c9e57d56a37cb8c5bd3ac2bad521c13317695fd9709fde22c19ada8e9b419a8e60b8219e6eb6f00000509dd036a4be6a0613b0ef5007fab52c8265434f5</hash>
      </hashes>
      <licenses>
        <license>
          <id>BSD-2-Clause</id>
        </license>
      </licenses>
      <purl>pkg:maven/com.github.luben/zstd-jni@1.5.7-6?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/luben/zstd-jni</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.roaringbitmap/RoaringBitmap@1.3.0?type=jar">
      <group>org.roaringbitmap</group>
      <name>RoaringBitmap</name>
      <version>1.3.0</version>
      <description>Roaring bitmaps are compressed bitmaps (also called bitsets) which tend to outperform conventional compressed bitmaps such as WAH or Concise.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">5ea65118238dc208252d95ff1868599c</hash>
        <hash alg="SHA-1">a46ce7a2dc494da69700ab421f081b1583857f6d</hash>
        <hash alg="SHA-256">73443a71a2e2401c7d518a487983539fcaf5f9652efbd178f929e7b6d36881d0</hash>
        <hash alg="SHA-512">1134d4e3c9bb8ff130583e10d00487131c1aab456b625f9289935b660046b07c9acdee0a1dbe9c1fae145c2b1b9897460b1aa3cc0574fc2be976a9781965d7c1</hash>
        <hash alg="SHA-384">0fe7bd9414e4705c41d8eafbfc2ffaf255230fd3804e0c9b2f0847d3124d9b1677df49cf2cfa880c43c45043353f7d2b</hash>
        <hash alg="SHA3-384">0350386ab16e071e5c17406a2dfbd4290fa841fcf7240b93760553588b90a64df79c21e54202b7f25c310446bd65ae64</hash>
        <hash alg="SHA3-256">eac8bd4158fa85c6158a7cbd6fdeda29401ac80d8272cdf2cd7e7c541d887f91</hash>
        <hash alg="SHA3-512">b3be67fad3ce4fbf4a1a77956d632538b0cb68c92d9ec7fe39799ca21a40491d859422d94686722872596c4a89ca0499622927f65174b9a88f0b3641bc58f5eb</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.roaringbitmap/RoaringBitmap@1.3.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/RoaringBitmap/RoaringBitmap</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/RoaringBitmap/RoaringBitmap/issues</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/RoaringBitmap/RoaringBitmap</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.scala-lang.modules/scala-xml_2.13@2.4.0?type=jar">
      <publisher>org.scala-lang.modules</publisher>
      <group>org.scala-lang.modules</group>
      <name>scala-xml_2.13</name>
      <version>2.4.0</version>
      <description>scala-xml</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">6b4f94f8521fb31d4c6ab0b013151dca</hash>
        <hash alg="SHA-1">4f0035ffe0d47a93d98ac75781bb7eecb8d9e658</hash>
        <hash alg="SHA-256">b549a1bf335bc4528cf26f005894c7c37220ac4e8450847973d8f4001b8f59ea</hash>
        <hash alg="SHA-512">1e4925fbcc6a300f0f27f3ac300dae5af325e96c31a2db47d639dfbdb48e59f831561d416ec86366e0c8130a34b2647dbca4c2b29bc4b679d5fc1cba481ca129</hash>
        <hash alg="SHA-384">470f133da383c5864862584df655c5dd56d5bfcffd09b99e9acbf7220446d84c9f3106fae68f4ea26755ccc08259252b</hash>
        <hash alg="SHA3-384">7fc54c8331d018f72c50e3f024ebf158a72deabf8aaac016a4fc1134e4385ea11bc5caa7ac3ee06258e959c7615ec820</hash>
        <hash alg="SHA3-256">52618654f524fed248bf2b4c1df0bbb005b4ff04d500c704d98ca44f91b11cbd</hash>
        <hash alg="SHA3-512">2dbf5dbfff58cf68b42c7757a7b96eeaeab51fe9b87f6c58365439356765ef8ab4306e582949d5c8594661a05621c45c8564056b441c28d31ed992b3a54d2161</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.scala-lang.modules/scala-xml_2.13@2.4.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://www.scala-lang.org/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/scala/scala-xml/issues</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/scala/scala-xml</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.scala-lang/scala-library@2.13.17?type=jar">
      <publisher>LAMP/EPFL</publisher>
      <group>org.scala-lang</group>
      <name>scala-library</name>
      <version>2.13.17</version>
      <description>Standard library for the Scala Programming Language</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">de703408ac5c03df228ae79ee67656cc</hash>
        <hash alg="SHA-1">766aafc5e3c310bde92e405988bc7f6eb31d7cf9</hash>
        <hash alg="SHA-256">b7822c4225243215f185925724a6edff92cf18777a136cc738276c4446fac76c</hash>
        <hash alg="SHA-512">46261b135417e74a52eb9d2313cf1e0dcbd68498f45550110a94872f72c4e47e6220cd1c9d1b11ccc1569cc38f39b1b2045c8917a24a0d004b6786709882e9b4</hash>
        <hash alg="SHA-384">d48cae2c43372823c3619bbc8a4fc2c1e7d01c0f4c1465f7d439856099fe3eb8d58d3a2b1df0164821fcb6d24f0a6962</hash>
        <hash alg="SHA3-384">af3ec98ab75ff8e242f6a1417ec9ac8bd3b270e3b9d814f977c72aac2e0fd260b85ad6baf5a597468611398dbca0f0bc</hash>
        <hash alg="SHA3-256">a540b31a6bb9272b012fecca6d9c638fad5bb1d630d73a5f59827d6d9c2aa6f9</hash>
        <hash alg="SHA3-512">c607a4e4e22cb64869855c3df85371b572ce12872e87432a585606ebdcd9639d9a8dfb4fa658250974435a808935d200e02e6a52672c3b4532b9d56854c94fff</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.scala-lang/scala-library@2.13.17?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://www.scala-lang.org/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/scala/bug/issues</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/scala/scala</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.scala-lang/scala-reflect@2.13.17?type=jar">
      <publisher>LAMP/EPFL</publisher>
      <group>org.scala-lang</group>
      <name>scala-reflect</name>
      <version>2.13.17</version>
      <description>Reflection Library for the Scala Programming Language</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">4b2ffedf3b993fff4a369314616ada2b</hash>
        <hash alg="SHA-1">d7ea6ad0d92e3bbe0afef1bdffbbe172704c8c47</hash>
        <hash alg="SHA-256">734533897bcfabe7a6e7fa09dbee165b257b0396e14e8a57c75111db8e04bb98</hash>
        <hash alg="SHA-512">f4a0b626998048a4b125538645e5afc3366530189398a895aee8b41e3ea46b9739e5090054f66af7f53c3005d15974c88760844c5074ab190950f0a4724401a4</hash>
        <hash alg="SHA-384">2ba29a0825529c96a95267948369453171719e928a3bf2c05c92451f9c95d323af7375affdd6f339576bec3bd3497cb2</hash>
        <hash alg="SHA3-384">d8640d729daa3134c74c96e7ce78f0b68c5abbc0f8375f1c857cae883e499e816be9a4ed2446ca06629c04393f81aef7</hash>
        <hash alg="SHA3-256">167b83e63a7a88a9908c72a783bc7dd087274e30edc2ee9219df3f34db6a2ca5</hash>
        <hash alg="SHA3-512">e828cce2c179074409046ce42a24106c63e1c6cc65015f5ec1a8f3a82ed896c20fe9c8261c5a396687ea520f8dbd0f03cbb950327e1fec3524d4aeb8fc7dc112</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.scala-lang/scala-reflect@2.13.17?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://www.scala-lang.org/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/scala/bug/issues</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/scala/scala</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.json4s/json4s-jackson_2.13@4.0.7?type=jar">
      <publisher>org.json4s</publisher>
      <group>org.json4s</group>
      <name>json4s-jackson_2.13</name>
      <version>4.0.7</version>
      <description>json4s-jackson</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">d6fe67474157a5379b23454ae797f8fb</hash>
        <hash alg="SHA-1">ea98516a3c0001a02ebabdc7dc57a865a609acb2</hash>
        <hash alg="SHA-256">3b76d426241ba14d0b5ed1a073a2e59fc4db1fc54ec55b79eb35efed19ed8d57</hash>
        <hash alg="SHA-512">d85ef8aea00c61d03f4adecb30b5b5d84e09d9e02df89890b5a21892dc0c7867533161038b5b863ccf63d7fb289db525f359fb914cad6c6285042ee8ca30c73a</hash>
        <hash alg="SHA-384">0d9106d3834b1cc8e1db24ef8ecd6663221a7ecda167c4a01c14f7cbacf708aa0f8140b774016f1cca5763b154cd9502</hash>
        <hash alg="SHA3-384">e8ad9ab7afe09a3a434283ddb16bb364f488b65043a15e372bc45f235b7db794921d06eb035383ee943c498725e5ebb7</hash>
        <hash alg="SHA3-256">c7db86a17a4c9ead699bc2ba7cbb62cd4be1302c202b8cceb0440b1b2d8356bc</hash>
        <hash alg="SHA3-512">0a9ebed52ed6ee627b0273f79a17f9be2b8d5436c0a8300945ef97278c70ee4a6faa420dbcd7594c8dd35b76763470fb889d23244e399d733362c7e58540691e</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.json4s/json4s-jackson_2.13@4.0.7?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/json4s/json4s</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/json4s/json4s</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.json4s/json4s-core_2.13@4.0.7?type=jar">
      <publisher>org.json4s</publisher>
      <group>org.json4s</group>
      <name>json4s-core_2.13</name>
      <version>4.0.7</version>
      <description>json4s-core</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">73617948f1e370da33d60a07e5d3d7cf</hash>
        <hash alg="SHA-1">309c43ab95fb94afe085aed2591e47771c78cec9</hash>
        <hash alg="SHA-256">e831e4a676964d3f38a408b464b3ba6d21b76730c01f13d2d0b9995945fa06ce</hash>
        <hash alg="SHA-512">39362fd1fe72a4378931e74d7d1b3fc02302e1cd1ff56833ccc2a8fe243194d73bef8a56cf44472432219504d862218b2e6f8415dbc1886f553e1b1acc8e97f4</hash>
        <hash alg="SHA-384">e956ee162fbbbd033dfb97484ab62a063cc7cbefe3ffbc127e422af29d9cec6f3e8c16306c95f6bd8513f9d7b21b5d64</hash>
        <hash alg="SHA3-384">8983368b8e0511974cdad44c47f0aa20c624a897974faeaa0adca8aa6e8a3a043fdc240a7b6fde1e82ac19869d95efb9</hash>
        <hash alg="SHA3-256">3d1a7f814fadd123d236c2b234aa9fafe17ba830462bf3edb50207237b31560f</hash>
        <hash alg="SHA3-512">649029fb653b8e324284afc2cf451affe02428c9bdf39b6d88e71274e6340860ebd6bc6e106ca2985794a26938310f6be4b68753255c67e77c7c84ac8cf2f6eb</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.json4s/json4s-core_2.13@4.0.7?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/json4s/json4s</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/json4s/json4s</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.json4s/json4s-ast_2.13@4.0.7?type=jar">
      <publisher>org.json4s</publisher>
      <group>org.json4s</group>
      <name>json4s-ast_2.13</name>
      <version>4.0.7</version>
      <description>json4s-ast</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">ffaf99b9959d4f42b718afc3ae60072f</hash>
        <hash alg="SHA-1">ed5f5779d939cd30b052adfef049032491bb258c</hash>
        <hash alg="SHA-256">3135eceb95b679ea228e3543267d12bea5f4bdb68e3e8fc55402824d85885e7e</hash>
        <hash alg="SHA-512">6594c1e2c481775138c46a9aa2a8722cbed2203422aec15f84d371750450fdbf69670aea13b1d7e1506fc2770c6d16f5b3188e51b301903ec5c11804ca2984f9</hash>
        <hash alg="SHA-384">57fc8c3090f8f1ee7db3105a7ce626fa44580aeae6a67d33afd2511ff2aa7523997947ae44e1125282b1e9ce6aa87db6</hash>
        <hash alg="SHA3-384">5e1be01389f6ec2614ad21f82d7b9f4f37f7cc9ba7892004866cf6cd3f8bb3da7dbd991094a57dd8f547c8a3c254e77b</hash>
        <hash alg="SHA3-256">bb0c494d5e896836f27aa9034d19e046b4a290c798d16bdb883d900b2e7e5e5e</hash>
        <hash alg="SHA3-512">a66fb976167b38ca0deece3d5304c1d576b9609bebb1b00222c409adfcc950d2d828dcb0466f73112fa64c3d0d88aa3dac165cf74018afb659f4fc433e72d8c9</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.json4s/json4s-ast_2.13@4.0.7?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/json4s/json4s</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/json4s/json4s</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.json4s/json4s-scalap_2.13@4.0.7?type=jar">
      <publisher>org.json4s</publisher>
      <group>org.json4s</group>
      <name>json4s-scalap_2.13</name>
      <version>4.0.7</version>
      <description>json4s-scalap</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">74c2111505af1b500aa6e81195130397</hash>
        <hash alg="SHA-1">2a5f4082412c102cea496250491155ed7c8a56ec</hash>
        <hash alg="SHA-256">69bdf853f04379970939022247495f30f60a3ef7292d6af77ad7bec4cb83ff4b</hash>
        <hash alg="SHA-512">60180242601d2a37fb8cef9c0afcc82b24a351978932ce225ca5b29ffc620b5eca2781ece041f8b12dc7b0a67e0e8177ce1defceab7bb34192d0efe97ce1281d</hash>
        <hash alg="SHA-384">7b234f3daa28aea45e33fc48dfe537bf5e626e17ebb79d4780bd504463d9c3a2439fd22414623c278d185798401e6a1b</hash>
        <hash alg="SHA3-384">6d16d631448ae00d397a4ecddb2d0d60a69f3070911d84c262ca652ff49dca75237c395f6b6a2649d85bc6dbc48f75ee</hash>
        <hash alg="SHA3-256">0e746a2797d1ff08ae83f7ed7391c598f4bf21ff35a503749b23c3621852fbdf</hash>
        <hash alg="SHA3-512">7154f75b528244836a80418e650faef08545228e0450bbbdb5175a31571a3afa72504c96cd7ae49bed74bb5ee962e75edcaca37b2b31099fe27eda6affc156f8</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.json4s/json4s-scalap_2.13@4.0.7?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/json4s/json4s</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/json4s/json4s</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.json4s/json4s-jackson-core_2.13@4.0.7?type=jar">
      <publisher>org.json4s</publisher>
      <group>org.json4s</group>
      <name>json4s-jackson-core_2.13</name>
      <version>4.0.7</version>
      <description>json4s-jackson-core</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">1ce091c295c796401e3295508457b075</hash>
        <hash alg="SHA-1">049e54efa393e5be7bbc2294e5a45099a09a88bb</hash>
        <hash alg="SHA-256">c189e11ddb2c8e15544386687d986108584934b06a025c09c334f24b11260528</hash>
        <hash alg="SHA-512">a28cedc3ea6690a78742b074f4b4d7c8887d74e07dffea1b282cecde07ab0547692faaf6691d9e9e04e7942b01e6eeaf6b232069a72512c8bfee7d45ae36cd45</hash>
        <hash alg="SHA-384">8483031254fd542bbd451a0ffd939d80a25adb1a27f07f3e740bb3f19a464f7cdb1ed928d1e186eab5135d884e962377</hash>
        <hash alg="SHA3-384">8dcd53da2d66d8aa69105ba1ff43b01d30a2b03dcea8cb8f4e31e421e96c307542c2cf3c6516fec53f8e5fd18a2330c5</hash>
        <hash alg="SHA3-256">57c372bdecdb64f25443ba7de61c1d01c2495d6c761d01850c9676c70a614041</hash>
        <hash alg="SHA3-512">728877fe748099dab6917f040e6bb31f0ddc3b06df58362ef30b2ef5cca5d4fd6af9a40511fdaa10bf4d7cc5f5ea9ef9593cd4c40d0c5ccb2923321c8ddd24a7</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.json4s/json4s-jackson-core_2.13@4.0.7?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/json4s/json4s</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/json4s/json4s</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.glassfish.jersey.core/jersey-client@3.0.18?type=jar">
      <publisher>Eclipse Foundation</publisher>
      <group>org.glassfish.jersey.core</group>
      <name>jersey-client</name>
      <version>3.0.18</version>
      <description>Jersey core client implementation</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">7143a36d32b9a4ac47a1f1695069bf25</hash>
        <hash alg="SHA-1">861e229322634623feb8375dad6c825bd01720c7</hash>
        <hash alg="SHA-256">6eb0009203ddc6c98d68be2f0ae9749304e88b91cce41f8898f8f1ca50b4eb5e</hash>
        <hash alg="SHA-512">d4a0608543ae8d0f72df3447b128783cc87a10027d8e268c46fd3edd6375628901cb9482457de3b6fcc9e619516638a3137ef5a60161fa09e058cfaa125560c1</hash>
        <hash alg="SHA-384">e2427263807ec9e0b480794a6508a8cb46e3503aef53fbe74e4700567728581fcc1eeef56bc997a24101c5cda357edae</hash>
        <hash alg="SHA3-384">2e5943c36814e22a3dc14451d16f38feea621d425cae5fd3470be3f41803666386b1fcdfb27c353cd131d62306cc44ba</hash>
        <hash alg="SHA3-256">a5c5e76e74640f2988806aec93e3fb0df13a6a38e1a96b14ffb774aa37a47c53</hash>
        <hash alg="SHA3-512">1bef5fbb1841ddf5cbe1feb444dda34226b6968cad389485cbc2b6aa56325d932f73894e130224023c2702c22198ec84ee25c34cbb36bdf724aa5f607eb011a1</hash>
      </hashes>
      <licenses>
        <license>
          <id>EPL-2.0</id>
        </license>
        <license>
          <id>GPL-2.0-with-classpath-exception</id>
        </license>
        <license>
          <id>BSD-3-Clause</id>
        </license>
        <license>
          <id>BSD-2-Clause</id>
        </license>
        <license>
          <name>Apache License, 2.0</name>
          <url>http://www.apache.org/licenses/LICENSE-2.0.html</url>
        </license>
        <license>
          <name>Public Domain</name>
          <url>https://creativecommons.org/publicdomain/zero/1.0/</url>
        </license>
        <license>
          <name>Modified BSD</name>
          <url>https://asm.ow2.io/license.html</url>
        </license>
        <license>
          <name>jQuery license</name>
          <url>jquery.org/license</url>
        </license>
        <license>
          <id>MIT</id>
          <url>https://opensource.org/license/mit/</url>
        </license>
        <license>
          <name>W3C license</name>
          <url>https://www.w3.org/Consortium/Legal/copyright-documents-19990405</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.glassfish.jersey.core/jersey-client@3.0.18?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://projects.eclipse.org/projects/ee4j.jersey/jersey-client</url>
        </reference>
        <reference type="build-system">
          <url>http://hudson.glassfish.org/job/Jersey-trunk-multiplatform/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://jakarta.oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/eclipse-ee4j/jersey/issues</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/eclipse-ee4j/jersey/jersey-client</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/jakarta.ws.rs/jakarta.ws.rs-api@3.0.0?type=jar">
      <publisher>Eclipse Foundation</publisher>
      <group>jakarta.ws.rs</group>
      <name>jakarta.ws.rs-api</name>
      <version>3.0.0</version>
      <description>Jakarta RESTful Web Services</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">dd98ad2f0edcec6c0f0875695b8647e9</hash>
        <hash alg="SHA-1">5eea182d6651a7257bc8c3614507e1540c766fc2</hash>
        <hash alg="SHA-256">0bcb2cf4522831ad83cc7e936b8db60e2afb2582d19d672eb17d01da2c777322</hash>
        <hash alg="SHA-512">25a57149d3b5b57d21ad7b97d5c293adb549b363fb9c22f5d894adab174cd3019886cfa2b8425b67644b12769075fd891352c5230b66846c9bbcd26bc98dc3a9</hash>
        <hash alg="SHA-384">5602c64b0612e2b6649b2ca2aeae9eab536bb816d41643aa1caace022010b4767cdc9ae3518e2d303476c09260bd3023</hash>
        <hash alg="SHA3-384">ed2e09bb8083474846fa7edb928527d7f37258351aa45e93f46cf40215e89317b6659a829fef3b4837449e347bfb5ca9</hash>
        <hash alg="SHA3-256">67066e127150ca5eec06bb65caaacf3635d5ed856918518932f4d7766725df1c</hash>
        <hash alg="SHA3-512">439072f3869ad8a6128f2b2592328ba604b41111df2938a20b112b7ff8f16d537d8ffc4f83b8fe762c3f8f716fffd73b692a15e90666a1b3fcf97b4e2e9f4388</hash>
      </hashes>
      <licenses>
        <license>
          <id>EPL-2.0</id>
          <url>https://www.eclipse.org/legal/epl-2.0</url>
        </license>
        <license>
          <id>GPL-2.0-with-classpath-exception</id>
          <url>https://www.gnu.org/software/classpath/license.html</url>
        </license>
      </licenses>
      <purl>pkg:maven/jakarta.ws.rs/jakarta.ws.rs-api@3.0.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/eclipse-ee4j/jaxrs-api</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://jakarta.oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/eclipse-ee4j/jaxrs-api/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>jaxrs-dev@eclipse.org</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/eclipse-ee4j/jaxrs-api</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/jakarta.inject/jakarta.inject-api@2.0.1?type=jar">
      <publisher>Eclipse Foundation</publisher>
      <group>jakarta.inject</group>
      <name>jakarta.inject-api</name>
      <version>2.0.1</version>
      <description>Jakarta Dependency Injection</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">72003bf6efcc8455d414bbd7da86c11c</hash>
        <hash alg="SHA-1">4c28afe1991a941d7702fe1362c365f0a8641d1e</hash>
        <hash alg="SHA-256">f7dc98062fccf14126abb751b64fab12c312566e8cbdc8483598bffcea93af7c</hash>
        <hash alg="SHA-512">f186b2ada470abba1cc3b4f8c4373d940fb7c71a051b2c26f7c204ad4dfb69235fbf3f9c33da36d744cb90f52d921c51d76c0ff263bacb35eafb66cab83dc47d</hash>
        <hash alg="SHA-384">405bd297a73901f013d48a0da028d04d400f3e61f4997c0e7297eb08120670a0e242e0002db8f130c33ab16cb02feb2d</hash>
        <hash alg="SHA3-384">4db7e54434d0a208c876868f5595b808f2728c0455feaa752ab7b569a2186fc37cb891c9aa0076de3d08f6da6ff06eba</hash>
        <hash alg="SHA3-256">3a5aba9f1ff1a130b76af886123eb375fa578498490df3dc60bb7ce7d59e9404</hash>
        <hash alg="SHA3-512">00bba8efc2d6e7f0a509b321868d75f1aaf0681a750d089d913bde8424ab7bb88aadf49de6e291e352523e4f8c117b1b48033ff31d4d665dcc43c4c6ea000ba9</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/jakarta.inject/jakarta.inject-api@2.0.1?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/eclipse-ee4j/injection-api</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://jakarta.oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/eclipse-ee4j/ee4j/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://dev.eclipse.org/mhonarc/lists/jakarta.ee-community/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/eclipse-ee4j/injection-api</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.glassfish.jersey.core/jersey-common@3.0.18?type=jar">
      <publisher>Eclipse Foundation</publisher>
      <group>org.glassfish.jersey.core</group>
      <name>jersey-common</name>
      <version>3.0.18</version>
      <description>Jersey core common packages</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">3ffe9f6abd7318e80b3f63bed81ded43</hash>
        <hash alg="SHA-1">6a55fce5d47a6ea1062f8faf08faff9ab46185eb</hash>
        <hash alg="SHA-256">8ad2eaf8f6825b8d5f729070376767c34c874b3e4cb87a3a908205f9b7fdc359</hash>
        <hash alg="SHA-512">3dbf6d92718ce8a2f8d8ef656f6509241853b64a3441c7a3c7a8180358b5e66dacc1f28fa2b532eeee9a8598640bf99c47c4379feb764b41d05ed3fa5a0b6a44</hash>
        <hash alg="SHA-384">b24799a50d50692ceb77fde22fb3f2d4c6e7c5b673478c9b4be469eae291da411b6f3db63b36af21c9ef45b3ec6b427b</hash>
        <hash alg="SHA3-384">31b210130e729daafc1384af72dcba74ecbd4492e733fabb97b3acb9307f0fdf2d0191a1e5134d680f3a4f563a3fb4de</hash>
        <hash alg="SHA3-256">8726d54b44061b380564aca654b0864981ce9400d8ddc105084a6df033036d9c</hash>
        <hash alg="SHA3-512">6db33bc08482ba7c22c1d810878cb62900a6fab75798075583b9d937e72f9115da483f8cf83f7d3a70a4f85e1cf6cded74e7fcf92de7e3653bb53bc93ae8fa6f</hash>
      </hashes>
      <licenses>
        <license>
          <id>EPL-2.0</id>
        </license>
        <license>
          <name>The GNU General Public License (GPL), Version 2, With Classpath Exception</name>
          <url>https://www.gnu.org/software/classpath/license.html</url>
        </license>
        <license>
          <name>Apache License, 2.0</name>
          <url>http://www.apache.org/licenses/LICENSE-2.0.html</url>
        </license>
        <license>
          <name>Public Domain</name>
          <url>https://creativecommons.org/publicdomain/zero/1.0/</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.glassfish.jersey.core/jersey-common@3.0.18?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://projects.eclipse.org/projects/ee4j.jersey/jersey-common</url>
        </reference>
        <reference type="build-system">
          <url>http://hudson.glassfish.org/job/Jersey-trunk-multiplatform/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://jakarta.oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/eclipse-ee4j/jersey/issues</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/eclipse-ee4j/jersey/jersey-common</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/jakarta.annotation/jakarta.annotation-api@2.1.1?type=jar">
      <publisher>Eclipse Foundation</publisher>
      <group>jakarta.annotation</group>
      <name>jakarta.annotation-api</name>
      <version>2.1.1</version>
      <description>Jakarta Annotations API</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">5dac2f68e8288d0add4dc92cb161711d</hash>
        <hash alg="SHA-1">48b9bda22b091b1f48b13af03fe36db3be6e1ae3</hash>
        <hash alg="SHA-256">5f65fdaf424eee2b55e1d882ba9bb376be93fb09b37b808be6e22e8851c909fe</hash>
        <hash alg="SHA-512">eabe8b855b735663684052ec4cc357cc737936fa57cebf144eb09f70b3b6c600db7fa6f1c93a4f36c5994b1b37dad2dfcec87a41448872e69552accfd7f52af6</hash>
        <hash alg="SHA-384">798597a6b80b423844d70609c54b00d725a357031888da7e5c3efd3914d1770be69aa7135de13ddb89a4420a5550e35b</hash>
        <hash alg="SHA3-384">9629b8ca82f61674f5573723bbb3c137060e1442062eb52fa9c90fc8f57ea7d836eb2fb765d160ec8bf300bcb6b820be</hash>
        <hash alg="SHA3-256">f71ffc2a2c2bd1a00dfc00c4be67dbe5f374078bd50d5b24c0b29fbcc6634ecb</hash>
        <hash alg="SHA3-512">aa4e29025a55878db6edb0d984bd3a0633f3af03fa69e1d26c97c87c6d29339714003c96e29ff0a977132ce9c2729d0e27e36e9e245a7488266138239bdba15e</hash>
      </hashes>
      <licenses>
        <license>
          <id>EPL-2.0</id>
        </license>
        <license>
          <id>GPL-2.0-with-classpath-exception</id>
        </license>
      </licenses>
      <purl>pkg:maven/jakarta.annotation/jakarta.annotation-api@2.1.1?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://projects.eclipse.org/projects/ee4j.ca</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://jakarta.oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/eclipse-ee4j/common-annotations-api/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://dev.eclipse.org/mhonarc/lists/ca-dev</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/eclipse-ee4j/common-annotations-api</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.glassfish.hk2/osgi-resource-locator@1.0.3?type=jar">
      <publisher>Eclipse Foundation</publisher>
      <group>org.glassfish.hk2</group>
      <name>osgi-resource-locator</name>
      <version>1.0.3</version>
      <description>Used by various API providers that rely on META-INF/services mechanism to locate providers.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">e7e82b82118c5387ae45f7bf3892909b</hash>
        <hash alg="SHA-1">de3b21279df7e755e38275137539be5e2c80dd58</hash>
        <hash alg="SHA-256">aab5d7849f7cfcda2cc7c541ba1bd365151d42276f151c825387245dfde3dd74</hash>
        <hash alg="SHA-512">4d84983a9b1c72f58661b576c78ca456a2106602c2ad211cd7e72d94464c8774173b34a35629c507c7c84c982f1de0c9bf48352458e8480be5f874d20d6e69a3</hash>
        <hash alg="SHA-384">9f92002296c66cc8996d459b95a9c531ec71b98a8b819121abbc7d636a6c4ace04c88878ba6917f71650280a880d1ce2</hash>
        <hash alg="SHA3-384">b27581d003ce715fba7e2958dbe73b64330b8586d94dd2f4b80b3d4861fd36415af6c2fe1005a798a7bd4f706d77e3d1</hash>
        <hash alg="SHA3-256">cf90e96adac2f1167ff71267db4a91c75d824f8a4b0359d2ab7d50b1c87c3952</hash>
        <hash alg="SHA3-512">75f9ff6c3ab03f4471ac04789c181b75edf4c5dbf985a5616b2c979de59aa478b02593036f740a6c7bb71afcb145c131a3ff3e5a6a53336abab22f2cc9825772</hash>
      </hashes>
      <licenses>
        <license>
          <id>EPL-2.0</id>
        </license>
        <license>
          <id>GPL-2.0-with-classpath-exception</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.glassfish.hk2/osgi-resource-locator@1.0.3?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://projects.eclipse.org/projects/ee4j/osgi-resource-locator</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/eclipse-ee4j/ee4j/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://dev.eclipse.org/mhonarc/lists/jakarta.ee-community/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/eclipse-ee4j/glassfish-hk2-extra</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.glassfish.jersey.core/jersey-server@3.0.18?type=jar">
      <publisher>Eclipse Foundation</publisher>
      <group>org.glassfish.jersey.core</group>
      <name>jersey-server</name>
      <version>3.0.18</version>
      <description>Jersey core server implementation</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">f343b4813b8db9797c12e378160d8986</hash>
        <hash alg="SHA-1">f68747cdc51dfa0c7207bcdb681bf6c2320aef6d</hash>
        <hash alg="SHA-256">3ec2978b0a739613d2fb835ba398c85413b41ed18407b126f5a52595efa530ad</hash>
        <hash alg="SHA-512">7f72bbc703a80ba425c43b0a40b4ffa69959a06fd40ceeb5c2c948a6fb262dcab731721ba9a4cd7d0c3330d77d33b9895e5dd07d71eb8bd3619657ab14cec576</hash>
        <hash alg="SHA-384">770d04cedf902a32097e75c3f026869337f67cc01e60f635c6fefc0f1f37c7e32a44d93d48f0203634491a49bfc8578f</hash>
        <hash alg="SHA3-384">9213b133fde1878efc3f22b03834b9bebf258d4ba25acdd430b2cc09af86c926b17dc8991d47fd4d5c5248cee07fa20f</hash>
        <hash alg="SHA3-256">4e0d763e1a84261feab7b2f7c09d58359a6087860e053c1d7bff405f995305c8</hash>
        <hash alg="SHA3-512">243087b8583e610b32be70fcfadd63af77d3f5f9f66b5ed417b14d84f6abd4db6bbd0e17c14f25417fba7133e90e53d9af33cfac1a0b11fd0dcfba988c9a9724</hash>
      </hashes>
      <licenses>
        <license>
          <id>EPL-2.0</id>
        </license>
        <license>
          <name>The GNU General Public License (GPL), Version 2, With Classpath Exception</name>
          <url>https://www.gnu.org/software/classpath/license.html</url>
        </license>
        <license>
          <name>Apache License, 2.0</name>
          <url>http://www.apache.org/licenses/LICENSE-2.0.html</url>
        </license>
        <license>
          <name>Modified BSD</name>
          <url>https://asm.ow2.io/license.html</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.glassfish.jersey.core/jersey-server@3.0.18?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://projects.eclipse.org/projects/ee4j.jersey/jersey-server</url>
        </reference>
        <reference type="build-system">
          <url>http://hudson.glassfish.org/job/Jersey-trunk-multiplatform/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://jakarta.oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/eclipse-ee4j/jersey/issues</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/eclipse-ee4j/jersey/jersey-server</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/jakarta.validation/jakarta.validation-api@3.0.2?type=jar">
      <publisher>Eclipse Foundation</publisher>
      <group>jakarta.validation</group>
      <name>jakarta.validation-api</name>
      <version>3.0.2</version>
      <description>Jakarta Bean Validation API</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">3a1ee6efca3e41e3320599790f54c5eb</hash>
        <hash alg="SHA-1">92b6631659ba35ca09e44874d3eb936edfeee532</hash>
        <hash alg="SHA-256">291c25e6910cc6a7ebd96d4c6baebf6d7c37676c5482c2d96146e901b62c1fc9</hash>
        <hash alg="SHA-512">8ff9a450e13dad49ac8268ab8c591e045e5056f9459efa09fbb3561b5c879526b344e2648602bf65d387620064cf0c3a00e1243c6422c85a21b53dbab8749a40</hash>
        <hash alg="SHA-384">ab594665f5416edc8b42687e4ca17583fdcf886725ed98a88beb42bb5980d3672a5a5b7dd93b73c2282393ef1814d21d</hash>
        <hash alg="SHA3-384">bd43bd51ad4b56fe5bed62d478554a0e2a183b8ce38ed8606adb52d219eefe2efedafdd3d530b1f680824f54a680ab4b</hash>
        <hash alg="SHA3-256">48b53a0b142c3b314427ea2133e54151ed8263c1627527b8bc824784596840d7</hash>
        <hash alg="SHA3-512">3b6ec58f766f0958be2529b66d12bf492dfb78c49bfd41be87d9102e0885144156a693828f201a2a7019774c02824dfcaf717394a8858779fc9b2cd44b74b453</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/jakarta.validation/jakarta.validation-api@3.0.2?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://beanvalidation.org</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://jakarta.oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://hibernate.atlassian.net/projects/BVAL/</url>
        </reference>
        <reference type="mailing-list">
          <url>https://dev.eclipse.org/mhonarc/lists/jakarta.ee-community/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/eclipse-ee4j/beanvalidation-api</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.glassfish.jersey.containers/jersey-container-servlet@3.0.18?type=jar">
      <publisher>Eclipse Foundation</publisher>
      <group>org.glassfish.jersey.containers</group>
      <name>jersey-container-servlet</name>
      <version>3.0.18</version>
      <description>Jersey core Servlet 3.x implementation</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">9cb415cbef4ea4403ba94125a773be7c</hash>
        <hash alg="SHA-1">c30607eb6fe18f99b1be38949e48c238a901cc5f</hash>
        <hash alg="SHA-256">285dce04c5b1959d5b4334ea134447d0c63a336879de0d582058abf6409cec49</hash>
        <hash alg="SHA-512">fca819f7dc407eae1e0182f99c5a721c5476a1f27db6d5a19ab2b842439cfdd05118592bf9ec7b2f92c06e01cd0e8285dc0bb73f56b50db149563d3e0ba11420</hash>
        <hash alg="SHA-384">bd7ce1f93dbdcb4746112ed07fcaca5ac6b638e2cfdd5a5b970dbd7af803318b5e9b8ebce16243d57a5d97059790443d</hash>
        <hash alg="SHA3-384">d907b30c22b742e0c3dd3d3c96b12a72b7dd700688008a7f909426e757f9b324ea12332289d67a889c5990cf7fb07338</hash>
        <hash alg="SHA3-256">d8572355d024dbc2901311b62c5994a04c0890ec8b0241d5cba3817cfada8966</hash>
        <hash alg="SHA3-512">9a06dcc1e0db538ea65ba0c1886b947fad531f399b2c83b75a4cd0bb21ad864822597b58c7f6f61dcc91e32f18a8fdd871ee6ccf796d70b88fd2487c1315e23f</hash>
      </hashes>
      <licenses>
        <license>
          <id>EPL-2.0</id>
        </license>
        <license>
          <id>GPL-2.0-with-classpath-exception</id>
        </license>
        <license>
          <id>BSD-3-Clause</id>
        </license>
        <license>
          <id>BSD-2-Clause</id>
        </license>
        <license>
          <name>Apache License, 2.0</name>
          <url>http://www.apache.org/licenses/LICENSE-2.0.html</url>
        </license>
        <license>
          <name>Public Domain</name>
          <url>https://creativecommons.org/publicdomain/zero/1.0/</url>
        </license>
        <license>
          <name>Modified BSD</name>
          <url>https://asm.ow2.io/license.html</url>
        </license>
        <license>
          <name>jQuery license</name>
          <url>jquery.org/license</url>
        </license>
        <license>
          <id>MIT</id>
          <url>https://opensource.org/license/mit/</url>
        </license>
        <license>
          <name>W3C license</name>
          <url>https://www.w3.org/Consortium/Legal/copyright-documents-19990405</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.glassfish.jersey.containers/jersey-container-servlet@3.0.18?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://projects.eclipse.org/projects/ee4j.jersey/project/jersey-container-servlet</url>
        </reference>
        <reference type="build-system">
          <url>http://hudson.glassfish.org/job/Jersey-trunk-multiplatform/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://jakarta.oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/eclipse-ee4j/jersey/issues</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/eclipse-ee4j/jersey/project/jersey-container-servlet</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.glassfish.jersey.containers/jersey-container-servlet-core@3.0.18?type=jar">
      <publisher>Eclipse Foundation</publisher>
      <group>org.glassfish.jersey.containers</group>
      <name>jersey-container-servlet-core</name>
      <version>3.0.18</version>
      <description>Jersey core Servlet 3.x implementation</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">1ee1d401e83a1fa691368263b7e2b0b7</hash>
        <hash alg="SHA-1">32e46bede9cb63178bafbb4ba3ca26e1a5d77ac0</hash>
        <hash alg="SHA-256">d46b4f35a1af6ded25e4fe558d30f93d42a7d0b587a6a5f4273d43d8debd1ca1</hash>
        <hash alg="SHA-512">eabb4268d301f2f24712f5b9b0ae4a72e6244be223a8a18cb5a9fd65f34e065274b6949c77b22e073a3f78564b90ba9c7b8762b78838b6150e0e08dddbea2f3a</hash>
        <hash alg="SHA-384">c4a597d856434070e6dc712150a9575804825d8a5659c3a279e252c06d29f07b510714826730d69719b150431da8a78f</hash>
        <hash alg="SHA3-384">5b5c6fb765bd45a4ab44a6b7874c18f7e23d5f0650e5327bda34e405694c1f36d90d5389606a4b1ffe23d952a283bc08</hash>
        <hash alg="SHA3-256">d083a4575f87a39e821c5aca706468e69c3dcc5d1b85eb0a4d76bfacc2fd0e18</hash>
        <hash alg="SHA3-512">27df8d79ae106667fc94c824fa7342d01ccb6123b441ee09486bfacfb915ae9f7d173c58e9471fc45a05c0aa71d850d7d11d221839eb4b8f72153d23a8743d61</hash>
      </hashes>
      <licenses>
        <license>
          <id>EPL-2.0</id>
        </license>
        <license>
          <id>GPL-2.0-with-classpath-exception</id>
        </license>
        <license>
          <id>BSD-3-Clause</id>
        </license>
        <license>
          <id>BSD-2-Clause</id>
        </license>
        <license>
          <name>Apache License, 2.0</name>
          <url>http://www.apache.org/licenses/LICENSE-2.0.html</url>
        </license>
        <license>
          <name>Public Domain</name>
          <url>https://creativecommons.org/publicdomain/zero/1.0/</url>
        </license>
        <license>
          <name>Modified BSD</name>
          <url>https://asm.ow2.io/license.html</url>
        </license>
        <license>
          <name>jQuery license</name>
          <url>jquery.org/license</url>
        </license>
        <license>
          <id>MIT</id>
          <url>https://opensource.org/license/mit/</url>
        </license>
        <license>
          <name>W3C license</name>
          <url>https://www.w3.org/Consortium/Legal/copyright-documents-19990405</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.glassfish.jersey.containers/jersey-container-servlet-core@3.0.18?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://projects.eclipse.org/projects/ee4j.jersey/project/jersey-container-servlet-core</url>
        </reference>
        <reference type="build-system">
          <url>http://hudson.glassfish.org/job/Jersey-trunk-multiplatform/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://jakarta.oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/eclipse-ee4j/jersey/issues</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/eclipse-ee4j/jersey/project/jersey-container-servlet-core</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.glassfish.jersey.inject/jersey-hk2@3.0.18?type=jar">
      <publisher>Eclipse Foundation</publisher>
      <group>org.glassfish.jersey.inject</group>
      <name>jersey-hk2</name>
      <version>3.0.18</version>
      <description>HK2 InjectionManager implementation</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">01c8a208e4c81c7b9aeaf512ba1ed902</hash>
        <hash alg="SHA-1">f3c53f582f1a2f1cfac84798de6f4091d972742d</hash>
        <hash alg="SHA-256">eef55a8e3c8267ef220272caa3fc587a3c02ad2f1edc22b1157ce9a0761abfa5</hash>
        <hash alg="SHA-512">707161f94b3f04c377429bfebb04b06306e009440287d21a6cb6ad86d8894bbfb0fdd7bc3b333adbcfec9530f7e3558710e9cf6ccb58212ce1099e532a419cb1</hash>
        <hash alg="SHA-384">c9457fefc774014aed948417b2142bda13ca66e6e8a389ce63d111c4fc4555b93b05d7ed969df64453e77af373e4b667</hash>
        <hash alg="SHA3-384">10dd13e9f60a6603ff1368e2def075ef74267495b84d353837a4193776dd77b13326d1f27b4c13494c4a12fd5a686f89</hash>
        <hash alg="SHA3-256">56c39af6b532203fa91906a534cc3ed0f270c66028fccf1aa05eb1ed77c3e2ee</hash>
        <hash alg="SHA3-512">f90cf6764e08a35cf9a3782dcb0676097ad6fa3fff4dd3f73e84f95011861a3c959a5d77756a87d1202990c47092d8ab227f6f6366c8bf8530f160f038f475d9</hash>
      </hashes>
      <licenses>
        <license>
          <id>EPL-2.0</id>
        </license>
        <license>
          <id>GPL-2.0-with-classpath-exception</id>
        </license>
        <license>
          <id>BSD-3-Clause</id>
        </license>
        <license>
          <id>BSD-2-Clause</id>
        </license>
        <license>
          <name>Apache License, 2.0</name>
          <url>http://www.apache.org/licenses/LICENSE-2.0.html</url>
        </license>
        <license>
          <name>Public Domain</name>
          <url>https://creativecommons.org/publicdomain/zero/1.0/</url>
        </license>
        <license>
          <name>Modified BSD</name>
          <url>https://asm.ow2.io/license.html</url>
        </license>
        <license>
          <name>jQuery license</name>
          <url>jquery.org/license</url>
        </license>
        <license>
          <id>MIT</id>
          <url>https://opensource.org/license/mit/</url>
        </license>
        <license>
          <name>W3C license</name>
          <url>https://www.w3.org/Consortium/Legal/copyright-documents-19990405</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.glassfish.jersey.inject/jersey-hk2@3.0.18?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://projects.eclipse.org/projects/ee4j.jersey/project/jersey-hk2</url>
        </reference>
        <reference type="build-system">
          <url>http://hudson.glassfish.org/job/Jersey-trunk-multiplatform/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://jakarta.oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/eclipse-ee4j/jersey/issues</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/eclipse-ee4j/jersey/project/jersey-hk2</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.glassfish.hk2/hk2-locator@3.0.6?type=jar">
      <publisher>Oracle Corporation</publisher>
      <group>org.glassfish.hk2</group>
      <name>hk2-locator</name>
      <version>3.0.6</version>
      <description>ServiceLocator Default Implementation</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">e976aff53fb156b02317d2b8bc40660d</hash>
        <hash alg="SHA-1">92d5c92c9f23bea4b8681c6f8d6ba3d708619f81</hash>
        <hash alg="SHA-256">e2664d21b017c3aa1518b913264602bea604edc54d356103c10afba99abd04fc</hash>
        <hash alg="SHA-512">bd5393502a4ec94b0f849ae60d5d83f5e3c29fe257d08a4a34a73524fdc172bbf58714ccfaa37e6ba6eaa8b035558c4bf5d26b61f82fb6f9d741d95e62fdb8d4</hash>
        <hash alg="SHA-384">0b6afaedd573654a40fcd628eb987f3fae13f465107e0e57c403751f49fc82bb3c12ce4fc9667fd5c952f1500c80b63b</hash>
        <hash alg="SHA3-384">bf558560ac20d535e3e5c199514ddd480cea1019c0ff37b45f4e526d3b76a8938ee58a8ac0efb0aafcd672de1ada46ca</hash>
        <hash alg="SHA3-256">0dc5dbb60795f75abdb5b2a78e569f943484f6ed5af9f9b6622382e59e3c4542</hash>
        <hash alg="SHA3-512">14e8be65a317c3dad65787f8cdf2d55c09f96a2df577533aa3c062a34e6a811dde8a793380ffd7e5e02597c0e009f91cfe93fe20c6931d856aefc2b4b88a4c3c</hash>
      </hashes>
      <licenses>
        <license>
          <id>EPL-2.0</id>
        </license>
        <license>
          <id>GPL-2.0-with-classpath-exception</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.glassfish.hk2/hk2-locator@3.0.6?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/eclipse-ee4j/glassfish-hk2/hk2-locator</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://jakarta.oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/eclipse-ee4j/glassfish-hk2/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://dev.eclipse.org/mhonarc/lists/glassfish-hk2-dev/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/eclipse-ee4j/glassfish-hk2/hk2-locator</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.glassfish.hk2.external/aopalliance-repackaged@3.0.6?type=jar">
      <publisher>Oracle Corporation</publisher>
      <group>org.glassfish.hk2.external</group>
      <name>aopalliance-repackaged</name>
      <version>3.0.6</version>
      <description>Dependency Injection Kernel</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">e07024ce0f95aa4a8797257c97fa5774</hash>
        <hash alg="SHA-1">e3c3f17b649c97155640616026bd32b1043b3c1d</hash>
        <hash alg="SHA-256">a82b6d1a348324ef88dc807c7cd7aaf633985cbff7b30036fb61a1b86981d840</hash>
        <hash alg="SHA-512">605075fbfa84d426ace71dc40036dd604d969a657d8990996e0910c654354a06de65b52e9b24e0f863cc9196223be5c816e4b655f13e14386396952e785962b1</hash>
        <hash alg="SHA-384">9b9a142c1a9b451a9918b6f70b391821c5bbac24ed0bcd3584e57fed9ab4e2f6cd636b65c762069547703c5bdbb0547f</hash>
        <hash alg="SHA3-384">7ea7aeef9d0dbfda36f75fddb4cb8d63d96db4f3a52e085017c055a082360cd1116e1e01de88dadaaf6d35fe7618cc47</hash>
        <hash alg="SHA3-256">751c96c0799d0c275276aefbec4ac6e8df507c6941aead48d2f46e7547c3b85b</hash>
        <hash alg="SHA3-512">a5b02c7033783d556364e96c8610e3b46cc6bc5b6cf2ed3d929c5008f1caca4f77d3b975f747ea1e1ca3b9a72e54558118ce452f7470f109f0e1a072a693195d</hash>
      </hashes>
      <licenses>
        <license>
          <id>EPL-2.0</id>
        </license>
        <license>
          <id>GPL-2.0-with-classpath-exception</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.glassfish.hk2.external/aopalliance-repackaged@3.0.6?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/eclipse-ee4j/glassfish-hk2/external/aopalliance-repackaged</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://jakarta.oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/eclipse-ee4j/glassfish-hk2/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://dev.eclipse.org/mhonarc/lists/glassfish-hk2-dev/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/eclipse-ee4j/glassfish-hk2/external/aopalliance-repackaged</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.glassfish.hk2/hk2-api@3.0.6?type=jar">
      <publisher>Oracle Corporation</publisher>
      <group>org.glassfish.hk2</group>
      <name>hk2-api</name>
      <version>3.0.6</version>
      <description>HK2 API module</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">37d753cad17273560c48b745f024cbaa</hash>
        <hash alg="SHA-1">5a5152dea2c43384f5c07985eb27140134074ecb</hash>
        <hash alg="SHA-256">c049a21a9fd9316c7e291a2bc28835f70d25affb623dc1599a83b6b84ec83a4f</hash>
        <hash alg="SHA-512">2ab96cb843cf7fedb97ca308f0877a391cd6da57885949cb5f4ffaade890e42cde5a037709da3e905735aed67b27186603faa4d9ee83ff05b199299311c080c2</hash>
        <hash alg="SHA-384">a0397611dc07fb93b0261281028670ee63f6bf79252ab5d894ce0bba6dd5f0ad255132dae1c5f14bc20c9bdd7397c513</hash>
        <hash alg="SHA3-384">025c0326f05cbc1b757dd3a9f8da2aaf51af3cbb7f1120a5cb9f7a6cd4a1cfea5f635abb91574d1faeaf351efe83f8c8</hash>
        <hash alg="SHA3-256">766c45f469c66adbf6b3a1fcba0b981659884b53592e44fd9e8723381ce09ab3</hash>
        <hash alg="SHA3-512">4e8f754573061d23c56185ab569d307265900dd873a63b30255f1c3c34a1866a2ff49020745e58cafcd19a9b8ba73c4caf00d7377863de59aefe483897db6252</hash>
      </hashes>
      <licenses>
        <license>
          <id>EPL-2.0</id>
        </license>
        <license>
          <id>GPL-2.0-with-classpath-exception</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.glassfish.hk2/hk2-api@3.0.6?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/eclipse-ee4j/glassfish-hk2/hk2-api</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://jakarta.oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/eclipse-ee4j/glassfish-hk2/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://dev.eclipse.org/mhonarc/lists/glassfish-hk2-dev/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/eclipse-ee4j/glassfish-hk2/hk2-api</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.glassfish.hk2/hk2-utils@3.0.6?type=jar">
      <publisher>Oracle Corporation</publisher>
      <group>org.glassfish.hk2</group>
      <name>hk2-utils</name>
      <version>3.0.6</version>
      <description>HK2 Implementation Utilities</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">4f0469e8a5957c5912639f92244a9662</hash>
        <hash alg="SHA-1">b3187d0673c0fd52de197e52c62545c34d4eda29</hash>
        <hash alg="SHA-256">fc84d85a0744b576d9ec7db5845eeb998ed532a9450dd19c8c922c3ee6926206</hash>
        <hash alg="SHA-512">2bdf1872f8401bcf39c6ea1a81475940b53aadaae171a513a2c196dafbfe1c5701e7eeb269a4dfabed5cb08f4284f48106f748946f0cab9958e8381893b65921</hash>
        <hash alg="SHA-384">5b84718eafebd903a295be59d825bdc9cc2722152ff2969c88db0fddfcc79f66de4f2f5a0ef3ff27875888de98af5668</hash>
        <hash alg="SHA3-384">3c487313866fb347fe9b52b90f6df74f830e2c3ed3d43d1dd920c500723cda8287ead009649271a70394ad1aaab958ac</hash>
        <hash alg="SHA3-256">ca99f8375cf00f996191b53737647f16214c7f81384ca6ce3097e448ccb5138a</hash>
        <hash alg="SHA3-512">4e05d078d7a70017235238abf02f7302914e4e00c96c33b91efed2d2815f298525fab3f1bc28bd9eb03581287cab2cc9e291d952cd949748fef3e381fa38c24f</hash>
      </hashes>
      <licenses>
        <license>
          <id>EPL-2.0</id>
        </license>
        <license>
          <id>GPL-2.0-with-classpath-exception</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.glassfish.hk2/hk2-utils@3.0.6?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/eclipse-ee4j/glassfish-hk2/hk2-utils</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://jakarta.oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/eclipse-ee4j/glassfish-hk2/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://dev.eclipse.org/mhonarc/lists/glassfish-hk2-dev/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/eclipse-ee4j/glassfish-hk2/hk2-utils</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.javassist/javassist@3.30.2-GA?type=jar">
      <publisher>Shigeru Chiba, www.javassist.org</publisher>
      <group>org.javassist</group>
      <name>javassist</name>
      <version>3.30.2-GA</version>
      <description>Javassist (JAVA programming ASSISTant) makes Java bytecode manipulation
    simple. It is a class library for editing bytecodes in Java.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">f5b827b8ddec0629cc7a6d7dafc45999</hash>
        <hash alg="SHA-1">284580b5e42dfa1b8267058566435d9e93fae7f7</hash>
        <hash alg="SHA-256">eba37290994b5e4868f3af98ff113f6244a6b099385d9ad46881307d3cb01aaf</hash>
        <hash alg="SHA-512">046c5b87732ef28540c56f88891238e49ac15fcc23e1f13e0b12de816831ba3de54e68a727b6163877a7b19b13f1362c0e6affa2664af1fdac5748632ed7a09e</hash>
        <hash alg="SHA-384">d1dfb87ac4d7797ea07098b7814190eed3aa16e86dd792916ff7f86c30ad456dd153f9ae4e77f13cee03e23dd3cfb24b</hash>
        <hash alg="SHA3-384">f70abfcb1b0d9e7903171bf52fe34b33ceffa9c53b697fabac9f2d3e02b8621446f7b2471d44e2cb70862e559b4d36b2</hash>
        <hash alg="SHA3-256">cf3f1d9150d71a6f23a749c24d355accb133991a9272110c5fa0ccff73220367</hash>
        <hash alg="SHA3-512">e294c989c20271f42a4bf0c63cbb691cb2fa284088c8a846983aa0e4948b4325131b8829b210214f539d30eb4e20b14c06f4b164208488719512739d78dfd454</hash>
      </hashes>
      <licenses>
        <license>
          <id>MPL-1.1</id>
        </license>
        <license>
          <id>LGPL-2.1-only</id>
        </license>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.javassist/javassist@3.30.2-GA?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://www.javassist.org/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.jboss.org/nexus/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://jira.jboss.org/jira/browse/JASSIST/</url>
        </reference>
        <reference type="vcs">
          <url>scm:git:git@github.com:jboss-javassist/javassist.git</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-all@4.2.7.Final?type=jar">
      <group>io.netty</group>
      <name>netty-all</name>
      <version>4.2.7.Final</version>
      <description>Netty is an asynchronous event-driven network application framework for
    rapid development of maintainable high performance protocol servers and
    clients.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">ba34be27fae7178dd2ed279bd2b87245</hash>
        <hash alg="SHA-1">deb73dd3e2b9206e788e2746b4eb466bae64d101</hash>
        <hash alg="SHA-256">49f02fc7a12cab70ee5caf5d41e74c94df9f2df140554f3d2f4562cf85f8e21f</hash>
        <hash alg="SHA-512">4a37a50299dc141c154845616e9f9459f41a59cbf375e185e22124bde15ba066358e516571ed6cb7bba03b7e75377bc8e321b03639a7251d13ec55d4a7c0ab10</hash>
        <hash alg="SHA-384">241bb0ff0584267a3e7f2c85f94194c3826fe9a13317cd37fd36c3928d2ee1bc10d45cbc1f2a37d35eb7c1d62c5e8ceb</hash>
        <hash alg="SHA3-384">3f2d32b746de25f60699b8cb08c79ddd8dd330ac3088ed12c52b1808f48db025880085e7ff2f5dde7984e23a3257118a</hash>
        <hash alg="SHA3-256">dd7555aca1f0ae8cef0da01144dbe8a95f6f18b3c8594382fd61599f6e87ff2b</hash>
        <hash alg="SHA3-512">1558cb4f27c29bc46efebf43cd771d5239dd8541524486561f197293fcef5216d46c2eb3d0cdb63da3d19123b1a578daa8f8a1c809081399f878e6f38cd5a495</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-all@4.2.7.Final?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://netty.io/netty-all/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty/netty-all</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-buffer@4.2.7.Final?type=jar">
      <publisher>The Netty Project</publisher>
      <group>io.netty</group>
      <name>netty-buffer</name>
      <version>4.2.7.Final</version>
      <description>Netty is an asynchronous event-driven network application framework for
    rapid development of maintainable high performance protocol servers and
    clients.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">f61bad1beda071e013f9b1d654cdf806</hash>
        <hash alg="SHA-1">5555ff561643bf2f8430fb57c24403c0efe15994</hash>
        <hash alg="SHA-256">b81613c8ed22b1cc39eccf2a28bd0c1d4561fb2e5e542061617ef4ce1d228bf5</hash>
        <hash alg="SHA-512">6d3a9297cc52074d29bbcb21061737d1f5df41253141cd0280ea6543ffcc6b3908554aabb9938176655a8618d35fed8c59cb028a89d02d77d466d2413aa13d23</hash>
        <hash alg="SHA-384">661c88fca915d1af01873fafd8abaa65dd073127410ae7b7c767e65dde16cc8cee819d34b23b2eb958f1ad6ceb82d436</hash>
        <hash alg="SHA3-384">76582ecbffe66b42942f320f4411c530669d10e68a7a41eefb8642d87213350aacbbc8d4ee59e8b6b879207495d26fad</hash>
        <hash alg="SHA3-256">065caf2446ad13406cbd57804d98a762240253de99f2b016f0563c624f292541</hash>
        <hash alg="SHA3-512">f55f3883d53eb55155d9cbed43e06c170b1612f62fed85075358e9c4e22a6d763b5a4b9b1abcd1168165133b034ec4f7f31b0de098ee5061b4b571e32cf2cb65</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-buffer@4.2.7.Final?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://netty.io/netty-buffer/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty/netty-buffer</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-codec-base@4.2.7.Final?type=jar">
      <publisher>The Netty Project</publisher>
      <group>io.netty</group>
      <name>netty-codec-base</name>
      <version>4.2.7.Final</version>
      <description>Netty is an asynchronous event-driven network application framework for
    rapid development of maintainable high performance protocol servers and
    clients.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">cb7cbd2f5331ea1d349f3c87df5a3221</hash>
        <hash alg="SHA-1">915e381ebabcf115f1c7ff7032d55c48afb50210</hash>
        <hash alg="SHA-256">6360415b7c87160afcde5e7d4946c35539b9f043e8166c91a7fff95cc6067d9f</hash>
        <hash alg="SHA-512">674e80d0bee4172893bb7838e6630768118c8ae10f65ba87b6b3bdb5bde88eefb6aa22e0513da05d6b5c6b0ff8e30b746e798970251f836986156016a5af4fed</hash>
        <hash alg="SHA-384">751fe21d59701a576deb3c7e8ad344dd73f26ff12d6a3e11366df140177c0ca6012daac427bfda8adb4bd2ec4975e82f</hash>
        <hash alg="SHA3-384">f1a39e8955837c841b56d376376da4309921a5aac4c7f5cfbd00470a47387cca40e3c8b2055f36d3f4e5a585076cb0f4</hash>
        <hash alg="SHA3-256">cfd2e5e6817f6c77531d907fee05dbdf0ca3127a3ebeb764b0b1c6065d84c685</hash>
        <hash alg="SHA3-512">e54580303688b84be33bc67fe915b3922a436d89351669eb432c292d8ed752f43e275a02ad19a5da1c7d385fd1e6a9b5ad036b06bd44b77de6ab363c69704e10</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-codec-base@4.2.7.Final?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://netty.io/netty-codec-base/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty/netty-codec-base</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-codec@4.2.7.Final?type=jar">
      <publisher>The Netty Project</publisher>
      <group>io.netty</group>
      <name>netty-codec</name>
      <version>4.2.7.Final</version>
      <description>Netty is an asynchronous event-driven network application framework for
    rapid development of maintainable high performance protocol servers and
    clients.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">c25b9e14b1109d4a5ee0524933deb56c</hash>
        <hash alg="SHA-1">e47bea286fb06764f48fe7b0d96956c4faa9b4c7</hash>
        <hash alg="SHA-256">5f369658381789998c042a98f02da71d9c39884bbb4f7fd58282f765e09ca031</hash>
        <hash alg="SHA-512">03ba73743ce2429e9d02d91fbd23304c07811fdd24025e2390572e2977ff7707596be4d58a3a51330f136ea38595455cfc99f4cbd7d1dd37f1aac4fb2355148f</hash>
        <hash alg="SHA-384">f4f0c1c3ada57a052e56e86c2c2bb534c36442de76ff872494eb4659e455058ccb4b9dd97e3715a2af11ad258c7456b1</hash>
        <hash alg="SHA3-384">afefd0f7a88f048dc0f4991c143523480206cdf2104457f6b9d35cf404972c8a488211a31d9aa43397fe6f5035815b30</hash>
        <hash alg="SHA3-256">cf71dbe699e527f55d0971cb78437cddf3d0342772ccca6ef8446f73db86c52c</hash>
        <hash alg="SHA3-512">dccaad03af1d7f003c62171de45850519f4cec24d1891018ff98c905d3f57bff1d05a346a34f4f638e4bb5a56d0fee861e5b821d61f976eec3c8a269507ea849</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-codec@4.2.7.Final?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://netty.io/netty-codec/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty/netty-codec</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-codec-dns@4.2.7.Final?type=jar">
      <publisher>The Netty Project</publisher>
      <group>io.netty</group>
      <name>netty-codec-dns</name>
      <version>4.2.7.Final</version>
      <description>Netty is an asynchronous event-driven network application framework for
    rapid development of maintainable high performance protocol servers and
    clients.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">f62a085a2a348c0926c4fe82cd623a9c</hash>
        <hash alg="SHA-1">95a2b329442a22a7d77de5fc5ecebbcf26b8cd4e</hash>
        <hash alg="SHA-256">148f08291e4d6f4e361f33ee691ce66b8c9a95ff845176bfb6bd88cffb95b2fd</hash>
        <hash alg="SHA-512">d5f49186652fa36f94b53ada418d75c2c1785fd8d6f847de01ff863fb5b326b03381e980e2f86c864133a6e0a7e4fc1e98ca7c311ed58ad1b2ac18532b745651</hash>
        <hash alg="SHA-384">afa3dfd7a366e84f376db71e80ac70a6c3eec5c8bd693513fa372467058527baf2bddd70c7b3443d14330b063830084d</hash>
        <hash alg="SHA3-384">a5465d6182c46be6020864603a193ae7c8912dba7078731b5c7cf652d51cdbee9f53db1a49147efb18c78f6f8de0ecea</hash>
        <hash alg="SHA3-256">5f47488032f8e609e2d8eb05e42d8046e11504ab29628d04a43275f9427d8b1e</hash>
        <hash alg="SHA3-512">b4010de1023ddebb9a55e3c3035597da9dd73ccf0e91826bbecd990b6d05bc6a996d2cea4c6518eeb157b9f3ee13d4181c702909162ac190397c0f4bfee7d803</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-codec-dns@4.2.7.Final?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://netty.io/netty-codec-dns/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty/netty-codec-dns</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-codec-compression@4.2.7.Final?type=jar">
      <publisher>The Netty Project</publisher>
      <group>io.netty</group>
      <name>netty-codec-compression</name>
      <version>4.2.7.Final</version>
      <description>Netty is an asynchronous event-driven network application framework for
    rapid development of maintainable high performance protocol servers and
    clients.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">d7df10ca556335a43abfa4e5e848b5b1</hash>
        <hash alg="SHA-1">572341bc1ca90fd9d6e47f1d2694aab5258566e9</hash>
        <hash alg="SHA-256">edd53ad34991804301a46571113d8ffb4d6f67e6d874674dafbb915724275cb3</hash>
        <hash alg="SHA-512">ee5fe7aafc807c1831f8ec15ff3af209599581d768bf2a784e676807fdb30a287747ad92fb4f1efa84134efe0d65c0c4023ea41c72d13d36a74293bd0ab81475</hash>
        <hash alg="SHA-384">0c359217c55af9b02a74a17ff08ad3ed7e3f728b3743098b313a25bb09beac383b53233457d5c4201b9f456f4ae6a924</hash>
        <hash alg="SHA3-384">af8135b70abdb6f113a73ec331e3d15d056a8d96c21cce3ed17f75cc115abf5c562c687b88548df091e7dee0c4050a14</hash>
        <hash alg="SHA3-256">0ee59f90a0f617267234618260321f6d9548ce2c4c7c12d427a43de72b7e6084</hash>
        <hash alg="SHA3-512">cbb5aea58ea8885e5f2b29edf3df39ed6d616ab254f842c9c06fd51999a4d2324f97096d074ed9f86e0d17c307e086949e96de78feb27f3838f42e12125120af</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-codec-compression@4.2.7.Final?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://netty.io/netty-codec-compression/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty/netty-codec-compression</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-codec-http@4.2.7.Final?type=jar">
      <publisher>The Netty Project</publisher>
      <group>io.netty</group>
      <name>netty-codec-http</name>
      <version>4.2.7.Final</version>
      <description>Netty is an asynchronous event-driven network application framework for
    rapid development of maintainable high performance protocol servers and
    clients.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">5c642451ebc737738b22ecb92664d32d</hash>
        <hash alg="SHA-1">b734c108854099c421fd94d92d9f865e4d4da853</hash>
        <hash alg="SHA-256">2984dd38420a61c4dd68fcacc51ffc528eb46f73f7795cdafdb3a4d6fcb76862</hash>
        <hash alg="SHA-512">5a99648de44e6c5c12e3a4cbc5473d87cda72da6201c13da55db1e055df8c50ec20c7b68655a768d8d20b55cd3c319ebf939b82926a2921de6867f2126db00a7</hash>
        <hash alg="SHA-384">10b5ec708acf00e90dd29310fb7803d1330936178146177030a58b2481aa1fefa6cc71f32af67db1202fe7e2a31b4ee3</hash>
        <hash alg="SHA3-384">6f208bb2a1289fb18eee42c3b5626323747bdd18f97f42f35d01b7c4b9cd6068a7e096a908847448a1141b8638135ada</hash>
        <hash alg="SHA3-256">5b2a751cb1806d283de0704b5bb27552b4e9867c539bc4b4b1e5100247ff710b</hash>
        <hash alg="SHA3-512">cf544baf51209117ba763f0d641a4d1146d53d6f6461e03980c8987e22052637bb1110ffd53b392601c9f90faa8478ba83a0565de122dc1d3eb3b02bf3295bfb</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-codec-http@4.2.7.Final?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://netty.io/netty-codec-http/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty/netty-codec-http</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-codec-http2@4.2.7.Final?type=jar">
      <publisher>The Netty Project</publisher>
      <group>io.netty</group>
      <name>netty-codec-http2</name>
      <version>4.2.7.Final</version>
      <description>Netty is an asynchronous event-driven network application framework for
    rapid development of maintainable high performance protocol servers and
    clients.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">b5de7d58a67e47262eb4000ba92bb21f</hash>
        <hash alg="SHA-1">ce3234f38c9b7a5f625bc75765fa9b62c99d7f71</hash>
        <hash alg="SHA-256">c98254983dffa9c62bccb0e39638e1138feb4dd7b46e7a663e790f6a070a9306</hash>
        <hash alg="SHA-512">af949a0835f8e5ef68ec9c459a6a56f7ca4944c1f0fdf8ad5c5574a9162bb8eb17bd73af2e433071c6464cada7f65af776e0135106047ab34a3bd4114bfd47b0</hash>
        <hash alg="SHA-384">f33589f4780e59210aa6f0ccb9b9d3ec2d1577cfdf783b0d3fa6230d9cf34e93a1b242441421f6625ce3a73180c579b3</hash>
        <hash alg="SHA3-384">7e11350bc77b0111dd4219cfca998af8d136d4cbd118d4a96d17e98754ceab76c38def7ecbb1c6e0ecab6541c703f238</hash>
        <hash alg="SHA3-256">7717af008cefb93e89909c7986c4ca6b99766040df5b797255d577ed4fccb24e</hash>
        <hash alg="SHA3-512">2347e52ec5d6367e6fc5f922853d4ec36ad965d56fb24cc97b172947457f2cb13792f0b11da343a385a8e0471b4e4a27dcb64ab69731a2282a983b6ebfabb041</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-codec-http2@4.2.7.Final?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://netty.io/netty-codec-http2/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty/netty-codec-http2</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-codec-http3@4.2.7.Final?type=jar">
      <group>io.netty</group>
      <name>netty-codec-http3</name>
      <version>4.2.7.Final</version>
      <description>Netty is an asynchronous event-driven network application framework for
    rapid development of maintainable high performance protocol servers and
    clients.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">95600094937f5a6b27fd472744bb4003</hash>
        <hash alg="SHA-1">c9b6155713d6017a21e71dea3e041c4143facf5c</hash>
        <hash alg="SHA-256">2d4d60ab8e3fda66f8b436ea1b034f68690a067e61957547a41be7792663c7d5</hash>
        <hash alg="SHA-512">4787c56f03e1e77fa2b67529f8bbc70090cc2905620e13431185f23985bf34bf423120cd10967c592b8174c68bbdd55c66866795611903b4ca596ddcbe4fa69b</hash>
        <hash alg="SHA-384">08174aa201abde974aae4bf862a76fe5c0ce9b26142ca5753d9bba39c07562abdfb5d2536be1df148a246f0ccacecfba</hash>
        <hash alg="SHA3-384">c7f9ecdf305265457a0fcbad1dbb46b500c6867719cad0583188a96f477869859bf811e71f20e4cf68051dced8be9c9a</hash>
        <hash alg="SHA3-256">9043792f09d61dc2083b46759f246c34871fcdcd962a68f19678c1bb48003f84</hash>
        <hash alg="SHA3-512">56d3e56a4c9f62461f6d4d4cf8efecad73d0489bb9d7d5f7eae8af663ea2f40cb3f2beb728f21c3f33d1dd544c7da7a845adbc28036d7d05c2b7361e9b1af2cf</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-codec-http3@4.2.7.Final?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://netty.io/netty-codec-http3/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty/netty-codec-http3</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-transport-native-unix-common@4.2.7.Final?type=jar">
      <publisher>The Netty Project</publisher>
      <group>io.netty</group>
      <name>netty-transport-native-unix-common</name>
      <version>4.2.7.Final</version>
      <description>Static library which contains common unix utilities.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">216eeadc4850e2836a8e106210ad48ad</hash>
        <hash alg="SHA-1">89953f04259ea7502cffb313630dd51e00e60669</hash>
        <hash alg="SHA-256">736703b3f6d127e182f5be888b6e15732b0c08d6634e00725352a6a9d19974b2</hash>
        <hash alg="SHA-512">69060e17be11a915d48b7751341e4c3a4a730eb66763c0e9610a83783bd3076498697ed7447fead5bb4bc1effd3f1c256945cce00f4476866c3167371eec7de4</hash>
        <hash alg="SHA-384">9e843f1dfe2f6095c17d5a473826818f249f7316d6c1136f7150e6ae0031dad0b323f2355ba69fa2f9d8b967fd73df61</hash>
        <hash alg="SHA3-384">bb497286eabb5d0da257dfdc7d4c586f361785947a20c7a9ef5dbbedce4c7e2e04800341ec6519e4afd321ba8d8a57f9</hash>
        <hash alg="SHA3-256">4b916586134b227a73168121a16d4667b87b8865b2227a5d5beb680023f441d2</hash>
        <hash alg="SHA3-512">762748aa040d2b20fc510569a36722d27ca30e013a33b73c2d517a101d982cb3088be52915fa37e6609726c7abb0bb94af836a4c3ee632f9ba334cc9774e42ff</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-transport-native-unix-common@4.2.7.Final?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://netty.io/netty-transport-native-unix-common/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty/netty-transport-native-unix-common</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-codec-socks@4.2.7.Final?type=jar">
      <publisher>The Netty Project</publisher>
      <group>io.netty</group>
      <name>netty-codec-socks</name>
      <version>4.2.7.Final</version>
      <description>Netty is an asynchronous event-driven network application framework for
    rapid development of maintainable high performance protocol servers and
    clients.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">b87f4ddd11e9adc257409b9d6cab35d0</hash>
        <hash alg="SHA-1">9f26324e436e8884bb4aa801a6e9151c0b50a754</hash>
        <hash alg="SHA-256">a5e245fb9038544d2a9bc8db86efd819aa6adb3be3257a879dafbe1bf78eff33</hash>
        <hash alg="SHA-512">83043fa8ba07e4ec9031bd522e64bb1117df64cc7ed1a93463e3220309c0c87a95d75b1d85c11bea442810357b20f846efac67f8e54a7cc91c3a1ccce4b37105</hash>
        <hash alg="SHA-384">6ee83c2dfece062aea166edd1a3bdec9c396961fa2e536b768d647c4162923c778bad4f8b909ba87a526d568868e5946</hash>
        <hash alg="SHA3-384">b34eb650d889c3a80b8840c5dfa4aa0d65932b63fe6baf2fecc7b4453003bcc1428f620178a7aeb1dbe558b5d103da9f</hash>
        <hash alg="SHA3-256">74cf53e1b5d7ced257610b4cedb6e7496634c424252800806cc284025405f63b</hash>
        <hash alg="SHA3-512">e902a44982425a7a8a3e755d1c06491f2f6f63be266d865e284aeae98ffbd30331145b5a4b207cbf440cec78168608f1db5e71ada83328e0778e57189e9b02ac</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-codec-socks@4.2.7.Final?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://netty.io/netty-codec-socks/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty/netty-codec-socks</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-codec-protobuf@4.2.7.Final?type=jar">
      <publisher>The Netty Project</publisher>
      <group>io.netty</group>
      <name>netty-codec-protobuf</name>
      <version>4.2.7.Final</version>
      <description>Netty is an asynchronous event-driven network application framework for
    rapid development of maintainable high performance protocol servers and
    clients.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">8b1621b16afd1dbe5c10c1140e1c3796</hash>
        <hash alg="SHA-1">228896874d933b1111cdf495c6a57e1207956a99</hash>
        <hash alg="SHA-256">4b25259b6f75ebfc77f014a08f69bad019116d4f5ca548fdc41f3dad8c0de331</hash>
        <hash alg="SHA-512">c330f06328abd0c618bc9b88d077f2711b8e78e964dab47219d54f7deef3cd5cf0dcfb07f44e4c397803c1c24c6ddf653e60f4870a5417ff7b80b231e5f62694</hash>
        <hash alg="SHA-384">dadb810de8ba847df6db25ef1b5c2dc168c2201996f7362258ee00a11236f5fdb6bb7c7963a9a61c49dcd84e4ab6010e</hash>
        <hash alg="SHA3-384">25cf4ec438022040630f8964a78c30a1b9b51ccb6bfe10e45cfb7632c0882313f3fbff99473580f04025dc40b6efce24</hash>
        <hash alg="SHA3-256">8474edb3b8c78634a48031423fd1f3d4d4807bf90cc3bd6784fd4aa722359ced</hash>
        <hash alg="SHA3-512">b1af0a4414a7403e166c865af746f2974512cb5b17e4ad47d5838a9568c78e519ba4ba4d3e8b166a56fb32626bfbfca208e1629b5363783f945e7cdb007e319a</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-codec-protobuf@4.2.7.Final?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://netty.io/netty-codec-protobuf/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty/netty-codec-protobuf</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-codec-marshalling@4.2.7.Final?type=jar">
      <publisher>The Netty Project</publisher>
      <group>io.netty</group>
      <name>netty-codec-marshalling</name>
      <version>4.2.7.Final</version>
      <description>Netty is an asynchronous event-driven network application framework for
    rapid development of maintainable high performance protocol servers and
    clients.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">f7a29ebd5f1542db9aab9e184b845b54</hash>
        <hash alg="SHA-1">575077a8a94d2cde5b8945871015616570c45e1c</hash>
        <hash alg="SHA-256">e550adb758eea43aa49de00e7418b098931711d4a31d62e65c41b0994c95b237</hash>
        <hash alg="SHA-512">2c24566a999d4bb7b87b5157431a01a40acbe3d25c072e654d5ca57bebb19a3bba082858364bc2665d4e3d0083110672e18d31f94a6c025a21e3187baab208dc</hash>
        <hash alg="SHA-384">6aa4742e0b434baa58d102c8446f7dda36bc150c539e81f0b11cc451f059fabb482e5301f626731050140cbb0ae6d9e8</hash>
        <hash alg="SHA3-384">99370ac2e63f345c371f713ff862196d880e5452489eb0c23ef328b2a7b26b5db9bbaaf9ba85c432610a7ccf145130bf</hash>
        <hash alg="SHA3-256">47755126c48b00f38a5313163989e3014d40620a357b844a019e140548350f6d</hash>
        <hash alg="SHA3-512">3bd7ff530db2117675c320d740fbf27f649a455073bf2050afd23556ec5a024a4dc98817451ad6ae2ca6fd93f8a61d08a93c31ae51b12d68f4346569062f209c</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-codec-marshalling@4.2.7.Final?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://netty.io/netty-codec-marshalling/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty/netty-codec-marshalling</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-common@4.2.7.Final?type=jar">
      <publisher>The Netty Project</publisher>
      <group>io.netty</group>
      <name>netty-common</name>
      <version>4.2.7.Final</version>
      <description>Netty is an asynchronous event-driven network application framework for
    rapid development of maintainable high performance protocol servers and
    clients.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">a7e1dba851328d20de72635d80aa8092</hash>
        <hash alg="SHA-1">11aa30df26af4fca3239ac1917f303a280f301e1</hash>
        <hash alg="SHA-256">2345bc0ed5843fa57aa49eba67529485c3a1d420fcf0429324c8220c7a80e9a6</hash>
        <hash alg="SHA-512">9af970dbd13a2d41ff7a5b28df2e15a7f06f20a30babfaf721b8a8256ff19492bc362575f9c1717372c8aea7fb99552140d383528f11af34efe4823ea5ba0d11</hash>
        <hash alg="SHA-384">fa27f77d6126520c674aa3c372f2b8b7c296a17de6cadaa81c9e782594f2eb56568da627985075e07070aae1009005d7</hash>
        <hash alg="SHA3-384">bbf2f3721041ea29153a9bf441dc5d1ffe88eef2ad6dc576e7dfe0eb7d0347d154b033605848801dd6de030eb18b7c22</hash>
        <hash alg="SHA3-256">1b5cd8f45abff1cf6e5dacbd31aa288e6ddf6105dc592928b71d89ca45cd89f5</hash>
        <hash alg="SHA3-512">5fd46e673896810a157b8612580f9f78ca0075b839f5c607e9936f559fc086fd0782f3a95683bfd998b53b80401769b00b2ab7fa299d30a47ff9c3c75138f5d1</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-common@4.2.7.Final?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://netty.io/netty-common/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty/netty-common</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-handler@4.2.7.Final?type=jar">
      <publisher>The Netty Project</publisher>
      <group>io.netty</group>
      <name>netty-handler</name>
      <version>4.2.7.Final</version>
      <description>Netty is an asynchronous event-driven network application framework for
    rapid development of maintainable high performance protocol servers and
    clients.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">5cc216424649736fdf10b7dcdec55700</hash>
        <hash alg="SHA-1">7ad8a1f851e2e6fe93cdd091871fda2b81c03b5b</hash>
        <hash alg="SHA-256">21d063409c12dbcec46d380c8856a0f7b6a5b68bb5f1d005eb065b4d64146cb3</hash>
        <hash alg="SHA-512">cfb3d74d4c8e753ff7fc31da3b88e0609dbd97d8e2e08afa8b7dfe98b90cc58daa3f31c254ef8274752af98703b6b7a12891c958ea9f3116ea50e404b26c8694</hash>
        <hash alg="SHA-384">e89cf648296f374e793fb603579fb37fa27d121747c6b15ebc93c3ff9a6c34b15d3e2ac074602baeb27dc92b38e02c4c</hash>
        <hash alg="SHA3-384">b057c6924dc0ea4fbdfb52dc9906d13fd69965157ffcf645adc23087a8f265df0438e097e5de2dcbc2aa8b87e5d0bcdf</hash>
        <hash alg="SHA3-256">4defc4222f6c31b8783615656aa689de5a7cb4b85158583d025d82764087b4f8</hash>
        <hash alg="SHA3-512">3063bb90a134876af26ac3991a51099e3ad712b1e188241ece45e88c3b2c9c4d54ee1bb717130a688a4845dee68930e3bf5603a62ac9356c4e018461af7c223d</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-handler@4.2.7.Final?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://netty.io/netty-handler/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty/netty-handler</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-handler-proxy@4.2.7.Final?type=jar">
      <publisher>The Netty Project</publisher>
      <group>io.netty</group>
      <name>netty-handler-proxy</name>
      <version>4.2.7.Final</version>
      <description>Netty is an asynchronous event-driven network application framework for
    rapid development of maintainable high performance protocol servers and
    clients.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">b8f9b84fc98f9766ecace9be44083480</hash>
        <hash alg="SHA-1">a1b6d07504fe98163f49d34c9a5efb22d8e84212</hash>
        <hash alg="SHA-256">8a31f546099256a5b9365213a1a950cc7fd2ceb9827ac63e0506216df6fa72f6</hash>
        <hash alg="SHA-512">9bab9abff6532027becc11972fa2cdc95c04b3646bcb71876763c1303d8a0861d20ee89648f904d7052d96652e656a4e1837b3970747cb86201e8df535f826bd</hash>
        <hash alg="SHA-384">15517cdaf06f7569bd8aef0f66773b8f7f96cbd63a2632a40488b5d615841324939302881f3ddebbef2f57b8848e18ce</hash>
        <hash alg="SHA3-384">64a82b15e3e3f9c39f105020ad08631ce5f2fd79e2fe5135ecc3b5cf29f4ce697e60c6dc50079ec6f7d7d5dc564d5270</hash>
        <hash alg="SHA3-256">21c558a2c9f81ded223ed8d3bd2bebd35329b7af1fd8223a7ea669d24c5a07d6</hash>
        <hash alg="SHA3-512">61b5a2c74dc5ff941e93235be91c5c99ecfea16e442089fbbeec19631e15189fa699071339d0fe2b325a51c536576f33cd0dd366bb57b3d99dacb9ff78734543</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-handler-proxy@4.2.7.Final?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://netty.io/netty-handler-proxy/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty/netty-handler-proxy</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-resolver@4.2.7.Final?type=jar">
      <publisher>The Netty Project</publisher>
      <group>io.netty</group>
      <name>netty-resolver</name>
      <version>4.2.7.Final</version>
      <description>Netty is an asynchronous event-driven network application framework for
    rapid development of maintainable high performance protocol servers and
    clients.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">61f623f17707bfa9ca27f5b2d3d24bc7</hash>
        <hash alg="SHA-1">5f3e5ef8de03992cd4fb46960dc0085ec1a12a12</hash>
        <hash alg="SHA-256">7e4d569867e6c08437fb21a220ea01c294b0e38f01149b683c895a1bcd928438</hash>
        <hash alg="SHA-512">77af369bb641dd71d5df7ae0d08a92ae81ab78394ccce0d254953176b5621bea5ae7122c1fd7460b4bfe967383f3dd2d0661b62b15d1fdcf4d91717f39ccf6b7</hash>
        <hash alg="SHA-384">54906f5a0f93d86386ef3c468eba4d71713e01e1c470f859c531d1bbf83cb4640252f508c0d58552bfc3970fcd9f9d1e</hash>
        <hash alg="SHA3-384">d7b969838a02fe447f1b24f839e611b707bd85fe2509c6f27d55b7480aa1369762c037fd9808d2410c495265ecd2f9e6</hash>
        <hash alg="SHA3-256">341d6b5886ae32be924a57ba70e4038d40d56ea6d5f266342894c367e661762b</hash>
        <hash alg="SHA3-512">3b224d1ab1a41c18e1f85df7aed1c311b576b3a92d8b7de77cdf043e6517e56cc318982fadb9e097164abc78e49767ad25fa5dce5246364145eef83e76175ae7</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-resolver@4.2.7.Final?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://netty.io/netty-resolver/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty/netty-resolver</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-resolver-dns@4.2.7.Final?type=jar">
      <publisher>The Netty Project</publisher>
      <group>io.netty</group>
      <name>netty-resolver-dns</name>
      <version>4.2.7.Final</version>
      <description>Netty is an asynchronous event-driven network application framework for
    rapid development of maintainable high performance protocol servers and
    clients.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">1c90a3a6ed8829cb7b015f9b5e1fa77f</hash>
        <hash alg="SHA-1">5975d21835704a84d51405b5c4f843337cbf2bb5</hash>
        <hash alg="SHA-256">e42ef6295648685e465f9d9f306664ec7b4452e972ae4b3eaa707a94b313f62b</hash>
        <hash alg="SHA-512">5008f14557e67de085337ac7d8b915eeb37af57d4625455815332234d014e0cb037210b353fef20eeca3ae860e1b62a7fd4fcc6a42fd451cd509ae9bb9f90547</hash>
        <hash alg="SHA-384">d552d106411a4231ee8795d24d26402ab8796e1509986d96b1985c4641e5d87955f93a1e37c055440de1cdbf8bdf91dd</hash>
        <hash alg="SHA3-384">2288a400a6f21bb683c2f352cc98bd60896928a41015c3ba700d80f3d1ce85e85cb5d51308416bd69f42f042124d3a39</hash>
        <hash alg="SHA3-256">a7f61af27feb3e62e1366ae8de1be57ed8f22132f16d9bdb2f4f46ace46d95bf</hash>
        <hash alg="SHA3-512">29b180112628fd362e80b76f1904b86f213688923ede696a36a1f018392245cc3d8629f6d643ecf88393b638178455473cefb3048940cbf772d0733099649a25</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-resolver-dns@4.2.7.Final?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://netty.io/netty-resolver-dns/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty/netty-resolver-dns</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-transport@4.2.7.Final?type=jar">
      <publisher>The Netty Project</publisher>
      <group>io.netty</group>
      <name>netty-transport</name>
      <version>4.2.7.Final</version>
      <description>Netty is an asynchronous event-driven network application framework for
    rapid development of maintainable high performance protocol servers and
    clients.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">355369c4efc693ca3a108ec4fc94311c</hash>
        <hash alg="SHA-1">83ea548981d0d8c4a98027cc1a6f9624f902e142</hash>
        <hash alg="SHA-256">aadc6fb05c14fb789368ca3f854721549c72f6c0d81798bbccf9de1bb716892b</hash>
        <hash alg="SHA-512">96ee8e11b14754777c79c420fbf62c0a94b8cc7b54dfd22a84461a20d91eb6eb861427a6c54a15bcc1861a6f67c1c0f1ae5b5040aa082eb84a29daa016331d6d</hash>
        <hash alg="SHA-384">4740c371aa66ed10bd166e3e9b5b9159e9f99b087be81847bf3b68f9add34f4cebefdcc831676e22faf2c06a8b9c3332</hash>
        <hash alg="SHA3-384">c34e0e04f8eea1cd343d7eca01b96bf55699b77988b1a5c9671241fcc9d6426099834ecc437f272c65f3cb06e48a3bdf</hash>
        <hash alg="SHA3-256">18974dcf669f31df8bcef069d3b23ec1643b3bcf3a7bc54e07ed897aafe75beb</hash>
        <hash alg="SHA3-512">80a051de0c30aa533946f57c98630d448f4d5639dbeac76863ce87881b6a38180fd93d9fd4fb9b8f48b0e1717752e1adec4395f4ea7560149fa71bf01fcc92d7</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-transport@4.2.7.Final?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://netty.io/netty-transport/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty/netty-transport</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-transport-classes-epoll@4.2.7.Final?type=jar">
      <publisher>The Netty Project</publisher>
      <group>io.netty</group>
      <name>netty-transport-classes-epoll</name>
      <version>4.2.7.Final</version>
      <description>Netty is an asynchronous event-driven network application framework for
    rapid development of maintainable high performance protocol servers and
    clients.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">5120c2c296a90c1a03202b43edf1452b</hash>
        <hash alg="SHA-1">1075c09f48a78eef9d819fbfd9096b903fdd362a</hash>
        <hash alg="SHA-256">4492948e6a7694398e5197cf15ed2e21d6662a739d010ae666fa276e7222853c</hash>
        <hash alg="SHA-512">6a3fb533caffc469e53df2649a315ab3470afddee761ec0b827046fbc713f2ce0bc7329e63b1406ea48dc8771365ee0ba6637d3dab46a822c1f5044aefbd9978</hash>
        <hash alg="SHA-384">ee0abf569a7236649d660706e1c558ce57574984e7f0bd51aff9d312071c7856f8ffbf12eafb5e7b0621a7a2d71cde05</hash>
        <hash alg="SHA3-384">d812d17b6ec728bc1c9202635fb46104890e83c71798b878d252966691326ab4d57138fd7ee2f760177eb04541cafa1e</hash>
        <hash alg="SHA3-256">3fe3f3a1711ef25ec8cc38d62bd315fea2518a611c24a50ccf194c0caed587dc</hash>
        <hash alg="SHA3-512">13d65a6b4c4e6aeb7fad301da37dbcb349190f24addf842abe6f3f29e58eacbf4a9f1d62a9a5655109b8381d984bf82631e2af10ced259834422b81f850c35d1</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-transport-classes-epoll@4.2.7.Final?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://netty.io/netty-transport-classes-epoll/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty/netty-transport-classes-epoll</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-transport-classes-kqueue@4.2.7.Final?type=jar">
      <publisher>The Netty Project</publisher>
      <group>io.netty</group>
      <name>netty-transport-classes-kqueue</name>
      <version>4.2.7.Final</version>
      <description>Netty is an asynchronous event-driven network application framework for
    rapid development of maintainable high performance protocol servers and
    clients.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">7f1ea4986d99bbd172229c23a4ef0192</hash>
        <hash alg="SHA-1">bdec7c23c75caabd848426d073c09568e8d5f94e</hash>
        <hash alg="SHA-256">a3eb1c94ae1a6be9e1d1ec52c3f5c510a75b04b8ef1ea86b7e77b3f1287ae3cc</hash>
        <hash alg="SHA-512">ae625894bd4a0aa240bdb21ecf49592a92dd1d3c87cd1e6ab52582c228f894867b1b048763175ec130eab8a71c3ff9b8f628e03db65995c4ca56bab5408abdb5</hash>
        <hash alg="SHA-384">f3cd632d97596de356b0d157c6ab75d646f318195abf102457a99db5ee8a2f5811368058fcef48f1d8108f59db77db2b</hash>
        <hash alg="SHA3-384">feeeeb0fc7c4e971268a8d8743218905a54eac473c0b4d3cf6065876aa3acf8c9436bcb8ee671ed84dba60b4bb3bdda2</hash>
        <hash alg="SHA3-256">20c3b349dff27220bc621adc8d4b444024444882166194473ec67a3666ec9c37</hash>
        <hash alg="SHA3-512">fb4c1f23d69a9513bbe3d4b8d76f1737559c3bd135b637041f5e752959e9f93e721f1f3fce704343b2ef806e4aa7fda67282221cdb0b25f581525a9e6eef35de</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-transport-classes-kqueue@4.2.7.Final?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://netty.io/netty-transport-classes-kqueue/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty/netty-transport-classes-kqueue</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-transport-classes-io_uring@4.2.7.Final?type=jar">
      <publisher>The Netty Project</publisher>
      <group>io.netty</group>
      <name>netty-transport-classes-io_uring</name>
      <version>4.2.7.Final</version>
      <description>Netty is an asynchronous event-driven network application framework for
    rapid development of maintainable high performance protocol servers and
    clients.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">bce41666351136e0ebe6d9382e5ac2fa</hash>
        <hash alg="SHA-1">daa8ff17a158927b38afb211b2b4fe1d07a4ee67</hash>
        <hash alg="SHA-256">ff966874c62f53ed072962f1bf5dbc49fddd4bd3c60bfc9a7e17ce34b39ac7af</hash>
        <hash alg="SHA-512">6ca99c864c04acc132684867b2b30ce8046054b1ccc7eacbebbc8e75dc5b55fa28a9a41319c4762ab5a53567dc595deb94911e9e6e4b7dc3a6174b801f595954</hash>
        <hash alg="SHA-384">033088f2bfb464cfbd5251c70acbfc7922ac046bf56728764a3cfd2ebc17eb1f444005542dbce1ac9934413db3e69ec5</hash>
        <hash alg="SHA3-384">cb1750bf1995f886592f8601e2838667d9ed512d9dc9d501dd2bc8db2d0514b549d2451948a7dd0a33c34fd63de48c5a</hash>
        <hash alg="SHA3-256">c60c8edc040bf20bf0bd2fc145a4b16db9fe564e2f51f34b00f1e19724ad7f24</hash>
        <hash alg="SHA3-512">38f0613a100a70ab4428357446201a28c8a95ebb5cbd562d3e269c5ec0c4fbd65220cc9d1a2f15250d9c87c225a9b5247365ac92679dc4bb15c73ed05ac1ba34</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-transport-classes-io_uring@4.2.7.Final?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://netty.io/netty-transport-classes-io_uring/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty/netty-transport-classes-io_uring</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-codec-classes-quic@4.2.7.Final?type=jar">
      <publisher>The Netty Project</publisher>
      <group>io.netty</group>
      <name>netty-codec-classes-quic</name>
      <version>4.2.7.Final</version>
      <description>Netty is an asynchronous event-driven network application framework for
    rapid development of maintainable high performance protocol servers and
    clients.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">debf6ea644122fb0fd35c6e06c9bec54</hash>
        <hash alg="SHA-1">98e80e8a575aa5cacd0db278a91fc4b34e4721fe</hash>
        <hash alg="SHA-256">7b26fb6ca2b9dee4f557229579bf7bd954320e54dd1f07faab342bdd22d3c75b</hash>
        <hash alg="SHA-512">f058ff225dbf6096d3d329caa83a19a5f4d90d050843d6dcc505569c5af8c8daa7171bad4eb3cf3d60e9c39e7439df0d9032dd1b4f43bfc4ae96de098f85bf84</hash>
        <hash alg="SHA-384">605e738375c53a585b0c2338ec22a07987c452c43e21a445888b5b9cf108baf6df22e0b555180268d9cc085e1cb260ed</hash>
        <hash alg="SHA3-384">99bc3889f6fa79a53861e61c1dd8b944b1c99043b5b110e1af2ca4da1fbccd93b56af7acfbdeb73e05f719203679f9ce</hash>
        <hash alg="SHA3-256">f5b032be7383980784007f62d21632558b21bbe91ae86f32fd62da02b998e346</hash>
        <hash alg="SHA3-512">aa553e21d6a7478bf0cd3a5954d01b9eb78e42c3da92ad8ae8e936da68e08f5f7283992c4b332ad6d954f597b34cac01b2b746440da37d40568271c5186144a1</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-codec-classes-quic@4.2.7.Final?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://netty.io/netty-codec-classes-quic/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty/netty-codec-classes-quic</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-transport-native-epoll@4.2.7.Final?classifier=linux-riscv64&amp;type=jar">
      <publisher>The Netty Project</publisher>
      <group>io.netty</group>
      <name>netty-transport-native-epoll</name>
      <version>4.2.7.Final</version>
      <description>Netty is an asynchronous event-driven network application framework for
    rapid development of maintainable high performance protocol servers and
    clients.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">12a70328afdc85feb88114a17f98252c</hash>
        <hash alg="SHA-1">5fafee6fbc00979f81513172b4a618c3f2aec51a</hash>
        <hash alg="SHA-256">6703a18b165ecc11309a375d15165b0111244c20431f01556d78ee9488f56198</hash>
        <hash alg="SHA-512">89fb3b4faf96d0dac830a66d193cc84779d026aa320ae98e81cd153383c5c07bed65f1f0e9cd2f54ac081d3e11ebdce181405b3d0e4068cedfda0fdf10abb986</hash>
        <hash alg="SHA-384">eb8e995855f78ea0e1cc3414c6a7eb3cb0164210897a3892f4802ad15443ba900f6f15df6e5945f43f451d422ab444c7</hash>
        <hash alg="SHA3-384">4d560a4e14b21d7de2d8dac4b8d69ed9d216ee021189c864bdbb1b39eeb1b5e681eaec5cae5acc94eeee510bee4f0df3</hash>
        <hash alg="SHA3-256">89f371da342a206c79dd40cacf563a4ad4fb0d022564bb594937ede8f9bf827c</hash>
        <hash alg="SHA3-512">dd75ffc3dfcb2ae00a44f8d9662d88fc9ac70f286061994efe5368f0dbbaf2624f3ff73183a029227049e315ddb47ba3e8977f1eed67db3faa7969aefdf7a1e8</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-transport-native-epoll@4.2.7.Final?classifier=linux-riscv64&amp;type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://netty.io/netty-transport-native-epoll/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty/netty-transport-native-epoll</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-transport-native-io_uring@4.2.7.Final?classifier=linux-x86_64&amp;type=jar">
      <publisher>The Netty Project</publisher>
      <group>io.netty</group>
      <name>netty-transport-native-io_uring</name>
      <version>4.2.7.Final</version>
      <description>Netty is an asynchronous event-driven network application framework for
    rapid development of maintainable high performance protocol servers and
    clients.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">771c6018bc9b6e1a4fc66a614cd2803e</hash>
        <hash alg="SHA-1">63515b21f83a8c1752fdc939109691ad24658141</hash>
        <hash alg="SHA-256">c236509f55bf921666f0232efeb7563279b6cb460d9e4a36c4aba40d2217bf62</hash>
        <hash alg="SHA-512">de541aa2a5582eb4bc7c0a30f6003f9d18b6ce1dc3c0328dda1ba97e4d3822408946bba2a3ad5a839e0032e86c97397c19993af4c601ba022b9c0a3e52ff8d18</hash>
        <hash alg="SHA-384">88e0e46fb410788378d5a0a50f5be83bf7cee9d55c5ef989279b9904acbd93f178237744d37bba9175f62eb6bb0c2183</hash>
        <hash alg="SHA3-384">b52b463ed849bdd82b75e3d91d009c820f08d17509385cca3b262d53966959e1bf4369cb3de096132f10fc6c33243794</hash>
        <hash alg="SHA3-256">05fe0f49c5aa71505b8f1b5d096db86cd3ceb11bffc559588ba603862ff606a9</hash>
        <hash alg="SHA3-512">ea91a41c1d514afa19a072e282fd9b02d0365ac641dfe9e462abfcf45c7343bbf52bb6f4aafcd4c137d68d5ef54c2239702e8c81d3f8e0e6b24bcc06d9c4d885</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-transport-native-io_uring@4.2.7.Final?classifier=linux-x86_64&amp;type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://netty.io/netty-transport-native-io_uring/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty/netty-transport-native-io_uring</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-transport-native-io_uring@4.2.7.Final?classifier=linux-aarch_64&amp;type=jar">
      <publisher>The Netty Project</publisher>
      <group>io.netty</group>
      <name>netty-transport-native-io_uring</name>
      <version>4.2.7.Final</version>
      <description>Netty is an asynchronous event-driven network application framework for
    rapid development of maintainable high performance protocol servers and
    clients.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">c542f291ff142fb1fd8d1836015ba0d0</hash>
        <hash alg="SHA-1">8027e634141b18fd43d01d090d393a70ff821bf8</hash>
        <hash alg="SHA-256">84fc39dc1019f4a6c5244b1d79a9714cb67f045bbdae4fef26f4981e6f67adbe</hash>
        <hash alg="SHA-512">95062012f741edfbb25ff7c469a60758f3992d55adcaef4c500d3252cbbc670e6ff149919c5586402a7224637f6e8d5ddf810920b469fd984a4fdd5972257667</hash>
        <hash alg="SHA-384">03a90cf8d4c6cb624ecfd8f4c16fb8e7319d5eb162ec5c22991157b715bd8d53e772a00785c26adf54127d3b1c1ec81b</hash>
        <hash alg="SHA3-384">24c827016527455c320e9a30fc4277971b009419438a02b9085d53a06444ea10f5c838264088f1bd1b1a2923d25e472b</hash>
        <hash alg="SHA3-256">db5d08350a1805bbbc284b1c528543b9ce3183630b0671d27e9c1c7cc64ccc45</hash>
        <hash alg="SHA3-512">2f9c5f9a4e151c0ba208ff38ba698972cc934c9040a9219b7202db33a652d7887dc5b82391a250280b058d2a4703e539614e0db8667ac8f37ebcd7e45dcd540c</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-transport-native-io_uring@4.2.7.Final?classifier=linux-aarch_64&amp;type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://netty.io/netty-transport-native-io_uring/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty/netty-transport-native-io_uring</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-transport-native-io_uring@4.2.7.Final?classifier=linux-riscv64&amp;type=jar">
      <publisher>The Netty Project</publisher>
      <group>io.netty</group>
      <name>netty-transport-native-io_uring</name>
      <version>4.2.7.Final</version>
      <description>Netty is an asynchronous event-driven network application framework for
    rapid development of maintainable high performance protocol servers and
    clients.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">d43c47586cb002bd9745c09091ad042b</hash>
        <hash alg="SHA-1">29d1b957c389285934275912b7565d794a9bce2e</hash>
        <hash alg="SHA-256">06ca33c231a414eb012c182dfbb7f977e399bc4000b1b81776e585fbc665dac3</hash>
        <hash alg="SHA-512">70220771c00964db1618186fac788e5b63e1b380ae14ae49d770ee08050c7bffeb03c86978af09f6c9561fb6f366d10be25613dd8bc32402c2c43472207d30b6</hash>
        <hash alg="SHA-384">eb9b7431a2b230767485dd8a32ee9c67676a9862d3d3ef864f248482cc5eae3f3b53277c735398cb6b22a4fbd461bd0c</hash>
        <hash alg="SHA3-384">ca384096921008f231b5b2a0564d73f65a2b95c16a58aa318425e7f80e82f3bb4ff2be54e77b6b198f498a4001a7559e</hash>
        <hash alg="SHA3-256">14af269e2af5a147629f9c059d16d04ceeccd8a8212a94d8a61ce2b34524f905</hash>
        <hash alg="SHA3-512">2d52f063721c6091d3f11f55c04df7b0507f3ebcbce7611c6c142aa3165de2343f1ede33c624e26937d5b599657cde9ef2253dfc9d5e32ea2ddda7e4f2f83830</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-transport-native-io_uring@4.2.7.Final?classifier=linux-riscv64&amp;type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://netty.io/netty-transport-native-io_uring/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty/netty-transport-native-io_uring</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-codec-native-quic@4.2.7.Final?classifier=linux-x86_64&amp;type=jar">
      <publisher>The Netty Project</publisher>
      <group>io.netty</group>
      <name>netty-codec-native-quic</name>
      <version>4.2.7.Final</version>
      <description>Netty is an asynchronous event-driven network application framework for
    rapid development of maintainable high performance protocol servers and
    clients.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">cc6ab70e10e1456ca841a8c9c14b0023</hash>
        <hash alg="SHA-1">6a3e4398852f926c4b22f381d89dae2388446ae8</hash>
        <hash alg="SHA-256">fb41fd610684c872329a5350ee746bb1f338c9e57af1a45c961a632aacc4e63f</hash>
        <hash alg="SHA-512">d7d1f678c947a0482a8157c049c9cc8f1789e82966d1ecbd6a4c41b523aaddfa1c703318ad4898393cb355a77b887dd02db849b89ce38e6e78205dde12c32320</hash>
        <hash alg="SHA-384">9ecc5cb40a6246116b070ac632eeaefcc0a6b9839e303280e0c07a7ed6052b3e3593a675982381aeb7c3ab186e171295</hash>
        <hash alg="SHA3-384">c14220dfefecc459e8ad1e8f06a8c2eac4bab4969ba8e4ad52291dda7c9ba38722d758f8489ad4693026c66245e8ac1c</hash>
        <hash alg="SHA3-256">dbc9d88e92e0d2c03df5ea9377451aa61da2c76685ae56661ca687b68c6f86cf</hash>
        <hash alg="SHA3-512">e29982c562e6d3c8d45bf0615029234519ffe8f4d5f77e57532fdf164ae41492a971c9dea379e08072cd00d11392f11e39c8feeff333d186e3b8d1ca89a3534c</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-codec-native-quic@4.2.7.Final?classifier=linux-x86_64&amp;type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://netty.io/netty-codec-native-quic/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty/netty-codec-native-quic</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-codec-native-quic@4.2.7.Final?classifier=linux-aarch_64&amp;type=jar">
      <publisher>The Netty Project</publisher>
      <group>io.netty</group>
      <name>netty-codec-native-quic</name>
      <version>4.2.7.Final</version>
      <description>Netty is an asynchronous event-driven network application framework for
    rapid development of maintainable high performance protocol servers and
    clients.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">3eb72a5bab9ef3d4829f88e5c422bace</hash>
        <hash alg="SHA-1">7ecd8d1de6b3eb7eeb3dcdb1034780826e141f1c</hash>
        <hash alg="SHA-256">9ddc92ea8c9cfcb247de06f217402e787bc40c8a698c45dee76f8f399cd14853</hash>
        <hash alg="SHA-512">89d81d7d9810a8d783800c4ff94e6a62886541676a87a4c5e13df19bab5b89d875e2d873d6d5f8b3af200328cc72cc5c315d9a29b1f2e8b7a9b51c228f19477e</hash>
        <hash alg="SHA-384">d8c717da9b1d7f9bd08122048e625c8c4c392ebfdcb6496ff60ad49e7867b91b6a9555c282c11f85078b22cd28d48143</hash>
        <hash alg="SHA3-384">7212e9377fde1e7df65cb693ee65054fb9f06c57da030faf6f332bb7b2ddd478adfc56522663be949a6a5b08194b7142</hash>
        <hash alg="SHA3-256">e126a77314a49e366e6cb3ab19a76dc4663df2a129bf007486e4e2f3af9d5e60</hash>
        <hash alg="SHA3-512">7803c8e796460e8c0a364eff7d24f102229d6e13ef7fbc498302578f1ec586d049d384af758f98c68a9cc12f74c73e3bc27bcf8095de84b1f592088d2f547d8d</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-codec-native-quic@4.2.7.Final?classifier=linux-aarch_64&amp;type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://netty.io/netty-codec-native-quic/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty/netty-codec-native-quic</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-codec-native-quic@4.2.7.Final?classifier=osx-x86_64&amp;type=jar">
      <publisher>The Netty Project</publisher>
      <group>io.netty</group>
      <name>netty-codec-native-quic</name>
      <version>4.2.7.Final</version>
      <description>Netty is an asynchronous event-driven network application framework for
    rapid development of maintainable high performance protocol servers and
    clients.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">8908731e8d56aa093f9b72a43d4a86af</hash>
        <hash alg="SHA-1">f3679a6cc103292931098b1dc835ffb831e27368</hash>
        <hash alg="SHA-256">ad5dff4f9ef9d3980edb77530e9d38bc5504e8b19a40752043ee9b51ebd4dd87</hash>
        <hash alg="SHA-512">2b23de85d51f872d43a823a17cc9d963ede78c5a735eaea49b74373f4d8124e0dc92e8b62914ef5924e2f479dd5041c855808ee59761fcaf2efcd237e54a6b2a</hash>
        <hash alg="SHA-384">7c5ba871f2184ecb34f13bb95495775e2f14af50337435ed2f095b2d9429edf2d03cfcc1a9fbc22b2cf023cf93db9b62</hash>
        <hash alg="SHA3-384">6c4879073b02374c957ec9e38ab2e6732b8bfe3962ab0d28ea9f5e24bbe6b23c2e9537026bbb5a0fbea6937710ebfc80</hash>
        <hash alg="SHA3-256">d9a54dae07b475285a2520a0602064801b80398c31aaa8438f90c1559183a443</hash>
        <hash alg="SHA3-512">e39a95cc955e7a304ab93cd5f671a3c802c5c8aa3e279db6e02b788431a05caeaea87d15f12cf276b9df2d4be60295ca1ed26196518ff6c65ddb89471aa9e4e3</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-codec-native-quic@4.2.7.Final?classifier=osx-x86_64&amp;type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://netty.io/netty-codec-native-quic/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty/netty-codec-native-quic</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-codec-native-quic@4.2.7.Final?classifier=osx-aarch_64&amp;type=jar">
      <publisher>The Netty Project</publisher>
      <group>io.netty</group>
      <name>netty-codec-native-quic</name>
      <version>4.2.7.Final</version>
      <description>Netty is an asynchronous event-driven network application framework for
    rapid development of maintainable high performance protocol servers and
    clients.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">3ffb9ec519ec64dca72d37f78fd27b68</hash>
        <hash alg="SHA-1">c30d746bd588c07bac4ac04abde576c05a3c0a28</hash>
        <hash alg="SHA-256">e80b5751fa50a21732ac87979d0063171362195c838b60a20d5d6395253e40b9</hash>
        <hash alg="SHA-512">e65d81d2b5aa9f370433af3953d88e65dfc9aed43bebf5ed655b9fd258adb8e7b0998d802495845d657f4b7339caaee45588ea5eef9ac9a11b16f52614c42c5a</hash>
        <hash alg="SHA-384">0a50ec4811a04226acdc39cff641acff3142f97b4c9f9575cb1f56f39b0d69fe7190aea3e18f47a7544b00a1603f6ec9</hash>
        <hash alg="SHA3-384">e5bebc76edf81140e9f33e407fe170d2e1f2621c20c71fccece09f196b02600968f371175545299c81b9efe56bedbaa6</hash>
        <hash alg="SHA3-256">9b4f3309fe9455180336b106166307d74106e860a153198c081286997f2c0f27</hash>
        <hash alg="SHA3-512">5b24f2bbfeda298ba7b9f473fbc1ac01165b3535d16d6fa26a0a0f4f2e2c434855e8a5bce082ec586d58feaad7c2f0b35e2d03a852c52c7267cb0a01f9c5485b</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-codec-native-quic@4.2.7.Final?classifier=osx-aarch_64&amp;type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://netty.io/netty-codec-native-quic/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty/netty-codec-native-quic</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-codec-native-quic@4.2.7.Final?classifier=windows-x86_64&amp;type=jar">
      <publisher>The Netty Project</publisher>
      <group>io.netty</group>
      <name>netty-codec-native-quic</name>
      <version>4.2.7.Final</version>
      <description>Netty is an asynchronous event-driven network application framework for
    rapid development of maintainable high performance protocol servers and
    clients.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">a344319b15853c1fed72d31e3d0f1d15</hash>
        <hash alg="SHA-1">c4f177d2a99668c209acc31b8b85df58e9166218</hash>
        <hash alg="SHA-256">02440b1f0a62a439cf6899f0e569c98b66560bf838f583cf50d8803bb17b43db</hash>
        <hash alg="SHA-512">d8da7e5a84e1da852649dae147521993d176147bfadc56b3792a02c914ab98ada08dbbf8a14d4cf2b26edb691c2c9262deb6edc00c8ca10dd8990e5deeddf343</hash>
        <hash alg="SHA-384">2a8d496d5c1d2dc16194d2b008ecac220288263184a6a280e97b8c685410d4c1e2d5d50427296fd15c8c298e748d2ff3</hash>
        <hash alg="SHA3-384">0365b7bb52044633e3e9309b25a3e8f344ac02597f445acbc86e937969b33925d2831dea7a4aa59e766421543e3e9dbe</hash>
        <hash alg="SHA3-256">79ce78a3ba389d8e2e96a883c847d156c311135faf64f57601b5d292ef207bc6</hash>
        <hash alg="SHA3-512">6012dc03919237db026cffccf2ca5ee4d9bd0fa09612b51d05b92d1572440c0d95ceb20b2b6804cc60cbd477bf0afb5c37bc97ab7ac47a9cfa564462ce2beee6</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-codec-native-quic@4.2.7.Final?classifier=windows-x86_64&amp;type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://netty.io/netty-codec-native-quic/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty/netty-codec-native-quic</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-transport-native-epoll@4.2.7.Final?classifier=linux-x86_64&amp;type=jar">
      <publisher>The Netty Project</publisher>
      <group>io.netty</group>
      <name>netty-transport-native-epoll</name>
      <version>4.2.7.Final</version>
      <description>Netty is an asynchronous event-driven network application framework for
    rapid development of maintainable high performance protocol servers and
    clients.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">04b8b55ec512ff5529e9aa161fd4c220</hash>
        <hash alg="SHA-1">e83998bfc10b5289d9bcbe807c4079ef0eed8e6f</hash>
        <hash alg="SHA-256">7f395c8fdbe6990f7664408b57d919042401b893178fcba48bebf1a61bf78618</hash>
        <hash alg="SHA-512">79432f65be193a2e6747c5c2012099f70d1d2b7734d0398f75fb1e7f116e47c586990d8a80834df7a3fa8ddcfec40045ff3c4847b284116735a879d1cadc6ecd</hash>
        <hash alg="SHA-384">a6a9775a04626e242a974574412359f84efd76c3f1e09b61a0b1fb7929bf9b0ec985d58f2b692b5b2fb519ad6fab9947</hash>
        <hash alg="SHA3-384">7b4d15e368a23f212bf4a26d5f15b40acf9c353557f9b12659d55c4ca62b2dd72a90915e993d47a2560b9d572ef2a45e</hash>
        <hash alg="SHA3-256">6d8cd870cd52807a10cb255de7bde93e921c99819b6a25373d75cd32bf70d803</hash>
        <hash alg="SHA3-512">e1e1134c63e3c4c5e4f4f90b09cf4106e198969578c9f170040767ac53fab0b82df65caca1e2a9248f60cc90fa5deddcc8a0fe9757308e729f9996941062d928</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-transport-native-epoll@4.2.7.Final?classifier=linux-x86_64&amp;type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://netty.io/netty-transport-native-epoll/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty/netty-transport-native-epoll</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-transport-native-epoll@4.2.7.Final?classifier=linux-aarch_64&amp;type=jar">
      <publisher>The Netty Project</publisher>
      <group>io.netty</group>
      <name>netty-transport-native-epoll</name>
      <version>4.2.7.Final</version>
      <description>Netty is an asynchronous event-driven network application framework for
    rapid development of maintainable high performance protocol servers and
    clients.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">4a4c505e6ca7a05e983643b00a9a6c5a</hash>
        <hash alg="SHA-1">98d02251c98c8f07a23ac5ea27657d9e0ef57614</hash>
        <hash alg="SHA-256">2f0c7309d7df48a88fb374c02cfb446e1a1e5fb597fb02d773c70ac07da2c268</hash>
        <hash alg="SHA-512">7c7a9ede931592b4dff3f22c9bca1e590d2371495383f29244ae6152ddc542eaa826fe344465b6c7812f9f7d6175598a2d7c82ba5acb274b06a5b75facc4235c</hash>
        <hash alg="SHA-384">3ad4f392fdb1e8840d53fb9a30545a4c89ad1a732784fbcb3afe7a148d2946578458f75aa322b69e9145834f410bafeb</hash>
        <hash alg="SHA3-384">b6900f68615e1902158b7fee479d3483a8f27a3c2f50bcc5803a35b8e850a3f3b9d9095c3fa99511c7796755a56eb234</hash>
        <hash alg="SHA3-256">e230d1efdc71d2dd3d6f80942c04fd2807f9b74ac2e3490469ad0868e0302d6f</hash>
        <hash alg="SHA3-512">44f8073200bbf8725caa6f5747607dbbd8b575fd80cf441719b84c8fee07b4577b63ffca8107316c339df1d76b9eed8b77155fece3b342b4251e5bba9607fa8a</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-transport-native-epoll@4.2.7.Final?classifier=linux-aarch_64&amp;type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://netty.io/netty-transport-native-epoll/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty/netty-transport-native-epoll</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-transport-native-kqueue@4.2.7.Final?classifier=osx-aarch_64&amp;type=jar">
      <publisher>The Netty Project</publisher>
      <group>io.netty</group>
      <name>netty-transport-native-kqueue</name>
      <version>4.2.7.Final</version>
      <description>Netty is an asynchronous event-driven network application framework for
    rapid development of maintainable high performance protocol servers and
    clients.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">1156a8da678f45052090f3de6bcf0112</hash>
        <hash alg="SHA-1">e5a0feef41410c8a5ae00c6cb4e0c99bd0aded6a</hash>
        <hash alg="SHA-256">7647a69558e3d49a352781c2ae81a97e16b442d7c6565a06b4ae0f15298489d5</hash>
        <hash alg="SHA-512">ef21c762341d22eadc3c046d8c6d5edbcc5b55aae163873122ecd333863cd892e658b03d93c35c83e5abf1073bd8f5d4854f1c394d1288b6f40461c87c4e91df</hash>
        <hash alg="SHA-384">b91776d60a419f7c340447121d64ef3018516b9884e230be6e5f67dd84bdeeb0135306e322ff4a37c71e02630dcf4cda</hash>
        <hash alg="SHA3-384">840c829af35d9fb901d8641367fa816638aa7926e1095707f30c67f57c4db5972929e374673b596181964af6155bdfc9</hash>
        <hash alg="SHA3-256">8aeaa31dbff78a330ea6de3374f03921957e767ce9e1d68d900d0f98db9b3fd7</hash>
        <hash alg="SHA3-512">955019e8c103eef8b428004fed72d87fa5fcfdd1a644ceb3dbe34dca99868bc91000cf0cf3608e791b251bb4b3a20e7a1bf486fed5761a6ceeb1bd5cc414a492</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-transport-native-kqueue@4.2.7.Final?classifier=osx-aarch_64&amp;type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://netty.io/netty-transport-native-kqueue/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty/netty-transport-native-kqueue</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.netty/netty-transport-native-kqueue@4.2.7.Final?classifier=osx-x86_64&amp;type=jar">
      <publisher>The Netty Project</publisher>
      <group>io.netty</group>
      <name>netty-transport-native-kqueue</name>
      <version>4.2.7.Final</version>
      <description>Netty is an asynchronous event-driven network application framework for
    rapid development of maintainable high performance protocol servers and
    clients.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">75a963883b6b2517f2e9a29b12fbd4a8</hash>
        <hash alg="SHA-1">40868fd4e43bce2798245f790624b58803dc26b6</hash>
        <hash alg="SHA-256">a29c08b6895746aaca796e72a429bc705f40267feb35f75cd8fbbcd4de6de99f</hash>
        <hash alg="SHA-512">a369597159691defd413a16e1ab0b5e1951fb98a822d4eb9d5304a65fae687d08752d15199a250cfba6b2d7552dbd44ecf0768e9bf0289b3db20bf7fad23529e</hash>
        <hash alg="SHA-384">c8e15230d2aeda71c915c965a74fe2f73d3d9fc7598a210e849b8476a12f0e7d7121c9743303b3f4af00c88d5e266162</hash>
        <hash alg="SHA3-384">143de3a976c6f1c05cfef8908b8d35301e3d671226814b9544640f5b642984746f17597a01b6108619aa9aa12a6a013f</hash>
        <hash alg="SHA3-256">c77f4c9ea700cc7ecb836a4929ca851e7d57de8187482145408fa9f232d715d2</hash>
        <hash alg="SHA3-512">75c1ef1d5cbed8cdf63dd71380fa427ea68f166189e08532c22f4d2e47947d3de27529f2ec8d0c787aba92447249be2f303b1dc3de47df80201067e4c14aaead</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/io.netty/netty-transport-native-kqueue@4.2.7.Final?classifier=osx-x86_64&amp;type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://netty.io/netty-transport-native-kqueue/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/netty/netty/netty-transport-native-kqueue</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/com.clearspring.analytics/stream@2.9.8?type=jar">
      <publisher>AddThis</publisher>
      <group>com.clearspring.analytics</group>
      <name>stream</name>
      <version>2.9.8</version>
      <description>A library for summarizing data in streams for which it is infeasible to store all events</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">4ce83343678bdeac3b7bd360cf73c312</hash>
        <hash alg="SHA-1">5ef966e6c758c508c9076928d380108ae3f9843c</hash>
        <hash alg="SHA-256">d18bf0abbc2f84f879172a50efd1e11b4fc0fa0b88e672c43fcc9e5501fd1c8b</hash>
        <hash alg="SHA-512">8114ddf27ef6144682b15878b55aea2c9972da0c46c5c5734e9afe0c6e1a944ea179bbe287f615f124014d8ddada8eb4ff04e07e23c9aaa4607eb510f7266a05</hash>
        <hash alg="SHA-384">dc52ec9bd5ea1b0b95589d1c06d036d76c7bb86d794bc537439e295f09ff75af5a4996bc0be1e63b5cff792ba311eb4f</hash>
        <hash alg="SHA3-384">6777486f5ee408a28c5ab3d9180a248669e5713668556262f151274c269ef0e4d9b363f62e4d929d1893fdd640f4c387</hash>
        <hash alg="SHA3-256">41f2caed538df5f22c00889ca1474d211a7c0cb850c4162abfb39a95053406c6</hash>
        <hash alg="SHA3-512">b89c41b71da0f79fcb8affafbc0e2ecbe22a1b930fffddabe0b68551298bf1eb2be1faf6f5306425d70e3a7fe16f3f1ddf61c3a5c38f5052a378aa3fad3e9405</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/com.clearspring.analytics/stream@2.9.8?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/addthis/stream-lib</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/addthis/stream-lib</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.dropwizard.metrics/metrics-core@4.2.37?type=jar">
      <group>io.dropwizard.metrics</group>
      <name>metrics-core</name>
      <version>4.2.37</version>
      <description>Metrics is a Java library which gives you unparalleled insight into what your code does in
        production. Metrics provides a powerful toolkit of ways to measure the behavior of critical
        components in your production environment.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">4a3150723624a4d3da1cf870fd54ee7a</hash>
        <hash alg="SHA-1">2d7ecb8e2b4d292c7eb87ab28cda586cb9773056</hash>
        <hash alg="SHA-256">3c70d19049d10f474ab803706b9c0677bcf5fd9e1afeb4f6c496f62e38b27678</hash>
        <hash alg="SHA-512">33a1d1ffe5d18e8d87762cc2c1f2fcff3bb044449225db6815b7e2ea74ac0a1ca6bba1b9f744e8bf261c5f7bfac585cfb4ff500a4609a0f27ae2607175cd7491</hash>
        <hash alg="SHA-384">52cb6de88b39759de1b3a5762fcb0cb2264f989c5740f3ad8170562148e384fd4226ba0205b8bc7c6ad334aa53c382f3</hash>
        <hash alg="SHA3-384">d8c1b9bda26ed823253dc982aa3ecd9c7bdce3a0e56c24688ea4a6e18bdbcd8a268c87aa7cac162c7fdf855e634c3570</hash>
        <hash alg="SHA3-256">9c35c5f3a38456a3a93fd453e285666dfdb618ed591c75377b980ad78d25ebc7</hash>
        <hash alg="SHA3-512">4354e4db6cb9747447832073842c4e0dec6291c86101736e14b209f3f72330fde89ccce69a88e3fc5999e100e64041a06ab26fcaea3dbc6f7e7d70b46fd2c08b</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/io.dropwizard.metrics/metrics-core@4.2.37?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://metrics.dropwizard.io/metrics-core</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/dropwizard/metrics/issues/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/dropwizard/metrics/metrics-core/</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.dropwizard.metrics/metrics-jvm@4.2.37?type=jar">
      <group>io.dropwizard.metrics</group>
      <name>metrics-jvm</name>
      <version>4.2.37</version>
      <description>A set of classes which allow you to monitor critical aspects of your Java Virtual Machine
        using Metrics.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">92bb43ebc95cc8a01f4708eeba14beea</hash>
        <hash alg="SHA-1">0032bf66fbf022637715f52a82ae3f8cbce13e91</hash>
        <hash alg="SHA-256">5428a69086194193fcde3a0efc51520f5cf6a0453c928d65fbe52f8325f57537</hash>
        <hash alg="SHA-512">268fed7918e0bf4a215fd505a9b566fc0d94fea7153cecbdab8162d997876f7c737d80b99430ce9df62752d226c6bdba0523a7ad19591820c15cf0e4ec6f53eb</hash>
        <hash alg="SHA-384">9f36772bd56a22c54ccc6e919523bc37ebe84c7990d75ed0bdf7ecf997e8479bb2eca8ea68575ec3f192e3f3adb6102e</hash>
        <hash alg="SHA3-384">23955fed7ea851e01c7863af19836b12ab2ab549f6267aa081622374dc4cabb3041851f4bef621c04cc760a20d11833a</hash>
        <hash alg="SHA3-256">eba89b4117e4988b9ea00c3cfd62ed37518cbcbfe219eb60e59d361205440f27</hash>
        <hash alg="SHA3-512">5b820051a90d69300bb0e9c5d934a71c7c75286f725d36af8f70b1acf93eefe370dec83b3a34a24d13782066eb75b96bf1849e18f0eb2b4fa6479db66d0ce6c9</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/io.dropwizard.metrics/metrics-jvm@4.2.37?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://metrics.dropwizard.io/metrics-jvm</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/dropwizard/metrics/issues/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/dropwizard/metrics/metrics-jvm/</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.dropwizard.metrics/metrics-json@4.2.37?type=jar">
      <group>io.dropwizard.metrics</group>
      <name>metrics-json</name>
      <version>4.2.37</version>
      <description>A set of Jackson modules which provide serializers for most Metrics classes.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">3e27d1a2a89d26c97fe0d17c3dbbfa22</hash>
        <hash alg="SHA-1">b7df85b601ad52996081daea3c63a85442377b09</hash>
        <hash alg="SHA-256">eb73cb82c3c03f207a87d924d325f043714e4805c62de0fe05edf89cf0b69e30</hash>
        <hash alg="SHA-512">6ecdac4a3e5eeb05f2ffebf17780af892185ca1754dc1ebdc7573bc2bf5448645c6956d3959f9c7dd761f9e84ff5daf3dabc2d0ba54d4f735e188bc2889a5107</hash>
        <hash alg="SHA-384">fc0bfc2520dde87093e30027401680aee7c9ccfb3f304f0a7ba89c7e94cf7029005b5beb487d9248b1bd142ddd052687</hash>
        <hash alg="SHA3-384">cde9c35d3e1820456360660a38e7fa3bba0cd5cf8f259dbe6244af1b6edf269bcf651a20fc9bb62c2e91524a7dba030a</hash>
        <hash alg="SHA3-256">c897363d92e43663b68f40dd10dbc6c03dad8718b4096166e0dcd3c6bca43129</hash>
        <hash alg="SHA3-512">bd916aefa67576cfa51365af56a42c73e6d3913dbec8a0176768bb3985dd7d4fff33cd227d62a4804dff5438391849932c920fd929d19be07ff0cf17bde59650</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/io.dropwizard.metrics/metrics-json@4.2.37?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://metrics.dropwizard.io/metrics-json</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/dropwizard/metrics/issues/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/dropwizard/metrics/metrics-json/</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.dropwizard.metrics/metrics-graphite@4.2.37?type=jar">
      <group>io.dropwizard.metrics</group>
      <name>metrics-graphite</name>
      <version>4.2.37</version>
      <description>A reporter for Metrics which announces measurements to a Graphite server.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">8b83c5397335351151318fd17056c0d0</hash>
        <hash alg="SHA-1">53fa874fc0a745920ba858c9390b24e93f718054</hash>
        <hash alg="SHA-256">75b93cbf33760173e7ab448326bd5bfc9334b054c4ce0348eb907d907db85218</hash>
        <hash alg="SHA-512">e406268941e66a52fc17d236b870234ae72a26284a0965d92bb979c14ef8ef81c69f2728ece4fb9f42e488615fa53e7ed1f2c988b301a7ec0bede1f72516c0cf</hash>
        <hash alg="SHA-384">1acd6be42bc914f2ff9a6dee21c15b3e0721689a6cbca15a0852dddbd148f5a78ad84d49d4a6c8f26efaa072256d555b</hash>
        <hash alg="SHA3-384">1f4804b0d21986e3d64e5666daa60adf8f29a2df6c551c17a4082db4b6ab5e722044f57e748974ea7b2fd252b18d61b4</hash>
        <hash alg="SHA3-256">6e76d6c0a2134b700de42307d21cd506df381819375d5de7732efd66b2c966f3</hash>
        <hash alg="SHA3-512">f5be1714ded5975e11310aa4c21c6e01b588a9ef8b8c2003749cd2cf80e68165def8d078ad05be150b1d3cfa6e117fd025ed447a8f484cbb7537d88c6792d0dc</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/io.dropwizard.metrics/metrics-graphite@4.2.37?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://metrics.dropwizard.io/metrics-graphite</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/dropwizard/metrics/issues/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/dropwizard/metrics/metrics-graphite/</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.dropwizard.metrics/metrics-jmx@4.2.37?type=jar">
      <group>io.dropwizard.metrics</group>
      <name>metrics-jmx</name>
      <version>4.2.37</version>
      <description>A set of classes which allow you to report metrics via JMX.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">b1ad3e8468e005d95428eb948ff5078e</hash>
        <hash alg="SHA-1">f02940396e411d70b529b6b4f46f26f4bffb5b5d</hash>
        <hash alg="SHA-256">26f96d12d14c18940778521454e08ddfc6022666557d8c6f06caf3a8a322603a</hash>
        <hash alg="SHA-512">fd4daa6d4e703cbcb57c38fa9370e5ec0fd19d7a28ab4209023bf8d5d22604c2f37b8251f1d8d64e762d65b76788b2f548d026744760e9ce71f6b75c156d0b7e</hash>
        <hash alg="SHA-384">bf8010ced4b4161996e0f7d8811fbe0eafd85df04af432003ce5b22e3d5ba3547a8f25ca9a2927d233cf4ce7a290b513</hash>
        <hash alg="SHA3-384">46ffea6583c7b11faafa4cc9a40c53789aa83a77ddf9b901599ec6f453e07ad4f4bdd190bcc0ae3ff1e35cce7a11034d</hash>
        <hash alg="SHA3-256">251a9293447ee375e7c15c441891ee410eaca3105d6e20f16606d27373202cd6</hash>
        <hash alg="SHA3-512">4ea89d07e796b11319a9e0a548f3fe0082458aa28d613970683b7418a4c357719383f5e8cbc5394dea0b5a4da934c7532a1666d1511eaa3ef396da545689b233</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/io.dropwizard.metrics/metrics-jmx@4.2.37?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://metrics.dropwizard.io/metrics-jmx</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/dropwizard/metrics/issues/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/dropwizard/metrics/metrics-jmx/</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2?type=jar">
      <publisher>FasterXML</publisher>
      <group>com.fasterxml.jackson.core</group>
      <name>jackson-databind</name>
      <version>2.21.2</version>
      <description>General data-binding functionality for Jackson: works on core streaming API</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">add2fbe739574bfd1877c2cca25f46d1</hash>
        <hash alg="SHA-1">71ab8ff75b4fd74afdee0004173fdd15de1d6a28</hash>
        <hash alg="SHA-256">8c982f01f148d805f0aaac2339011244757e0df7c6ff8951f2fa3f433b8ed849</hash>
        <hash alg="SHA-512">1a47b012447bc8c3d0bc603b95fce1640d7fe7ead08bc33c106c0de811f061a1eda871863e4e1411e9c0c9c716d47c69960f7e492f54e8610f3e40c99f5c3962</hash>
        <hash alg="SHA-384">933e7dd454a933ff1fa451ff63d870708b9ca8cdf68b849594a08d9859468cc19b15836cef741f6c9ffb8cde31cc5c76</hash>
        <hash alg="SHA3-384">f2ef8662730bd798307c483f18f1bd54fc4fd5c9cacf4eba0715222cb4a3e46ea60dde95994764604f0621a05a1ce0c1</hash>
        <hash alg="SHA3-256">0bcf55950a1f2eb63569142af0d863b2496791cf9da864ff9b8b73796250c5f0</hash>
        <hash alg="SHA3-512">58132245b550d327faf1c8a2a0bccc85188a2abbab806ea646ce3b83340a750df534ed51db3de2a2fa167e4612371ea1ab84ab8d1badab5509f44d9c73958396</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/FasterXML/jackson</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://central.sonatype.com/api/v1/publisher</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/FasterXML/jackson-databind/issues</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/FasterXML/jackson-databind</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/com.fasterxml.jackson.module/jackson-module-scala_2.13@2.21.2?type=jar">
      <publisher>com.fasterxml.jackson.module</publisher>
      <group>com.fasterxml.jackson.module</group>
      <name>jackson-module-scala_2.13</name>
      <version>2.21.2</version>
      <description>jackson-module-scala</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">4c34856d8f367a0a40619f82ffffbc8d</hash>
        <hash alg="SHA-1">8b52be04f2e3d106a6f6cacd267cc5febed927cb</hash>
        <hash alg="SHA-256">24f56b094ae46ab4005ac703a1be14be72dd8f0d81111508fc6e35163f251452</hash>
        <hash alg="SHA-512">ffba837caac7b74c3165f4ace62fad82edfd19e2efcc565bc9892a07d30b66d7affdbc17a3066fd4de013e74807e80f93a101394fca64142328c90c8dfc2361e</hash>
        <hash alg="SHA-384">e244d17c92ac76b091ea3337858a252a4ff89cd414b28d06a9da014c63a4b26a79c1a65576958c972396b91d214229c1</hash>
        <hash alg="SHA3-384">d2b35b00ad9beaf543587e4548a3bad513ffb2e45f15cdbd64779c9bb61a2cdf7f01d5fe966dc51e2ad1cb30641b9d3f</hash>
        <hash alg="SHA3-256">19d6687d70c54a34d62cfa386e062d6c67fca81fcc8c3bc6455237a2a0fd92e6</hash>
        <hash alg="SHA3-512">1f44a267be7e2fc9c24578f249f837ef04fed2ba9e2f1fe1253c740c48c2fa6852544199d1d2db27f15fea63c86efdf1823ddfa6c5b03135a69182b9e3e5f799</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/com.fasterxml.jackson.module/jackson-module-scala_2.13@2.21.2?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/FasterXML/jackson-module-scala</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/FasterXML/jackson-module-scala</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/com.thoughtworks.paranamer/paranamer@2.8.3?type=jar">
      <group>com.thoughtworks.paranamer</group>
      <name>paranamer</name>
      <version>2.8.3</version>
      <description>Paranamer allows runtime access to constructor and method parameter names for Java classes</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">2ac658965d0ed96c4ee2cd8e5bd4b07b</hash>
        <hash alg="SHA-1">75ae4eb129574b7fc0df5fa8808d7ed625be815d</hash>
        <hash alg="SHA-256">a9df136f2e926b37a838a5b4e2227343c3a755d15724b3a8350b4aea4b158945</hash>
        <hash alg="SHA-512">c880f95b14a4f48f34bc1a85264ad2aae3d96868c81a5e05b68bb1da100cfd68b77c8952194b3db3b20cb7d9e51ea48f6d74c5a9c469bfe190ab8da1e8cbadc3</hash>
        <hash alg="SHA-384">e79918c5f60f35536d6125cf73e13d44da12a19a7406da526ddd29c39f9004f6ed3c687fea8b58df19ff798bbf56b118</hash>
        <hash alg="SHA3-384">97b3dd9b3238b74fcf06eb5cf9af1f53dff534dc31622bafc8ce5efef5044fb3ac8ce56460387b0193e20302fc123d89</hash>
        <hash alg="SHA3-256">1d2e577cd10ae03f276a45bdfa9add2716db323588dd32a42ff89b4ee8ad0304</hash>
        <hash alg="SHA3-512">a7f4daf40ec6bbe10fee6b3778400b10e020c87f60d22576261d69eb406bba271ec3546a2d4c00234708e01eed9b0d564a90f356eb26693cbbab562d6618c76c</hash>
      </hashes>
      <licenses>
        <license>
          <id>BSD-4-Clause</id>
        </license>
      </licenses>
      <purl>pkg:maven/com.thoughtworks.paranamer/paranamer@2.8.3?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/paul-hammant/paranamer/paranamer</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/paul-hammant/paranamer/paranamer</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/net.razorvine/pickle@1.5?type=jar">
      <group>net.razorvine</group>
      <name>pickle</name>
      <version>1.5</version>
      <description>A feature complete pickle protocol implementation (Python's builtin serialization mechanism)</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">6187a95b6d982b63992a1f5bc747c9b8</hash>
        <hash alg="SHA-1">40c199d316db0e24bd93d349a35fb425045661e9</hash>
        <hash alg="SHA-256">ec762e69e4a699b544ac68b306d12f1f546d7581f165f3ffea819b703066424b</hash>
        <hash alg="SHA-512">c8830027edeea04289bbf47a330312eabe4b200760aaeb1112d048caef9298542788539a97cd63a369ab3476683d3e82081e0198779413bb047e0a5858b7491f</hash>
        <hash alg="SHA-384">0d7c573708f9629ac7617fcc3f9c11a82dc4e3464e1ceaaa27d09d66055c23ee8d6ffb2d68b7891a016da86215944196</hash>
        <hash alg="SHA3-384">7c28c2a6233e81612d00b8973c14b7986a0a1e385bb0b5748819562fefa4b9c247f58e6173b953cde151b1abd6e31647</hash>
        <hash alg="SHA3-256">480fd5ff9d203b1d2370a1a6e065e8be791fa5fec3b3d4141a7a61880a548e78</hash>
        <hash alg="SHA3-512">d384469619adc405c6d0a2851ec716c2555e2063e2aa141cc72fc6213a09b2b7a8db4ef6a10538690d5869118dfa205e8a7197e47afc50e43ece2366d5fe8509</hash>
      </hashes>
      <licenses>
        <license>
          <id>MIT</id>
          <url>https://opensource.org/license/mit/</url>
        </license>
      </licenses>
      <purl>pkg:maven/net.razorvine/pickle@1.5?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/irmen/pickle</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/irmen/pickle/issues</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/irmen/pickle</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/net.sf.py4j/py4j@0.10.9.9?type=jar">
      <group>net.sf.py4j</group>
      <name>py4j</name>
      <version>0.10.9.9</version>
      <description>Py4J enables Python programs running in a Python interpreter to dynamically access Java objects in a Java Virtual Machine. Methods are called as if the Java objects resided in the Python interpreter and Java collections can be accessed through standard Python collection methods. Py4J also enables Java programs to call back Python objects.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">82241e9bdc71cb59a05ad153f1feca7f</hash>
        <hash alg="SHA-1">801fc9ed56ae8052805b86cb9c459257a633e75e</hash>
        <hash alg="SHA-256">bc4c4b1e731ab18496cc6eab31e7353701b32fc5c3047764a0656acf5344a54b</hash>
        <hash alg="SHA-512">63b2bdaebd853bccb96f176898e53b2040a733a73afde2bf92b5a3c1057c083d291f95f0938f84b82782889ce9e06538227140326b3569101bc578d55cd0b579</hash>
        <hash alg="SHA-384">e7a55cb93df90bd6a12ab2efb8db564827cea4b281b2959432ddeb36637f66583215a358ab577ad65cc339ea813d2999</hash>
        <hash alg="SHA3-384">549e9ff58862841c0a027ae37606edc5d130dcf521993b61f7d47434790c228088c42e6b8f3d570f0aa4bad387f0c385</hash>
        <hash alg="SHA3-256">d9a6a5fc9622de23b4392cee741115af3222526032bf35baa38dfc18160666cb</hash>
        <hash alg="SHA3-512">85371a86a34a8bd359f0311bf1b0ee06bf99fec5ee97649727fe518eeb8a605a35b230a4c4c3c02e0ae62f6b2986f9d6c3d4e18396d48fa125ec74c14bc80f0c</hash>
      </hashes>
      <licenses>
        <license>
          <id>BSD-3-Clause</id>
        </license>
      </licenses>
      <purl>pkg:maven/net.sf.py4j/py4j@0.10.9.9?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://nexus.sonatype.org/oss-repository-hosting.html/py4j</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.commons/commons-crypto@1.1.0?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.commons</group>
      <name>commons-crypto</name>
      <version>1.1.0</version>
      <description>Apache Commons Crypto is a cryptographic library optimized with AES-NI (Advanced Encryption
Standard New Instructions). It provides Java API for both cipher level and Java stream level.
Developers can use it to implement high performance AES encryption/decryption with the minimum
code and effort. Please note that Crypto doesn't implement the cryptographic algorithm such as
AES directly. It wraps to Openssl or JCE which implement the algorithms.

Features
--------

1. Cipher API for low level cryptographic operations.
2. Java stream API (CryptoInputStream/CryptoOutputStream) for high level stream encryption/decryption.
3. Both optimized with high performance AES encryption/decryption. (1400 MB/s - 1700 MB/s throughput in modern Xeon processors).
4. JNI-based implementation to achieve comparable performance to the native C/C++ version based on OpenSsl.
5. Portable across various operating systems (currently only Linux/MacOSX/Windows);
   Apache Commons Crypto loads the library according to your machine environment (it checks system properties, `os.name` and `os.arch`).
6. Simple usage. Add the commons-crypto-(version).jar file to your classpath.


Export restrictions
-------------------

This distribution includes cryptographic software.
The country in which you currently reside may have restrictions
on the import, possession, use, and/or re-export to another country,
of encryption software. BEFORE using any encryption software,
please check your country's laws, regulations and policies
concerning the import, possession, or use, and re-export of
encryption software, to see if this is permitted.
See &lt;http://www.wassenaar.org/> for more information.

The U.S. Government Department of Commerce, Bureau of Industry and Security (BIS),
has classified this software as Export Commodity Control Number (ECCN) 5D002.C.1,
which includes information security software using or performing
cryptographic functions with asymmetric algorithms.
The form and manner of this Apache Software Foundation distribution makes
it eligible for export under the License Exception
ENC Technology Software Unrestricted (TSU) exception
(see the BIS Export Administration Regulations, Section 740.13)
for both object code and source code.

The following provides more details on the included cryptographic software:

* Commons Crypto use [Java Cryptography Extension](http://docs.oracle.com/javase/8/docs/technotes/guides/security/crypto/CryptoSpec.html) provided by Java
* Commons Crypto link to and use [OpenSSL](https://www.openssl.org/) ciphers</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">c71451f3c4737ba6d84f9bd9e8f2400d</hash>
        <hash alg="SHA-1">4a8b4caa84032a0f1f1dad16875820a4f37524b7</hash>
        <hash alg="SHA-256">44dc28551cdba731658090d9b10d2eead9839c269d70cdcd7d56c0423df5227f</hash>
        <hash alg="SHA-512">62acf1d90ad667c8f3f9b267c6f4fefa57eb914ef57a24e10a7dc6ea7bf1f2a6933db831f836dc2ca0fe86aff84a6d1a0fb3c8bb34c7c24e3e1190778efb241d</hash>
        <hash alg="SHA-384">0d7c20964ab9cbde60d3d03ca92b481e30f969b30adc336b77ec8b8dcb660e327bfff8c98cb9c30163e7bdf5ffbae486</hash>
        <hash alg="SHA3-384">a86cd2c434475336d6258dbccae98575888b910a935517ddb832bbefd944b0427ebb7742e5ef65e5e7e2046f94a4fc27</hash>
        <hash alg="SHA3-256">aea2f3e041185d2f7ede524ebdc76f76708db74da5023dc34d2d75c0fe2ec6c2</hash>
        <hash alg="SHA3-512">313cd4870c67daf90157f6567e969cfe8845f0cf4b90f7667dfbadd4cb35a526109a59b60e1bb677a9938471c15ebdfe973038e0cdfba2f06db98fdbf88e8710</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.commons/commons-crypto@1.1.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://commons.apache.org/proper/commons-crypto/</url>
        </reference>
        <reference type="build-system">
          <url>https://builds.apache.org/search/?q=Commons-CRYPTO</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://issues.apache.org/jira/browse/CRYPTO</url>
        </reference>
        <reference type="mailing-list">
          <url>https://mail-archives.apache.org/mod_mbox/commons-user/</url>
        </reference>
        <reference type="vcs">
          <url>https://gitbox.apache.org/repos/asf?p=commons-crypto.git</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/com.google.protobuf/protobuf-java@4.33.0?type=jar">
      <group>com.google.protobuf</group>
      <name>protobuf-java</name>
      <version>4.33.0</version>
      <description>Core Protocol Buffers library. Protocol Buffers are a way of encoding structured data in an
    efficient yet extensible format.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">21e99d7cd67288277331e29583448db2</hash>
        <hash alg="SHA-1">5f82a81e6e7b6b7434d05a7bdd666b84d9eb0bc5</hash>
        <hash alg="SHA-256">6c50b4323a101dfd7b8aea209337ac49ecf5d8e33e0b210b196fc654291ed2cc</hash>
        <hash alg="SHA-512">3e872f8422cc53641cb10be6fc23a1583b0ad5177b8dbd327119c074c3023e4d5794afbdd1cfd17675bdcc78f0c43da11ace9ba333f31ef8ed8ec5353882e0cc</hash>
        <hash alg="SHA-384">4fd2b2c5950663cd0ea022b0b4d72346fd751cdd79439aa158bb95857f7d793b1abd17daf23e708820ca39306d3de13f</hash>
        <hash alg="SHA3-384">7ab419342657f7413586f86f98802d7197a553776e01bb5b65dec4c3e76a4efbcb214be267239e4e1be64d31531a7257</hash>
        <hash alg="SHA3-256">e15e9a0272bb5d24f6b13e886e597afcef3ef26c7afab7374eb0634773a424fb</hash>
        <hash alg="SHA3-512">20246f028032c44e05660164287f98dcb31ff3357d25120d603227a28b1e345859020eabd9901711b03cc84fc211662bb393c7ba10900b3f084eefdd90ed9a12</hash>
      </hashes>
      <licenses>
        <license>
          <id>BSD-3-Clause</id>
          <url>https://opensource.org/licenses/BSD-3-Clause</url>
        </license>
      </licenses>
      <purl>pkg:maven/com.google.protobuf/protobuf-java@4.33.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://developers.google.com/protocol-buffers/protobuf-java/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/protocolbuffers/protobuf/protobuf-java</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.spark/spark-sql-api_2.13@4.1.2?type=jar">
      <publisher>Apache Software Foundation</publisher>
      <group>org.apache.spark</group>
      <name>spark-sql-api_2.13</name>
      <version>4.1.2</version>
      <description>The Apache Software Foundation provides support for the Apache community of open-source software projects.
    The Apache projects are characterized by a collaborative, consensus based development process, an open and
    pragmatic software license, and a desire to create high quality software that leads the way in its field.
    We consider ourselves not simply a group of projects sharing a server, but rather a community of developers
    and users.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">2afaff373bce657eac743856882e9986</hash>
        <hash alg="SHA-1">fbe8bf19306fd817f4627eec9d59a958f764dd8a</hash>
        <hash alg="SHA-256">1448733d5bd7d2b65330b9a160d345a1b6f39628ab495d6a99012183cafb8b15</hash>
        <hash alg="SHA-512">f2658d652d17db04a07b171ae106461732c019ed8d2a4ca433091ba17947256d4ef068d72a58c3195290891fe86e687068eff766160ba883a81c60fe510b3b19</hash>
        <hash alg="SHA-384">b80f41cac7946e31fff89fa355c32836885275031e202db8708eaebe26652c5ce326f123847fdb275a433f32fff41018</hash>
        <hash alg="SHA3-384">59c48679e4695ca256cbe62021420d547ac5dda2215630f7c137f4a76eb07e59e52a609ed0f40bbf992310e9b790e6a8</hash>
        <hash alg="SHA3-256">1c8e03df3b641279ccbd6191a7839976dc5624458b86181de39269d43f6745e8</hash>
        <hash alg="SHA3-512">427310fba4a8160155db3fc9025e684a03e7443cc06086407815171cd1459a8371084d8cdfa4b2932288c03be299b9cc89654944dcde98106ebd4758b6e3cf21</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.spark/spark-sql-api_2.13@4.1.2?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://spark.apache.org/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://issues.apache.org/jira/browse/SPARK</url>
        </reference>
        <reference type="mailing-list">
          <url>dev-subscribe@spark.apache.org</url>
        </reference>
        <reference type="vcs">
          <url>scm:git:git@github.com:apache/spark.git/sql/spark-sql-api_2.13</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.scala-lang.modules/scala-parser-combinators_2.13@2.4.0?type=jar">
      <publisher>org.scala-lang.modules</publisher>
      <group>org.scala-lang.modules</group>
      <name>scala-parser-combinators_2.13</name>
      <version>2.4.0</version>
      <description>scala-parser-combinators</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">7e722e68df2f86977cfcc71c9a50b64f</hash>
        <hash alg="SHA-1">4c21da00e1416078ba0bf4a2be63aa86de92753c</hash>
        <hash alg="SHA-256">e36dccdc21fd4bc770907a9e126d7e3901e71a191eb9ea8e93a0227774e0945d</hash>
        <hash alg="SHA-512">b413c755b1980c6c01dbc61199eb8f5f0231273a3a48ed58cf437fc7b6c34b4bf0a533fe8163b357671e6bffb61fabee92def220434a26e900c70af81558c8bd</hash>
        <hash alg="SHA-384">a3a29bc9161bba67fee068df2387107b0da2aeb784f28d82ebc7dd0eb86548ea65ce8395ae5f8230c75e3f82cda77216</hash>
        <hash alg="SHA3-384">a9013001acaa4d51756e51990945fbead6eb2d3c1251faf726367c131732914a6c1e908a9aa85f9b715cd860fe87f0d2</hash>
        <hash alg="SHA3-256">73a21689748b42397efd7013e479bb754d3f21ab58a4907fa210fc1fd8c9b9cc</hash>
        <hash alg="SHA3-512">44c9513f18aed4e9482b211fdce8bf7f29a2704de71f8fbef5ab4a136af8ae064dfdc7c625f5abb5ff95aa1088b290e7d34cc510cfa4dd674e631b84a57a9932</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.scala-lang.modules/scala-parser-combinators_2.13@2.4.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://www.scala-lang.org/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/scala/scala-parser-combinators/issues</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/scala/scala-parser-combinators</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.antlr/antlr4-runtime@4.13.1?type=jar">
      <publisher>ANTLR</publisher>
      <group>org.antlr</group>
      <name>antlr4-runtime</name>
      <version>4.13.1</version>
      <description>The ANTLR 4 Runtime</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">dd465ddb2a8dbf69eb6c94e69a0d5f0f</hash>
        <hash alg="SHA-1">17125bae1d965624e265ef49552f6465a2bfa307</hash>
        <hash alg="SHA-256">54665d2838cc66458343468efc539e454fc95b46a8a04b13c6ac43fc9be63505</hash>
        <hash alg="SHA-512">63eb51bfcee49c52848d8b7c3c46d8b4d367d85fb3c3db7175eaacba94e4d0c227b78e5955a0e86e575e1c6206fc2a43e5fa96fb04ad7c16e24ec94015cfc18b</hash>
        <hash alg="SHA-384">9e5e022d1eff5870f53e0e17d09d737eebb5b859c3403e78308af4616a86cde0830842b81a389ac4a0df871fb1032124</hash>
        <hash alg="SHA3-384">20f3a927369f6bfd94bd8b244e0e9330d4438736414c403b712098f6aad9a1140bc17333cacf194f1b9e99c0f62ffdfa</hash>
        <hash alg="SHA3-256">5696b3e757e6135c1aa56452b86ff0456425d13b97b33ace3f4d3dc6c752c4b6</hash>
        <hash alg="SHA3-512">33251a06eaeaa56f274548e47b405cce279a9e54e34d65bc382d2482887bd470e5080da4f75c221658c3e70aea79e748bd0a3f47e49e37805174e23f71747b92</hash>
      </hashes>
      <licenses>
        <license>
          <id>BSD-3-Clause</id>
          <url>https://opensource.org/licenses/BSD-3-Clause</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.antlr/antlr4-runtime@4.13.1?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://www.antlr.org/antlr4-runtime/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/antlr/antlr4/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://groups.google.com/forum/?fromgroups#!forum/antlr-discussion</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/antlr/antlr4/tree/master/antlr4-runtime</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.arrow/arrow-vector@18.3.0?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.arrow</group>
      <name>arrow-vector</name>
      <version>18.3.0</version>
      <description>An off-heap reference implementation for Arrow columnar data format.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">da1a43b8b4fba046b03a560b35a8fa63</hash>
        <hash alg="SHA-1">a51efb8471503ab184ce6fa75bf1b21922b04073</hash>
        <hash alg="SHA-256">b37eda92daccaffc12abf5ed425db1d0bdb3edea150a6ca856f1cf4292442299</hash>
        <hash alg="SHA-512">f09fe6d5f605c90e5268d59982d22292d6c1c215d7c333f24d9a969b8af769184b521d4f37b6676672ee8701ce2e71af138fac578d9e327fbed3577ebfb66106</hash>
        <hash alg="SHA-384">297c9f81dc7de56aa667b821b79948a40aa65142e59212414e384abfe4857ecec3d2473e8b0feabefe229b38582276bb</hash>
        <hash alg="SHA3-384">68457c8154b9068be21228e4f54d1905afa06101c886456ef2633391a590043868356145af3a2c5ed6e576bdd9dc7894</hash>
        <hash alg="SHA3-256">b928eab9e447204faacf246d2c79869274f0cc5efd3980f6565edcb10fbcff9d</hash>
        <hash alg="SHA3-512">8a7602ab9fd56c203f52fb2cc2c44ab6305f4fad47b5ae64a2a010ff9a8f3744490aae327a04647aa00f5de30c764c517e160e25d3a178640d99da218495a877</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.arrow/arrow-vector@18.3.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://arrow.apache.org/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/apache/arrow-java/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://lists.apache.org/list.html?dev@arrow.apache.org</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/apache/arrow-java/tree/v18.3.0</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.arrow/arrow-format@18.3.0?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.arrow</group>
      <name>arrow-format</name>
      <version>18.3.0</version>
      <description>Generated Java files from the IPC Flatbuffer definitions.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">213e8910c5b1fed8efe83cd2b740b544</hash>
        <hash alg="SHA-1">72528fdd5869baffb2d985cb5179f5bf63a1473d</hash>
        <hash alg="SHA-256">728297d7757d192053ce071cc59e76c8a03ff4f5e430177fa97e96b29dd2de1b</hash>
        <hash alg="SHA-512">3350e1719458065a7a60004064f475276ea58c4942199144acd9448d8360d3ef874fb7dfdf75b7cc041da3afcc8935d3cd2d6f243d4fe68bcae0a3638e28f6f0</hash>
        <hash alg="SHA-384">e03bbca9ef73a8361a1c458eac360846b89745802b9d0a6d0d9def28d91e2f43602e06ff1dbbe761fb67cca1a94a9eb7</hash>
        <hash alg="SHA3-384">aa256d3c37e8558adf671dfb19ec8c732082d527a091b0cfb286a2707813b6aeb6d80001ce40836b17c4f16c3d9bd5e8</hash>
        <hash alg="SHA3-256">fbce5672f9e58af49cf845d2fe9db6fbf0dcb1f04149bdff7eb89c894a33f68d</hash>
        <hash alg="SHA3-512">5502d6905dded6fbe1d53eacf726201510f99aac6229302a3c5a30feb70deab07b35840a43a869f3a226b0fa69aeec23edc03cbae89068c206bc0410e2bfdfb8</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.arrow/arrow-format@18.3.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://arrow.apache.org/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/apache/arrow-java/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://lists.apache.org/list.html?dev@arrow.apache.org</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/apache/arrow-java/tree/v18.3.0</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/com.fasterxml.jackson.datatype/jackson-datatype-jsr310@2.21.2?type=jar">
      <publisher>FasterXML</publisher>
      <group>com.fasterxml.jackson.datatype</group>
      <name>jackson-datatype-jsr310</name>
      <version>2.21.2</version>
      <description>Add-on module to support JSR-310 (Java 8 Date &amp; Time API) data types.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">6687c3b16dbc8c1f25536d1888d0822a</hash>
        <hash alg="SHA-1">65b0cef8d997561541b7db6bbb1f6d42913b60e0</hash>
        <hash alg="SHA-256">a083d57cd1c4a28fefcc6bd071740779eb7fc1c22a3c1b40451b5477c443f02f</hash>
        <hash alg="SHA-512">f82a57f7bcd13051e358c9f296ed7b6cd33ddd39b70f655644425d7de5c01672106715f767993d7cb689efd1d5cf62070884e05e0b281178664cc879c76e7cf1</hash>
        <hash alg="SHA-384">fcc9843f2edba8967804919ce8f32a43c8f0bbdf5912786efb475a1f0ccf9ed1a00d5138a656b24d02f21c1f7827a249</hash>
        <hash alg="SHA3-384">4eb968169fc1c67d5ab3bbb24220e2704a7717ecdd136969c5fc592f133409315f35ba469371d7421accac61b160e130</hash>
        <hash alg="SHA3-256">5124918ece7931d2c3b8df169d99d75012153bc9350b471cc5ae3e55fe5553f3</hash>
        <hash alg="SHA3-512">4e0575fe8524c507cc8adcc9882d250a42f6f22f45c01749b861d7ec9da92cc8199c5a9ecc15229be428ffa6b1f29bb259ecb1308690af4cca2c27e80ab10688</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/com.fasterxml.jackson.datatype/jackson-datatype-jsr310@2.21.2?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/FasterXML/jackson-modules-java8/jackson-datatype-jsr310</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://central.sonatype.com/api/v1/publisher</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/FasterXML/jackson-modules-java8/issues</url>
        </reference>
        <reference type="vcs">
          <url>http://github.com/FasterXML/jackson-modules-java8/jackson-datatype-jsr310</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/com.google.flatbuffers/flatbuffers-java@25.2.10?type=jar">
      <group>com.google.flatbuffers</group>
      <name>flatbuffers-java</name>
      <version>25.2.10</version>
      <description>Memory Efficient Serialization Library</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">cadad6a81a9f7dc532ab7a5cb97a50c7</hash>
        <hash alg="SHA-1">9bb1a149ec48588fc04a3d00a3cc4e0135273b4e</hash>
        <hash alg="SHA-256">587bd6c31cda747587493a113bec8602d3a0b0ca579b2b1b838ef71b19e6525d</hash>
        <hash alg="SHA-512">9c4b26d5554b7a6f9907f18033ec0fc060fd2af58d836d033e2b076319d782473f7f0a3ef4f9d16e859b2c5b15f73d83ac889323dbdcbd7563ea495c59b9c626</hash>
        <hash alg="SHA-384">d560b2c573b607ab3c34f7ef13887814204fabb0e49e5f98f28c5f0f8fa7a86feeeca5f7a830237a7d8e735ca0df8d8a</hash>
        <hash alg="SHA3-384">f70604f012c9f91eeb264fd4245dd3b1ac3a6039ca8d46ccd6a24e7f4d0976d92eb14097ef92595eb49aa8d7124a84ec</hash>
        <hash alg="SHA3-256">c5af0cdd09bdc4197104b03820b944e0a24193bcc7ecafdd621b711cec27999b</hash>
        <hash alg="SHA3-512">52291e71a8d81ce74519f7e5d2d7c3e8bcdd699e137d02ab3d620e848f4732c33dccd5cd670875cc3b4efb12ff80b34b987b5a634aac6f816fb7c80c48678c4a</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/com.google.flatbuffers/flatbuffers-java@25.2.10?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/google/flatbuffers</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/google/flatbuffers</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.arrow/arrow-memory-netty@18.3.0?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.arrow</group>
      <name>arrow-memory-netty</name>
      <version>18.3.0</version>
      <description>Netty allocator and utils for allocating memory in Arrow</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">358a576835b93f7db806ea6775e5c6a8</hash>
        <hash alg="SHA-1">48e3c2bc75c062a3d585f740c8a20ba4b0bd6b48</hash>
        <hash alg="SHA-256">1ab5100b54ce57c2a72106206663ce1c2ed84c7e173b3dbc3a57af474ec42c73</hash>
        <hash alg="SHA-512">ceb4c94848eb0434c674be28e4904f6ddfa3b41c0b7dd7d156b9292d441aa049ff89ed0be81e9a8838fddb72f10c634a377860ca9f660d3acdb9227df777c6ae</hash>
        <hash alg="SHA-384">cf6988f70ed9f6978e6d06d290b5466b010bbfe411c59f29051b547c708f2d909620f6baf33167cc3943b7128dc553c6</hash>
        <hash alg="SHA3-384">203b2928c436bc0fcb215567b3bd46b686d87bf416c8651689a94258fbbce52f79781f5d2ea52f0be73005a5adf3e169</hash>
        <hash alg="SHA3-256">810e148071377411740d197561e5f52dfa1ff9f682d9c2a98099f7986e7e0304</hash>
        <hash alg="SHA3-512">a9cd26ab3ce7db5c7bbd28740888314a649aa1efef5747a0491d54c397205e0a02473ee5fa64efaa82106f257da39b5e6352df3c342d720fe37f0bbacc53ef57</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.arrow/arrow-memory-netty@18.3.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://arrow.apache.org/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/apache/arrow-java/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://lists.apache.org/list.html?dev@arrow.apache.org</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/apache/arrow-java/tree/v18.3.0</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.arrow/arrow-memory-netty-buffer-patch@18.3.0?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.arrow</group>
      <name>arrow-memory-netty-buffer-patch</name>
      <version>18.3.0</version>
      <description>Netty Buffer needed to patch that is consumed by Arrow Memory Netty</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">5f39dba4a3a4064e3b273ebb10629545</hash>
        <hash alg="SHA-1">66ffb49ec116865017346be7a27bb0d16454c80a</hash>
        <hash alg="SHA-256">465c7acdd254d7e3ee60946356959ca42aa0e389cc4d1ce78afd51c48126b050</hash>
        <hash alg="SHA-512">2d357642cbe8bc981671ae03c25fa2c47f2fcce556bddba95c4210834a82903e2d08f56ea0e64a100e5fde49d7d7cf6ad7efe8d6fb293a3fd317f1f2e647a93d</hash>
        <hash alg="SHA-384">04efe20cfb0d01a70302aa806c1856b88bc97650d5e067a428716b48906a5f474a6aaa03680c6d8001307bfc5bf88bed</hash>
        <hash alg="SHA3-384">3730ad78690ad0ff8bdbaccdc584209f705a0b22c1212c424a0fe6ab6b7c8dcb4beeba5cc8da310699a4ba3d7d459a51</hash>
        <hash alg="SHA3-256">28bb8327cf49d64874567884be019d190e50786c7015c281019376ea35440e36</hash>
        <hash alg="SHA3-512">9bd9debeef676c770be3e95773303461d9b39d7c5d3180299ba5a93c72175d8ac1cf59c79a2b08fae2c005875bd509251c97ae92de2b750acbea513823106571</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.arrow/arrow-memory-netty-buffer-patch@18.3.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://arrow.apache.org/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/apache/arrow-java/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://lists.apache.org/list.html?dev@arrow.apache.org</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/apache/arrow-java/tree/v18.3.0</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.spark/spark-sketch_2.13@4.1.2?type=jar">
      <publisher>Apache Software Foundation</publisher>
      <group>org.apache.spark</group>
      <name>spark-sketch_2.13</name>
      <version>4.1.2</version>
      <description>The Apache Software Foundation provides support for the Apache community of open-source software projects.
    The Apache projects are characterized by a collaborative, consensus based development process, an open and
    pragmatic software license, and a desire to create high quality software that leads the way in its field.
    We consider ourselves not simply a group of projects sharing a server, but rather a community of developers
    and users.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">f6d04ceb4f105748fe40a2bd8fc477a2</hash>
        <hash alg="SHA-1">8397ea3e4f6d76b76027a08004fa4796a3bc9f06</hash>
        <hash alg="SHA-256">4d51fe92ef52911481004bb26673faed507403d2baae09d4b5d4f5ecbced6dac</hash>
        <hash alg="SHA-512">3adcaada3d2cf8e41544631560e2055e11bd64a8a86f41066625cc7aeb7e04bcbcc99a1d9d3a977673c13ccc799f69404ca81f001dd0cd185ecf9361412a3566</hash>
        <hash alg="SHA-384">a6ba3dedf09c61e0bf35def915b0ee3d567eda89e5932b040493130f4abece5682a4e71ec6d932d07bb5f0ff888834a1</hash>
        <hash alg="SHA3-384">48dbaab3006669f3044a345e2072a692546b99569db29955c9aadebe5e2e7895188859addcfbac4d1cd7404e779fa097</hash>
        <hash alg="SHA3-256">32e9d5ad5c5025694d75fc326bcd6507799691c255935f6f83b80b0b2a38d1ad</hash>
        <hash alg="SHA3-512">f95122c55edfd7237032776893eaa02bd1b5862898240e64e6b080d65bd11329ccaabb44d91b897cb282237c252ab33b7b5e9c40ec70bc98e7864df31e35d95c</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.spark/spark-sketch_2.13@4.1.2?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://spark.apache.org/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://issues.apache.org/jira/browse/SPARK</url>
        </reference>
        <reference type="mailing-list">
          <url>dev-subscribe@spark.apache.org</url>
        </reference>
        <reference type="vcs">
          <url>scm:git:git@github.com:apache/spark.git/common/spark-sketch_2.13</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.spark/spark-variant_2.13@4.1.2?type=jar">
      <publisher>Apache Software Foundation</publisher>
      <group>org.apache.spark</group>
      <name>spark-variant_2.13</name>
      <version>4.1.2</version>
      <description>The Apache Software Foundation provides support for the Apache community of open-source software projects.
    The Apache projects are characterized by a collaborative, consensus based development process, an open and
    pragmatic software license, and a desire to create high quality software that leads the way in its field.
    We consider ourselves not simply a group of projects sharing a server, but rather a community of developers
    and users.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">2b1e35f8a7f7a8c8f718d67ec3da98bb</hash>
        <hash alg="SHA-1">e933df7c791c52e3061be6943a5982857031861d</hash>
        <hash alg="SHA-256">1534c052b173ebc9193bd392aeaf35adc2165d5299515ba4a48c4c4281e0783d</hash>
        <hash alg="SHA-512">062501654278af3b33afbc8f22a657dc0f23bd809b63ba60c98be1d5b120e7797a765343706539db01019e9facf1654e5d29dd0bf36b40ec4f41f43aa872f657</hash>
        <hash alg="SHA-384">217dde2054b22125ac71aba2d8e39f115c1a18996467660729a3d3f1e8d03c4c594a008c741107eacf762e5d971aa0d2</hash>
        <hash alg="SHA3-384">be7381c045a0348944175e5c47ff482cc6c02cf503d86caffda8dba7d892102dbdc877fe92540ffe47399e23cc12e11b</hash>
        <hash alg="SHA3-256">43f6cc0aa5723e7b4d0cf2d6dc289588b430b61f1d7a0e783b9c61bb4fff967c</hash>
        <hash alg="SHA3-512">ba4746e259fdf3e51d0ae47fbce95d4e94307ca1781a51922ca4301a75ce43d7e2e73f1305831a658c5739edd1f112f6a259437a764b5719dbfc212e2aaac8da</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.spark/spark-variant_2.13@4.1.2?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://spark.apache.org/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://issues.apache.org/jira/browse/SPARK</url>
        </reference>
        <reference type="mailing-list">
          <url>dev-subscribe@spark.apache.org</url>
        </reference>
        <reference type="vcs">
          <url>scm:git:git@github.com:apache/spark.git/common/spark-variant_2.13</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.codehaus.janino/janino@3.1.9?type=jar">
      <group>org.codehaus.janino</group>
      <name>janino</name>
      <version>3.1.9</version>
      <description>The "JANINO" implementation of the "commons-compiler" API: Super-small, super-fast, independent from the JDK's "tools.jar".</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">597cbcd4d0b8273552758c50bf423926</hash>
        <hash alg="SHA-1">536fb0c44627faae32ca7a8a24734f4aab38c878</hash>
        <hash alg="SHA-256">7df88d90aa165ab48bdebea425fa009eeef04918c82e98cdbea5e747e114508d</hash>
        <hash alg="SHA-512">840dba1621f06322d6ede76c941665e4e119f26ca1b7cb1a510a2bd9d692d3a5d75ac79477055824c2af37958e1c330daf6e1fbb9fd5bbba82db3a3f6077ff11</hash>
        <hash alg="SHA-384">85599d163bfe4c2d66e526d549c5bd26bc4137c4bb80099130782e42cfb9d5a55d34b11d98877cf11436536d3f1f9aa3</hash>
        <hash alg="SHA3-384">022e052fab4609e939df1a251e5c1283635bdf6ec24047e095a0d8a557a0323ade1a4380f277235561bd36a608700056</hash>
        <hash alg="SHA3-256">0d215b105b0bd362604dc9e14c8af2e7f77d5f39891c0127c97397667be386d4</hash>
        <hash alg="SHA3-512">f7a77aabd5a1b1c5237b321995bfe9725c217d3beb94ac2bb49bce3e238c4ddac4fd6752ee14a6aff1d01a09bacf915fe06ace351d654fa52fd98621cb828681</hash>
      </hashes>
      <licenses>
        <license>
          <id>BSD-3-Clause</id>
          <url>https://opensource.org/licenses/BSD-3-Clause</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.codehaus.janino/janino@3.1.9?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://janino-compiler.github.io/janino/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/janino-compiler/janino</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.codehaus.janino/commons-compiler@3.1.9?type=jar">
      <group>org.codehaus.janino</group>
      <name>commons-compiler</name>
      <version>3.1.9</version>
      <description>The "commons-compiler" API, including the "IExpressionEvaluator", "IScriptEvaluator", "IClassBodyEvaluator" and "ISimpleCompiler" interfaces.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">e14b760178e0c2105e2951c2f452a1d1</hash>
        <hash alg="SHA-1">f0d70bb319e9339aea90a8665693e69848acc598</hash>
        <hash alg="SHA-256">d988a3ebc17188e9a1a3efadd8e958b90eb995c4fcc077292a5dfe5fe1109d25</hash>
        <hash alg="SHA-512">0d290612b69ddece1c58ae0a60c6a544893800f588a424afb7bc12215a9e3bfe775ff6bac749f16c7b4e32e186ad29bceb80112df4082f16ce1f749685135e80</hash>
        <hash alg="SHA-384">ab1394175f2509bcdc5aa1c76294ba146ba09bae259401932f08bb9b5debd11049d2c751e503e4255d4efd4a4f199107</hash>
        <hash alg="SHA3-384">fe833869d4e4743df14004cb57cdc1812d9e920a5e04f286f3cb9192b34c605cc12288624f5608c00f232139efa1514c</hash>
        <hash alg="SHA3-256">4677b5bcefdccd7cf4293bfaa4700af7fbe9bc1d17e857c8a9a7405fe1b03f58</hash>
        <hash alg="SHA3-512">d81c4c9562e7c8a7761e2c787e91fc6f0fa8a75ea016800d1ee87e0bbd4b278d6f52077d1a40b16d16dd5714f561dd93cf06662b046f33794782a2d728042fca</hash>
      </hashes>
      <licenses>
        <license>
          <id>BSD-3-Clause</id>
          <url>https://opensource.org/licenses/BSD-3-Clause</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.codehaus.janino/commons-compiler@3.1.9?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://janino-compiler.github.io/commons-compiler/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/janino-compiler/commons-compiler</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/com.univocity/univocity-parsers@2.9.1?type=jar">
      <publisher>Univocity Software Pty Ltd</publisher>
      <group>com.univocity</group>
      <name>univocity-parsers</name>
      <version>2.9.1</version>
      <description>univocity's open source parsers for processing different text formats using a consistent API</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">7032ba85007afd0bfc702a72bf486fd0</hash>
        <hash alg="SHA-1">081827d186e42129f23c3f1e002b757ad4b4e769</hash>
        <hash alg="SHA-256">31685122d5e392e98672ed6009a95a4c1623ca1185567bd44ee94527d454e5c3</hash>
        <hash alg="SHA-512">95656c856840b203507e42c33ef15bbf1995ad364ff229dba4f6358713259cbcad96a4aeb11db57d3f5ace2500bcfd702dd9457bea45186aa5ae7ed1bfd60559</hash>
        <hash alg="SHA-384">c29f921251bafd86bcc18b5cedf28fa53a3cbbc0fb8631c72c61038b02ce53c2141900faa54586edbbaa519cc5a815ab</hash>
        <hash alg="SHA3-384">d620a82f969d032e4500ecd1ac93354888164c30f54c375572e005fbbcf640b9a3df0230f6981d9f701253273698b154</hash>
        <hash alg="SHA3-256">f772ddaa17883c4ba0c804f9d622cb2ab83619e827b32175978d90380a63985c</hash>
        <hash alg="SHA3-512">befd7c25e69ea7ec0e34f4f6df5e5300f60e9f5311dc880e2fcfe7c87b2e020d3ac58e5988a9df615269531500c5d87e03654fa0b66b020a008900eefa9a213e</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/com.univocity/univocity-parsers@2.9.1?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://github.com/univocity/univocity-parsers</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/univocity/univocity-parsers/issues</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/univocity/univocity-parsers</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.ws.xmlschema/xmlschema-core@2.3.1?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.ws.xmlschema</group>
      <name>xmlschema-core</name>
      <version>2.3.1</version>
      <description>Commons XMLSchema is a light weight schema object model that can be used to manipulate or
        generate XML schema.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">76e1deab5e6e1caa5fed31b3482cd266</hash>
        <hash alg="SHA-1">5a83fc4e79d128f38c9e32138537060678151759</hash>
        <hash alg="SHA-256">648f7f7e5228d89069cbc54c32404209f242581bc1c1e2e74229114f081071aa</hash>
        <hash alg="SHA-512">e08630e6f6fbe2b960a7c161ddff46e135566bcb1dd2aaf3707ac01a843fb462ac1c7eeb830aca7fc88cbe3ffadc235adac07ec019e166050860ed73d249c21f</hash>
        <hash alg="SHA-384">456b8a1dab0dfbccc13d9b78b195aef80d6989ccbd3a421e3e60305a4d2d48704d2f6b157c593ac2371661a505098c13</hash>
        <hash alg="SHA3-384">5bb23dd4714285adb3e64b85d33df68f4368b818a4c94e74e036b416c34ff3dbdffc70651cf7f531323aba0141800dcd</hash>
        <hash alg="SHA3-256">c01a671e540963e96245c65b633f0d17da112307c95e75c869884e92cdf7b523</hash>
        <hash alg="SHA3-512">be1141504bbc979f485f8fcdb00de037489ab5fb2f7b1401b95d1157b21684c105eb5ce985b6798fe0fc287dd0126843d1c78597fbdb3bf66f0b82c6516df9c7</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.ws.xmlschema/xmlschema-core@2.3.1?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://ws.apache.org/commons/xmlschema20/xmlschema-core/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://issues.apache.org/jira/browse/XMLSCHEMA</url>
        </reference>
        <reference type="mailing-list">
          <url>https://mail-archives.apache.org/mod_mbox/ws-dev/</url>
        </reference>
        <reference type="vcs">
          <url>https://gitbox.apache.org/repos/asf?p=ws-xmlschema.git;a=summary/xmlschema-core</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.datasketches/datasketches-java@6.2.0?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.datasketches</group>
      <name>datasketches-java</name>
      <version>6.2.0</version>
      <description>Core sketch algorithms used alone and by other Java repositories in the DataSketches library.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">d8340f968d83e174d5128cf2c8ab5420</hash>
        <hash alg="SHA-1">18dae2764002081c26c5a1ec9e691162cd0853a8</hash>
        <hash alg="SHA-256">1b55103e1f7564150a0867eca4ce3bca13cd5935a32c199a5e738f8c5c24901a</hash>
        <hash alg="SHA-512">256e6181eded3cee344837f6c05df1242fa982435f7702da5460db56220a88836cf9921f233365e532a50a96dfcc54a2eb993a3e4649314bafec0bf5df39925f</hash>
        <hash alg="SHA-384">e0d0a3fef00cfc139c974035e3ca5c8e7dc7282634bc6b108d2e1545d3cc54d5f336eb4e7ee03f53f4cff29304d0e507</hash>
        <hash alg="SHA3-384">ad2675fd983f0959760ef922dfeea9a5747a2f3b71b2715263d006970500816ea10e5baa4447eb42359cfee46db9bd2e</hash>
        <hash alg="SHA3-256">534da2beb3a2eda5d044eca7327fc45c29915124d83a8954d5eef8d44a602b82</hash>
        <hash alg="SHA3-512">f45e85111162d988f5a88cff5a491e42db88ac0e962507a160a2e6a910b07370cfc34696a291254dd56505f79d6f9547820d13716918067d8d92c6b789491803</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.datasketches/datasketches-java@6.2.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://datasketches.apache.org/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/apache/datasketches-java/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://mail-archives.apache.org/mod_mbox/datasketches-dev</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/apache/datasketches-java</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.datasketches/datasketches-memory@3.0.2?type=jar">
      <group>org.apache.datasketches</group>
      <name>datasketches-memory</name>
      <version>3.0.2</version>
      <description>High-performance native memory access.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">43aab521416080f2ec0447b830c5d535</hash>
        <hash alg="SHA-1">af230826edc1f83e2fd058a94342e49dcc13941f</hash>
        <hash alg="SHA-256">a3dbdec4de16bf2b0a4c9b1b253bd4064d587675fc76063f8972cdfa104c66cb</hash>
        <hash alg="SHA-512">1e149da646773e046b9cb9e555319fca328a02de106cd981f7f4b27c078b96f5c57dd355d03b29c8af4885b957ab6981a62c23cd4c69293951aced5299ecace3</hash>
        <hash alg="SHA-384">b9cdad5feba4a0ce9981e120d9ad32888cbff62af9dfaf917bf1eb23131275bb8f14eafa40ad119ab027929d6e49fa86</hash>
        <hash alg="SHA3-384">ebb576f5d67274052e82a4563d40f514a7bfc3117c0e8dd9881837725460d7d5fb2f193b874a8d04aa002dbf7a642add</hash>
        <hash alg="SHA3-256">4b3906252408d76891d0111daccd737434197a6f869fbcdac97a4d493854e3aa</hash>
        <hash alg="SHA3-512">0a6fd12e89dd581bf87a026316873b1cc8d5d85d4b96b8d37c534645fe13c4d5b10cdcc183a6cc3f81c1864696181ecbb156d663f1fa9b08ba21a09eab95985b</hash>
      </hashes>
      <purl>pkg:maven/org.apache.datasketches/datasketches-memory@3.0.2?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://datasketches.apache.org/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/apache/datasketches-memory/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://mail-archives.apache.org/mod_mbox/datasketches-dev</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/apache/datasketches-memory</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.scala-lang.modules/scala-parallel-collections_2.13@1.2.0?type=jar">
      <publisher>org.scala-lang.modules</publisher>
      <group>org.scala-lang.modules</group>
      <name>scala-parallel-collections_2.13</name>
      <version>1.2.0</version>
      <description>scala-parallel-collections</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">2e890c378c7acabdb46c6723ff584dc5</hash>
        <hash alg="SHA-1">ef79a2a89674427d67fa5912038b262abe7b40da</hash>
        <hash alg="SHA-256">4eae6e68cf44e9f709970355590ae981883edf6484608d747376a56cbb285432</hash>
        <hash alg="SHA-512">8bc0ac14198032e1e163e0faafd6ef1ce8ac384e2286b058546f01b540e7105f3f3392426171022aa586854babf4912c54734222ba6a40d4a08f0cd2f28b4bdc</hash>
        <hash alg="SHA-384">2a0ee0b78adefca05fe8ee5e530dd29323eec0568fcdf1248a86062fb42691f893d9c289be24bfbbeed2b731bda60bd0</hash>
        <hash alg="SHA3-384">54a7191426fb8ebd5aedb2c14706d02724b9213468db70fd27801d95b98f217b302e56aeaa59ce7c31189e0b555e73a4</hash>
        <hash alg="SHA3-256">058884cbace235e31084f8fc1c2f0047d1468f674697ca198a4ae333e48c293e</hash>
        <hash alg="SHA3-512">1f164933883ae6c9bdea67b0cda11414996e7aa1d4cff25a7bf0e20d4e51a0d66f7abc8a0992baa2a0b9fe5796c0e1785ba4e7efe0ae8c8eadd7c5f36dac2f6e</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.scala-lang.modules/scala-parallel-collections_2.13@1.2.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://www.scala-lang.org/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/scala/scala-parallel-collections/issues</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/scala/scala-parallel-collections</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/com.google.guava/guava@33.4.8-jre?type=jar">
      <group>com.google.guava</group>
      <name>guava</name>
      <version>33.4.8-jre</version>
      <description>Guava is a suite of core and expanded libraries that include
    utility classes, Google's collections, I/O classes, and
    much more.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">72920caab34426c5815e3b00f80e3b01</hash>
        <hash alg="SHA-1">e70a3268e6cd3e7d458aa15787ce6811c34e96ae</hash>
        <hash alg="SHA-256">f3d7f57f67fd622f4d468dfdd692b3a5e3909246c28017ac3263405f0fe617ed</hash>
        <hash alg="SHA-512">82c43d82fee2b3264e53cd2e9451865f9467ec0baa68d0ddfffa06a1e5465872913150ef96e99ea91daec4387248d832ec9398859f2fa5f08f65caf103306ba3</hash>
        <hash alg="SHA-384">6645343c3c7a989539d8e77a53b0b848bc1cd739a405353aa6c00b3e4e6c58a93770c988e53d4c0326ed7ea608eb5820</hash>
        <hash alg="SHA3-384">cc6d1a11626c5ba5fdec819fdc4c0e97afa3e946744dbf9dae10f9ad77f6570703356e301a686c7727b80095d3ec4bea</hash>
        <hash alg="SHA3-256">b09ae5778552402e8e5780adbee939191ea149cbf0faf2f9c15a818167730df0</hash>
        <hash alg="SHA3-512">de052d07cf9a308fe4c1a0743534cf8b651fbd6e5f570b0c1a3d9a3269669fbae164bbbfcd089a52729b3a1d8917fbb73c1dac65cb61f93fc200568f32d09a27</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/com.google.guava/guava@33.4.8-jre?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/google/guava</url>
        </reference>
        <reference type="build-system">
          <url>https://github.com/google/guava/actions</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/google/guava/issues</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/google/guava/guava</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/com.google.guava/failureaccess@1.0.3?type=jar">
      <group>com.google.guava</group>
      <name>failureaccess</name>
      <version>1.0.3</version>
      <description>Contains
    com.google.common.util.concurrent.internal.InternalFutureFailureAccess and
    InternalFutures. Most users will never need to use this artifact. Its
    classes are conceptually a part of Guava, but they're in this separate
    artifact so that Android libraries can use them without pulling in all of
    Guava (just as they can use ListenableFuture by depending on the
    listenablefuture artifact).</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">29a782e90f6b37218b18bb880d2a8f4a</hash>
        <hash alg="SHA-1">aeaffd00d57023a2c947393ed251f0354f0985fc</hash>
        <hash alg="SHA-256">cbfc3906b19b8f55dd7cfd6dfe0aa4532e834250d7f080bd8d211a3e246b59cb</hash>
        <hash alg="SHA-512">72be228e7805da5623e42bf024ded7d9147023c66b22f4dbd04ac6898201af46ee82e1f92ea51eb0595f1b49151c4b8ecb862653d4906c17609c42544ee97abf</hash>
        <hash alg="SHA-384">9dd1a2a08efda311604992d3e7cee64873bc8c64de3b423b1b3a3dcc1f7f0810bb03901fbfe39a5f835accb0646f4ad8</hash>
        <hash alg="SHA3-384">ffd67766c165ee77e96824e06de2c19864a6e61f785b2085eb825f308f173d71f2555559d90d910f33f3367378ace0e3</hash>
        <hash alg="SHA3-256">08a77b528a72ca412b36e4004692705ebfd75cfb4897c88632d367d08a34b09f</hash>
        <hash alg="SHA3-512">7cba6c266babbe8272f029eea6e2cbddadee96eb1a16916a6eb2441a55837867ce717385d4388735fd83f2f6555931077c0ebda011a1ee9a37ac38c8c0c43a65</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/com.google.guava/failureaccess@1.0.3?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/google/guava/failureaccess</url>
        </reference>
        <reference type="build-system">
          <url>https://github.com/google/guava/actions</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/google/guava/issues</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/google/guava/failureaccess</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/com.google.guava/listenablefuture@9999.0-empty-to-avoid-conflict-with-guava?type=jar">
      <group>com.google.guava</group>
      <name>listenablefuture</name>
      <version>9999.0-empty-to-avoid-conflict-with-guava</version>
      <description>An empty artifact that Guava depends on to signal that it is providing
    ListenableFuture -- but is also available in a second "version" that
    contains com.google.common.util.concurrent.ListenableFuture class, without
    any other Guava classes. The idea is:

    - If users want only ListenableFuture, they depend on listenablefuture-1.0.

    - If users want all of Guava, they depend on guava, which, as of Guava
    27.0, depends on
    listenablefuture-9999.0-empty-to-avoid-conflict-with-guava. The 9999.0-...
    version number is enough for some build systems (notably, Gradle) to select
    that empty artifact over the "real" listenablefuture-1.0 -- avoiding a
    conflict with the copy of ListenableFuture in guava itself. If users are
    using an older version of Guava or a build system other than Gradle, they
    may see class conflicts. If so, they can solve them by manually excluding
    the listenablefuture artifact or manually forcing their build systems to
    use 9999.0-....</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">d094c22570d65e132c19cea5d352e381</hash>
        <hash alg="SHA-1">b421526c5f297295adef1c886e5246c39d4ac629</hash>
        <hash alg="SHA-256">b372a037d4230aa57fbeffdef30fd6123f9c0c2db85d0aced00c91b974f33f99</hash>
        <hash alg="SHA-512">c5987a979174cbacae2e78b319f080420cc71bcdbcf7893745731eeb93c23ed13bff8d4599441f373f3a246023d33df03e882de3015ee932a74a774afdd0782f</hash>
        <hash alg="SHA-384">caff9b74079f95832ca7f6029346b34b606051cc8c5a4389fac263511d277ada0c55f28b0d43011055b268c6eb7184d5</hash>
        <hash alg="SHA3-384">e939f08df0545847ea0d3e4b04a114b08499ad069ba8ec9461d1779f87a56e0c37273630a0f4c14e78c348d3ac7eb97f</hash>
        <hash alg="SHA3-256">1f0a8b1177773b3a8ace839df5eed63cbf56b24a38714898a6e4ed065c42559f</hash>
        <hash alg="SHA3-512">6b495ecc2a18b17365cb08d124a0da47f04bcdde81927b5245edf3edd8e498c3c3fb92ce6a4127f660bac851bb1d3e4510e5c20d03be47ce99dc296d360db285</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/com.google.guava/listenablefuture@9999.0-empty-to-avoid-conflict-with-guava?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/google/guava/listenablefuture</url>
        </reference>
        <reference type="build-system">
          <url>https://travis-ci.org/google/guava</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/google/guava/issues</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/google/guava/listenablefuture</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.jspecify/jspecify@1.0.0?type=jar">
      <group>org.jspecify</group>
      <name>jspecify</name>
      <version>1.0.0</version>
      <description>An artifact of well-named and well-specified annotations to power static analysis checks</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">9133aba420d0ca3b001dbb6ae9992cf6</hash>
        <hash alg="SHA-1">7425a601c1c7ec76645a78d22b8c6a627edee507</hash>
        <hash alg="SHA-256">1fad6e6be7557781e4d33729d49ae1cdc8fdda6fe477bb0cc68ce351eafdfbab</hash>
        <hash alg="SHA-512">efded31ef5b342f09422935076e599789076431e93a746685c0607e7de5592719ba6aacde0be670b3f064d1e85630d58d5bce6b34aed2a288fdb34f745efb7bc</hash>
        <hash alg="SHA-384">814f860e5a44ead6c457676841eef471a8b87be31b84c60a8a4477a18a9cbcb6e3c2ae700969d5c5e52309d961e0537a</hash>
        <hash alg="SHA3-384">c8844e5b71e5ecfbb7366097ce34af2f5863d86d5ccc3f9ec384d8ade4b60ccc8124c7fc88664f1afd2b0962fc8775bf</hash>
        <hash alg="SHA3-256">4b4f08ad7606a3ac62997779484919a302267b26d26ee19125f8a7eea60e8a71</hash>
        <hash alg="SHA3-512">65c6845ebae981cb81b61107707ced39f5b377dae970b47606ef482aaf10e3729def0da40d9377c43abbfb483a5ceae039b0d51c129c50a6d36ad351a5d6b01e</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.jspecify/jspecify@1.0.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://jspecify.org/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/jspecify/jspecify/</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/com.google.errorprone/error_prone_annotations@2.36.0?type=jar">
      <publisher>Google LLC</publisher>
      <group>com.google.errorprone</group>
      <name>error_prone_annotations</name>
      <version>2.36.0</version>
      <description>Error Prone is a static analysis tool for Java that catches common programming mistakes at compile-time.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">0e48e5ba2cd0a8d8d09bad849b99f6a6</hash>
        <hash alg="SHA-1">227d4d4957ccc3dc5761bd897e3a0ee587e750a7</hash>
        <hash alg="SHA-256">77440e270b0bc9a249903c5a076c36a722c4886ca4f42675f2903a1c53ed61a5</hash>
        <hash alg="SHA-512">bd6f5650902526d3db06aa1cc7bd36723658166acfabb823aca27d0b2c3814e83ae24a8217ce915c3e194c2c696a102580b4c21ef5dba61f7610bcb8d580f566</hash>
        <hash alg="SHA-384">a5cb9ba6b5bf550de90def11ec4bb014410a14949f8598856e1693e213ec0e7d2b3c6cb41b34ba8cfe209a29801de529</hash>
        <hash alg="SHA3-384">00492c18861d7d4fa5517ccf2bcc5c170b575ff9fe88fdc834827d9fc8747846d6345f5270c64dc130228f53ac96f1b6</hash>
        <hash alg="SHA3-256">ec8420b1f4e27c3eef932a764c4cedc8b3547e114285227ceb0612e93648ac29</hash>
        <hash alg="SHA3-512">344bc9be8f3417d4bc3e9e073bff4657aace3cac73e5ace038a11f1435d04d3182f344b8237cd6b311ab0748042a4c4f84259713ec2dcbe472c75cde2e787320</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/com.google.errorprone/error_prone_annotations@2.36.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://errorprone.info/error_prone_annotations</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/google/error-prone/error_prone_annotations</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/com.google.j2objc/j2objc-annotations@3.0.0?type=jar">
      <group>com.google.j2objc</group>
      <name>j2objc-annotations</name>
      <version>3.0.0</version>
      <description>A set of annotations that provide additional information to the J2ObjC
    translator to modify the result of translation.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">f59529b29202a5baf37f491ea5ec8627</hash>
        <hash alg="SHA-1">7399e65dd7e9ff3404f4535b2f017093bdb134c7</hash>
        <hash alg="SHA-256">88241573467ddca44ffd4d74aa04c2bbfd11bf7c17e0c342c94c9de7a70a7c64</hash>
        <hash alg="SHA-512">1406b1aa53b19f8269129d96ce8b64bf36f215eacf7d8f1e0adadee31614e53bb3f7acf4ff97418c5bfc75677a6f3cd637c3d9889d1e85117b6fa12467c91e9f</hash>
        <hash alg="SHA-384">24373643a4e2f8e1cf919d495e1e79b24dd9dbbbeecb06477be8764313f0b3b465fde74ea2cf5542fc8cba090132052f</hash>
        <hash alg="SHA3-384">afa264c8d8d946e43438ae728f0ae7a2c12797b56f9ad885d5b3e9a7396eb8481ca6840c2a990a7c5da45968794b36d8</hash>
        <hash alg="SHA3-256">4df89618b479d5fbede9363c6f914218a44007f48f29c6b6d58243558ced6152</hash>
        <hash alg="SHA3-512">b25b2ad8dddeed8757ffe22a96cfa7511617d86baa0ed4a25b1850162b54e1132d40dbc2dfca0a6ff0a350b16628a0d2b523418eeb8f986e0f505833da4f7181</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/com.google.j2objc/j2objc-annotations@3.0.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/google/j2objc/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>http://github.com/google/j2objc</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.hive/hive-cli@2.3.10?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.hive</group>
      <name>hive-cli</name>
      <version>2.3.10</version>
      <description>The Apache Software Foundation provides support for the Apache community of open-source software projects.
    The Apache projects are characterized by a collaborative, consensus based development process, an open and
    pragmatic software license, and a desire to create high quality software that leads the way in its field.
    We consider ourselves not simply a group of projects sharing a server, but rather a community of developers
    and users.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">71080fe05d4563d7d7c88ecf4f5de718</hash>
        <hash alg="SHA-1">5274373b1c233a0efb0958c66f4b10fca6b02d6c</hash>
        <hash alg="SHA-256">a60c94060a08100dfb2cfefbb273373b16ab55540548a74e3f01075a97f5b043</hash>
        <hash alg="SHA-512">98511307401cdac2511e84184a922b7a568759da134674d7c9afa2b57dff47f37cffa90fa40981da2c68dc286710b333915005ee4cac5d2cfd369a41c3557627</hash>
        <hash alg="SHA-384">a38f4c25c77e614490f8b307fa22b4d53fb30af2a6983d9ed959dec0f77e840ca56bedf30c2d964a4a21666b0d7c1112</hash>
        <hash alg="SHA3-384">45772258f848213e4d71951b00566f080dc4b7d51e8b24eccf3ca15d48ce712b8c9bf73a8d62e2f7be57990d8afa259d</hash>
        <hash alg="SHA3-256">ec3bf9999b5efaed405747765e60c9ee64686d066cf00b1aa4ef74414500360a</hash>
        <hash alg="SHA3-512">7e177999c2c3a7127de9c01a63e7686c0c6e45a8fd68ad6916d4cc2048d6c17545856a7c4a597c9f6f925f59d24d610cd89114fa98e1225e9f5ab225024d3468</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.hive/hive-cli@2.3.10?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://hive.apache.org/hive-cli</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="mailing-list">
          <url>http://mail-archives.apache.org/mod_mbox/www-announce/</url>
        </reference>
        <reference type="vcs">
          <url>http://svn.apache.org/viewvc/maven/pom/tags/apache-14/hive/hive-cli</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/jline/jline@2.14.6?type=jar">
      <group>jline</group>
      <name>jline</name>
      <version>2.14.6</version>
      <description>Sonatype helps open source projects to set up Maven repositories on https://oss.sonatype.org/</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">480423551649bc6980b43f09e4717272</hash>
        <hash alg="SHA-1">c3aeac59c022bdc497c8c48ed86fa50450e4896a</hash>
        <hash alg="SHA-256">97d1acaac82409be42e622d7a54d3ae9d08517e8aefdea3d2ba9791150c2f02d</hash>
        <hash alg="SHA-512">27f6e2523e539383cede51d8eae7e97d49038c5a66cb4a94a9ce85165f16e7382b937a238cdb0c92e1136af56c5f57bcc6c04435a370c5d49f7e4bd32f0d9194</hash>
        <hash alg="SHA-384">3ccd9d87500b42c743c91654b0f12d2e2c06a953eaf3d6acb07f2b9c2c861ffb8aaffdc5ed0aabefdc400f0d33944e00</hash>
        <hash alg="SHA3-384">68cff80ade4fbb8180d7e6c28088150a5be3d2fa1178fb25f14ec9a2c74451378c44b6326b5ec78627d6b22ef14af15f</hash>
        <hash alg="SHA3-256">cd69c13b1942eca5906ee8d780b72ac3a0b2f6e460c9d8b33f5504f233de9264</hash>
        <hash alg="SHA3-512">b3fcbc1ab0d65f5e6f3655c0f45e6b0fadbaec62160aa7f8199b9795c5938b14bf43bfe87093129ec63699b75102576a369ab2a7574a103efc6807c98d57f95b</hash>
      </hashes>
      <licenses>
        <license>
          <id>BSD-4-Clause</id>
        </license>
      </licenses>
      <purl>pkg:maven/jline/jline@2.14.6?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://nexus.sonatype.org/oss-repository-hosting.html/jline</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/jline/jline2/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://groups.google.com/group/jline-users</url>
        </reference>
        <reference type="vcs">
          <url>http://github.com/jline/jline2</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.hive/hive-jdbc@2.3.10?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.hive</group>
      <name>hive-jdbc</name>
      <version>2.3.10</version>
      <description>The Apache Software Foundation provides support for the Apache community of open-source software projects.
    The Apache projects are characterized by a collaborative, consensus based development process, an open and
    pragmatic software license, and a desire to create high quality software that leads the way in its field.
    We consider ourselves not simply a group of projects sharing a server, but rather a community of developers
    and users.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">d1b4fa4e3239a15b05a3da2dbd428c7f</hash>
        <hash alg="SHA-1">b3addbd48e9ca6b5394a8d7125dc4cb36c639f6b</hash>
        <hash alg="SHA-256">d68b59a0c78faada79657af09cc8256b748963828a35d75881c25642a1ba0414</hash>
        <hash alg="SHA-512">8b24b05b15d6b00f722c7394a9493b5175d6d60604480616b21a2d5ae81c1b5f7ba7995536f80e5c9ddfd44a9c378ba78de2315b8692936356570de1a2de5c4d</hash>
        <hash alg="SHA-384">37441da4aa8b4c4cad4a637979073924c2692d54ff92379fc3267cefe8853fff4e9d0ea630980b5e3ffd1addbc6eb3f8</hash>
        <hash alg="SHA3-384">40fe33cefb052dfa26f25800c2f8b1d1505cdc76e1e1803c4d06d2fd7aea25df60e3146ef2da7ea044b9132b28097199</hash>
        <hash alg="SHA3-256">ec9064b418074087ae78ab4d27d2d018efe21a8d24655cff7370fb28d36c7f62</hash>
        <hash alg="SHA3-512">dfc58055b9ae931511f22010cb00bb6faecee8f6b8cf10b48d1c3aeeb8693f37e30ecfa1e7e234c6ec799c7c831bf11b3d88e073bc20dc11d7346e184bb1a95d</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.hive/hive-jdbc@2.3.10?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://hive.apache.org/hive-jdbc</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="mailing-list">
          <url>http://mail-archives.apache.org/mod_mbox/www-announce/</url>
        </reference>
        <reference type="vcs">
          <url>http://svn.apache.org/viewvc/maven/pom/tags/apache-14/hive/hive-jdbc</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.hive/hive-beeline@2.3.10?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.hive</group>
      <name>hive-beeline</name>
      <version>2.3.10</version>
      <description>The Apache Software Foundation provides support for the Apache community of open-source software projects.
    The Apache projects are characterized by a collaborative, consensus based development process, an open and
    pragmatic software license, and a desire to create high quality software that leads the way in its field.
    We consider ourselves not simply a group of projects sharing a server, but rather a community of developers
    and users.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">45adf92e378e592f0afae223cbdea9e0</hash>
        <hash alg="SHA-1">08dbfe1f78c01f33c74082e2ef6910b44e6988ec</hash>
        <hash alg="SHA-256">569ec193ae8619c06479705ab0ad3b11c81c095c825c657ae389054cc027de16</hash>
        <hash alg="SHA-512">9506110d88e74afc13fed9816d049cebc5d4331af6790217e7536019ed97d54ed8b09797a4412b737aa224fe583c484efd476e2f0031c8b0dd54edfbb472adde</hash>
        <hash alg="SHA-384">e6861b4f8dad60980a567ba4e29be110a9452f753e4952b1ee8d0c2c4d48f51f4fe00eadfea57ce6943f04eb933bc161</hash>
        <hash alg="SHA3-384">d5757ecc392f90ef933740e578bb2a9b69d6fff8b0d121313445d082551803e9556e361adb648a89719b3b38804b69f1</hash>
        <hash alg="SHA3-256">4d530f4bae3b8e0f739c53b167bbc9befeef3b4da04ffafeb39ddc2a45c1222b</hash>
        <hash alg="SHA3-512">91936a041d8dd5bafe2b8578177c389e180015f2b1454a46cd2cb13d286a98fe3ec337bcc4fcac46bb869a39354da7e86779e1c6cf981b007a4ad063d15cf22d</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.hive/hive-beeline@2.3.10?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://hive.apache.org/hive-beeline</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="mailing-list">
          <url>http://mail-archives.apache.org/mod_mbox/www-announce/</url>
        </reference>
        <reference type="vcs">
          <url>http://svn.apache.org/viewvc/maven/pom/tags/apache-14/hive/hive-beeline</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/net.sf.supercsv/super-csv@2.2.0?type=jar">
      <publisher>Super CSV</publisher>
      <group>net.sf.supercsv</group>
      <name>super-csv</name>
      <version>2.2.0</version>
      <description>Super CSV is a fast, programmer-friendly, free CSV package for Java</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">f1becdf4405593130cdf5d4a82adadcb</hash>
        <hash alg="SHA-1">610e18fff0e7bd6cd072310f0d73fc982ffb6834</hash>
        <hash alg="SHA-256">bf743e0c1f1c42d19df236d82fa0b34128cd5e82cde6e491e316ec274f94bfbe</hash>
        <hash alg="SHA-512">963b3b18832d35abdefbf1e10154d86c8deb0d98ad9377aa3004adc879ab4ed0c47b5283dccc971d0607e7f6e0e79054470ba3f13917443f4c660b8599a2b86f</hash>
        <hash alg="SHA-384">0e39e035811f85750522bffe28c49cffbca68480109ef0e5e7e81df9d55ff8167615fa6ef6a09f2b2b54677f43591744</hash>
        <hash alg="SHA3-384">da3f39b8be22883df363de54de762e103bb99c35c7b546fc10a89162e8ea6f93b7abbdcc0b73e5bb8bf83aaece13fca1</hash>
        <hash alg="SHA3-256">79a16aac8497d17639c25b7dfac4751b9e02b2c7876ae39356ddea283e06be47</hash>
        <hash alg="SHA3-512">56d582290415a314f0a042b82233c68c0d5ed3e53930b20b247417bb2bf53dd18ec89dc0b9288ae1e0ec49e7a77d98ccc28c328f1d91a57f2021f240e974fd08</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/net.sf.supercsv/super-csv@2.2.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://supercsv.sourceforge.net/super-csv</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://sourceforge.net/p/supercsv/bugs/</url>
        </reference>
        <reference type="vcs">
          <url>https://sourceforge.net/p/supercsv/code/tags/v2.2.0/super-csv</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.hive/hive-service-rpc@4.0.0?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.hive</group>
      <name>hive-service-rpc</name>
      <version>4.0.0</version>
      <description>The Apache Software Foundation provides support for the Apache community of open-source software projects.
    The Apache projects are characterized by a collaborative, consensus based development process, an open and
    pragmatic software license, and a desire to create high quality software that leads the way in its field.
    We consider ourselves not simply a group of projects sharing a server, but rather a community of developers
    and users.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">2f50edac101f963fe3c7386897907048</hash>
        <hash alg="SHA-1">f56e0b6afb9e416338100d2c81e91fd81f031942</hash>
        <hash alg="SHA-256">78b544d19579cec2ee4d07f9599cece6af9dc7f829d44f6070db5a7425eb6372</hash>
        <hash alg="SHA-512">97305235166cb04f8043bdf039ddccc7323b123b26d7d645682c6e29ba65709dd8e722ffb3b6ab146738a07dc495141f55654c2a9bd056d4ecdf23936bddb79d</hash>
        <hash alg="SHA-384">604239e407057488c89f047f9d029245d044477c6b249c667eaf4876ef9838189f3813b7b975f1b69616fbc5c8090a9a</hash>
        <hash alg="SHA3-384">4e522bccceb18708911b3cad5cdf25e62c097618a407d4176b545811a1947451606bb3e67b152452f8b3713ff722d8c8</hash>
        <hash alg="SHA3-256">d0a7ef5fa506465aae86708c94bd153169ee38b82869ea23c30891f8d83b10c9</hash>
        <hash alg="SHA3-512">ae4c256b8e58b44e40ad0cd91fe98d1a33974012f3b58ee95ed71b3832d84ef1d1b36049ab8387a10e87cd44a118556753ed809e72cd82d4825042ba3a1d66cd</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.hive/hive-service-rpc@4.0.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://hive.apache.org/hive-service-rpc</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="mailing-list">
          <url>https://mail-archives.apache.org/mod_mbox/www-announce/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/apache/maven-apache-parent/tree/apache-23/hive/hive-service-rpc</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.eclipse.jetty/jetty-server@11.0.26?type=jar">
      <publisher>Webtide</publisher>
      <group>org.eclipse.jetty</group>
      <name>jetty-server</name>
      <version>11.0.26</version>
      <description>The core jetty server artifact.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">46ce87c274cb41e99ed7f4ad94f35f2b</hash>
        <hash alg="SHA-1">8b67e8fa033ff80941ab71bbf4d0e979fcc023ea</hash>
        <hash alg="SHA-256">3cc3b203b96c7115151ea94cad8af43c0914bfb6fe20cf2ca8378ec6822fa471</hash>
        <hash alg="SHA-512">75bd7d315d0f59adb58f976138baa05f485d2b356f4e760af62f170d5d0df5e5007e88fbb3b6f3c4ebc05f330f7258d69ee90a621cf0dcd422126559d037ce0a</hash>
        <hash alg="SHA-384">353cf0dd3e8472fb478e181fd84c7e5cd7ade09ee30bc2ff83ec97b8d98dabb50f1a21ad77b6f29b9931846f4ca039a7</hash>
        <hash alg="SHA3-384">6afdebf687e4e05d09f8df84722cb082c9dc5fb32b9a8ff68bb3b8ef2f39c648a0325107886b3e3299cd6d0f968d6429</hash>
        <hash alg="SHA3-256">02844122cd423e7f883a14aeba51264a13d538bed7bda9cac6fccca285f4ee6e</hash>
        <hash alg="SHA3-512">41cae2cd5be45e40c6f1b8be1520e3aeb40df61f23908be9a0bf017e65281a39edbe876779c54f7f0cf411e4423e11a82f5e1c6fc16fdaec7344e0b7812faddc</hash>
      </hashes>
      <licenses>
        <license>
          <id>EPL-2.0</id>
        </license>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.eclipse.jetty/jetty-server@11.0.26?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://jetty.org/jetty-server</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repo.maven.apache.org/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/jetty/jetty.project/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://www.eclipse.org/lists/jetty-dev/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/jetty/jetty.project/jetty-server</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.eclipse.jetty/jetty-io@11.0.26?type=jar">
      <publisher>Webtide</publisher>
      <group>org.eclipse.jetty</group>
      <name>jetty-io</name>
      <version>11.0.26</version>
      <description>The Eclipse Jetty Project</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">87a746ee1df40a19829d6117646cb39d</hash>
        <hash alg="SHA-1">85df42e2627a070ac8bff865e25d8b37f7648d53</hash>
        <hash alg="SHA-256">ce0ef76071e361d97f102e5cb48928b3cc66ac899d12be3ef0af8d06b4f768a1</hash>
        <hash alg="SHA-512">a1de2937de36292a09396983f807368bf466064c1984c32602009052a3e1dc2bd47b435e9670bdd12724f6866903113aba6c0de4d199b016ef1f1f13d1b18b55</hash>
        <hash alg="SHA-384">c2e2c961c64f79e20592b358f04fbb7a9aa273448ad516ca6cdcdda102503cc0a3534862ecc8e0660bf1721cb26f6c3d</hash>
        <hash alg="SHA3-384">9c85463d92d265abf35ba28d2486bb0fcfec0d91badd94472cc3a1d048b6869d9c9f3802e374d79a7ab5837ca849dde2</hash>
        <hash alg="SHA3-256">df85b6ee29e200c30b3877b02c43913565d19811f8fec06311890decd49fff18</hash>
        <hash alg="SHA3-512">c572d74d82f8b6b8a1f951e35f4dad7d33281bd7fb63ba6b53a1330de59c0f07b73107fd6eb1fd40876a38334de6c9bf0dc91b295f227af170e3d3717f46db57</hash>
      </hashes>
      <licenses>
        <license>
          <id>EPL-2.0</id>
        </license>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.eclipse.jetty/jetty-io@11.0.26?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://jetty.org/jetty-io</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repo.maven.apache.org/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/jetty/jetty.project/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://www.eclipse.org/lists/jetty-dev/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/jetty/jetty.project/jetty-io</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.eclipse.jetty.toolchain/jetty-jakarta-servlet-api@5.0.2?type=jar">
      <publisher>Mort Bay Consulting</publisher>
      <group>org.eclipse.jetty.toolchain</group>
      <name>jetty-jakarta-servlet-api</name>
      <version>5.0.2</version>
      <description>The Eclipse Jetty Toolchain Parent</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">7de826f76a829dc9dfb41e437ff4bd01</hash>
        <hash alg="SHA-1">027fce6d666a203526236d33d00e202a4136230f</hash>
        <hash alg="SHA-256">efb20997729f32bfa6c8a8319037c353f7ad460d5d49f336bf232998ea2358db</hash>
        <hash alg="SHA-512">44db94070731986ba232aadadad891d44e7013e2de5c9eb5d8195b6cc8c211b8cc10b36f5d38d8e43a1d34e38e7dfb309223aac34ee407546c9b2d30e450de19</hash>
        <hash alg="SHA-384">b4e0af890dd49c349a6f744ed1367ec782f8d11a8bfc8c94fcaa3f807d0512aff5541ed7f58a88e830745b737bc9ce86</hash>
        <hash alg="SHA3-384">3933bc15944ea29ba8e2decf49c0bc427c3f9e26fd57a5c036ad03b59897e4bd4ff463e35e8714ef64dc1c7ab4a6ea90</hash>
        <hash alg="SHA3-256">faa2caa2b27390704cf992cc33d8fc047b65aa3e252c85378e91edc7cd017e20</hash>
        <hash alg="SHA3-512">8c678be5cc90f9ab9cf9ba4ab4fe29e9c91df1e44c74db4641e5778aa15f18beccb28683ca31e160242e40db4a7777acb3f266aa3a4f1c50f7385b41f1b88416</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
        <license>
          <id>EPL-1.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.eclipse.jetty.toolchain/jetty-jakarta-servlet-api@5.0.2?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://eclipse.org/jetty/jetty-jakarta-servlet-api</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/eclipse/jetty.toolchain</url>
        </reference>
        <reference type="mailing-list">
          <url>http://dev.eclipse.org/mhonarc/lists/jetty-dev/maillist.html</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/eclipse/jetty.toolchain/tree/master/jetty-jakarta-servlet-api</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar">
      <publisher>QOS.ch</publisher>
      <group>org.slf4j</group>
      <name>slf4j-api</name>
      <version>2.0.17</version>
      <description>The slf4j API</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">b6480d114a23683498ac3f746f959d2f</hash>
        <hash alg="SHA-1">d9e58ac9c7779ba3bf8142aff6c830617a7fe60f</hash>
        <hash alg="SHA-256">7b751d952061954d5abfed7181c1f645d336091b679891591d63329c622eb832</hash>
        <hash alg="SHA-512">9a3e79db6666a6096a3021bb2e1d918f30f589d8de51d6b600f8ebd92515a510ae2d8f87919cc2dfa8365d64f10194cac8dfa0fb950160eef0e9da06f6caaeb9</hash>
        <hash alg="SHA-384">6ea24f814a9b6ece428cfd0535e2f3b8927005745ef61006b50fdb5a90126ee5ea05650155382b3b755c5bce38ef3944</hash>
        <hash alg="SHA3-384">9b1015052f0ec43f9be09764e131834157599611cb52f6fe591c4ac6a8ab4817518f2a4b8871e5e738c8678e93af5557</hash>
        <hash alg="SHA3-256">00559b4f4066b4917ba4fe2a6f23111eaeada321112d030910d218ced9084b5e</hash>
        <hash alg="SHA3-512">9579c2f7e7516e177c2d493ccc9eb8150978cf19f6f09b28d116f6935239fd56dc6af2b62b3336f79b0b462445550cd1fb5377a07001a6f44aaab6a32fa2fa47</hash>
      </hashes>
      <licenses>
        <license>
          <id>MIT</id>
          <url>https://opensource.org/license/mit/</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://www.slf4j.org</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/qos-ch/slf4j/slf4j-parent/slf4j-api</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.eclipse.jetty/jetty-servlet@11.0.26?type=jar">
      <publisher>Webtide</publisher>
      <group>org.eclipse.jetty</group>
      <name>jetty-servlet</name>
      <version>11.0.26</version>
      <description>Jetty Servlet Container</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">551976020bdae1008a5a2e3238c7c43e</hash>
        <hash alg="SHA-1">870444992e28c2c4b9b8c530f540cdf5db1f1c26</hash>
        <hash alg="SHA-256">c09469f1045f9e207732692b3bc56e8fe4d0599de52d3bd593927c4a9060e679</hash>
        <hash alg="SHA-512">65c491e2879b255d504eb0c31c7c3748532f87332a21ce4cd8052bb669b8fd68978c50350e3b004b41c3ab8fb68ad9372bb6d118b9784ad3019a3f23ce50364a</hash>
        <hash alg="SHA-384">2c86eb4da672adcd40f403c8a38f320d59f13759cdf9dcafadda00c2a3b8971dd4e9f79954d86485aa88dfe3e60b0288</hash>
        <hash alg="SHA3-384">0313f25286b025ee483d29a90c470dc68d99262acd1bc3fd6c924ef40571fe9a4ea02331d57822fbba8ac01bd117d82a</hash>
        <hash alg="SHA3-256">7d6ad0db47e5f3fed6f60079b35cec28f00201d7421d15eafb22097c1c7fbdb7</hash>
        <hash alg="SHA3-512">53db27b7a179a010e92708ea2bfbced78ef4293506c0a042a5b69483ed2fdc59bf91cb6a009219b7090e59fc52e8c9f86df6c042bf807915f4db566eee32de6a</hash>
      </hashes>
      <licenses>
        <license>
          <id>EPL-2.0</id>
        </license>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.eclipse.jetty/jetty-servlet@11.0.26?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://jetty.org/jetty-servlet</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repo.maven.apache.org/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/jetty/jetty.project/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://www.eclipse.org/lists/jetty-dev/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/jetty/jetty.project/jetty-servlet</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/javax.servlet/javax.servlet-api@4.0.1?type=jar">
      <publisher>GlassFish Community</publisher>
      <group>javax.servlet</group>
      <name>javax.servlet-api</name>
      <version>4.0.1</version>
      <description>Java.net - The Source for Java Technology Collaboration</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">b80414033bf3397de334b95e892a2f44</hash>
        <hash alg="SHA-1">a27082684a2ff0bf397666c3943496c44541d1ca</hash>
        <hash alg="SHA-256">83a03dd877d3674576f0da7b90755c8524af099ccf0607fc61aa971535ad7c60</hash>
        <hash alg="SHA-512">763dec9801f647b1a45e492eb2a67f6a60fc608bef4738eb7b1a92d93f1f6db02b32f4c6553d4557c320dfc25c0ea0b9854c59e793262b6ca453c71caf05ef38</hash>
        <hash alg="SHA-384">9f4522458bdb1c7cbc0e88271d1e4326193c8e4d422ef8b75c3dcadf0bf86a91389890ab2d25a8cc6cf276f625475cd3</hash>
        <hash alg="SHA3-384">be8a209d1912492e86e611fc42e59512a89c464aa78cea3c5badd3290a6564d8bde55933a7c5d8113d9acc848a382751</hash>
        <hash alg="SHA3-256">f94dd8bf0908ca77e5213d166035a427e658ff4a59d35daa7e281c5fb2fc390a</hash>
        <hash alg="SHA3-512">3abbd3cad570557be24b69f700c217c7c8e1736d4db74f3ac28dd96b80822ac1c7631b3a9a15b9738754a3d68e4e7f13b732820eb8b8e8e329690ec2a23c621c</hash>
      </hashes>
      <licenses>
        <expression>(CDDL-1.0 OR GPL-2.0-with-classpath-exception)</expression>
      </licenses>
      <purl>pkg:maven/javax.servlet/javax.servlet-api@4.0.1?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://javaee.github.io/servlet-spec/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://maven.java.net/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/javaee/servlet-spec/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>servlet-spec@javaee.groups.io</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/javaee/servlet-spec</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.rocksdb/rocksdbjni@9.8.4?type=jar">
      <publisher>Facebook</publisher>
      <group>org.rocksdb</group>
      <name>rocksdbjni</name>
      <version>9.8.4</version>
      <description>RocksDB fat jar that contains .so files for linux32 and linux64 (glibc and musl-libc), jnilib files
        for Mac OSX, and a .dll for Windows x64.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">cf83b3439db59f840b00454dd89f5796</hash>
        <hash alg="SHA-1">1cb5c057d3f76feb98e75e22df57dd4fd1d05976</hash>
        <hash alg="SHA-256">b60144a306bf7dd3de2b6fea947681fe940ba1510b9bc36ece836484af7bb7fa</hash>
        <hash alg="SHA-512">8e01f935a1f9f2e6b425ed3b49808df15e329df27f686e9b9229195675bd139ed848a7ebd9578dab08af663f51bfefaee4fa7cff06440bbdd46baecd6aaa8a47</hash>
        <hash alg="SHA-384">b90ef2dd638ce430a9394b9299a8656906f20826ad68ae94778a69c25e783e6050cd0f444c318731f9edc4da374387ba</hash>
        <hash alg="SHA3-384">d671cffa47053a78ee52dc99bb74f5b08fb92146156d1d3fc0c2ae73929ef113a6c9ddb68305df62f6a8d6be5e8c2490</hash>
        <hash alg="SHA3-256">8a3cf71b947cee33ba8582f11e399cfa7e1f98113b529edc893e433930978a0d</hash>
        <hash alg="SHA3-512">24be057dcf4d8d5278c241e7539ee35af0a7627b9f31fc168b1eb434c3789574c8a4cd11db69efdd46a646980ff533fb22dcb8f8c6d76af7d1303d32ee8cd0a2</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
        <license>
          <name>GNU General Public License, version 2</name>
          <url>http://www.gnu.org/licenses/gpl-2.0.html</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.rocksdb/rocksdbjni@9.8.4?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://rocksdb.org</url>
        </reference>
        <reference type="mailing-list">
          <url>https://groups.google.com/forum/#!forum/rocksdb</url>
        </reference>
        <reference type="vcs">
          <url>scm:git:https://github.com/facebook/rocksdb.git</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.spark/spark-catalyst_2.13@4.1.2?type=jar">
      <publisher>Apache Software Foundation</publisher>
      <group>org.apache.spark</group>
      <name>spark-catalyst_2.13</name>
      <version>4.1.2</version>
      <description>The Apache Software Foundation provides support for the Apache community of open-source software projects.
    The Apache projects are characterized by a collaborative, consensus based development process, an open and
    pragmatic software license, and a desire to create high quality software that leads the way in its field.
    We consider ourselves not simply a group of projects sharing a server, but rather a community of developers
    and users.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">6bc1d0013dbcd83d81547b40a59295a0</hash>
        <hash alg="SHA-1">135da93ed617aa99c114c6820c330cc0e8a3783e</hash>
        <hash alg="SHA-256">197585dfcb678588bfa08f46e2e18e06038fa6edc57c69827dc4591e31dfeada</hash>
        <hash alg="SHA-512">fb58f77e8ec0329e3b8142736d4516b1e79199802769561dcce96b7d8d0e4149d368bca3820f3f9c9323d1fe018da720f2518eacccc24c1de7855c0633208451</hash>
        <hash alg="SHA-384">9e480999d6c49c1c87b4ea50c1b59078c6f2829750f84ca4c96b996a713c7b5f02874d58d55150d488e5dbc3fa9f6522</hash>
        <hash alg="SHA3-384">5158e1e6fb71a63f0ac3beace340e7730d331783d860c3cf3887a00168e7b6d82fd583d07f8c8c765ce53f32490275db</hash>
        <hash alg="SHA3-256">b2884ea78b765e1ca893c825f9918a09b68849a6a84414a0b4728e2eb4faa636</hash>
        <hash alg="SHA3-512">dbf9ee4d63311a03c07f81312804165d60d58aba3fd52bcdcf31442b666270fc68a4a1672bb93dd55e997315d2fa6709b7f6c79f278107f53fc7ef7bfd005834</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.spark/spark-catalyst_2.13@4.1.2?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://spark.apache.org/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://issues.apache.org/jira/browse/SPARK</url>
        </reference>
        <reference type="mailing-list">
          <url>dev-subscribe@spark.apache.org</url>
        </reference>
        <reference type="vcs">
          <url>scm:git:git@github.com:apache/spark.git/sql/spark-catalyst_2.13</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.orc/orc-format@1.1.1?classifier=shaded-protobuf&amp;type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.orc</group>
      <name>orc-format</name>
      <version>1.1.1</version>
      <description>ORC is a self-describing type-aware columnar file format designed
        for Hadoop workloads. It is optimized for large streaming reads,
        but with integrated support for finding required rows
        quickly. Storing data in a columnar format lets the reader read,
        decompress, and process only the values that are required for the
        current query.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">20f3c86b75fc87817d77e55b7d2ab758</hash>
        <hash alg="SHA-1">c88ccce44a5ebcb6d2b7948efdcebb903a9131c8</hash>
        <hash alg="SHA-256">8d7fee1fd60fe6e4589c8b46d58d118e45613aa416a14ac0835e12150f3ee2a9</hash>
        <hash alg="SHA-512">40fe6fdda8add9ea73ce0f58b2356d8a3420d4e9aeb056717207f500fa95f13de307261259babfdd2c511cbda9caea6b6b1b30a9c03af207ace4b0c27468d971</hash>
        <hash alg="SHA-384">be317341c812be0405d90460c06eb303b296b45b55e65923a4022565bad65deb2740d70423cefe5305cad485bd7b6f7a</hash>
        <hash alg="SHA3-384">472737d826e23f53ea20049d3d5618e13e49861226ad3199e49b4e76fbdb50d361fc5d7b6289ce2d57b5b90b053cee20</hash>
        <hash alg="SHA3-256">d37ae1d70402aad9660f372c09ce7f6a7a2cd519eb81019ac687373e6e5ac311</hash>
        <hash alg="SHA3-512">4158fd92b7c176f0e283595f95deb88f2e826c2d126e017621b1a8b25fce035b724cc1e8d984ad671ffbf12788adbc25daa6a086a694682b1a6d5f74df379148</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.orc/orc-format@1.1.1?classifier=shaded-protobuf&amp;type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://orc.apache.org</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="mailing-list">
          <url>https://mail-archives.apache.org/mod_mbox/orc-user/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/apache/maven-apache-parent/tree/apache-29/orc-format</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.orc/orc-core@2.2.2?classifier=shaded-protobuf&amp;type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.orc</group>
      <name>orc-core</name>
      <version>2.2.2</version>
      <description>The core reader and writer for ORC files. Uses the vectorized column batch
    for the in memory representation.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">5b77de04ee289594ff407cc3b06681df</hash>
        <hash alg="SHA-1">2f77e9026d32d41d76395718bec1a4de239b280d</hash>
        <hash alg="SHA-256">f490d0d587d0dfd68b40ae22016518fa24fa8c8cabf43c19a94b3e933496d017</hash>
        <hash alg="SHA-512">867b388df744ffe3fc4e4b018570cc66949f728d6ff187a6fc324d8a73d6cd3f4989abb00cea6154774941ffa5696e2638ec9c28033cf7026f3e8f1db2263fbf</hash>
        <hash alg="SHA-384">40777ecfae6d24334df9582b9764b9f4e6f4a83d842d6a16e9c973ee5dd38fd1dcc6436184d6732f3181118c0503fb14</hash>
        <hash alg="SHA3-384">234216edbd05616e237ad87a4b3b3547061cd341bbf3544931b9ec86223ba93d8606f50b9e15a9925ee86e5f9751267e</hash>
        <hash alg="SHA3-256">67e43a65ae22e529ea3c23cebb0f4a59737d46d1fe96afa4f743176be8d89b54</hash>
        <hash alg="SHA3-512">09cc2fa6b5d9bc75cca4a2f47c9da63112b48d20c6b0479c2771c6691e622332fa3af90976c11e0bc724b8d84c86cbfe2fb5d72595aab99dbbda2fd2ba3edafb</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.orc/orc-core@2.2.2?classifier=shaded-protobuf&amp;type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://orc.apache.org/orc-core</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="mailing-list">
          <url>https://mail-archives.apache.org/mod_mbox/orc-user/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/apache/maven-apache-parent/tree/apache-27/orc/orc-core</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.orc/orc-shims@2.2.2?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.orc</group>
      <name>orc-shims</name>
      <version>2.2.2</version>
      <description>A shim layer for supporting various versions of Hadoop dynamically.

    This module uses a higher version of Hadoop so that we can create shims
    that let us use new features of Hadoop without having a hard dependency
    on the latest version.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">4cd8d82c5f64bdea5889980031119e3d</hash>
        <hash alg="SHA-1">53aac880786737768335512d6028ac3154510db0</hash>
        <hash alg="SHA-256">46c730ca9aef90bd9df03bdfc50564a51a4cf5da9f2888e97b9b0faa1e88c260</hash>
        <hash alg="SHA-512">3934dd7fdb9dc7798f782651b6810119257b3b63afd73ac00a3a2380dd5c6dce2c2b8a3b227c34033921183a4e97b80f18ae393327d81f5c04b8ab5e0ac8b942</hash>
        <hash alg="SHA-384">6986a7bc045693edf5ff405688072110400fd05c7f0903e354472b63608d58deb0ef509db2fd746e952e3a11df5d492f</hash>
        <hash alg="SHA3-384">6a55b3ea2ef34672f699e959aa1c86d458267c1dfef1d8bb66743b1539535835e5bcec61ba78179b5e0577f9d529d69a</hash>
        <hash alg="SHA3-256">60b444f2d87ca524d0cb1806cc6589a2deb0f6088cb8b30a84ad602242b3b7ce</hash>
        <hash alg="SHA3-512">16fc4b466844acf26a10da56fdd72d30658fbe6b26acc29f4bdce7a063ca8fe8401639c89fb51b7dc9bad4b74db6c4ef8d645369422ac95bd34d9ab2b5803e50</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.orc/orc-shims@2.2.2?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://orc.apache.org/orc-shims</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="mailing-list">
          <url>https://mail-archives.apache.org/mod_mbox/orc-user/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/apache/maven-apache-parent/tree/apache-27/orc/orc-shims</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/io.airlift/aircompressor@2.0.3?type=jar">
      <group>io.airlift</group>
      <name>aircompressor</name>
      <version>2.0.3</version>
      <description>Compression algorithms</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">6bc89228727ab2a3ed7df7cecef85158</hash>
        <hash alg="SHA-1">d7032ede4ff2c124d4913807ebd6868af66f1721</hash>
        <hash alg="SHA-256">b86bb66f610079e0bf790d62e2ff68853eb0dc4748a6d68ae28bce92b68094aa</hash>
        <hash alg="SHA-512">726f9c919b8bc517b247954b93701e10dd68fa2d62bef6a5aad4a6dc9e1137bae97755d4dbd0bf799513e1a7fcaae733ede7ade42b6d9bdca6f93784297539c0</hash>
        <hash alg="SHA-384">398a184408d407798bbce8ecf72c064de31797017e5cf197a785467aae13f2f1b3746aec096cdf6b8c401a3500a02833</hash>
        <hash alg="SHA3-384">570b3fe83097e77cad881f608aecc984f4d6c4937654b6cc0f72070767cb259202fdce69bd84344dcd960d8a271f0c81</hash>
        <hash alg="SHA3-256">2e27dc2de17cfb514cd49d9fea569aa965defa2c1a784c662a7c890a556183c9</hash>
        <hash alg="SHA3-512">f43d2d8da54e3c47125661fda170802426f621a8d5d937a9126db5e6e4ca779a549b206da9c9276febf47ee3bc497d77f64a14bb812088c6cff2ffdb9e156041</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/io.airlift/aircompressor@2.0.3?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://github.com/airlift/aircompressor</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repo.maven.apache.org/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/airlift/aircompressor/tree/release-2.x</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.threeten/threeten-extra@1.8.0?type=jar">
      <publisher>ThreeTen.org</publisher>
      <group>org.threeten</group>
      <name>threeten-extra</name>
      <version>1.8.0</version>
      <description>Additional functionality that enhances JSR-310 dates and times in Java SE 8 and later</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">4af91264b2e3d26f4c41f055f7ce02f8</hash>
        <hash alg="SHA-1">d3b1ac7e361b642132e529f562622aac7dfea752</hash>
        <hash alg="SHA-256">51e4d21edc4e9447f7760c050e0baee75d7d973f387ba605a17abdc4d24fd6d8</hash>
        <hash alg="SHA-512">b60d18135450dbca9660097f6f726676940c1925343e0ce9547e57e68beb321ecd5df73710332113e1ea3aba71fb5ceb0483cc8f41806a3c6ef075d3c690aae6</hash>
        <hash alg="SHA-384">b6e8c6861fe876ac0fc34f97b4966c8816d94ab566cfe8458709b48825cf600fcec4d845de35a3d518d4c28e160b665b</hash>
        <hash alg="SHA3-384">1eaf035067146399ff4698dfe6f418e2f812d203b7b8b9b2bb7afaa34b4d380bbc06d8836456e732111ea2c35820d09a</hash>
        <hash alg="SHA3-256">981ad37d8273108f1bd1de37f7bca594b8ef49ab33dfbbc2e84c647aba733ead</hash>
        <hash alg="SHA3-512">7b528b1f6d625f647f63fc7117c006dce4c08c5f447151c34b1acfa9bd8062c2c31f2e579a38024dad6f86d9f3e7f0cc4a3ea0e9c011926b49413515045a291d</hash>
      </hashes>
      <licenses>
        <license>
          <id>BSD-3-Clause</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.threeten/threeten-extra@1.8.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://www.threeten.org/threeten-extra</url>
        </reference>
        <reference type="distribution">
          <url>https://oss.sonatype.org/content/repositories/threeten-releases</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/ThreeTen/threeten-extra/issues</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/ThreeTen/threeten-extra</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.locationtech.jts/jts-core@1.20.0?type=jar">
      <group>org.locationtech.jts</group>
      <name>jts-core</name>
      <version>1.20.0</version>
      <description>The JTS Topology Suite is an API for 2D linear geometry predicates and functions.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">8de91edea80ac2de00c07226458649fb</hash>
        <hash alg="SHA-1">25b72c9548a328cb1aea8a6b89d710a31ade5403</hash>
        <hash alg="SHA-256">6a783d8f9dba3d3cf7265435f134402f63c05838aa6cbcc4297ad3a5b2842baf</hash>
        <hash alg="SHA-512">3d6e32203f36517447cc027d741d1be301d454d34707d9fcb870d49dd686e7f1f72cff4b36bdd90ed8f2bee7e3afade7b3a1457de9c15777b91f47cdace91a6e</hash>
        <hash alg="SHA-384">5a9f3ca93e90797313a7983a54edd80c44a48ba46647677b934b46e23273b2facbea8b752353dd47d6ee18e2a92779b6</hash>
        <hash alg="SHA3-384">02182b13041cdf61fc75323cc34dc7676b175fb34a05dd002f3da6fd190201655949bfff4c5875cc36d0b8bfbab31e4f</hash>
        <hash alg="SHA3-256">8ac7798576ed86c7873e85319bc4e0c205373928517859f9a53c9e74d057781d</hash>
        <hash alg="SHA3-512">6927a7e2cb64065d3b7d3a01443804e189d560b840ce93afd34e77894b281e0387f5fdb9fa2bde9381781bdd979cfc3e4399d6d8091fd8d6d0c2f89001450223</hash>
      </hashes>
      <licenses>
        <license>
          <id>EPL-2.0</id>
        </license>
        <license>
          <id>BSD-3-Clause</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.locationtech.jts/jts-core@1.20.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://www.locationtech.org/projects/technology.jts/jts-modules/jts-core</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/locationtech/jts/jts-modules/jts-core</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.orc/orc-mapreduce@2.2.2?classifier=shaded-protobuf&amp;type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.orc</group>
      <name>orc-mapreduce</name>
      <version>2.2.2</version>
      <description>An implementation of Hadoop's mapred and mapreduce input and output formats
    for ORC files. They use the core reader and writer, but present the data
    to the user in Writable objects.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">256c1db8ac05e9a04fa32b749060bdc2</hash>
        <hash alg="SHA-1">1e5d4135bece8c4d10156e0c951a9dc6c2ba139e</hash>
        <hash alg="SHA-256">48880400107e0e6ac535c2c8074dbaf9c67cb41f49851c2eea235724d3699144</hash>
        <hash alg="SHA-512">5801270afeb83fafb083b73957e3afbcf7a92af5043af4186c8f9e791011aa13b4d48e8b3e46d0a71d45f0adb762430d78c8da2399527455daa2f29ba9013947</hash>
        <hash alg="SHA-384">1d0850852186dec8eb55a2d13928a7abde3d1c6b637eaa143d88af5032190086ae09122f3ad11efed4d65e45d300d16f</hash>
        <hash alg="SHA3-384">07a05fe6027e6bc690860d208672ede26286a3f2579278a6fa8e8ed75480ade464dc6820475d9a9b3e63465f945c524a</hash>
        <hash alg="SHA3-256">b6def9129322847959ee07028440861fa7283ba0476be098a3f118a325fbb975</hash>
        <hash alg="SHA3-512">1ce9fc3828006d500487e8eaf4a98529837bed7bc5bbcae92b989544a482e8e1b5c1aed06879fe62d155a494405e7654cda3730505df5a4437fa63ac878aac3e</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.orc/orc-mapreduce@2.2.2?classifier=shaded-protobuf&amp;type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://orc.apache.org/orc-mapreduce</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="mailing-list">
          <url>https://mail-archives.apache.org/mod_mbox/orc-user/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/apache/maven-apache-parent/tree/apache-27/orc/orc-mapreduce</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.hive/hive-storage-api@2.8.1?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.hive</group>
      <name>hive-storage-api</name>
      <version>2.8.1</version>
      <description>The Apache Software Foundation provides support for the Apache community of open-source software projects.
    The Apache projects are characterized by a collaborative, consensus based development process, an open and
    pragmatic software license, and a desire to create high quality software that leads the way in its field.
    We consider ourselves not simply a group of projects sharing a server, but rather a community of developers
    and users.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">bea1adb65022d4616d23be770207600d</hash>
        <hash alg="SHA-1">4b151bcdfe290542f27a442ed09be99f815f88e8</hash>
        <hash alg="SHA-256">2bb77d246a9724a371301049239c6e53039efe4136b0ed34ee5a9c7b3cd861d8</hash>
        <hash alg="SHA-512">e76d1f1dcae0fcf26c56bf2006776a39b46572e9a67fcfab26774506a30de0a92447dcc545894c1796bbe092df53a51216c56721bfbc05c8a9b5fe9636ff07e7</hash>
        <hash alg="SHA-384">93eb2ba57fc637800ba539994682cf764436617f1b1584aa71f288797dad73e6b5dd95bc1dfb19be802a60e31b139866</hash>
        <hash alg="SHA3-384">1b2ce0214f9767816e67c928ff90d0da0fb0a309de6f9a13f624c89d0d01d41e8476e6f66de5a8236fd9edb761538e5a</hash>
        <hash alg="SHA3-256">352ec7ea1b92294e1b02b52b37c73e9b08d6c612c2fce173cd7e43317a9491e3</hash>
        <hash alg="SHA3-512">d67d633607797d8f75d6c8f581fb3858421358b7a4daa079fc9960c2e397f33e7535eef5796b3876c29a311f896c02b4b867812a212efebd12e1fc63a8c79402</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.hive/hive-storage-api@2.8.1?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://www.apache.org/hive-storage-api/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="mailing-list">
          <url>https://mail-archives.apache.org/mod_mbox/www-announce/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/apache/maven-apache-parent/tree/apache-23/hive-storage-api</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.parquet/parquet-column@1.16.0?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.parquet</group>
      <name>parquet-column</name>
      <version>1.16.0</version>
      <description>Parquet is a columnar storage format that supports nested data. This provides the java implementation.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">73af95491c3d04116a7f5817dbab0701</hash>
        <hash alg="SHA-1">77138c128c64cd3fd38104fb0fc380a94138eb27</hash>
        <hash alg="SHA-256">034ec38dc4c58a0677bdaed666c9a7a8c68c269cce0d61dce4b7b49f7a0b9d7e</hash>
        <hash alg="SHA-512">2f488436d39fe74784258ce011be2a2fcbd2d70e57f6d66be1f2b0a626a35514af51659acf6bf728acfc48c814ebb7592bb87cf8140ae904e041bd97f1728d61</hash>
        <hash alg="SHA-384">00ce9826c70efd157a131fc70d9c037d664bd7c4cc762cfc92f0d0def700195d45e2276471f7477cd1080e32cf996733</hash>
        <hash alg="SHA3-384">6d48ac3dce4e3594efaeabb27bf34e37dcd1aaf837e71ac14cd7861ce582c29b3daaafb7807c03ef0cea96b07ca98bb0</hash>
        <hash alg="SHA3-256">6b37e854e44bb0770ea72bc8f4117c760986cbd7bc98564a259aca06fe2f71ee</hash>
        <hash alg="SHA3-512">b68cc6a2a8848742b235b35e055d824496b7962af59e7154ad00e3013946e0ad35ef36493616eafa38960ac5d91a531da82ed7cd0ea348d9d381706b6bfdaee8</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.parquet/parquet-column@1.16.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://parquet.apache.org</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/apache/parquet-java/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>dev-subscribe@parquet.apache.org</url>
        </reference>
        <reference type="vcs">
          <url>scm:git:git@github.com:apache/parquet-mr.git/parquet-column</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.parquet/parquet-common@1.16.0?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.parquet</group>
      <name>parquet-common</name>
      <version>1.16.0</version>
      <description>Parquet is a columnar storage format that supports nested data. This provides the java implementation.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">d2969de801289419497e2998fd0912eb</hash>
        <hash alg="SHA-1">1282e60bc5cfa32491c2c3214b97141029d21205</hash>
        <hash alg="SHA-256">7c7d120b83c923f9f5044e53518e6e8cc26d7993b89051b2a9979c3afdbc7811</hash>
        <hash alg="SHA-512">a6f55ed24bcb7613edf687ba7892fadcdbbd2ce464ca801a990cc80a6ef893ad2f87c7d3da5385fd3a53356638a559bc8292ea7ab5876349e3310e5437e51166</hash>
        <hash alg="SHA-384">9d10253ddc84f502ee8e7c71866d2027245ed9c5337105d3f5780847c361a49c5e386c87c07de0838d8ed0d0a1cc3a23</hash>
        <hash alg="SHA3-384">691093bc1b25599bf40527dd795bbabe2d8555b0e7bee1856867ada0fb1ebc292bc9fcfba5572d108ba536e4b72c1cb3</hash>
        <hash alg="SHA3-256">9d6dcd4de4949417a2f1382cff2bf3f721b9f7107d0671b919d8c046a539a9bd</hash>
        <hash alg="SHA3-512">d75a4ed31ba53d71e608823988ff89f581fa701f117b274c7f074e1e3ccda95ab8631501d6a61dc2ccae16d607183410f3877f70e7b009fb3d63cb29b673c939</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.parquet/parquet-common@1.16.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://parquet.apache.org</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/apache/parquet-java/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>dev-subscribe@parquet.apache.org</url>
        </reference>
        <reference type="vcs">
          <url>scm:git:git@github.com:apache/parquet-mr.git/parquet-common</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.parquet/parquet-encoding@1.16.0?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.parquet</group>
      <name>parquet-encoding</name>
      <version>1.16.0</version>
      <description>Parquet is a columnar storage format that supports nested data. This provides the java implementation.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">2eac36dee805e8a2eae4427b73465dad</hash>
        <hash alg="SHA-1">f6d1428ec90cb71fdc5d9b4b66e7ec55b55a9856</hash>
        <hash alg="SHA-256">da7b8f3a458871e70de6f883539a39d8dc9e8ec67312d3b95ea1dbca4b68f5b3</hash>
        <hash alg="SHA-512">a044c41cf834da7a051addfdf0c07cadc1ab01b17e5d8e5ff7a1cf244f034f46e5c213d43aad570f3da297246dc30672fef2613bdb7d8c7f8f6e97fda829571e</hash>
        <hash alg="SHA-384">4234ae29adc8f8667a039092909ed578260758d40f61732ed5607e9cdcff1af4608f9ffe58c2837e64a119bdf5480002</hash>
        <hash alg="SHA3-384">55a63127d6c8b9ba09b74dae1ea2d0fb4377fc9c18849af4488867cb20df282fe7d0630833531b5ff46b76574da30467</hash>
        <hash alg="SHA3-256">5d8de3d06392de7c9f369e4a89d55fda43ed5ee31031aa8a1741e465ef345a82</hash>
        <hash alg="SHA3-512">001030d7004e14865fb9d6d74a64f25977f70f6b977261940f35201366dc4f7f2ee7e912b8952492c623342eeacb8d68533351887857d1ac2adcae11b4e7d918</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.parquet/parquet-encoding@1.16.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://parquet.apache.org</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/apache/parquet-java/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>dev-subscribe@parquet.apache.org</url>
        </reference>
        <reference type="vcs">
          <url>scm:git:git@github.com:apache/parquet-mr.git/parquet-encoding</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.parquet/parquet-hadoop@1.16.0?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.parquet</group>
      <name>parquet-hadoop</name>
      <version>1.16.0</version>
      <description>Parquet is a columnar storage format that supports nested data. This provides the java implementation.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">d7a337cb0e7937addf616fb7e57b2b91</hash>
        <hash alg="SHA-1">4fbda919bfa47ce54a00a7e4bb2d294e90b16642</hash>
        <hash alg="SHA-256">06d9ecec624434c21680d736833aa4873655438dda9e64ccbeec1772d52cdfd5</hash>
        <hash alg="SHA-512">56bb4c207ee10b34852b9a4952665566da4824001eebc1ad7ae0a296257ff82cef6c8001fa64e4aa6714b50128af20fdd969d188c073ec6e7094131954b47357</hash>
        <hash alg="SHA-384">e5ab8e6efab9d7bc389e1510c5bedf166b86e19dcb7930d957b49c9c96a943d6e5e8d572311aac1cd2dc8bc560302e89</hash>
        <hash alg="SHA3-384">da5ac13c19316c303ecc92fe650b5854ef07c94f78bf5aad83c441d2a748bd90aab430d906b2a4732e9fa61b3943cb37</hash>
        <hash alg="SHA3-256">916a728418c21dde5a351d5c55e0d25a2bad2b9c8cfc6b60e5b2f6b9cfee50eb</hash>
        <hash alg="SHA3-512">61729b5e74864166c0237238ecf1fa107e567fa22eeb31d8727b327426ee1e8946815ecdd27097d8cdf9b3834d5ca7a86eb275a493b63c953d9af6f5c753701c</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.parquet/parquet-hadoop@1.16.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://parquet.apache.org</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/apache/parquet-java/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>dev-subscribe@parquet.apache.org</url>
        </reference>
        <reference type="vcs">
          <url>scm:git:git@github.com:apache/parquet-mr.git/parquet-hadoop</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.parquet/parquet-format-structures@1.16.0?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.parquet</group>
      <name>parquet-format-structures</name>
      <version>1.16.0</version>
      <description>Parquet-mr related java classes to use the parquet-format thrift structures.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">96a5d94b6a23487f058ba71cf9f7afe5</hash>
        <hash alg="SHA-1">e3feb5200a4469b04464c36201cc076869c68ad8</hash>
        <hash alg="SHA-256">aae70622e2ab2f6a6678d03054a8bf94731ecea98025dedbea6c7a6defbc9ee0</hash>
        <hash alg="SHA-512">b3b048a2bc65f6583d141f774827e04136f3cf0e6f550bdf8d0468514a248eeb8687a080dee4e68ce1cc4f0671096acbc9115567020cc8cb563480ed21c3125e</hash>
        <hash alg="SHA-384">6f4d5f941f5d93f4419aa6cb4b760b4f530334b25aa36e176a43d54a627859f377f6d8bf6d86d1d32d4bbb33ef14cc62</hash>
        <hash alg="SHA3-384">78658eaec6b26766ed377016f5182aa3bb8dc0b0efa2acc4bacde629eeda6a2829bb940c48bc5b728574539bef02290e</hash>
        <hash alg="SHA3-256">4a3cfa815014754011e90ac8abfefc2305ad78bad344ad026db7610367453d53</hash>
        <hash alg="SHA3-512">10a5f3824f546d1a94bc3b1597f418530892bb2c3e7fd84511001965731a1b133cec9f974e3e8172cce8dc4793d108ea6334f934e27c37941077a4f1c5f6d11a</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.parquet/parquet-format-structures@1.16.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://parquet.apache.org/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/apache/parquet-java/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>dev-subscribe@parquet.apache.org</url>
        </reference>
        <reference type="vcs">
          <url>scm:git:git@github.com:apache/parquet-mr.git/parquet-format-structures</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.parquet/parquet-jackson@1.16.0?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.parquet</group>
      <name>parquet-jackson</name>
      <version>1.16.0</version>
      <description>Parquet is a columnar storage format that supports nested data. This provides the java implementation.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">0ceda1bbb5ef64f3b8d20e70bdc92eb2</hash>
        <hash alg="SHA-1">9d0f499d9b7053774688c1f8aeba7367a71affb9</hash>
        <hash alg="SHA-256">12e8fbc43d989fc26336c2649b7cfcc82f5ee82b808258b6f79c24320aee001f</hash>
        <hash alg="SHA-512">d2c7dddf33bd6cfe0ebc58d268c83600c7790d867f9e209dbf72b91c0ef48afbc5a8a14c086ab122c54323146abb59a97ed06ff55373ce21e0e994ea001a3a8d</hash>
        <hash alg="SHA-384">68db0aa0c6285f1b46a9833ce9366318c9fdfb967f1f848435f9c398f5bf17b96cc2882f1bf174bfc90e0747725a67c7</hash>
        <hash alg="SHA3-384">5aea56f8e3c7cb8a3f7fd2c33c5f7fd78caec94618b888b67d69c3e2eaf619dcf46b10a5ad82cdc0a7934f4c41371d68</hash>
        <hash alg="SHA3-256">ebd3253ba1758a189368863dd546f2c56926fc5c96379921d51986ed934b2824</hash>
        <hash alg="SHA3-512">da7660531470727499ae71499d36cf8465245b376d67f3b7aee9a617ed5c9f67b97c9b02980c4d1886b15e449361f6aa7f935f28772c8748c049fe1deeab34c4</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.parquet/parquet-jackson@1.16.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://parquet.apache.org</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/apache/parquet-java/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>dev-subscribe@parquet.apache.org</url>
        </reference>
        <reference type="vcs">
          <url>scm:git:git@github.com:apache/parquet-mr.git/parquet-jackson</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.xbean/xbean-asm9-shaded@4.28?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.xbean</group>
      <name>xbean-asm9-shaded</name>
      <version>4.28</version>
      <description>Repackaged and shaded asm jars</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">8d415e91d3ad09e8a48e4b29f76ad92b</hash>
        <hash alg="SHA-1">471e7d9eaad31e23799ac11699c81f0e1a5bbedc</hash>
        <hash alg="SHA-256">5f8eac35b579cc2321c18d88e2ce99ef87c0b162c66855dad8dca67a3dae656d</hash>
        <hash alg="SHA-512">feef7d99148fa72d14d13aa9b6b616ad9d530a3a81a01e32c1a7ffaccec14165cd590a7569b809c11a27b099d411bab713450916ad81fee7e69fa3312ce062d5</hash>
        <hash alg="SHA-384">b776c08d1bd3415ee018db7d0edb8b015aaf711999a18c5e05a28583d802f454306daac18559c0a28f3870c86a6b3d91</hash>
        <hash alg="SHA3-384">b6beda050d1428ecc6c9d14fd575772af87e38b26c20beee2374df515db4e336e480dd5c8b6ea4367e0fb02db2060c4d</hash>
        <hash alg="SHA3-256">922c33083f0b3488cf33352725201f3fce3e1bdd3cbb54426b8f3a58407d8441</hash>
        <hash alg="SHA3-512">28eca25f9917c7bb89573e247d28c4fb7976127056ce963f12d3ca3a3d2632a5765149e3309ba483f7317d9cba6686947f2b14499e2c9ddf0b8e3bc5eb9f8dd5</hash>
      </hashes>
      <purl>pkg:maven/org.apache.xbean/xbean-asm9-shaded@4.28?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://geronimo.apache.org/maven/xbean/4.28/xbean-asm9-shaded</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>http://issues.apache.org/jira/browse/XBEAN</url>
        </reference>
        <reference type="mailing-list">
          <url>mailto:xbean-dev-subscribe@geronimo.apache.org</url>
        </reference>
        <reference type="vcs">
          <url>https://gitbox.apache.org/repos/asf/geronimo-xbean.git/xbean-asm9-shaded</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/com.ibm.icu/icu4j@77.1?type=jar">
      <group>com.ibm.icu</group>
      <name>icu4j</name>
      <version>77.1</version>
      <description>International Components for Unicode for Java (ICU4J) is a mature, widely used Java library
    providing Unicode and Globalization support</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">3e8d6fc9877483a0699efa1843b92326</hash>
        <hash alg="SHA-1">38693cf0b1d7362a8b726af74dc06026a7c23809</hash>
        <hash alg="SHA-256">b3640b9f416a4411fd33c59abbeea8fd57d024c23e1819bf9673220a97499fe3</hash>
        <hash alg="SHA-512">79cc9eed08f8ee403552fdba5b3e236b328df15a183a2000d0db01b802095e07c54b3cec416bae2d9daec04617ff568f2b28a345853eb95f779b51ab7d21dc17</hash>
        <hash alg="SHA-384">30f713993abc5a2f17f65cb63e0339960c98c70490e87d7776c3c8ad52b064481e36321494934e6ccebabecd7778a1f4</hash>
        <hash alg="SHA3-384">71c5000bd091f6c978f461748a0ddf209d0a360ca6be1f07b464d16ff4896e5613fc268a076143244b963cbd1f1501d4</hash>
        <hash alg="SHA3-256">16b5c29b2ba49d75748aa65aa396f0bb767441f4da88b0cbd2c0ddb39530b69b</hash>
        <hash alg="SHA3-512">bb892ee7e9c2e8fc06f3f5bf49c79003c65db745c70b23e02a4f5c15451c8be56d162f15dc1dcee2e6dc6b37ade554989717739b9f37c52d2738345ec5a71fda</hash>
      </hashes>
      <licenses>
        <license>
          <id>Unicode-3.0</id>
          <url>https://www.unicode.org/license.txt</url>
        </license>
      </licenses>
      <purl>pkg:maven/com.ibm.icu/icu4j@77.1?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://icu.unicode.org/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/unicode-org/icu</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.arrow/arrow-compression@18.3.0?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.arrow</group>
      <name>arrow-compression</name>
      <version>18.3.0</version>
      <description>(Experimental/Contrib) A library for working with the compression/decompression of Arrow data.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">7b284bab1b1861486e18ff7d385ecaec</hash>
        <hash alg="SHA-1">f7c0b9cadf829e5e75ca651a984e8278e316f31b</hash>
        <hash alg="SHA-256">58222c8986706dffa56e0b4d60087cf26d6c3a77311f287bb25e2baf5bf15451</hash>
        <hash alg="SHA-512">2ef551281298d5b2b510a78901936f41d64bdb43d4f68533d45f8c11b00661fe3377168368e99a92bfadd72911e1f728fd7208fa092502d607d2f8d9c2cd34d1</hash>
        <hash alg="SHA-384">f12fd526ecdf6d64bbf45435f802fb02a5c1c4134fd3c02ca6d0c239a8e9a1635f4e85b17a5e3e02dbf94b570f3dad2f</hash>
        <hash alg="SHA3-384">cdca5b47e26f18c130fbd2c9be5d6272ca610523bed88b9e5ea705bc49e221f229103d9484b8a060d70183b9fef0c662</hash>
        <hash alg="SHA3-256">bf1fea48518a2c97f967898bad8742e3044ee157fc4d031a92fa9133d30fa403</hash>
        <hash alg="SHA3-512">2d5413ddb35598b8a68c42f2d47a3f2ef1304db1583b37061c7e7e05e781d3ef0753e51a89d00a74ed0617356ae82f1ef761a2fab599fc652140c2181c435f9c</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.arrow/arrow-compression@18.3.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://arrow.apache.org/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/apache/arrow-java/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://lists.apache.org/list.html?dev@arrow.apache.org</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/apache/arrow-java/tree/v18.3.0</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.arrow/arrow-memory-core@18.3.0?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.arrow</group>
      <name>arrow-memory-core</name>
      <version>18.3.0</version>
      <description>Core off-heap memory management libraries for Arrow ValueVectors.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">bf6788fa833ce6bf56fc9cb221490a0c</hash>
        <hash alg="SHA-1">1f5bc66deb7d2120ac01341241cb859cf3f17751</hash>
        <hash alg="SHA-256">32ed0719bf2ba42becc3a88c95722851cf1bb88b37d06c95654a1152bed6ef2e</hash>
        <hash alg="SHA-512">b53815c8663f24629df68871139bcefa6887628e8a528d6bb4ab4148a9d5cff951701545ac7af0fc3ebd1b9381be3b9fa52d0be384a0125fc66944fb214da287</hash>
        <hash alg="SHA-384">0f62cec2b61944320b07e833c6cbaddbd7dd8dc2568bfccae7c55496c8702413ba2924d991129150b0fb49a8b140fc4b</hash>
        <hash alg="SHA3-384">5284a1e44d7e76bc6fe291e35bdfcb0882ce7fd4b5ed1abf32aeb6998be4d3e844b8e7d5d07a5f8dd272dc71fb995a77</hash>
        <hash alg="SHA3-256">efe242ba8ccdc2c8dfd2b318a7cadc5ea36d43476b25bc0b66e8c9ea4708271b</hash>
        <hash alg="SHA3-512">180d7786f4832924b49bf9ca21b72db70d2cd13d9abfe3469026b2277b367afc21f553e982ebdc5b2dc558969840c4674a8ce838b2fd7b56862cf5ef871c0b89</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.arrow/arrow-memory-core@18.3.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://arrow.apache.org/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://github.com/apache/arrow-java/issues</url>
        </reference>
        <reference type="mailing-list">
          <url>https://lists.apache.org/list.html?dev@arrow.apache.org</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/apache/arrow-java/tree/v18.3.0</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.spark/spark-tags_2.13@4.1.2?type=jar">
      <publisher>Apache Software Foundation</publisher>
      <group>org.apache.spark</group>
      <name>spark-tags_2.13</name>
      <version>4.1.2</version>
      <description>The Apache Software Foundation provides support for the Apache community of open-source software projects.
    The Apache projects are characterized by a collaborative, consensus based development process, an open and
    pragmatic software license, and a desire to create high quality software that leads the way in its field.
    We consider ourselves not simply a group of projects sharing a server, but rather a community of developers
    and users.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">7406afbee89c004197e24bb8c5484eb3</hash>
        <hash alg="SHA-1">07acf3f501e67edc973a89ebbf2d88e0f748a814</hash>
        <hash alg="SHA-256">9d6488817e15c0d339ee5019808357043d0821eeffddebe1569b978102c09a41</hash>
        <hash alg="SHA-512">e24b930e169e7e79607110c956198996efae4b45c397ddcf26ca63596171a7e78ef228f97306e266a7e29c44c9debe9341ffdd12d99ffa8aa55c5b388417ecf3</hash>
        <hash alg="SHA-384">5bc7b1d877f30a351e23fc557e37550a85c32c4b762863dc0aa7b923172af2bac89665996fd4b08ae97ab21108dd89b0</hash>
        <hash alg="SHA3-384">9be6f08df96e445405f471a552e992028c87448f7d7ab06f65479dba39e2f4cd44cd1f16ef891f8ec0b2f5a8d1d89d1f</hash>
        <hash alg="SHA3-256">4ac8affe8419366ddf695dd49140a280fef467638cb3b82366ba2f285ed8818d</hash>
        <hash alg="SHA3-512">81c0cbd781eebc2fc17a00712cf184b5e49914c33bebe09fcc8f014cdd22a04497186e883fbe570786366accfeeb996ed5513c8c1b94e7e784943e2bc32b9314</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.spark/spark-tags_2.13@4.1.2?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://spark.apache.org/</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://issues.apache.org/jira/browse/SPARK</url>
        </reference>
        <reference type="mailing-list">
          <url>dev-subscribe@spark.apache.org</url>
        </reference>
        <reference type="vcs">
          <url>scm:git:git@github.com:apache/spark.git/common/spark-tags_2.13</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/net.sf.jpam/jpam@1.1?type=jar">
      <group>net.sf.jpam</group>
      <name>jpam</name>
      <version>1.1</version>
      <description>Jpam is a Java-PAM bridge.  PAM, or Pluggable Authentication Modules, is a standard security architecture used on Linux, Solaris, HP-UX, Mac OS X and other Unix systems.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">f0459c2d72cc35f947bac690729a32a2</hash>
        <hash alg="SHA-1">cb3d91c2dfda767518a371dbb02edfd6a4aa0600</hash>
        <hash alg="SHA-256">3db38287ef038b01b7e73f2c62c3e7107af24a6b0cf95fda904b4330edcf8b28</hash>
        <hash alg="SHA-512">351158427146927fc9485e48cd3bb1c0c10cf7eb09f5acdb391c9fccab6d3fcb999891f2c943579c4c44258becd044991d2fce2f2eb3e72d223495dfdd7ba7a1</hash>
        <hash alg="SHA-384">3ab8636df5d052f034b1de7c7c4eb8f4cff5edb8302c368056679cbf377ec6d72119aa37958193de26ffcdbd92b6e10b</hash>
        <hash alg="SHA3-384">45ddfcc27fc3e060621de1a664b90d6519a80ff746ffb9b98b4e44d2fff8a0c71c364050dc49aa4596d938d74c5521e4</hash>
        <hash alg="SHA3-256">ab3ef7cc8da28c104a00f517a4b834d8133d960460be8c6cadf4f4c85bd2bc79</hash>
        <hash alg="SHA3-512">7de7a903e7bef7ab5ff59e61fe0223381d9db860f1125f848ad5c6bd8d6cc83f13a9ffc7381da83382072f3ebe284356c23d0268a44a4e843b7eb4b98d56e000</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/net.sf.jpam/jpam@1.1?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://jpam.sf.net</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://sourceforge.net/tracker/?group_id=116930</url>
        </reference>
        <reference type="mailing-list">
          <url>http://sourceforge.net/mailarchive/forum.php?forum=jpam-list</url>
        </reference>
        <reference type="vcs">
          <url>http://svn.sourceforge.net/viewcvs.cgi/jpam/</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/commons-cli/commons-cli@1.10.0?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>commons-cli</group>
      <name>commons-cli</name>
      <version>1.10.0</version>
      <description>Apache Commons CLI provides a simple API for presenting, processing, and validating a Command Line Interface.</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">d3064531ede2b338a8f9290916125919</hash>
        <hash alg="SHA-1">6fd35d70709c2b3da6122e72278266bc02b5eaa3</hash>
        <hash alg="SHA-256">1b273d92160b9fa69c3e65389a5c4decd2f38a697e458e6f75080ae09e886404</hash>
        <hash alg="SHA-512">e7374d3d24256fcb60a87728373466a21df8f3e03b0e49c711773dbcc23d26ecdad1abcc114c45a49d7de668c5db193a60ccc1aa75a1d6601bd9e112c3214cbe</hash>
        <hash alg="SHA-384">335be29e7334826bdce55273be27dac4b829ca4a1350a986f15679ff143f9cc4ad78baf12138ec5af928d1935ca578d3</hash>
        <hash alg="SHA3-384">df109cf6a273fd3630569d290d05eb412fb33197dc44876d8e0287394712a3a4a0327d4e8c3d53a4c5fe1d36f58e89e1</hash>
        <hash alg="SHA3-256">41302d4bbff3be7b62827802c2c4f867a990f3ca6124fecb232e626f579d11ca</hash>
        <hash alg="SHA3-512">b42e538c56e0781cdd54d73d759f74fd3a4a160ffa449f4d7829ef271042c2acf415031fd0a2ac73d469b0e5b8883d1e165649a5bac34a20c5c34be97e93dd54</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
          <url>https://www.apache.org/licenses/LICENSE-2.0</url>
        </license>
      </licenses>
      <purl>pkg:maven/commons-cli/commons-cli@1.10.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>https://commons.apache.org/proper/commons-cli/</url>
        </reference>
        <reference type="build-system">
          <url>https://github.com/apache/commons-cli/actions</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>https://issues.apache.org/jira/browse/CLI</url>
        </reference>
        <reference type="mailing-list">
          <url>https://mail-archives.apache.org/mod_mbox/commons-user/</url>
        </reference>
        <reference type="vcs">
          <url>https://gitbox.apache.org/repos/asf?p=commons-cli.git</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.apache.httpcomponents/httpcore@4.4.16?type=jar">
      <publisher>The Apache Software Foundation</publisher>
      <group>org.apache.httpcomponents</group>
      <name>httpcore</name>
      <version>4.4.16</version>
      <description>Apache HttpComponents Core (blocking I/O)</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">28d2cd9bf8789fd2ec774fb88436ebd1</hash>
        <hash alg="SHA-1">51cf043c87253c9f58b539c9f7e44c8894223850</hash>
        <hash alg="SHA-256">6c9b3dd142a09dc468e23ad39aad6f75a0f2b85125104469f026e52a474e464f</hash>
        <hash alg="SHA-512">168026436a6bcf5e96c0c59606638abbdc30de4b405ae55afde70fdf2895e267a3d48bba6bdadc5a89f38e31da3d9a9dc91e1cab7ea76f5e04322cf1ec63b838</hash>
        <hash alg="SHA-384">ba9ceaee1a37ca3201d6a1315ecb0327b495489efd0baa155c219c475df8d3eb69fe77ab0026563db406497626da6562</hash>
        <hash alg="SHA3-384">b9dc44dcc7cc86d5036f26d54c4003a2d72808ae7b07a0808bb53505c6d4281b5ad213eb1f3d0fef1113dec57cb0dfe1</hash>
        <hash alg="SHA3-256">fd8ab51846476c6c18822151c9ec07b39a9633010b5d20ea937fc6910407bc64</hash>
        <hash alg="SHA3-512">b42fa528242981a9d70e4f68ab75a24292df5112c44c21b6f18cb9201ce747885ba1d4dc69bc3d14d0da46a6c2638f937c11bc45749abeb55dc89ddada90cdda</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.apache.httpcomponents/httpcore@4.4.16?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://hc.apache.org/httpcomponents-core-ga</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://repository.apache.org/service/local/staging/deploy/maven2</url>
        </reference>
        <reference type="issue-tracker">
          <url>http://issues.apache.org/jira/browse/HTTPCORE</url>
        </reference>
        <reference type="mailing-list">
          <url>http://mail-archives.apache.org/mod_mbox/hc-httpclient-users/</url>
        </reference>
        <reference type="vcs">
          <url>https://github.com/apache/httpcomponents-core/tree/4.4.16/httpcore</url>
        </reference>
      </externalReferences>
    </component>
    <component type="library" bom-ref="pkg:maven/org.spark-project.spark/unused@1.0.0?type=jar">
      <group>org.spark-project.spark</group>
      <name>unused</name>
      <version>1.0.0</version>
      <description>Sonatype helps open source projects to set up Maven repositories on https://oss.sonatype.org/</description>
      <scope>required</scope>
      <hashes>
        <hash alg="MD5">763373ce9fe48581d4f2b8ffca35bb82</hash>
        <hash alg="SHA-1">205fe37a2fade6ce6dfcf8eff57ed21a4a1c22af</hash>
        <hash alg="SHA-256">00fd27fc9bde701581e7dcf5b95981d9e749a1c176bb8bfcd49f675768ff6bf0</hash>
        <hash alg="SHA-512">08a6ac8d2dc9d89ff557c7e96096c76e687efe3ce166aa6dbb76865bbef64dc8b6ecb5561ef03c2451a688ccdb3876b8f16b9137d02c290a698e917a5656b6fa</hash>
        <hash alg="SHA-384">c8c51d0d851835107db273d7ce522f026587d922c9d1d34739c3dedf9b7737c1c491e961dc7931f46c476d28acbc91f6</hash>
        <hash alg="SHA3-384">49f87e8e11e7a4d9da068d33185a89bb8e7eef339a0e2932246acbaa8ad90a30ec353e9e71147a78a8b74dfe4bdd3a3b</hash>
        <hash alg="SHA3-256">a943ae35f4d584810323330b6ef241a869b0187e4d3dfd79f8e504ebb0882cf2</hash>
        <hash alg="SHA3-512">1e7845ca316f39bc5ffc75afe0dcb437fe13b8c2133a396824dec8f3a5bd56243086989264f8f40df4cb2ba749709e3a90cdceb39c05727cbd82d86570e4f57d</hash>
      </hashes>
      <licenses>
        <license>
          <id>Apache-2.0</id>
        </license>
      </licenses>
      <purl>pkg:maven/org.spark-project.spark/unused@1.0.0?type=jar</purl>
      <externalReferences>
        <reference type="website">
          <url>http://nexus.sonatype.org/oss-repository-hosting.html/unused</url>
        </reference>
        <reference type="distribution-intake">
          <url>https://oss.sonatype.org/service/local/staging/deploy/maven2/</url>
        </reference>
      </externalReferences>
    </component>
  </components>
  <dependencies>
    <dependency ref="pkg:maven/org.apache.spark/spark-hive-thriftserver_2.13@4.1.2?type=jar">
      <dependency ref="pkg:maven/org.apache.spark/spark-hive_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/org.scala-lang.modules/scala-parallel-collections_2.13@1.2.0?type=jar"/>
      <dependency ref="pkg:maven/com.google.guava/guava@33.4.8-jre?type=jar"/>
      <dependency ref="pkg:maven/org.apache.hive/hive-cli@2.3.10?type=jar"/>
      <dependency ref="pkg:maven/org.apache.hive/hive-jdbc@2.3.10?type=jar"/>
      <dependency ref="pkg:maven/org.apache.hive/hive-beeline@2.3.10?type=jar"/>
      <dependency ref="pkg:maven/org.apache.hive/hive-service-rpc@4.0.0?type=jar"/>
      <dependency ref="pkg:maven/org.eclipse.jetty/jetty-server@11.0.26?type=jar"/>
      <dependency ref="pkg:maven/org.eclipse.jetty/jetty-servlet@11.0.26?type=jar"/>
      <dependency ref="pkg:maven/javax.servlet/javax.servlet-api@4.0.1?type=jar"/>
      <dependency ref="pkg:maven/org.apache.spark/spark-tags_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/net.sf.jpam/jpam@1.1?type=jar"/>
      <dependency ref="pkg:maven/commons-cli/commons-cli@1.10.0?type=jar"/>
      <dependency ref="pkg:maven/org.apache.httpcomponents/httpcore@4.4.16?type=jar"/>
      <dependency ref="pkg:maven/org.spark-project.spark/unused@1.0.0?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.spark/spark-hive_2.13@4.1.2?type=jar">
      <dependency ref="pkg:maven/org.apache.spark/spark-core_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/commons-lang/commons-lang@2.6?type=jar"/>
      <dependency ref="pkg:maven/org.apache.spark/spark-sql_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/org.apache.spark/spark-pipelines_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/org.scala-lang.modules/scala-parallel-collections_2.13@1.2.0?type=jar"/>
      <dependency ref="pkg:maven/org.apache.hive/hive-common@2.3.10?type=jar"/>
      <dependency ref="pkg:maven/org.apache.hive/hive-exec@2.3.10?classifier=core&amp;type=jar"/>
      <dependency ref="pkg:maven/org.apache.hive/hive-metastore@2.3.10?type=jar"/>
      <dependency ref="pkg:maven/org.apache.hive/hive-serde@2.3.10?type=jar"/>
      <dependency ref="pkg:maven/org.apache.hive/hive-shims@2.3.10?type=jar"/>
      <dependency ref="pkg:maven/org.apache.avro/avro@1.12.1?type=jar"/>
      <dependency ref="pkg:maven/org.apache.avro/avro-mapred@1.12.1?type=jar"/>
      <dependency ref="pkg:maven/org.apache.httpcomponents/httpclient@4.5.14?type=jar"/>
      <dependency ref="pkg:maven/javax.servlet/javax.servlet-api@4.0.1?type=jar"/>
      <dependency ref="pkg:maven/commons-codec/commons-codec@1.19.0?type=jar"/>
      <dependency ref="pkg:maven/joda-time/joda-time@2.14.0?type=jar"/>
      <dependency ref="pkg:maven/com.google.code.findbugs/jsr305@3.0.0?type=jar"/>
      <dependency ref="pkg:maven/org.datanucleus/datanucleus-core@4.1.17?type=jar"/>
      <dependency ref="pkg:maven/org.apache.hadoop/hadoop-client-runtime@3.4.2?type=jar"/>
      <dependency ref="pkg:maven/org.apache.thrift/libthrift@0.16.0?type=jar"/>
      <dependency ref="pkg:maven/org.apache.thrift/libfb303@0.9.3?type=jar"/>
      <dependency ref="pkg:maven/org.apache.derby/derby@10.16.1.1?type=jar"/>
      <dependency ref="pkg:maven/org.apache.derby/derbytools@10.16.1.1?type=jar"/>
      <dependency ref="pkg:maven/org.spark-project.spark/unused@1.0.0?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.spark/spark-core_2.13@4.1.2?type=jar">
      <dependency ref="pkg:maven/org.scala-lang.modules/scala-parallel-collections_2.13@1.2.0?type=jar"/>
      <dependency ref="pkg:maven/org.apache.avro/avro@1.12.1?type=jar"/>
      <dependency ref="pkg:maven/org.apache.avro/avro-mapred@1.12.1?type=jar"/>
      <dependency ref="pkg:maven/com.twitter/chill_2.13@0.10.0?type=jar"/>
      <dependency ref="pkg:maven/com.twitter/chill-java@0.10.0?type=jar"/>
      <dependency ref="pkg:maven/com.esotericsoftware/kryo-shaded@4.0.3?type=jar"/>
      <dependency ref="pkg:maven/org.objenesis/objenesis@3.4?type=jar"/>
      <dependency ref="pkg:maven/org.apache.hadoop/hadoop-client-api@3.4.2?type=jar"/>
      <dependency ref="pkg:maven/org.apache.hadoop/hadoop-client-runtime@3.4.2?type=jar"/>
      <dependency ref="pkg:maven/org.apache.spark/spark-launcher_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/org.apache.spark/spark-kvstore_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/org.apache.spark/spark-network-common_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/org.apache.spark/spark-network-shuffle_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/org.apache.spark/spark-unsafe_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/org.apache.spark/spark-common-utils_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/org.apache.curator/curator-recipes@5.9.0?type=jar"/>
      <dependency ref="pkg:maven/org.apache.zookeeper/zookeeper@3.9.4?type=jar"/>
      <dependency ref="pkg:maven/io.jsonwebtoken/jjwt-api@0.12.6?type=jar"/>
      <dependency ref="pkg:maven/io.jsonwebtoken/jjwt-impl@0.12.6?type=jar"/>
      <dependency ref="pkg:maven/io.jsonwebtoken/jjwt-jackson@0.12.6?type=jar"/>
      <dependency ref="pkg:maven/org.eclipse.jetty/jetty-plus@11.0.26?type=jar"/>
      <dependency ref="pkg:maven/org.eclipse.jetty/jetty-security@11.0.26?type=jar"/>
      <dependency ref="pkg:maven/org.eclipse.jetty/jetty-util@11.0.26?type=jar"/>
      <dependency ref="pkg:maven/org.eclipse.jetty/jetty-server@11.0.26?type=jar"/>
      <dependency ref="pkg:maven/org.eclipse.jetty/jetty-http@11.0.26?type=jar"/>
      <dependency ref="pkg:maven/org.eclipse.jetty/jetty-servlet@11.0.26?type=jar"/>
      <dependency ref="pkg:maven/org.eclipse.jetty/jetty-proxy@11.0.26?type=jar"/>
      <dependency ref="pkg:maven/org.eclipse.jetty/jetty-client@11.0.26?type=jar"/>
      <dependency ref="pkg:maven/org.eclipse.jetty/jetty-servlets@11.0.26?type=jar"/>
      <dependency ref="pkg:maven/javax.servlet/javax.servlet-api@4.0.1?type=jar"/>
      <dependency ref="pkg:maven/jakarta.servlet/jakarta.servlet-api@5.0.0?type=jar"/>
      <dependency ref="pkg:maven/commons-codec/commons-codec@1.19.0?type=jar"/>
      <dependency ref="pkg:maven/org.apache.commons/commons-compress@1.28.0?type=jar"/>
      <dependency ref="pkg:maven/org.apache.commons/commons-lang3@3.19.0?type=jar"/>
      <dependency ref="pkg:maven/org.apache.commons/commons-math3@3.6.1?type=jar"/>
      <dependency ref="pkg:maven/org.apache.commons/commons-text@1.14.0?type=jar"/>
      <dependency ref="pkg:maven/commons-io/commons-io@2.21.0?type=jar"/>
      <dependency ref="pkg:maven/org.apache.commons/commons-collections4@4.5.0?type=jar"/>
      <dependency ref="pkg:maven/com.google.code.findbugs/jsr305@3.0.0?type=jar"/>
      <dependency ref="pkg:maven/com.ning/compress-lzf@1.1.2?type=jar"/>
      <dependency ref="pkg:maven/org.xerial.snappy/snappy-java@1.1.10.8?type=jar"/>
      <dependency ref="pkg:maven/org.lz4/lz4-java@1.8.0?type=jar"/>
      <dependency ref="pkg:maven/com.github.luben/zstd-jni@1.5.7-6?type=jar"/>
      <dependency ref="pkg:maven/org.roaringbitmap/RoaringBitmap@1.3.0?type=jar"/>
      <dependency ref="pkg:maven/org.scala-lang.modules/scala-xml_2.13@2.4.0?type=jar"/>
      <dependency ref="pkg:maven/org.scala-lang/scala-library@2.13.17?type=jar"/>
      <dependency ref="pkg:maven/org.scala-lang/scala-reflect@2.13.17?type=jar"/>
      <dependency ref="pkg:maven/org.json4s/json4s-jackson_2.13@4.0.7?type=jar"/>
      <dependency ref="pkg:maven/org.glassfish.jersey.core/jersey-client@3.0.18?type=jar"/>
      <dependency ref="pkg:maven/org.glassfish.jersey.core/jersey-common@3.0.18?type=jar"/>
      <dependency ref="pkg:maven/org.glassfish.jersey.core/jersey-server@3.0.18?type=jar"/>
      <dependency ref="pkg:maven/org.glassfish.jersey.containers/jersey-container-servlet@3.0.18?type=jar"/>
      <dependency ref="pkg:maven/org.glassfish.jersey.containers/jersey-container-servlet-core@3.0.18?type=jar"/>
      <dependency ref="pkg:maven/org.glassfish.jersey.inject/jersey-hk2@3.0.18?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-all@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport-native-epoll@4.2.7.Final?classifier=linux-x86_64&amp;type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport-native-epoll@4.2.7.Final?classifier=linux-aarch_64&amp;type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport-native-kqueue@4.2.7.Final?classifier=osx-aarch_64&amp;type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport-native-kqueue@4.2.7.Final?classifier=osx-x86_64&amp;type=jar"/>
      <dependency ref="pkg:maven/com.clearspring.analytics/stream@2.9.8?type=jar"/>
      <dependency ref="pkg:maven/io.dropwizard.metrics/metrics-core@4.2.37?type=jar"/>
      <dependency ref="pkg:maven/io.dropwizard.metrics/metrics-jvm@4.2.37?type=jar"/>
      <dependency ref="pkg:maven/io.dropwizard.metrics/metrics-json@4.2.37?type=jar"/>
      <dependency ref="pkg:maven/io.dropwizard.metrics/metrics-graphite@4.2.37?type=jar"/>
      <dependency ref="pkg:maven/io.dropwizard.metrics/metrics-jmx@4.2.37?type=jar"/>
      <dependency ref="pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2?type=jar"/>
      <dependency ref="pkg:maven/com.fasterxml.jackson.module/jackson-module-scala_2.13@2.21.2?type=jar"/>
      <dependency ref="pkg:maven/net.razorvine/pickle@1.5?type=jar"/>
      <dependency ref="pkg:maven/net.sf.py4j/py4j@0.10.9.9?type=jar"/>
      <dependency ref="pkg:maven/org.apache.spark/spark-tags_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/org.apache.commons/commons-crypto@1.1.0?type=jar"/>
      <dependency ref="pkg:maven/com.google.protobuf/protobuf-java@4.33.0?type=jar"/>
      <dependency ref="pkg:maven/org.spark-project.spark/unused@1.0.0?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.scala-lang.modules/scala-parallel-collections_2.13@1.2.0?type=jar">
      <dependency ref="pkg:maven/org.scala-lang/scala-library@2.13.17?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.scala-lang/scala-library@2.13.17?type=jar"/>
    <dependency ref="pkg:maven/org.apache.avro/avro@1.12.1?type=jar">
      <dependency ref="pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.2?type=jar"/>
      <dependency ref="pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2?type=jar"/>
      <dependency ref="pkg:maven/org.apache.commons/commons-compress@1.28.0?type=jar"/>
      <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.2?type=jar"/>
    <dependency ref="pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2?type=jar">
      <dependency ref="pkg:maven/com.fasterxml.jackson.core/jackson-annotations@2.21?type=jar"/>
      <dependency ref="pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.2?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/com.fasterxml.jackson.core/jackson-annotations@2.21?type=jar"/>
    <dependency ref="pkg:maven/org.apache.commons/commons-compress@1.28.0?type=jar">
      <dependency ref="pkg:maven/commons-codec/commons-codec@1.19.0?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/commons-codec/commons-codec@1.19.0?type=jar"/>
    <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
    <dependency ref="pkg:maven/org.apache.avro/avro-mapred@1.12.1?type=jar">
      <dependency ref="pkg:maven/org.apache.avro/avro-ipc@1.12.1?type=jar"/>
      <dependency ref="pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.2?type=jar"/>
      <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.avro/avro-ipc@1.12.1?type=jar">
      <dependency ref="pkg:maven/org.apache.avro/avro@1.12.1?type=jar"/>
      <dependency ref="pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.2?type=jar"/>
      <dependency ref="pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2?type=jar"/>
      <dependency ref="pkg:maven/org.xerial.snappy/snappy-java@1.1.10.8?type=jar"/>
      <dependency ref="pkg:maven/org.tukaani/xz@1.10?type=jar"/>
      <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.xerial.snappy/snappy-java@1.1.10.8?type=jar"/>
    <dependency ref="pkg:maven/org.tukaani/xz@1.10?type=jar"/>
    <dependency ref="pkg:maven/com.twitter/chill_2.13@0.10.0?type=jar">
      <dependency ref="pkg:maven/org.scala-lang/scala-library@2.13.17?type=jar"/>
      <dependency ref="pkg:maven/com.twitter/chill-java@0.10.0?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/com.twitter/chill-java@0.10.0?type=jar"/>
    <dependency ref="pkg:maven/com.esotericsoftware/kryo-shaded@4.0.3?type=jar">
      <dependency ref="pkg:maven/com.esotericsoftware/minlog@1.3.0?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/com.esotericsoftware/minlog@1.3.0?type=jar"/>
    <dependency ref="pkg:maven/org.objenesis/objenesis@3.4?type=jar"/>
    <dependency ref="pkg:maven/org.apache.hadoop/hadoop-client-api@3.4.2?type=jar">
      <dependency ref="pkg:maven/org.xerial.snappy/snappy-java@1.1.10.8?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.hadoop/hadoop-client-runtime@3.4.2?type=jar">
      <dependency ref="pkg:maven/org.apache.hadoop/hadoop-client-api@3.4.2?type=jar"/>
      <dependency ref="pkg:maven/org.xerial.snappy/snappy-java@1.1.10.8?type=jar"/>
      <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
      <dependency ref="pkg:maven/com.google.code.findbugs/jsr305@3.0.0?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/com.google.code.findbugs/jsr305@3.0.0?type=jar"/>
    <dependency ref="pkg:maven/org.apache.spark/spark-launcher_2.13@4.1.2?type=jar">
      <dependency ref="pkg:maven/org.apache.spark/spark-tags_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/org.spark-project.spark/unused@1.0.0?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.spark/spark-tags_2.13@4.1.2?type=jar">
      <dependency ref="pkg:maven/org.scala-lang/scala-library@2.13.17?type=jar"/>
      <dependency ref="pkg:maven/org.spark-project.spark/unused@1.0.0?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.spark-project.spark/unused@1.0.0?type=jar"/>
    <dependency ref="pkg:maven/org.apache.spark/spark-kvstore_2.13@4.1.2?type=jar">
      <dependency ref="pkg:maven/org.apache.spark/spark-tags_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/org.apache.spark/spark-common-utils_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/org.fusesource.leveldbjni/leveldbjni-all@1.8?type=jar"/>
      <dependency ref="pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.2?type=jar"/>
      <dependency ref="pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2?type=jar"/>
      <dependency ref="pkg:maven/com.fasterxml.jackson.core/jackson-annotations@2.21?type=jar"/>
      <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
      <dependency ref="pkg:maven/org.rocksdb/rocksdbjni@9.8.4?type=jar"/>
      <dependency ref="pkg:maven/org.spark-project.spark/unused@1.0.0?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.spark/spark-common-utils_2.13@4.1.2?type=jar">
      <dependency ref="pkg:maven/org.apache.spark/spark-tags_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/org.apache.spark/spark-common-utils-java_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/org.apache.xbean/xbean-asm9-shaded@4.28?type=jar"/>
      <dependency ref="pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2?type=jar"/>
      <dependency ref="pkg:maven/com.fasterxml.jackson.module/jackson-module-scala_2.13@2.21.2?type=jar"/>
      <dependency ref="pkg:maven/org.apache.ivy/ivy@2.5.3?type=jar"/>
      <dependency ref="pkg:maven/oro/oro@2.0.8?type=jar"/>
      <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
      <dependency ref="pkg:maven/org.slf4j/jul-to-slf4j@2.0.17?type=jar"/>
      <dependency ref="pkg:maven/org.slf4j/jcl-over-slf4j@2.0.17?type=jar"/>
      <dependency ref="pkg:maven/org.apache.logging.log4j/log4j-slf4j2-impl@2.24.3?type=jar"/>
      <dependency ref="pkg:maven/org.apache.logging.log4j/log4j-api@2.24.3?type=jar"/>
      <dependency ref="pkg:maven/org.apache.logging.log4j/log4j-core@2.24.3?type=jar"/>
      <dependency ref="pkg:maven/org.apache.logging.log4j/log4j-1.2-api@2.24.3?type=jar"/>
      <dependency ref="pkg:maven/org.apache.logging.log4j/log4j-layout-template-json@2.24.3?type=jar"/>
      <dependency ref="pkg:maven/org.spark-project.spark/unused@1.0.0?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.spark/spark-common-utils-java_2.13@4.1.2?type=jar">
      <dependency ref="pkg:maven/org.apache.spark/spark-tags_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2?type=jar"/>
      <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
      <dependency ref="pkg:maven/org.slf4j/jul-to-slf4j@2.0.17?type=jar"/>
      <dependency ref="pkg:maven/org.slf4j/jcl-over-slf4j@2.0.17?type=jar"/>
      <dependency ref="pkg:maven/org.apache.logging.log4j/log4j-slf4j2-impl@2.24.3?type=jar"/>
      <dependency ref="pkg:maven/org.apache.logging.log4j/log4j-api@2.24.3?type=jar"/>
      <dependency ref="pkg:maven/org.apache.logging.log4j/log4j-core@2.24.3?type=jar"/>
      <dependency ref="pkg:maven/org.apache.logging.log4j/log4j-1.2-api@2.24.3?type=jar"/>
      <dependency ref="pkg:maven/org.apache.logging.log4j/log4j-layout-template-json@2.24.3?type=jar"/>
      <dependency ref="pkg:maven/org.spark-project.spark/unused@1.0.0?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.slf4j/jul-to-slf4j@2.0.17?type=jar">
      <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.slf4j/jcl-over-slf4j@2.0.17?type=jar">
      <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.logging.log4j/log4j-slf4j2-impl@2.24.3?type=jar">
      <dependency ref="pkg:maven/org.apache.logging.log4j/log4j-api@2.24.3?type=jar"/>
      <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
      <dependency ref="pkg:maven/org.apache.logging.log4j/log4j-core@2.24.3?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.logging.log4j/log4j-api@2.24.3?type=jar"/>
    <dependency ref="pkg:maven/org.apache.logging.log4j/log4j-core@2.24.3?type=jar">
      <dependency ref="pkg:maven/org.apache.logging.log4j/log4j-api@2.24.3?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.logging.log4j/log4j-1.2-api@2.24.3?type=jar">
      <dependency ref="pkg:maven/org.apache.logging.log4j/log4j-api@2.24.3?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.logging.log4j/log4j-layout-template-json@2.24.3?type=jar">
      <dependency ref="pkg:maven/org.apache.logging.log4j/log4j-core@2.24.3?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.xbean/xbean-asm9-shaded@4.28?type=jar"/>
    <dependency ref="pkg:maven/com.fasterxml.jackson.module/jackson-module-scala_2.13@2.21.2?type=jar">
      <dependency ref="pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.2?type=jar"/>
      <dependency ref="pkg:maven/com.fasterxml.jackson.core/jackson-annotations@2.21?type=jar"/>
      <dependency ref="pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2?type=jar"/>
      <dependency ref="pkg:maven/com.thoughtworks.paranamer/paranamer@2.8.3?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/com.thoughtworks.paranamer/paranamer@2.8.3?type=jar"/>
    <dependency ref="pkg:maven/org.apache.ivy/ivy@2.5.3?type=jar"/>
    <dependency ref="pkg:maven/oro/oro@2.0.8?type=jar"/>
    <dependency ref="pkg:maven/org.fusesource.leveldbjni/leveldbjni-all@1.8?type=jar"/>
    <dependency ref="pkg:maven/org.rocksdb/rocksdbjni@9.8.4?type=jar"/>
    <dependency ref="pkg:maven/org.apache.spark/spark-network-common_2.13@4.1.2?type=jar">
      <dependency ref="pkg:maven/io.netty/netty-all@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport-native-epoll@4.2.7.Final?classifier=linux-x86_64&amp;type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport-native-epoll@4.2.7.Final?classifier=linux-aarch_64&amp;type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport-native-kqueue@4.2.7.Final?classifier=osx-aarch_64&amp;type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport-native-kqueue@4.2.7.Final?classifier=osx-x86_64&amp;type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-tcnative-boringssl-static@2.0.74.Final?classifier=linux-x86_64&amp;type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-tcnative-boringssl-static@2.0.74.Final?classifier=linux-aarch_64&amp;type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-tcnative-boringssl-static@2.0.74.Final?classifier=osx-aarch_64&amp;type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-tcnative-boringssl-static@2.0.74.Final?classifier=osx-x86_64&amp;type=jar"/>
      <dependency ref="pkg:maven/org.fusesource.leveldbjni/leveldbjni-all@1.8?type=jar"/>
      <dependency ref="pkg:maven/org.rocksdb/rocksdbjni@9.8.4?type=jar"/>
      <dependency ref="pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2?type=jar"/>
      <dependency ref="pkg:maven/com.fasterxml.jackson.core/jackson-annotations@2.21?type=jar"/>
      <dependency ref="pkg:maven/io.dropwizard.metrics/metrics-core@4.2.37?type=jar"/>
      <dependency ref="pkg:maven/com.google.code.findbugs/jsr305@3.0.0?type=jar"/>
      <dependency ref="pkg:maven/com.google.guava/guava@33.4.8-jre?type=jar"/>
      <dependency ref="pkg:maven/com.google.guava/failureaccess@1.0.3?type=jar"/>
      <dependency ref="pkg:maven/org.apache.commons/commons-crypto@1.1.0?type=jar"/>
      <dependency ref="pkg:maven/com.google.crypto.tink/tink@1.16.0?type=jar"/>
      <dependency ref="pkg:maven/org.roaringbitmap/RoaringBitmap@1.3.0?type=jar"/>
      <dependency ref="pkg:maven/org.apache.spark/spark-common-utils-java_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/org.spark-project.spark/unused@1.0.0?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/io.netty/netty-all@4.2.7.Final?type=jar">
      <dependency ref="pkg:maven/io.netty/netty-buffer@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-codec-base@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-codec@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-codec-dns@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-codec-compression@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-codec-http@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-codec-http2@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-codec-http3@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport-native-unix-common@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-codec-socks@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-codec-protobuf@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-codec-marshalling@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-common@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-handler@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-handler-proxy@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-resolver@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-resolver-dns@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport-classes-epoll@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport-classes-kqueue@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport-classes-io_uring@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-codec-classes-quic@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport-native-epoll@4.2.7.Final?classifier=linux-x86_64&amp;type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport-native-epoll@4.2.7.Final?classifier=linux-aarch_64&amp;type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport-native-epoll@4.2.7.Final?classifier=linux-riscv64&amp;type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport-native-io_uring@4.2.7.Final?classifier=linux-x86_64&amp;type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport-native-io_uring@4.2.7.Final?classifier=linux-aarch_64&amp;type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport-native-io_uring@4.2.7.Final?classifier=linux-riscv64&amp;type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport-native-kqueue@4.2.7.Final?classifier=osx-x86_64&amp;type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport-native-kqueue@4.2.7.Final?classifier=osx-aarch_64&amp;type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-codec-native-quic@4.2.7.Final?classifier=linux-x86_64&amp;type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-codec-native-quic@4.2.7.Final?classifier=linux-aarch_64&amp;type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-codec-native-quic@4.2.7.Final?classifier=osx-x86_64&amp;type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-codec-native-quic@4.2.7.Final?classifier=osx-aarch_64&amp;type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-codec-native-quic@4.2.7.Final?classifier=windows-x86_64&amp;type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/io.netty/netty-buffer@4.2.7.Final?type=jar"/>
    <dependency ref="pkg:maven/io.netty/netty-codec-base@4.2.7.Final?type=jar"/>
    <dependency ref="pkg:maven/io.netty/netty-codec@4.2.7.Final?type=jar"/>
    <dependency ref="pkg:maven/io.netty/netty-codec-dns@4.2.7.Final?type=jar"/>
    <dependency ref="pkg:maven/io.netty/netty-codec-compression@4.2.7.Final?type=jar"/>
    <dependency ref="pkg:maven/io.netty/netty-codec-http@4.2.7.Final?type=jar"/>
    <dependency ref="pkg:maven/io.netty/netty-codec-http2@4.2.7.Final?type=jar"/>
    <dependency ref="pkg:maven/io.netty/netty-codec-http3@4.2.7.Final?type=jar"/>
    <dependency ref="pkg:maven/io.netty/netty-transport-native-unix-common@4.2.7.Final?type=jar"/>
    <dependency ref="pkg:maven/io.netty/netty-codec-socks@4.2.7.Final?type=jar"/>
    <dependency ref="pkg:maven/io.netty/netty-codec-protobuf@4.2.7.Final?type=jar"/>
    <dependency ref="pkg:maven/io.netty/netty-codec-marshalling@4.2.7.Final?type=jar"/>
    <dependency ref="pkg:maven/io.netty/netty-common@4.2.7.Final?type=jar"/>
    <dependency ref="pkg:maven/io.netty/netty-handler@4.2.7.Final?type=jar"/>
    <dependency ref="pkg:maven/io.netty/netty-handler-proxy@4.2.7.Final?type=jar"/>
    <dependency ref="pkg:maven/io.netty/netty-resolver@4.2.7.Final?type=jar"/>
    <dependency ref="pkg:maven/io.netty/netty-resolver-dns@4.2.7.Final?type=jar"/>
    <dependency ref="pkg:maven/io.netty/netty-transport@4.2.7.Final?type=jar"/>
    <dependency ref="pkg:maven/io.netty/netty-transport-classes-epoll@4.2.7.Final?type=jar"/>
    <dependency ref="pkg:maven/io.netty/netty-transport-classes-kqueue@4.2.7.Final?type=jar"/>
    <dependency ref="pkg:maven/io.netty/netty-transport-classes-io_uring@4.2.7.Final?type=jar"/>
    <dependency ref="pkg:maven/io.netty/netty-codec-classes-quic@4.2.7.Final?type=jar"/>
    <dependency ref="pkg:maven/io.netty/netty-transport-native-epoll@4.2.7.Final?classifier=linux-x86_64&amp;type=jar">
      <dependency ref="pkg:maven/io.netty/netty-common@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-buffer@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport-native-unix-common@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport-classes-epoll@4.2.7.Final?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/io.netty/netty-transport-native-epoll@4.2.7.Final?classifier=linux-aarch_64&amp;type=jar">
      <dependency ref="pkg:maven/io.netty/netty-common@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-buffer@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport-native-unix-common@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport-classes-epoll@4.2.7.Final?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/io.netty/netty-transport-native-epoll@4.2.7.Final?classifier=linux-riscv64&amp;type=jar">
      <dependency ref="pkg:maven/io.netty/netty-common@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-buffer@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport-native-unix-common@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport-classes-epoll@4.2.7.Final?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/io.netty/netty-transport-native-io_uring@4.2.7.Final?classifier=linux-x86_64&amp;type=jar">
      <dependency ref="pkg:maven/io.netty/netty-common@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-buffer@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport-native-unix-common@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport-classes-io_uring@4.2.7.Final?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/io.netty/netty-transport-native-io_uring@4.2.7.Final?classifier=linux-aarch_64&amp;type=jar">
      <dependency ref="pkg:maven/io.netty/netty-common@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-buffer@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport-native-unix-common@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport-classes-io_uring@4.2.7.Final?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/io.netty/netty-transport-native-io_uring@4.2.7.Final?classifier=linux-riscv64&amp;type=jar">
      <dependency ref="pkg:maven/io.netty/netty-common@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-buffer@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport-native-unix-common@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport-classes-io_uring@4.2.7.Final?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/io.netty/netty-transport-native-kqueue@4.2.7.Final?classifier=osx-x86_64&amp;type=jar">
      <dependency ref="pkg:maven/io.netty/netty-common@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-buffer@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport-native-unix-common@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport-classes-kqueue@4.2.7.Final?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/io.netty/netty-transport-native-kqueue@4.2.7.Final?classifier=osx-aarch_64&amp;type=jar">
      <dependency ref="pkg:maven/io.netty/netty-common@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-buffer@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport-native-unix-common@4.2.7.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-transport-classes-kqueue@4.2.7.Final?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/io.netty/netty-codec-native-quic@4.2.7.Final?classifier=linux-x86_64&amp;type=jar">
      <dependency ref="pkg:maven/io.netty/netty-codec-classes-quic@4.2.7.Final?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/io.netty/netty-codec-native-quic@4.2.7.Final?classifier=linux-aarch_64&amp;type=jar">
      <dependency ref="pkg:maven/io.netty/netty-codec-classes-quic@4.2.7.Final?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/io.netty/netty-codec-native-quic@4.2.7.Final?classifier=osx-x86_64&amp;type=jar">
      <dependency ref="pkg:maven/io.netty/netty-codec-classes-quic@4.2.7.Final?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/io.netty/netty-codec-native-quic@4.2.7.Final?classifier=osx-aarch_64&amp;type=jar">
      <dependency ref="pkg:maven/io.netty/netty-codec-classes-quic@4.2.7.Final?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/io.netty/netty-codec-native-quic@4.2.7.Final?classifier=windows-x86_64&amp;type=jar">
      <dependency ref="pkg:maven/io.netty/netty-codec-classes-quic@4.2.7.Final?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/io.netty/netty-tcnative-boringssl-static@2.0.74.Final?classifier=linux-x86_64&amp;type=jar">
      <dependency ref="pkg:maven/io.netty/netty-tcnative-classes@2.0.74.Final?type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-tcnative-boringssl-static@2.0.74.Final?classifier=linux-aarch_64&amp;type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-tcnative-boringssl-static@2.0.74.Final?classifier=osx-x86_64&amp;type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-tcnative-boringssl-static@2.0.74.Final?classifier=osx-aarch_64&amp;type=jar"/>
      <dependency ref="pkg:maven/io.netty/netty-tcnative-boringssl-static@2.0.74.Final?classifier=windows-x86_64&amp;type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/io.netty/netty-tcnative-classes@2.0.74.Final?type=jar"/>
    <dependency ref="pkg:maven/io.netty/netty-tcnative-boringssl-static@2.0.74.Final?classifier=linux-aarch_64&amp;type=jar"/>
    <dependency ref="pkg:maven/io.netty/netty-tcnative-boringssl-static@2.0.74.Final?classifier=osx-x86_64&amp;type=jar"/>
    <dependency ref="pkg:maven/io.netty/netty-tcnative-boringssl-static@2.0.74.Final?classifier=osx-aarch_64&amp;type=jar"/>
    <dependency ref="pkg:maven/io.netty/netty-tcnative-boringssl-static@2.0.74.Final?classifier=windows-x86_64&amp;type=jar"/>
    <dependency ref="pkg:maven/io.dropwizard.metrics/metrics-core@4.2.37?type=jar">
      <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/com.google.guava/guava@33.4.8-jre?type=jar">
      <dependency ref="pkg:maven/com.google.guava/failureaccess@1.0.3?type=jar"/>
      <dependency ref="pkg:maven/com.google.guava/listenablefuture@9999.0-empty-to-avoid-conflict-with-guava?type=jar"/>
      <dependency ref="pkg:maven/org.jspecify/jspecify@1.0.0?type=jar"/>
      <dependency ref="pkg:maven/com.google.errorprone/error_prone_annotations@2.36.0?type=jar"/>
      <dependency ref="pkg:maven/com.google.j2objc/j2objc-annotations@3.0.0?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/com.google.guava/failureaccess@1.0.3?type=jar"/>
    <dependency ref="pkg:maven/com.google.guava/listenablefuture@9999.0-empty-to-avoid-conflict-with-guava?type=jar"/>
    <dependency ref="pkg:maven/org.jspecify/jspecify@1.0.0?type=jar"/>
    <dependency ref="pkg:maven/com.google.errorprone/error_prone_annotations@2.36.0?type=jar"/>
    <dependency ref="pkg:maven/com.google.j2objc/j2objc-annotations@3.0.0?type=jar"/>
    <dependency ref="pkg:maven/org.apache.commons/commons-crypto@1.1.0?type=jar"/>
    <dependency ref="pkg:maven/com.google.crypto.tink/tink@1.16.0?type=jar">
      <dependency ref="pkg:maven/com.google.code.findbugs/jsr305@3.0.0?type=jar"/>
      <dependency ref="pkg:maven/com.google.code.gson/gson@2.11.0?type=jar"/>
      <dependency ref="pkg:maven/com.google.protobuf/protobuf-java@4.33.0?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/com.google.code.gson/gson@2.11.0?type=jar"/>
    <dependency ref="pkg:maven/com.google.protobuf/protobuf-java@4.33.0?type=jar"/>
    <dependency ref="pkg:maven/org.roaringbitmap/RoaringBitmap@1.3.0?type=jar"/>
    <dependency ref="pkg:maven/org.apache.spark/spark-network-shuffle_2.13@4.1.2?type=jar">
      <dependency ref="pkg:maven/org.apache.spark/spark-network-common_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/org.apache.commons/commons-lang3@3.19.0?type=jar"/>
      <dependency ref="pkg:maven/io.dropwizard.metrics/metrics-core@4.2.37?type=jar"/>
      <dependency ref="pkg:maven/org.apache.spark/spark-tags_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/org.roaringbitmap/RoaringBitmap@1.3.0?type=jar"/>
      <dependency ref="pkg:maven/org.spark-project.spark/unused@1.0.0?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.commons/commons-lang3@3.19.0?type=jar"/>
    <dependency ref="pkg:maven/org.apache.spark/spark-unsafe_2.13@4.1.2?type=jar">
      <dependency ref="pkg:maven/org.apache.spark/spark-tags_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/org.apache.spark/spark-common-utils_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/org.apache.spark/spark-variant_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/com.ibm.icu/icu4j@77.1?type=jar"/>
      <dependency ref="pkg:maven/com.twitter/chill_2.13@0.10.0?type=jar"/>
      <dependency ref="pkg:maven/com.esotericsoftware/kryo-shaded@4.0.3?type=jar"/>
      <dependency ref="pkg:maven/org.objenesis/objenesis@3.4?type=jar"/>
      <dependency ref="pkg:maven/com.google.code.findbugs/jsr305@3.0.0?type=jar"/>
      <dependency ref="pkg:maven/org.spark-project.spark/unused@1.0.0?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.spark/spark-variant_2.13@4.1.2?type=jar">
      <dependency ref="pkg:maven/org.apache.spark/spark-tags_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/org.apache.spark/spark-common-utils_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.2?type=jar"/>
      <dependency ref="pkg:maven/org.spark-project.spark/unused@1.0.0?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/com.ibm.icu/icu4j@77.1?type=jar"/>
    <dependency ref="pkg:maven/org.apache.curator/curator-recipes@5.9.0?type=jar">
      <dependency ref="pkg:maven/org.apache.curator/curator-framework@5.9.0?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.curator/curator-framework@5.9.0?type=jar">
      <dependency ref="pkg:maven/org.apache.curator/curator-client@5.9.0?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.curator/curator-client@5.9.0?type=jar">
      <dependency ref="pkg:maven/org.apache.zookeeper/zookeeper@3.9.4?type=jar"/>
      <dependency ref="pkg:maven/com.google.guava/guava@33.4.8-jre?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.zookeeper/zookeeper@3.9.4?type=jar">
      <dependency ref="pkg:maven/org.apache.zookeeper/zookeeper-jute@3.9.4?type=jar"/>
      <dependency ref="pkg:maven/org.apache.yetus/audience-annotations@0.12.0?type=jar"/>
      <dependency ref="pkg:maven/commons-io/commons-io@2.21.0?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.zookeeper/zookeeper-jute@3.9.4?type=jar">
      <dependency ref="pkg:maven/org.apache.yetus/audience-annotations@0.12.0?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.yetus/audience-annotations@0.12.0?type=jar"/>
    <dependency ref="pkg:maven/commons-io/commons-io@2.21.0?type=jar"/>
    <dependency ref="pkg:maven/io.jsonwebtoken/jjwt-api@0.12.6?type=jar"/>
    <dependency ref="pkg:maven/io.jsonwebtoken/jjwt-impl@0.12.6?type=jar">
      <dependency ref="pkg:maven/io.jsonwebtoken/jjwt-api@0.12.6?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/io.jsonwebtoken/jjwt-jackson@0.12.6?type=jar">
      <dependency ref="pkg:maven/io.jsonwebtoken/jjwt-api@0.12.6?type=jar"/>
      <dependency ref="pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.eclipse.jetty/jetty-plus@11.0.26?type=jar">
      <dependency ref="pkg:maven/jakarta.transaction/jakarta.transaction-api@2.0.0?type=jar"/>
      <dependency ref="pkg:maven/org.eclipse.jetty/jetty-jndi@11.0.26?type=jar"/>
      <dependency ref="pkg:maven/org.eclipse.jetty/jetty-webapp@11.0.26?type=jar"/>
      <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/jakarta.transaction/jakarta.transaction-api@2.0.0?type=jar"/>
    <dependency ref="pkg:maven/org.eclipse.jetty/jetty-jndi@11.0.26?type=jar">
      <dependency ref="pkg:maven/org.eclipse.jetty/jetty-util@11.0.26?type=jar"/>
      <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.eclipse.jetty/jetty-util@11.0.26?type=jar">
      <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.eclipse.jetty/jetty-webapp@11.0.26?type=jar">
      <dependency ref="pkg:maven/org.eclipse.jetty/jetty-servlet@11.0.26?type=jar"/>
      <dependency ref="pkg:maven/org.eclipse.jetty/jetty-xml@11.0.26?type=jar"/>
      <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.eclipse.jetty/jetty-servlet@11.0.26?type=jar">
      <dependency ref="pkg:maven/org.eclipse.jetty/jetty-security@11.0.26?type=jar"/>
      <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.eclipse.jetty/jetty-security@11.0.26?type=jar">
      <dependency ref="pkg:maven/org.eclipse.jetty/jetty-server@11.0.26?type=jar"/>
      <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.eclipse.jetty/jetty-server@11.0.26?type=jar">
      <dependency ref="pkg:maven/org.eclipse.jetty/jetty-http@11.0.26?type=jar"/>
      <dependency ref="pkg:maven/org.eclipse.jetty/jetty-io@11.0.26?type=jar"/>
      <dependency ref="pkg:maven/org.eclipse.jetty.toolchain/jetty-jakarta-servlet-api@5.0.2?type=jar"/>
      <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.eclipse.jetty/jetty-http@11.0.26?type=jar">
      <dependency ref="pkg:maven/org.eclipse.jetty/jetty-io@11.0.26?type=jar"/>
      <dependency ref="pkg:maven/org.eclipse.jetty/jetty-util@11.0.26?type=jar"/>
      <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.eclipse.jetty/jetty-io@11.0.26?type=jar">
      <dependency ref="pkg:maven/org.eclipse.jetty/jetty-util@11.0.26?type=jar"/>
      <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.eclipse.jetty.toolchain/jetty-jakarta-servlet-api@5.0.2?type=jar"/>
    <dependency ref="pkg:maven/org.eclipse.jetty/jetty-xml@11.0.26?type=jar">
      <dependency ref="pkg:maven/org.eclipse.jetty/jetty-util@11.0.26?type=jar"/>
      <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.eclipse.jetty/jetty-proxy@11.0.26?type=jar">
      <dependency ref="pkg:maven/org.eclipse.jetty/jetty-client@11.0.26?type=jar"/>
      <dependency ref="pkg:maven/org.eclipse.jetty/jetty-util@11.0.26?type=jar"/>
      <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.eclipse.jetty/jetty-client@11.0.26?type=jar">
      <dependency ref="pkg:maven/org.eclipse.jetty/jetty-alpn-client@11.0.26?type=jar"/>
      <dependency ref="pkg:maven/org.eclipse.jetty/jetty-http@11.0.26?type=jar"/>
      <dependency ref="pkg:maven/org.eclipse.jetty/jetty-io@11.0.26?type=jar"/>
      <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.eclipse.jetty/jetty-alpn-client@11.0.26?type=jar">
      <dependency ref="pkg:maven/org.eclipse.jetty/jetty-io@11.0.26?type=jar"/>
      <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.eclipse.jetty/jetty-servlets@11.0.26?type=jar">
      <dependency ref="pkg:maven/org.eclipse.jetty/jetty-http@11.0.26?type=jar"/>
      <dependency ref="pkg:maven/org.eclipse.jetty/jetty-io@11.0.26?type=jar"/>
      <dependency ref="pkg:maven/org.eclipse.jetty/jetty-util@11.0.26?type=jar"/>
      <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/javax.servlet/javax.servlet-api@4.0.1?type=jar"/>
    <dependency ref="pkg:maven/jakarta.servlet/jakarta.servlet-api@5.0.0?type=jar"/>
    <dependency ref="pkg:maven/org.apache.commons/commons-math3@3.6.1?type=jar"/>
    <dependency ref="pkg:maven/org.apache.commons/commons-text@1.14.0?type=jar">
      <dependency ref="pkg:maven/org.apache.commons/commons-lang3@3.19.0?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.commons/commons-collections4@4.5.0?type=jar"/>
    <dependency ref="pkg:maven/com.ning/compress-lzf@1.1.2?type=jar"/>
    <dependency ref="pkg:maven/org.lz4/lz4-java@1.8.0?type=jar"/>
    <dependency ref="pkg:maven/com.github.luben/zstd-jni@1.5.7-6?type=jar"/>
    <dependency ref="pkg:maven/org.scala-lang.modules/scala-xml_2.13@2.4.0?type=jar">
      <dependency ref="pkg:maven/org.scala-lang/scala-library@2.13.17?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.scala-lang/scala-reflect@2.13.17?type=jar">
      <dependency ref="pkg:maven/org.scala-lang/scala-library@2.13.17?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.json4s/json4s-jackson_2.13@4.0.7?type=jar">
      <dependency ref="pkg:maven/org.scala-lang/scala-library@2.13.17?type=jar"/>
      <dependency ref="pkg:maven/org.json4s/json4s-core_2.13@4.0.7?type=jar"/>
      <dependency ref="pkg:maven/org.json4s/json4s-jackson-core_2.13@4.0.7?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.json4s/json4s-core_2.13@4.0.7?type=jar">
      <dependency ref="pkg:maven/org.scala-lang/scala-library@2.13.17?type=jar"/>
      <dependency ref="pkg:maven/org.json4s/json4s-ast_2.13@4.0.7?type=jar"/>
      <dependency ref="pkg:maven/org.json4s/json4s-scalap_2.13@4.0.7?type=jar"/>
      <dependency ref="pkg:maven/com.thoughtworks.paranamer/paranamer@2.8.3?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.json4s/json4s-ast_2.13@4.0.7?type=jar">
      <dependency ref="pkg:maven/org.scala-lang/scala-library@2.13.17?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.json4s/json4s-scalap_2.13@4.0.7?type=jar">
      <dependency ref="pkg:maven/org.scala-lang/scala-library@2.13.17?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.json4s/json4s-jackson-core_2.13@4.0.7?type=jar">
      <dependency ref="pkg:maven/org.scala-lang/scala-library@2.13.17?type=jar"/>
      <dependency ref="pkg:maven/org.json4s/json4s-ast_2.13@4.0.7?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.glassfish.jersey.core/jersey-client@3.0.18?type=jar">
      <dependency ref="pkg:maven/jakarta.ws.rs/jakarta.ws.rs-api@3.0.0?type=jar"/>
      <dependency ref="pkg:maven/org.glassfish.jersey.core/jersey-common@3.0.18?type=jar"/>
      <dependency ref="pkg:maven/jakarta.inject/jakarta.inject-api@2.0.1?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/jakarta.ws.rs/jakarta.ws.rs-api@3.0.0?type=jar"/>
    <dependency ref="pkg:maven/org.glassfish.jersey.core/jersey-common@3.0.18?type=jar">
      <dependency ref="pkg:maven/jakarta.ws.rs/jakarta.ws.rs-api@3.0.0?type=jar"/>
      <dependency ref="pkg:maven/jakarta.annotation/jakarta.annotation-api@2.1.1?type=jar"/>
      <dependency ref="pkg:maven/jakarta.inject/jakarta.inject-api@2.0.1?type=jar"/>
      <dependency ref="pkg:maven/org.glassfish.hk2/osgi-resource-locator@1.0.3?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/jakarta.annotation/jakarta.annotation-api@2.1.1?type=jar"/>
    <dependency ref="pkg:maven/jakarta.inject/jakarta.inject-api@2.0.1?type=jar"/>
    <dependency ref="pkg:maven/org.glassfish.hk2/osgi-resource-locator@1.0.3?type=jar"/>
    <dependency ref="pkg:maven/org.glassfish.jersey.core/jersey-server@3.0.18?type=jar">
      <dependency ref="pkg:maven/org.glassfish.jersey.core/jersey-common@3.0.18?type=jar"/>
      <dependency ref="pkg:maven/org.glassfish.jersey.core/jersey-client@3.0.18?type=jar"/>
      <dependency ref="pkg:maven/jakarta.ws.rs/jakarta.ws.rs-api@3.0.0?type=jar"/>
      <dependency ref="pkg:maven/jakarta.annotation/jakarta.annotation-api@2.1.1?type=jar"/>
      <dependency ref="pkg:maven/jakarta.inject/jakarta.inject-api@2.0.1?type=jar"/>
      <dependency ref="pkg:maven/jakarta.validation/jakarta.validation-api@3.0.2?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/jakarta.validation/jakarta.validation-api@3.0.2?type=jar"/>
    <dependency ref="pkg:maven/org.glassfish.jersey.containers/jersey-container-servlet@3.0.18?type=jar">
      <dependency ref="pkg:maven/org.glassfish.jersey.containers/jersey-container-servlet-core@3.0.18?type=jar"/>
      <dependency ref="pkg:maven/org.glassfish.jersey.core/jersey-common@3.0.18?type=jar"/>
      <dependency ref="pkg:maven/org.glassfish.jersey.core/jersey-server@3.0.18?type=jar"/>
      <dependency ref="pkg:maven/jakarta.ws.rs/jakarta.ws.rs-api@3.0.0?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.glassfish.jersey.containers/jersey-container-servlet-core@3.0.18?type=jar">
      <dependency ref="pkg:maven/jakarta.inject/jakarta.inject-api@2.0.1?type=jar"/>
      <dependency ref="pkg:maven/org.glassfish.jersey.core/jersey-common@3.0.18?type=jar"/>
      <dependency ref="pkg:maven/org.glassfish.jersey.core/jersey-server@3.0.18?type=jar"/>
      <dependency ref="pkg:maven/jakarta.ws.rs/jakarta.ws.rs-api@3.0.0?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.glassfish.jersey.inject/jersey-hk2@3.0.18?type=jar">
      <dependency ref="pkg:maven/org.glassfish.jersey.core/jersey-common@3.0.18?type=jar"/>
      <dependency ref="pkg:maven/org.glassfish.hk2/hk2-locator@3.0.6?type=jar"/>
      <dependency ref="pkg:maven/org.javassist/javassist@3.30.2-GA?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.glassfish.hk2/hk2-locator@3.0.6?type=jar">
      <dependency ref="pkg:maven/org.glassfish.hk2.external/aopalliance-repackaged@3.0.6?type=jar"/>
      <dependency ref="pkg:maven/org.glassfish.hk2/hk2-api@3.0.6?type=jar"/>
      <dependency ref="pkg:maven/org.glassfish.hk2/hk2-utils@3.0.6?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.glassfish.hk2.external/aopalliance-repackaged@3.0.6?type=jar"/>
    <dependency ref="pkg:maven/org.glassfish.hk2/hk2-api@3.0.6?type=jar">
      <dependency ref="pkg:maven/org.glassfish.hk2/hk2-utils@3.0.6?type=jar"/>
      <dependency ref="pkg:maven/org.glassfish.hk2.external/aopalliance-repackaged@3.0.6?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.glassfish.hk2/hk2-utils@3.0.6?type=jar"/>
    <dependency ref="pkg:maven/org.javassist/javassist@3.30.2-GA?type=jar"/>
    <dependency ref="pkg:maven/com.clearspring.analytics/stream@2.9.8?type=jar">
      <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/io.dropwizard.metrics/metrics-jvm@4.2.37?type=jar">
      <dependency ref="pkg:maven/io.dropwizard.metrics/metrics-core@4.2.37?type=jar"/>
      <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/io.dropwizard.metrics/metrics-json@4.2.37?type=jar">
      <dependency ref="pkg:maven/io.dropwizard.metrics/metrics-core@4.2.37?type=jar"/>
      <dependency ref="pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.2?type=jar"/>
      <dependency ref="pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/io.dropwizard.metrics/metrics-graphite@4.2.37?type=jar">
      <dependency ref="pkg:maven/io.dropwizard.metrics/metrics-core@4.2.37?type=jar"/>
      <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/io.dropwizard.metrics/metrics-jmx@4.2.37?type=jar">
      <dependency ref="pkg:maven/io.dropwizard.metrics/metrics-core@4.2.37?type=jar"/>
      <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/net.razorvine/pickle@1.5?type=jar"/>
    <dependency ref="pkg:maven/net.sf.py4j/py4j@0.10.9.9?type=jar"/>
    <dependency ref="pkg:maven/commons-lang/commons-lang@2.6?type=jar"/>
    <dependency ref="pkg:maven/org.apache.spark/spark-sql_2.13@4.1.2?type=jar">
      <dependency ref="pkg:maven/org.rocksdb/rocksdbjni@9.8.4?type=jar"/>
      <dependency ref="pkg:maven/com.univocity/univocity-parsers@2.9.1?type=jar"/>
      <dependency ref="pkg:maven/org.apache.spark/spark-sketch_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/org.apache.spark/spark-core_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/org.apache.spark/spark-catalyst_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/org.apache.spark/spark-tags_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/org.scala-lang.modules/scala-parallel-collections_2.13@1.2.0?type=jar"/>
      <dependency ref="pkg:maven/org.apache.orc/orc-format@1.1.1?classifier=shaded-protobuf&amp;type=jar"/>
      <dependency ref="pkg:maven/org.apache.orc/orc-core@2.2.2?classifier=shaded-protobuf&amp;type=jar"/>
      <dependency ref="pkg:maven/org.apache.orc/orc-mapreduce@2.2.2?classifier=shaded-protobuf&amp;type=jar"/>
      <dependency ref="pkg:maven/org.apache.hive/hive-storage-api@2.8.1?type=jar"/>
      <dependency ref="pkg:maven/org.apache.parquet/parquet-column@1.16.0?type=jar"/>
      <dependency ref="pkg:maven/org.apache.parquet/parquet-hadoop@1.16.0?type=jar"/>
      <dependency ref="pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2?type=jar"/>
      <dependency ref="pkg:maven/org.apache.ws.xmlschema/xmlschema-core@2.3.1?type=jar"/>
      <dependency ref="pkg:maven/org.apache.xbean/xbean-asm9-shaded@4.28?type=jar"/>
      <dependency ref="pkg:maven/com.google.protobuf/protobuf-java@4.33.0?type=jar"/>
      <dependency ref="pkg:maven/com.ibm.icu/icu4j@77.1?type=jar"/>
      <dependency ref="pkg:maven/org.apache.arrow/arrow-compression@18.3.0?type=jar"/>
      <dependency ref="pkg:maven/org.spark-project.spark/unused@1.0.0?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/com.univocity/univocity-parsers@2.9.1?type=jar"/>
    <dependency ref="pkg:maven/org.apache.spark/spark-sketch_2.13@4.1.2?type=jar">
      <dependency ref="pkg:maven/org.apache.spark/spark-tags_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/org.spark-project.spark/unused@1.0.0?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.spark/spark-catalyst_2.13@4.1.2?type=jar">
      <dependency ref="pkg:maven/org.apache.spark/spark-core_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/org.apache.spark/spark-sql-api_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/org.apache.spark/spark-tags_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/org.apache.spark/spark-unsafe_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/org.apache.spark/spark-sketch_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/org.apache.spark/spark-variant_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/org.scala-lang.modules/scala-parallel-collections_2.13@1.2.0?type=jar"/>
      <dependency ref="pkg:maven/org.codehaus.janino/janino@3.1.9?type=jar"/>
      <dependency ref="pkg:maven/org.codehaus.janino/commons-compiler@3.1.9?type=jar"/>
      <dependency ref="pkg:maven/commons-codec/commons-codec@1.19.0?type=jar"/>
      <dependency ref="pkg:maven/com.univocity/univocity-parsers@2.9.1?type=jar"/>
      <dependency ref="pkg:maven/org.apache.ws.xmlschema/xmlschema-core@2.3.1?type=jar"/>
      <dependency ref="pkg:maven/org.apache.datasketches/datasketches-java@6.2.0?type=jar"/>
      <dependency ref="pkg:maven/org.spark-project.spark/unused@1.0.0?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.spark/spark-sql-api_2.13@4.1.2?type=jar">
      <dependency ref="pkg:maven/org.scala-lang/scala-reflect@2.13.17?type=jar"/>
      <dependency ref="pkg:maven/org.scala-lang.modules/scala-parser-combinators_2.13@2.4.0?type=jar"/>
      <dependency ref="pkg:maven/org.apache.spark/spark-common-utils_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/org.apache.spark/spark-unsafe_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/org.apache.spark/spark-sketch_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/org.apache.commons/commons-lang3@3.19.0?type=jar"/>
      <dependency ref="pkg:maven/org.json4s/json4s-jackson_2.13@4.0.7?type=jar"/>
      <dependency ref="pkg:maven/org.antlr/antlr4-runtime@4.13.1?type=jar"/>
      <dependency ref="pkg:maven/org.apache.arrow/arrow-vector@18.3.0?type=jar"/>
      <dependency ref="pkg:maven/org.apache.arrow/arrow-memory-netty@18.3.0?type=jar"/>
      <dependency ref="pkg:maven/org.spark-project.spark/unused@1.0.0?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.scala-lang.modules/scala-parser-combinators_2.13@2.4.0?type=jar">
      <dependency ref="pkg:maven/org.scala-lang/scala-library@2.13.17?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.antlr/antlr4-runtime@4.13.1?type=jar"/>
    <dependency ref="pkg:maven/org.apache.arrow/arrow-vector@18.3.0?type=jar">
      <dependency ref="pkg:maven/org.apache.arrow/arrow-format@18.3.0?type=jar"/>
      <dependency ref="pkg:maven/org.apache.arrow/arrow-memory-core@18.3.0?type=jar"/>
      <dependency ref="pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2?type=jar"/>
      <dependency ref="pkg:maven/com.fasterxml.jackson.datatype/jackson-datatype-jsr310@2.21.2?type=jar"/>
      <dependency ref="pkg:maven/commons-codec/commons-codec@1.19.0?type=jar"/>
      <dependency ref="pkg:maven/com.google.flatbuffers/flatbuffers-java@25.2.10?type=jar"/>
      <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.arrow/arrow-format@18.3.0?type=jar">
      <dependency ref="pkg:maven/com.google.flatbuffers/flatbuffers-java@25.2.10?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/com.google.flatbuffers/flatbuffers-java@25.2.10?type=jar"/>
    <dependency ref="pkg:maven/org.apache.arrow/arrow-memory-core@18.3.0?type=jar">
      <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/com.fasterxml.jackson.datatype/jackson-datatype-jsr310@2.21.2?type=jar">
      <dependency ref="pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.arrow/arrow-memory-netty@18.3.0?type=jar">
      <dependency ref="pkg:maven/org.apache.arrow/arrow-memory-core@18.3.0?type=jar"/>
      <dependency ref="pkg:maven/org.apache.arrow/arrow-memory-netty-buffer-patch@18.3.0?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.arrow/arrow-memory-netty-buffer-patch@18.3.0?type=jar">
      <dependency ref="pkg:maven/org.apache.arrow/arrow-memory-core@18.3.0?type=jar"/>
      <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.codehaus.janino/janino@3.1.9?type=jar">
      <dependency ref="pkg:maven/org.codehaus.janino/commons-compiler@3.1.9?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.codehaus.janino/commons-compiler@3.1.9?type=jar"/>
    <dependency ref="pkg:maven/org.apache.ws.xmlschema/xmlschema-core@2.3.1?type=jar"/>
    <dependency ref="pkg:maven/org.apache.datasketches/datasketches-java@6.2.0?type=jar">
      <dependency ref="pkg:maven/org.apache.datasketches/datasketches-memory@3.0.2?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.datasketches/datasketches-memory@3.0.2?type=jar"/>
    <dependency ref="pkg:maven/org.apache.orc/orc-format@1.1.1?classifier=shaded-protobuf&amp;type=jar"/>
    <dependency ref="pkg:maven/org.apache.orc/orc-core@2.2.2?classifier=shaded-protobuf&amp;type=jar">
      <dependency ref="pkg:maven/org.apache.orc/orc-shims@2.2.2?type=jar"/>
      <dependency ref="pkg:maven/io.airlift/aircompressor@2.0.3?type=jar"/>
      <dependency ref="pkg:maven/org.apache.hadoop/hadoop-client-runtime@3.4.2?type=jar"/>
      <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
      <dependency ref="pkg:maven/org.threeten/threeten-extra@1.8.0?type=jar"/>
      <dependency ref="pkg:maven/org.locationtech.jts/jts-core@1.20.0?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.orc/orc-shims@2.2.2?type=jar">
      <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/io.airlift/aircompressor@2.0.3?type=jar"/>
    <dependency ref="pkg:maven/org.threeten/threeten-extra@1.8.0?type=jar"/>
    <dependency ref="pkg:maven/org.locationtech.jts/jts-core@1.20.0?type=jar"/>
    <dependency ref="pkg:maven/org.apache.orc/orc-mapreduce@2.2.2?classifier=shaded-protobuf&amp;type=jar">
      <dependency ref="pkg:maven/org.apache.hadoop/hadoop-client-api@3.4.2?type=jar"/>
      <dependency ref="pkg:maven/org.apache.hadoop/hadoop-client-runtime@3.4.2?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.hive/hive-storage-api@2.8.1?type=jar">
      <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.parquet/parquet-column@1.16.0?type=jar">
      <dependency ref="pkg:maven/org.apache.parquet/parquet-common@1.16.0?type=jar"/>
      <dependency ref="pkg:maven/org.apache.parquet/parquet-encoding@1.16.0?type=jar"/>
      <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
      <dependency ref="pkg:maven/org.locationtech.jts/jts-core@1.20.0?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.parquet/parquet-common@1.16.0?type=jar">
      <dependency ref="pkg:maven/org.apache.parquet/parquet-format-structures@1.16.0?type=jar"/>
      <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.parquet/parquet-format-structures@1.16.0?type=jar"/>
    <dependency ref="pkg:maven/org.apache.parquet/parquet-encoding@1.16.0?type=jar">
      <dependency ref="pkg:maven/org.apache.parquet/parquet-common@1.16.0?type=jar"/>
      <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.parquet/parquet-hadoop@1.16.0?type=jar">
      <dependency ref="pkg:maven/org.apache.parquet/parquet-column@1.16.0?type=jar"/>
      <dependency ref="pkg:maven/org.apache.parquet/parquet-format-structures@1.16.0?type=jar"/>
      <dependency ref="pkg:maven/org.apache.parquet/parquet-common@1.16.0?type=jar"/>
      <dependency ref="pkg:maven/org.apache.parquet/parquet-jackson@1.16.0?type=jar"/>
      <dependency ref="pkg:maven/org.xerial.snappy/snappy-java@1.1.10.8?type=jar"/>
      <dependency ref="pkg:maven/io.airlift/aircompressor@2.0.3?type=jar"/>
      <dependency ref="pkg:maven/org.slf4j/slf4j-api@2.0.17?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.parquet/parquet-jackson@1.16.0?type=jar"/>
    <dependency ref="pkg:maven/org.apache.arrow/arrow-compression@18.3.0?type=jar">
      <dependency ref="pkg:maven/org.apache.arrow/arrow-vector@18.3.0?type=jar"/>
      <dependency ref="pkg:maven/org.apache.arrow/arrow-memory-core@18.3.0?type=jar"/>
      <dependency ref="pkg:maven/org.apache.commons/commons-compress@1.28.0?type=jar"/>
      <dependency ref="pkg:maven/com.github.luben/zstd-jni@1.5.7-6?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.spark/spark-pipelines_2.13@4.1.2?type=jar">
      <dependency ref="pkg:maven/org.scala-lang/scala-library@2.13.17?type=jar"/>
      <dependency ref="pkg:maven/org.apache.spark/spark-core_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/org.apache.spark/spark-sql_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/org.scala-lang.modules/scala-parallel-collections_2.13@1.2.0?type=jar"/>
      <dependency ref="pkg:maven/org.apache.spark/spark-tags_2.13@4.1.2?type=jar"/>
      <dependency ref="pkg:maven/org.spark-project.spark/unused@1.0.0?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.hive/hive-common@2.3.10?type=jar">
      <dependency ref="pkg:maven/commons-cli/commons-cli@1.10.0?type=jar"/>
      <dependency ref="pkg:maven/org.apache.commons/commons-lang3@3.19.0?type=jar"/>
      <dependency ref="pkg:maven/jline/jline@2.14.6?type=jar"/>
      <dependency ref="pkg:maven/joda-time/joda-time@2.14.0?type=jar"/>
      <dependency ref="pkg:maven/org.apache.commons/commons-compress@1.28.0?type=jar"/>
      <dependency ref="pkg:maven/com.tdunning/json@1.8?type=jar"/>
      <dependency ref="pkg:maven/io.dropwizard.metrics/metrics-core@4.2.37?type=jar"/>
      <dependency ref="pkg:maven/io.dropwizard.metrics/metrics-jvm@4.2.37?type=jar"/>
      <dependency ref="pkg:maven/io.dropwizard.metrics/metrics-json@4.2.37?type=jar"/>
      <dependency ref="pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2?type=jar"/>
      <dependency ref="pkg:maven/com.github.joshelser/dropwizard-metrics-hadoop-metrics2-reporter@0.1.2?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/commons-cli/commons-cli@1.10.0?type=jar"/>
    <dependency ref="pkg:maven/jline/jline@2.14.6?type=jar"/>
    <dependency ref="pkg:maven/joda-time/joda-time@2.14.0?type=jar"/>
    <dependency ref="pkg:maven/com.tdunning/json@1.8?type=jar"/>
    <dependency ref="pkg:maven/com.github.joshelser/dropwizard-metrics-hadoop-metrics2-reporter@0.1.2?type=jar">
      <dependency ref="pkg:maven/io.dropwizard.metrics/metrics-core@4.2.37?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.hive/hive-exec@2.3.10?classifier=core&amp;type=jar">
      <dependency ref="pkg:maven/commons-io/commons-io@2.21.0?type=jar"/>
      <dependency ref="pkg:maven/org.antlr/antlr-runtime@3.5.2?type=jar"/>
      <dependency ref="pkg:maven/org.antlr/ST4@4.0.4?type=jar"/>
      <dependency ref="pkg:maven/org.apache.commons/commons-compress@1.28.0?type=jar"/>
      <dependency ref="pkg:maven/org.apache.ivy/ivy@2.5.3?type=jar"/>
      <dependency ref="pkg:maven/org.datanucleus/datanucleus-core@4.1.17?type=jar"/>
      <dependency ref="pkg:maven/com.google.code.gson/gson@2.11.0?type=jar"/>
      <dependency ref="pkg:maven/stax/stax-api@1.0.1?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.antlr/antlr-runtime@3.5.2?type=jar"/>
    <dependency ref="pkg:maven/org.antlr/ST4@4.0.4?type=jar">
      <dependency ref="pkg:maven/org.antlr/antlr-runtime@3.5.2?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.datanucleus/datanucleus-core@4.1.17?type=jar"/>
    <dependency ref="pkg:maven/stax/stax-api@1.0.1?type=jar"/>
    <dependency ref="pkg:maven/org.apache.hive/hive-metastore@2.3.10?type=jar">
      <dependency ref="pkg:maven/javolution/javolution@5.5.1?type=jar"/>
      <dependency ref="pkg:maven/com.google.protobuf/protobuf-java@4.33.0?type=jar"/>
      <dependency ref="pkg:maven/com.zaxxer/HikariCP@2.5.1?type=jar"/>
      <dependency ref="pkg:maven/commons-cli/commons-cli@1.10.0?type=jar"/>
      <dependency ref="pkg:maven/org.apache.commons/commons-lang3@3.19.0?type=jar"/>
      <dependency ref="pkg:maven/org.apache.derby/derby@10.16.1.1?type=jar"/>
      <dependency ref="pkg:maven/org.datanucleus/datanucleus-api-jdo@4.2.4?type=jar"/>
      <dependency ref="pkg:maven/org.datanucleus/datanucleus-core@4.1.17?type=jar"/>
      <dependency ref="pkg:maven/org.datanucleus/datanucleus-rdbms@4.1.19?type=jar"/>
      <dependency ref="pkg:maven/commons-pool/commons-pool@1.5.4?type=jar"/>
      <dependency ref="pkg:maven/commons-dbcp/commons-dbcp@1.4?type=jar"/>
      <dependency ref="pkg:maven/javax.jdo/jdo-api@3.0.1?type=jar"/>
      <dependency ref="pkg:maven/org.datanucleus/javax.jdo@3.2.0-m3?type=jar"/>
      <dependency ref="pkg:maven/org.antlr/antlr-runtime@3.5.2?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/javolution/javolution@5.5.1?type=jar"/>
    <dependency ref="pkg:maven/com.zaxxer/HikariCP@2.5.1?type=jar"/>
    <dependency ref="pkg:maven/org.apache.derby/derby@10.16.1.1?type=jar">
      <dependency ref="pkg:maven/org.apache.derby/derbyshared@10.16.1.1?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.derby/derbyshared@10.16.1.1?type=jar"/>
    <dependency ref="pkg:maven/org.datanucleus/datanucleus-api-jdo@4.2.4?type=jar"/>
    <dependency ref="pkg:maven/org.datanucleus/datanucleus-rdbms@4.1.19?type=jar"/>
    <dependency ref="pkg:maven/commons-pool/commons-pool@1.5.4?type=jar"/>
    <dependency ref="pkg:maven/commons-dbcp/commons-dbcp@1.4?type=jar">
      <dependency ref="pkg:maven/commons-pool/commons-pool@1.5.4?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/javax.jdo/jdo-api@3.0.1?type=jar">
      <dependency ref="pkg:maven/javax.transaction/jta@1.1?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/javax.transaction/jta@1.1?type=jar"/>
    <dependency ref="pkg:maven/org.datanucleus/javax.jdo@3.2.0-m3?type=jar">
      <dependency ref="pkg:maven/javax.transaction/transaction-api@1.1?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/javax.transaction/transaction-api@1.1?type=jar"/>
    <dependency ref="pkg:maven/org.apache.hive/hive-serde@2.3.10?type=jar">
      <dependency ref="pkg:maven/org.apache.commons/commons-lang3@3.19.0?type=jar"/>
      <dependency ref="pkg:maven/net.sf.opencsv/opencsv@2.3?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/net.sf.opencsv/opencsv@2.3?type=jar"/>
    <dependency ref="pkg:maven/org.apache.hive/hive-shims@2.3.10?type=jar">
      <dependency ref="pkg:maven/org.apache.hive.shims/hive-shims-common@2.3.10?type=jar"/>
      <dependency ref="pkg:maven/org.apache.hive.shims/hive-shims-0.23@2.3.10?type=jar"/>
      <dependency ref="pkg:maven/org.apache.hive.shims/hive-shims-scheduler@2.3.10?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.hive.shims/hive-shims-common@2.3.10?type=jar">
      <dependency ref="pkg:maven/org.apache.commons/commons-lang3@3.19.0?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.hive.shims/hive-shims-0.23@2.3.10?type=jar">
      <dependency ref="pkg:maven/org.apache.hive.shims/hive-shims-common@2.3.10?type=jar"/>
      <dependency ref="pkg:maven/org.apache.commons/commons-lang3@3.19.0?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.hive.shims/hive-shims-scheduler@2.3.10?type=jar">
      <dependency ref="pkg:maven/org.apache.hive.shims/hive-shims-common@2.3.10?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.httpcomponents/httpclient@4.5.14?type=jar">
      <dependency ref="pkg:maven/org.apache.httpcomponents/httpcore@4.4.16?type=jar"/>
      <dependency ref="pkg:maven/commons-codec/commons-codec@1.19.0?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.httpcomponents/httpcore@4.4.16?type=jar"/>
    <dependency ref="pkg:maven/org.apache.thrift/libthrift@0.16.0?type=jar">
      <dependency ref="pkg:maven/org.apache.httpcomponents/httpclient@4.5.14?type=jar"/>
      <dependency ref="pkg:maven/org.apache.httpcomponents/httpcore@4.4.16?type=jar"/>
      <dependency ref="pkg:maven/org.apache.commons/commons-lang3@3.19.0?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.thrift/libfb303@0.9.3?type=jar">
      <dependency ref="pkg:maven/org.apache.thrift/libthrift@0.16.0?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.derby/derbytools@10.16.1.1?type=jar">
      <dependency ref="pkg:maven/org.apache.derby/derbyshared@10.16.1.1?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.hive/hive-cli@2.3.10?type=jar">
      <dependency ref="pkg:maven/commons-cli/commons-cli@1.10.0?type=jar"/>
      <dependency ref="pkg:maven/org.apache.commons/commons-lang3@3.19.0?type=jar"/>
      <dependency ref="pkg:maven/jline/jline@2.14.6?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.hive/hive-jdbc@2.3.10?type=jar">
      <dependency ref="pkg:maven/org.apache.httpcomponents/httpclient@4.5.14?type=jar"/>
      <dependency ref="pkg:maven/org.apache.httpcomponents/httpcore@4.4.16?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/org.apache.hive/hive-beeline@2.3.10?type=jar">
      <dependency ref="pkg:maven/commons-cli/commons-cli@1.10.0?type=jar"/>
      <dependency ref="pkg:maven/org.apache.commons/commons-lang3@3.19.0?type=jar"/>
      <dependency ref="pkg:maven/commons-io/commons-io@2.21.0?type=jar"/>
      <dependency ref="pkg:maven/jline/jline@2.14.6?type=jar"/>
      <dependency ref="pkg:maven/net.sf.supercsv/super-csv@2.2.0?type=jar"/>
    </dependency>
    <dependency ref="pkg:maven/net.sf.supercsv/super-csv@2.2.0?type=jar"/>
    <dependency ref="pkg:maven/org.apache.hive/hive-service-rpc@4.0.0?type=jar"/>
    <dependency ref="pkg:maven/net.sf.jpam/jpam@1.1?type=jar"/>
  </dependencies>
</bom>
