Professional Documents
Culture Documents
Standardizing SBOMs - Post-Nashville - 09-29-19 PDF
Standardizing SBOMs - Post-Nashville - 09-29-19 PDF
#.#*('$'#/)$#('$((),$'!'#$%')$#!#(*%%!.#'!)&*()$#(
$*),)')($),').'*(#)$$)'.)$.,$' #(*%%$'))'$#$#*(#((
'((*)#)#*#!)'$#)#( #$,#+*!#'!)($',)')'*((%'$%'#!!
+#)!#(#)'"(%!$#)$#())*#)%')($))($),'.)(+!$%'()))
($),'(#*()$'*#"$'#"$'$)')!(%)($$$*'$'#/)$#0(*(#((
"#.'%.(!(.()"(" ())(%'((##*#+$!&*()$#($'!"$()
+'.$#
*))#)$#($*($##).#)#($'$),'
!!$)'!(
#$'")$##
#*('$'#/)$#(,-)#()$*#'()##)($),'$#)#)$)'$%')$#!(.()"()
(*%%!'$""*#)($))($),',)'))&*%"#)(($),'"$').'')!.
(*%%!.#($),' ))(")")($),'+!$%"#))$$!($(.()"$'#/)$#()$(,$
,!! .#(*%%!.#))$$!())'$*#)$#!)$(*%%!.#*)$")
#$'")$##)$
##)
()#'/)$##()$(*%%$')#!%)#)')$#$)'#)
+!$%"#)(((("#)##!.(()$$!(#)$)"'#+%(!)(#-%!$''$(()
"' )
#"!$""$##$'")$#(
$!!$,#(*(($#-%!$'((+'!'#),.(#
#*()$!%*#'()##
'((($),'(*%%!.##$%')$#('( (##*('$'#/)$#(##)()"#"!
#$'")$###
)$(*%%$'))$(*(($!!$,#))((*(($#$#)'$!)))(
(")$*!+#)$$!)$)$$!-#(,)#)($),')$$!($(.()"#($*)$,))
)$*!%)*'((%)$$!)$)$$!#$'")$#-#()#'
$*(*!)$#*('$'#/)$#(#
#()$#!*)(#$'")$#))#!(
$''!)##$##)#'!)#$'")$#$*))($),'()"$+()'$*)(*%%!.##
#)$$%')$#()(!($')!)))
(("!!#$#((%$((!)$!%()
#)')$##$%)$## %"#"#)$
)(("%!(%$((! .#'+#
))"#"!/)$#()$")+#))#)
())#- #.#$'")$#)),!!
##+$!+$+')"($*!(%')!."#($)#$''!)#!# )$)
*))($*!#$)#!*#)
)$(#$)"#))#
(())
))'#$'")$#
$'"$''##$'")$#$*)(%+'($#$($),'".')($+'$''$+'
##*%)
*)$',))#,'+(#$'")$#$*!%'$+
$'-"%!#$'")$#$*),)$"%$##)($#)#$"%$##)((($")# .)$*#'()##)
#)*'$)($),'!# )$#
#)$"%$##)('))(#$'")$#$(#$)#
#%'$+()$'#/)$#!$#)-)$'*#'()##,)$)'($),'$"%$##)(,'#!*.
)+!$%'($)$"%$##)(#+#)#)
("(((#)!)$)*#)$#!).$
(
###)'%'(
$,+'#$'")$#$*)+*!#'!)(#)($),'($*!(%')'$")
(##,
$#('#($+'!!))"#) #$,!$*),))$$$*))+*!#'!).$,)$
")))#'(()!($#($$%')$#!!.*(*!#.$'#/)$#%!###)$*)!/
($'(*').$)'(.()"(,!!#)$+)+)())#$##))#$'")$##)
()$)'+*!#'!)."#"#))+)(*)))"%%#((%'))+).$##!#
##.*)*'%'+(+-()#$
($'!!$)($),'#)#)'%'(
#)$)'##-"%!$$#).%$#$'")$#))$*!$#('$'#!*($##)
()!#(#)'"($')($),',#)(')'#/)$#(##!#(#)'"(
,#+').! *)$'(%+'($#$)($),'))!#(#(-))%$#)$
'!(')$###(!.#!*#)
)!#(#)'"($($),''$$#'#
)$'#/)$#,$*!##$'#/)$#!!).)$*#'()##"%))'"($!#(#$)
(%
($')'#)+'($#($($),').,!!+#)'#)'%'(#*().,!!
1
#
#'+
',"
#
7"""&&&!("
#8
1
-2016
&!&!
$ & %
*16)01543)13
4!.$!2$):).'7)4().4(% %6%,/0-%.4//,).'#/3934%-
.%%$4/!.!,9:%!.$$%4%2-).%4(%2%,%6!.#%/&!.9#(!.'%34/4(/3%,)#%.3%3&2/-/.%6%23)/./&4(%
3/&47!2%4/!./4(%2"544(%'%2-!.%,)#%.3).').&/2-!4)/.7/5,$"%!6!),!",%).4(%3&/24(%$)&&%2%.4
6%23)/.3/&4(%3/&47!2%
).!,,9&/24(/3%7)4(()'(%2!3352!.#%#/.#%2.3).&/2-!4)/.!"/544(%#2%!4/2/&4(%3/&47!2%4(%3/52#%
,/#!4)/./&4(%#/-0/.%.434(!4!2%).#,5$%$).4(%3/&47!2%!.$4(%#/-0),!4)/.$%4!),3/04)/.3!.$4//,3
53%$4/"5),$4(%3/&47!2%7/5,$"%!%842%-%,96!,5!",%490%/&).&/2-!4)/.4/).#,5$%).4(%3).#%
4()3).&/2-!4)/.)334!4)#/.#%4(%3/&47!2%)3#2%!4%$!.$"9-/6).'4(2/5'(4(%3500,9#(!).!,/.'7)4(4(%
3/&47!2%4(!4).&/2-!4)/.7/5,$"%2%!$),9!6!),!",%4/$/7.342%!-#/.35-%23/&4(!43/&47!2%()3490%/&
!3352!.#%).&/2-!4)/.)3/.%4(!47/5,$"%6%29$)&&)#5,4)&./4)-0/33)",%4//"4!)./4(%27)3%
3!'%#%.!2)/3&/2%.$53%253%/&3
3!'%#%.!2)/
(%,0).'0!24)%35.!-")'5/53,92%&%24/42!.3&%2/2052#(!3%!30%#)&)#3/&47!2%
#/-0/.%.47/5,$2%15)2%4(%!"),)494/!24)#5,!4%4(%#/-0/.%.4!54(/2#/-0/.%.4.!-%!.$4(%6%23)/./&
4(%3/&47!2%!37%,,!3/4(%2#/-0/.%.434(!4-!9"%54),):%$"94(!4#/-0/.%.4/2#/--5.)#!4).'4(!4
4(%2%!2%.//4(%2#/-0/.%.43"%).'54),):%$&4(!4#!../4"%34!4%$4(%.4(%5.+./7.34!4%/&54),):!4)/.
/&/4(%2#/-0/.%.43.%%$34/"%#/--5.)#!4%$(%!54(/2/&4(%3(/5,$!,3/"%#/.6%9%$
!,,/7).')44/"%$)&&%2%.44(!.4(%#/-0/.%.4!54(/2!37%,,!34(%4)-%$!4%/&4(%)43%,&
/.3)$%2!4)/.&/2$%./4).'4(%"!3)3/&4(%).&/2-!4)/.#!0452%$)3"%).'$)3#533%$/2%8!-0,%#2%!4%$
&2/-%)4(%2
!"5),$4//,"490%4//,3#0!23).'!0!#+!'%-!.!'%2/2$-!.5!,%0%.$).'/.4(%
30%#)&)#0!24/&4(%).&/2-!4)/.3/-%!002/!#(%$-!9"%-/2%;!##52!4%</2;2%0%!4!",%<4(!.
/4(%23"54(!6).'4(%).&/2-!4)/.7),,!,,/74(%2%#)0)%.4/&4(%4/-!+%4(%)2/7.!33%33-%.4).!
-/2%342!)'(4&/27!2$-!..%2).!,,9!7!94/").$4(!4).&/2-!4)/.4/4(%!#45!,3/&47!2%!.$02/6)$%!
5.)15%").$).'4/)44(2/5'(%)4(%2!(!3(/&4(%3/&47!2%!/2!-534"%).#,5$%$).4(%
3!'%#%.!2)/
(%,0).'$%4%2-).%7(%4(%2!002/02)!4%#(/)#%37%2%-!$%&/23%#52).'4(%3/&47!2%
$52).'4(%#2%!4)/.02/#%337/5,$2%15)2%).!$$)4)/.4/4(%"!3)#5.!-")'5/532%&%2%.#%).&/2-!4)/.&2/-
3!'%#%.!2)/).&/2-!4)/.!"/544(%#/-0),!4)/.!.$&/2-5,!4)/./04)/.353%$).42!.3&/2-).'4(%
3/52#%#/-0/.%.43!.$0!243).4/4(%2%35,4!.43/&47!2%/2%8!-0,%7%2%!$$2%3330!#%,!9/54
2!.$/-):!4)/.$!4!%8%#54)/.02%6%.4)/.3/,54)/.34(!4-/.)4/2&/234!#+/6%2&,/73/24(!4
).6!,)$!4%72)4%34/!$*!#%.4-%-/29).34!#+3).6/+%$./4(%2%8!-0,%7/5,$"%7(%.$9.!-)#,).+).')3
53%$7(!4)34(%).4%.$%$/0%2!4).'3934%-%.6)2/.-%.4()3).&/2-!4)/.7),,!,,/74(!44(/3%$9.!-)#
,)"2!2)%3).4(%"%4(%30%#)&)#/.%3&/24(!4%.6)2/.-%.46%2353!,,6%23)/.3).!,,97!3
2%02/$5#%!",%#/-0),!4)/.53%$ (%.$/.%&/2%!#(3/&47!2%#/-0/.%.44()3)3+./7.!30%$)'2%%
3!'%#%.!2)/
(%,0).'$%4%2-).%7(%4(%24(%3/&47!2%)3!54(%.4)#7/5,$2%15)2%).!$$)4)/.4/4(%"!3)#
5.!-")'5/532%&%2%.#%).&/2-!4)/.&2/-3!'%#%.!2)/#!0452).').&/2-!4)/.!"/544(%/2'!.):!4)/.3
4(!4(!.$,%$/27%2%).6/,6%$).4(%#2%!4)/./24(%3/52#).'/&4(%3/&47!2%!.$)43#/.34)45%.40!243()3)3
/&4%.2%&%22%$4/!3 !.$&/#53%3/.%34!",)3().'4(%#(!)./Ȗ/$9/&4(%3/&47!2%!.$)3
42!$)4)/.!,,9!##/-0,)3(%$"953).'3)'.).'4%#(.)15%34/6!,)$!4%4(%3/52#%/&%!#()4%-!3)4-/6%3!,/.'
4(%3500,9#(!).
3!'%#%.!2)/
(%,0).'$%4%2-).%7(%4(%24(%3/&47!2%!.$).&/2-!4)/.!2%5.!,4%2%$7/5,$
2%15)2%).!$$)4)/.4/4(%"!3)#5.!-")'5/532%&%2%.#%).&/2-!4)/.&2/-3!'%#%.!2)/).&/2-!4)/.
!"/544(%
/&4(!43/&47!2%)43#/.34)45%.40!243!.$4(%)43%,&!34(%90!33!,/.'4(%3500,9
#(!).()3)3/&4%.!##/-0,)3(%$"953).'!(!3(/&4(%3/&47!2%#/-0/.%.43).4(%!.$53).'
3)'.).'4%#(.)15%34/%.352%4(%).4%'2)49/&4(%!3)40!33%3!,/.'%!#(,).+/&4(%3500,9#(!).&2/-
4(%#2%!4/23/&4(%3/&47!2%4/4(%53%23/&)4
3!'%#%.!2)/
(%,0).'$%4%2-).%7(%4(%24(%0,!..%$53%/&4(%3/&47!2%)4%-)3!,)'.%$7)4()43
).4%,,%#45!,02/0%249#/.342!).437/5,$2%15)2%4(%"!3)#5.!-")'5/532%&%2%.#%).&/2-!4)/.&2/-3!'%
#%.!2)/!.$4(%,)#%.3%3&/24(%3/&47!2%!.$)43#/-0/.%.43()3)3/&4%.!44%-04%$"9-!00).'4(%
).&/2-!4)/.!6!),!",%).05",)#/0%.3/52#%2%0/3)4/2)%3!"/54#522%.4,)#%.3%4%2-3&/24(%3/&47!2%
#/-0/.%.43"54(!6).'4(%).&/2-!4)/.&/2!30%#)&)#0)%#%/&3/&47!2%).#,5$%$).4(%7/5,$
*
%*().
""
"
!
$).#()-,+#)+
1+"/"'7'+%4'1&'+1&##3#),-*#+1,,)'+%!,0601#*
#)'*'+1#2+!#/1'+16+")'*'11&#""'1',+)#$$,/1+##"#"1,, 1'+21&,/'11'3#'+$,/*1',+2-,+4&'!&1,
*(#"#!'0',+0
0%#!#+/',&#)-'+%"#1#/*'+#4&#/1&#/#/#+6
'+0,$14/#
'1#*,/+6,$1&#!,+01'12#+1-/104,2)"/#.2'/#1&# 0'!2+* '%2,20/#$#/#+!#'+$,/*1',+$/,*0%#
!#+/',#1#/*'+'+%4&#/1&#/#/#(+,4+32)+#/ ')'1'#0'0+,/*))6!!,*-)'0&#" 6*--'+%1&#
2-1,"1#'+$,/*1',+3') )#'+-2 )'!)6(+,4+32)+#/ ')'16/#-,0'1,/'#0 ,21(+,4+32)+#/ ')'1'#01,
1�,$14/#!,*-,+#+10'+0,$14/#'1#*6#+!,2/%'+%'+"#5'+%-2 )'!/#-,0'1,/'#04'1&
'"#+1'1'#01&'0*--'+%4')) #*,/##$$#!1'3#+"#$$'!'#+1+"-,00' )621,*1 )#-12/'+%+"
!,+3#6'+%'+$,/*1',+ ,211&#+,+'*-!1,$32)+#/ ')'1'#0'+'+!,/-,/1#"!,*-,+#+10'0,$01/,+%
'+1#/#01+"!,2)" #!!,**,"1#" 6'+!)2"'+%+,1#0!,**#+1$'#)"4&#/#011#*#+10 ,2102!&
+)60'0!,2)" #!,+3#6#"
0%#!#+/',
&#)-'+%"#1#/*'+#4&#/1�,$14/#+"'10!,*-,+#+10/#
4,2)"/#.2'/#1&# 0'!2+* '%2,20/#$#/#+!#'+$,/*1',+$/,*0%#!#+/', 214,2)" #!,//#)1#"
1,1&1'+$,/*1',++,1'+!)2"#"'+1&#'10#)$&'0'0!2//#+1)6!!,*-)'0&#"#'1&#/ 61&#"#3#),-'+%
,/%+'71',+,/+,1&#/-/,3'"'+%1&#/#02)10,$011'!"6+*'!1&/#1+",1&#/#3)21',+0+"+)60'0
+"-/,3'"'+%+002/+!#!0#/#-/#0#+1'+%&,41&#!)'*0,$0$#160#!2/'16+"/#0')'#+!#/#02--,/1#"
6#3'"#+!#1&20-/,3'"'+%#3'"#+!# 0#" ,211�,$14/#1'#"1,1&#$,/1&#
0,$14/#
0%#!#+/',&#)-'+%"#1#/*'+#4&11�,$14/#-/,3'"'+%0#/3'!#'011&#-,'+1,$#5#!21',+4,2)"
/#.2'/#1&# 0'!2+* '%2,20/#$#/#+!#'+$,/*1',+$/,*0%#!#+/',&'0!,2)" #!!,*-)'0&#" 6
1�#/3'!#-/,3'"'+%1�%#!#+/','+$,/*1',+$,//!&'3)),%%'+%11&#-,'+11&10,$14/#
0#/3'!#'0'+3,(#"0,'14,2)" #3') )#$,//#1/,0-#!1'3#+)60'0 ,2132)+#/ ')'1'#0$,2+"1,&3# ##+
'+1�,$14/#1&14020#" 61�#/3'!#3'+%1&'0'+$,/*1',+4,2)")),4$2/1&#/+)60'0,$4&#/
1 )+#/ ')'16'+1�#/3'!#40#5-),'1#"4&#+1&#,/%+'71',+20#"'1&'0",#0+,1/#-)!#1&#+##"1,
'+3#01'%1#1&#$2))$2+!1',+)'16,$1�#/3'!# #'+%'+3,(#"+"&3'+%!,+$'"#+!#1&1'10$2+!1',+)'16
",#0+,1'+!)2"#&/*$2)!- ')'1'#0$0%#!#+/',0
+"/#,$'+1#/#011,+,/%+'71',+1&#
$'#)"0+##"#"1,-/,3'"#-#"'%/##-/,3#++!#'+1#%/'16+"'+1#))#!12)-/,-#/16!,+01/'+104,2)"+##"1,
#),%%#"
0%#!#+/',#)-'+%"#1#/*'+#4&#//#.2'/#""#0'/#"0#.2#+!#,$01#-0$,/1�,$14/#+"'10
!,*-,+#+10&0 ##+!,*-)#1#"'+0-#!'$'#",/"#/+"4'1&+,""'1',+)01#-04,2)"/#.2'/#'+""'1',+
1,1&# 0'!2+* '%2,20/#$#/#+!#'+$,/*1',+$/,*0%#!#+/',+"1&#-/,3#++!#'+$,/*1',+
$/,*0%#!#+/',
)'01,$,/"#/#"01#-0+"/#.2'/#*#+10$,/#!&01#-&'0'+$,/*1',+'0/#$#//#"1,
0
+"-/,3'"#0002/+!#1,1&#",4+01/#*!,+02*#/01&10,$14/#&0
!,*-)#1#"#5-#!1#"/#.2'/#"01#-0+"1&1+,2+#5-#!1#"+"-,1#+1'))6*)'!',2001#-0&3# ##+
'+0#/1#"'+1,1&#",!2*#+1#"02--)6!&'+0#.2#+!#&'0!,2)" #,$%/#121')'164&#/#3)'"1'+%4&#/
1�-#!'$'#"1,,)!&'+,$#3#!-0#+3'/,+*#+14#/#$,)),4#"
+ )'+%,,)1,,,)5!&+%#0
,#+ )#1,,)1,1,,)20#4'1&'+1&#'1#/1'3#0,$14/#"#3#),-*#+1'+1#%/1',++"1#01'+%#!,0601#*,$
1,,)03#/60*))01+"/"$,/*101/2!12/#1&11�,$14/#1,,)#!,0601#*!+21')'7#01*,3#
!,"#+"!,*-,+#+101&/,2%&1&#'/4,/($),40$/,*-/1+#/1,,)1,-/1+#/1,,)'0-/2"#+1+"#00#+1')
&#+0,*#,+#1"#3#),-*#+10&,-&0+##"1,#51#/+)'7#1&#'+$,/*1',+1&#$')#
$,/*1+"01/2!12/# *6 #!- )#+"--/,-/'1#$,/1&1#5-,/11',+ 21'+"'0!200',+04'1&
*+6,$1�,$14/#"#3#),-*#+11,,)!/#1,/01",+10##*1,0###'1&#/,/00,*#1&'+%
9
#&!#'1
42" #@" '+#$+." '/" .A
:
*,
.8?==7/9*978;"#""" #"!#"#&!# #(#"##
#-!
#! !#1
2>7<7*$"!#!##! !
#&!
##1
2"@+!.87+<79>.
++>7<7A
:
3978?! !#+!#"!"!%+ !%!$")"#!$##+" *08?/78>=</8<
&!$,!
)&!&("# !&""!"%+%&
&+)"''&,!&$!+)&!&$" '!&+)!!&$&!)&"&$&""%
!&(!&$!'%"%&!$
%+&"&&!"!%%&!&!$"'#&!& $&!
"(!"&%&&"&#%&%!%%%#+&$'"&%"&)$#$"(!!!"
'%&"+!"$ &"!!&#$"$ '&"!" #&"!"%!"$ &"!%!&%
*&$ +$&"$"($"$*&$&&&!"$ &"!'$&+!"!%%&!&+&$&&
"&)$("# !&""!"%+%&
%&"$+%"&)$)%$&$" %$&%&$&!)&! #&+!&!$&!&"($
%!!")"&!'!&"!&++#* #%!'%#!'!%"!!
!&$&"!%)&&'%$'%$!&$%&"$!!$&$(!!"$ &"!!" '!&"!)&"&$
##&"!%!%$(%%)%"&!$-"'%#!.&(&%!&)&)(
!"#$&"!+!&%"&)$&&#$"$ %)!'%"&)$)%" #!&"!$+"$
&&)"'$'!"!&&$&%+%& '&,!%&!$!&$%)&&"#$&!%+%& &$"'%&!$
$$%!'!&"!%&&)$!&&& "" #&"!
'$#&%&&+#" #"!!&%
"%"&)$" #&"!!($"! !&
!&%&+#"("# !&!($"! !&&" #$%& !&"""!)&&"&"$&&
#$"(%& !% %"$$&!! "+!&%"'$%% !" #"!!&%!&'$!)"$
)&&"$#"%&"$%&&"#!%"'$!#'$%" #"!!&%" $" !&$&("# !&
!($"! !&%%$%'&%" "$"$&!"&"$%&&$"&!'%%&("# !&
&""""!$!&$#$%%!"'%"!$"'#%
"!& #"$$+##$"&"'! '"&"+/%%"&)$%("(&")$% "$"!%% +
!$! !&##$")$&("# !&%&$&%)&!-"&%.$ )"$&&%%
!#'&"'&#'&%$!!!"'%#!!!&$&"!%$+!#!&$&"!%)&"%&
"#$&!%+%& $$+ # !&!&("#$! &+)"$&"%)&%'##"$&!
'!&"!" #"!!&%$!"$&%###&"!'!&"!&+&+$$&! &"!+
&##&"!%!&"$"$$!&!($"! !&%%'% )"' ""$"&$%
)&##$"#$&"$%&$&"!"#&"$ %#($%"!%!&'$%$"'&&"&$%#$&"&'
#&%
&&%%&+"("# !&&&+&"!!%!!"$ &"!!('!$&+!"$ &"!"$&
&$#$&+" #"!!&%!$ )"$%!" $& !&"!"$!,&"!/%'"#$&"!%
+
%*()/
""
"
!
$)/#().-,#),
1+!/!&7&+$4&1%&+1%""3"),-*"+1,,)&+$ ,0601"*
Vulnerability
Information
Licensing
Package Repos Information
(Public & Private)
Test
Source Code
Repos
(Public & Private)
Operations
&+))61%"0,#14/"1%1&0 /"1"!,/*,!&#&"!4&))+""!1,"1"01"!+!%,-"#2))6-21&+1,,-"/1&,+0
&$2/" &))201/1"01%"+2*"/,20-1%01%10,#14/" ,*-,+"+10,/&+#,/*1&,+,210,#14/"
,*-,+"+10 +""5-" 1"!1,#),4"14""+1%/,2$%,211%"!&##"/"+1-/10,#1%"0,#14/"!"3"),-*"+1
1,,)&+$" ,0601"*
%",#14/""3"),-*"+1,,)&+$ ,0601"*"*"//$+&71&,+0
&1%&+1%"3/&,20$/,2-&+$,# -&)&1&"0!"-& 1"!&+&$2/" 1%"/"/"*+6-/,!2 10,1%,-"+0,2/ "
+! ),0"!0,2/ "1%14,2)!+""!1,&+ ,/-,/1"+1&3"/")1"!&)&1&"01, /"1"*+&-2)1"
*+$"1"01+! ,+1/,)1%"0,#14/"+!&10,/1%"#,/"0"")"#212/")/$"21%,-"#2))6
!&*&+&0%&+$*,2+1,#1%"0,#14/" ,*-,+"+103&))"#,//"20"61%&/!-/1&"04&))+,1%3"0
/"1"!61%",/&$&+)21%,/&+$,/$+&71&,++!0,1%",#14/",*-,0&1&,++)60&0 ,**2+&16
&!"+1&#&"!"),44&))",#1"+/")&"!2-,+1, /"1"+!-,-2)1"0#,/1%"0" ,*-,+"+10%"
,'" 1&3",#1%&0"##,/1&01,%3",+"01/2 12/"1%1,1% ,**2+&1&"0 +)"3"/$"+!-/,3&!"0
4%"/"!"0&/"!%"#,)),4&+$0&51)"0-/,3&!")&01&+$0,#1%" -&)&1&"03&))"1,!61,02--,/1
!"3"),-*"+1+! ,*-,0&1&,++)60&0"##,/10
%"
1)"0&))201/1"0,*",#1%" 2//"+1*"*"/0,#0 /*"4,/(0
),2!,,)0,2/ "
,!" ($""-,0&1,/&"02&)!%,/",$/-%6-&)&1&"0+!
,#14/",*-,0&1&,++)60&0
-&)&1&"0!!&1&,+)1)"0#,/1"01&+$1,,)0+!,-"/1&,+)*+$"*"+11,,)01%1 ,2)!21&)&7"+!
)"3"/$"04&))" /"1"!01%1!1&0$1%"/"!
$ !!
4 ')'- ''( +4"* !*,$&$!&
&,$) )0&!&
?,!$) ,0'&!$* ,4"*
&*!$ "&'
)-$ ()!& %)!
( ()# ),($ '4"* &*')$'.
4 /()** &* ') 50')
''+*+)( $*# ,((+ &!+0
$,++) ++!- &)$&!&
%
1,) $',',&)0 .+ +
',!$ ''$$',,!$ !-'+$
&
"
%1'& '* ''$'&+!&)
,& ( -&&
**%$ '#) !*+)0 -& ',)')
1,)'&+!&) !+ , )')+!+')0 /,*7'&+0(8 ',)('
!*+)0 !+
)')0 )!+') ,-)*!'&
&*+$# $!+ !&' )'"+
'#) &,$
!+,#+ ,)&+* ('*!+')0 '*+!&
' "
&*!$ ,!$)''+ +)!) )&+
,+')!+ !)$
!+$
%!+0
%'' # ' ))')%
!+)!* ),!*'&+)'$
&+)!+0 )-!*
,!$#!+ !&$,!$) &#!&* )&'
(
$#,#'+.)'%('*!+!'& $/+'
&*!+7$/)8 '&+0(
&$0*!*70&'(*0*8
'& &&$ &0#
! $! +7'+.)8
&*!&)0 !+',)
!&+++ ',)$)
@
9><=C
')(')+!'&4$$)! +*)*)-4(()'-'),$!$*2!*+)!,+!'&&$!%!+4*'3=C6<=BA@6=>
'!%-!'"'*%"'%&&*'!'
"&,&'
"'!'
!'&'"&(##"%''&%&!%"&
'!'!!&!%"&&(&&"!#&! "'&##%'%*%&)% !'&"
!"% '"!&%&'&!%"&*%"%'""*!*'' #''"#'(%' !
!'&'"&(##"%''&&&%#"'!' !'&&"*!!' "(%
* ##'"'&&',%!"%!(%%!''"('&"!+'%!!"% '"!''*"(
"%%''"'*&"*!!'%'&"'&(&$(!'(%&
'%"(
&!%"
,
$)'(.
""
"
!(.#'(-,+#(*
-
$)'(.
""
"
!(.#'(-,+#(*
.
$)'(.
""
"
!(.#'(-,+#(*
('
$)'(.
""
"
!(.#'(-,+#(*
!
!
((
$)'(.
""
"
!(.#'(-,+#(*