Skip to content

Commit 8c23dbf

Browse files
Merge pull request #373 from marvin-hansen/main
Updated SBOM for all crates.
2 parents 3d62fa8 + beb7ba8 commit 8c23dbf

File tree

24 files changed

+1429
-1523
lines changed

24 files changed

+1429
-1523
lines changed

deep_causality/sbom.spdx.json

Lines changed: 144 additions & 108 deletions
Original file line numberDiff line numberDiff line change
@@ -1,20 +1,20 @@
11
{
22
"SPDXID": "SPDXRef-DOCUMENT",
33
"creationInfo": {
4-
"created": "2025-09-25T08:37:40Z",
4+
"created": "2025-11-03T05:27:30Z",
55
"creators": [
66
"Tool: cargo-sbom-v0.10.0"
77
]
88
},
99
"dataLicense": "CC0-1.0",
10-
"documentNamespace": "https://spdx.org/spdxdocs/deep_causality-38b3b83f-71c6-46fd-b32a-af26b84c3171",
10+
"documentNamespace": "https://spdx.org/spdxdocs/deep_causality-560e1bb7-36b6-4b65-b614-9331c9d083a3",
1111
"files": [
1212
{
1313
"SPDXID": "SPDXRef-File-deep_causality",
1414
"checksums": [
1515
{
1616
"algorithm": "SHA1",
17-
"checksumValue": "8b4f6265dafc3ded58f148ce9a097f17a066811c"
17+
"checksumValue": "83f960491ec328db80c3735ce6e87f297ebc451a"
1818
}
1919
],
2020
"fileName": "./Cargo.lock",
@@ -27,47 +27,45 @@
2727
"name": "deep_causality",
2828
"packages": [
2929
{
30-
"SPDXID": "SPDXRef-Package-libc-0.2.175",
31-
"description": "Raw FFI bindings to platform libraries like libc.",
30+
"SPDXID": "SPDXRef-Package-getrandom-0.3.4",
31+
"description": "A small cross-platform library for retrieving random data from system source",
3232
"downloadLocation": "registry+https://github.com/rust-lang/crates.io-index",
3333
"externalRefs": [
3434
{
3535
"referenceCategory": "PACKAGE-MANAGER",
36-
"referenceLocator": "pkg:cargo/libc@0.2.175",
36+
"referenceLocator": "pkg:cargo/getrandom@0.3.4",
3737
"referenceType": "purl"
3838
}
3939
],
4040
"licenseConcluded": "MIT OR Apache-2.0",
4141
"licenseDeclared": "MIT OR Apache-2.0",
42-
"name": "libc",
43-
"versionInfo": "0.2.175"
42+
"name": "getrandom",
43+
"versionInfo": "0.3.4"
4444
},
4545
{
46-
"SPDXID": "SPDXRef-Package-deep--causality--data--structures-0.10.1",
47-
"description": "Data structures for for deep_causality crate.",
48-
"downloadLocation": "NONE",
49-
"licenseConcluded": "MIT",
50-
"licenseDeclared": "MIT",
51-
"name": "deep_causality_data_structures",
52-
"versionInfo": "0.10.1"
46+
"SPDXID": "SPDXRef-Package-wasip2-1.0.1-plus-wasi-0.2.4",
47+
"description": "WASIp2 API bindings for Rust",
48+
"downloadLocation": "registry+https://github.com/rust-lang/crates.io-index",
49+
"externalRefs": [
50+
{
51+
"referenceCategory": "PACKAGE-MANAGER",
52+
"referenceLocator": "pkg:cargo/[email protected]%2Bwasi-0.2.4",
53+
"referenceType": "purl"
54+
}
55+
],
56+
"licenseConcluded": "Apache-2.0 OR Apache-2.0 OR MIT",
57+
"licenseDeclared": "Apache-2.0 OR Apache-2.0 OR MIT",
58+
"name": "wasip2",
59+
"versionInfo": "1.0.1+wasi-0.2.4"
5360
},
5461
{
55-
"SPDXID": "SPDXRef-Package-deep--causality--rand-0.1.2",
62+
"SPDXID": "SPDXRef-Package-deep--causality--rand-0.1.3",
5663
"description": "Random number utils for for deep_causality crate.",
5764
"downloadLocation": "NONE",
5865
"licenseConcluded": "MIT",
5966
"licenseDeclared": "MIT",
6067
"name": "deep_causality_rand",
61-
"versionInfo": "0.1.2"
62-
},
63-
{
64-
"SPDXID": "SPDXRef-Package-deep--causality--num-0.1.2",
65-
"description": "Number utils for for deep_causality crate.",
66-
"downloadLocation": "NONE",
67-
"licenseConcluded": "MIT",
68-
"licenseDeclared": "MIT",
69-
"name": "deep_causality_num",
70-
"versionInfo": "0.1.2"
68+
"versionInfo": "0.1.3"
7169
},
7270
{
7371
"SPDXID": "SPDXRef-Package-r-efi-5.3.0",
@@ -87,62 +85,54 @@
8785
"versionInfo": "5.3.0"
8886
},
8987
{
90-
"SPDXID": "SPDXRef-Package-wasi-0.14.7-plus-wasi-0.2.4",
91-
"description": "WASI API bindings for Rust",
88+
"SPDXID": "SPDXRef-Package-deep--causality--num-0.1.5",
89+
"description": "Number utils for for deep_causality crate.",
90+
"downloadLocation": "NONE",
91+
"licenseConcluded": "MIT",
92+
"licenseDeclared": "MIT",
93+
"name": "deep_causality_num",
94+
"versionInfo": "0.1.5"
95+
},
96+
{
97+
"SPDXID": "SPDXRef-Package-cfg-if-1.0.3",
98+
"description": "A macro to ergonomically define an item depending on a large number of #[cfg]\nparameters. Structured like an if-else chain, the first matching branch is the\nitem that gets emitted.\n",
9299
"downloadLocation": "registry+https://github.com/rust-lang/crates.io-index",
93100
"externalRefs": [
94101
{
95102
"referenceCategory": "PACKAGE-MANAGER",
96-
"referenceLocator": "pkg:cargo/[email protected]%2Bwasi-0.2.4",
103+
"referenceLocator": "pkg:cargo/[email protected]",
97104
"referenceType": "purl"
98105
}
99106
],
100-
"licenseConcluded": "Apache-2.0 OR Apache-2.0 OR MIT",
101-
"licenseDeclared": "Apache-2.0 OR Apache-2.0 OR MIT",
102-
"name": "wasi",
103-
"versionInfo": "0.14.7+wasi-0.2.4"
107+
"licenseConcluded": "MIT OR Apache-2.0",
108+
"licenseDeclared": "MIT OR Apache-2.0",
109+
"name": "cfg-if",
110+
"versionInfo": "1.0.3"
104111
},
105112
{
106-
"SPDXID": "SPDXRef-Package-wasip2-1.0.1-plus-wasi-0.2.4",
107-
"description": "WASIp2 API bindings for Rust",
113+
"SPDXID": "SPDXRef-Package-libc-0.2.175",
114+
"description": "Raw FFI bindings to platform libraries like libc.",
108115
"downloadLocation": "registry+https://github.com/rust-lang/crates.io-index",
109116
"externalRefs": [
110117
{
111118
"referenceCategory": "PACKAGE-MANAGER",
112-
"referenceLocator": "pkg:cargo/[email protected]%2Bwasi-0.2.4",
119+
"referenceLocator": "pkg:cargo/[email protected]",
113120
"referenceType": "purl"
114121
}
115122
],
116-
"licenseConcluded": "Apache-2.0 OR Apache-2.0 OR MIT",
117-
"licenseDeclared": "Apache-2.0 OR Apache-2.0 OR MIT",
118-
"name": "wasip2",
119-
"versionInfo": "1.0.1+wasi-0.2.4"
123+
"licenseConcluded": "MIT OR Apache-2.0",
124+
"licenseDeclared": "MIT OR Apache-2.0",
125+
"name": "libc",
126+
"versionInfo": "0.2.175"
120127
},
121128
{
122-
"SPDXID": "SPDXRef-Package-ultragraph-0.8.7",
123-
"description": "Hypergraph data structure.",
129+
"SPDXID": "SPDXRef-Package-deep--causality--data--structures-0.10.2",
130+
"description": "Data structures for for deep_causality crate.",
124131
"downloadLocation": "NONE",
125-
"homepage": "https://github.com/deepcausality/deep_causality/tree/main/ultragraph",
126132
"licenseConcluded": "MIT",
127133
"licenseDeclared": "MIT",
128-
"name": "ultragraph",
129-
"versionInfo": "0.8.7"
130-
},
131-
{
132-
"SPDXID": "SPDXRef-Package-cfg-if-1.0.3",
133-
"description": "A macro to ergonomically define an item depending on a large number of #[cfg]\nparameters. Structured like an if-else chain, the first matching branch is the\nitem that gets emitted.\n",
134-
"downloadLocation": "registry+https://github.com/rust-lang/crates.io-index",
135-
"externalRefs": [
136-
{
137-
"referenceCategory": "PACKAGE-MANAGER",
138-
"referenceLocator": "pkg:cargo/[email protected]",
139-
"referenceType": "purl"
140-
}
141-
],
142-
"licenseConcluded": "MIT OR Apache-2.0",
143-
"licenseDeclared": "MIT OR Apache-2.0",
144-
"name": "cfg-if",
145-
"versionInfo": "1.0.3"
134+
"name": "deep_causality_data_structures",
135+
"versionInfo": "0.10.2"
146136
},
147137
{
148138
"SPDXID": "SPDXRef-Package-wit-bindgen-0.46.0",
@@ -162,111 +152,157 @@
162152
"versionInfo": "0.46.0"
163153
},
164154
{
165-
"SPDXID": "SPDXRef-Package-deep--causality--uncertain-0.2.3",
155+
"SPDXID": "SPDXRef-Package-deep--causality-0.11.7",
156+
"description": "Computational causality library. Provides causality graph, collections, context and causal reasoning.",
157+
"downloadLocation": "NONE",
158+
"homepage": "https://deepcausality.com/about/",
159+
"licenseConcluded": "MIT",
160+
"licenseDeclared": "MIT",
161+
"name": "deep_causality",
162+
"versionInfo": "0.11.7"
163+
},
164+
{
165+
"SPDXID": "SPDXRef-Package-deep--causality--uncertain-0.3.3",
166166
"description": "A First-Order Type for Uncertain Programming for the DeepCausality project.'",
167167
"downloadLocation": "NONE",
168168
"licenseConcluded": "MIT",
169169
"licenseDeclared": "MIT",
170170
"name": "deep_causality_uncertain",
171-
"versionInfo": "0.2.3"
171+
"versionInfo": "0.3.3"
172172
},
173173
{
174-
"SPDXID": "SPDXRef-Package-deep--causality-0.11.4",
175-
"description": "Computational causality library. Provides causality graph, collections, context and causal reasoning.",
174+
"SPDXID": "SPDXRef-Package-deep--causality--tensor-0.1.6",
175+
"description": "Tensor data structure for for deep_causality crate.",
176176
"downloadLocation": "NONE",
177-
"homepage": "https://deepcausality.com/about/",
178177
"licenseConcluded": "MIT",
179178
"licenseDeclared": "MIT",
180-
"name": "deep_causality",
181-
"versionInfo": "0.11.4"
179+
"name": "deep_causality_tensor",
180+
"versionInfo": "0.1.6"
182181
},
183182
{
184-
"SPDXID": "SPDXRef-Package-getrandom-0.3.3",
185-
"description": "A small cross-platform library for retrieving random data from system source",
186-
"downloadLocation": "registry+https://github.com/rust-lang/crates.io-index",
187-
"externalRefs": [
188-
{
189-
"referenceCategory": "PACKAGE-MANAGER",
190-
"referenceLocator": "pkg:cargo/[email protected]",
191-
"referenceType": "purl"
192-
}
193-
],
194-
"licenseConcluded": "MIT OR Apache-2.0",
195-
"licenseDeclared": "MIT OR Apache-2.0",
196-
"name": "getrandom",
197-
"versionInfo": "0.3.3"
183+
"SPDXID": "SPDXRef-Package-deep--causality--haft-0.2.1",
184+
"description": "HKT traits for for the deep_causality crate.",
185+
"downloadLocation": "NONE",
186+
"licenseConcluded": "MIT",
187+
"licenseDeclared": "MIT",
188+
"name": "deep_causality_haft",
189+
"versionInfo": "0.2.1"
190+
},
191+
{
192+
"SPDXID": "SPDXRef-Package-deep--causality--ast-0.1.0",
193+
"description": "AST data structure for deep_causality crate.",
194+
"downloadLocation": "NONE",
195+
"licenseConcluded": "MIT",
196+
"licenseDeclared": "MIT",
197+
"name": "deep_causality_ast",
198+
"versionInfo": "0.1.0"
199+
},
200+
{
201+
"SPDXID": "SPDXRef-Package-ultragraph-0.8.8",
202+
"description": "Hypergraph data structure.",
203+
"downloadLocation": "NONE",
204+
"homepage": "https://github.com/deepcausality/deep_causality/tree/main/ultragraph",
205+
"licenseConcluded": "MIT",
206+
"licenseDeclared": "MIT",
207+
"name": "ultragraph",
208+
"versionInfo": "0.8.8"
198209
}
199210
],
200211
"relationships": [
201212
{
202-
"relatedSpdxElement": "SPDXRef-Package-deep--causality--data--structures-0.10.1",
213+
"relatedSpdxElement": "SPDXRef-Package-deep--causality--tensor-0.1.6",
203214
"relationshipType": "DEPENDS_ON",
204-
"spdxElementId": "SPDXRef-Package-deep--causality-0.11.4"
215+
"spdxElementId": "SPDXRef-Package-deep--causality-0.11.7"
205216
},
206217
{
207-
"relatedSpdxElement": "SPDXRef-Package-deep--causality--num-0.1.2",
218+
"relatedSpdxElement": "SPDXRef-Package-deep--causality--num-0.1.5",
208219
"relationshipType": "DEPENDS_ON",
209-
"spdxElementId": "SPDXRef-Package-deep--causality--rand-0.1.2"
220+
"spdxElementId": "SPDXRef-Package-deep--causality-0.11.7"
210221
},
211222
{
212-
"relatedSpdxElement": "SPDXRef-Package-wasi-0.14.7-plus-wasi-0.2.4",
223+
"relatedSpdxElement": "SPDXRef-Package-cfg-if-1.0.3",
213224
"relationshipType": "DEPENDS_ON",
214-
"spdxElementId": "SPDXRef-Package-getrandom-0.3.3"
225+
"spdxElementId": "SPDXRef-Package-getrandom-0.3.4"
215226
},
216227
{
217-
"relatedSpdxElement": "SPDXRef-Package-deep--causality--rand-0.1.2",
228+
"relatedSpdxElement": "SPDXRef-Package-getrandom-0.3.4",
218229
"relationshipType": "DEPENDS_ON",
219-
"spdxElementId": "SPDXRef-Package-deep--causality--uncertain-0.2.3"
230+
"spdxElementId": "SPDXRef-Package-deep--causality--rand-0.1.3"
231+
},
232+
{
233+
"relatedSpdxElement": "SPDXRef-Package-r-efi-5.3.0",
234+
"relationshipType": "DEPENDS_ON",
235+
"spdxElementId": "SPDXRef-Package-getrandom-0.3.4"
220236
},
221237
{
222238
"relatedSpdxElement": "SPDXRef-File-deep_causality",
223239
"relationshipType": "DESCRIBES",
224240
"spdxElementId": "SPDXRef-DOCUMENT"
225241
},
226242
{
227-
"relatedSpdxElement": "SPDXRef-Package-deep--causality--uncertain-0.2.3",
243+
"relatedSpdxElement": "SPDXRef-Package-deep--causality--uncertain-0.3.3",
244+
"relationshipType": "DEPENDS_ON",
245+
"spdxElementId": "SPDXRef-Package-deep--causality-0.11.7"
246+
},
247+
{
248+
"relatedSpdxElement": "SPDXRef-Package-deep--causality-0.11.7",
249+
"relationshipType": "GENERATED_FROM",
250+
"spdxElementId": "SPDXRef-File-deep_causality"
251+
},
252+
{
253+
"relatedSpdxElement": "SPDXRef-Package-libc-0.2.175",
228254
"relationshipType": "DEPENDS_ON",
229-
"spdxElementId": "SPDXRef-Package-deep--causality-0.11.4"
255+
"spdxElementId": "SPDXRef-Package-getrandom-0.3.4"
230256
},
231257
{
232-
"relatedSpdxElement": "SPDXRef-Package-getrandom-0.3.3",
258+
"relatedSpdxElement": "SPDXRef-Package-deep--causality--data--structures-0.10.2",
233259
"relationshipType": "DEPENDS_ON",
234-
"spdxElementId": "SPDXRef-Package-deep--causality--rand-0.1.2"
260+
"spdxElementId": "SPDXRef-Package-deep--causality-0.11.7"
235261
},
236262
{
237-
"relatedSpdxElement": "SPDXRef-Package-cfg-if-1.0.3",
263+
"relatedSpdxElement": "SPDXRef-Package-deep--causality--rand-0.1.3",
264+
"relationshipType": "DEPENDS_ON",
265+
"spdxElementId": "SPDXRef-Package-deep--causality--uncertain-0.3.3"
266+
},
267+
{
268+
"relatedSpdxElement": "SPDXRef-Package-deep--causality--num-0.1.5",
269+
"relationshipType": "DEPENDS_ON",
270+
"spdxElementId": "SPDXRef-Package-deep--causality--tensor-0.1.6"
271+
},
272+
{
273+
"relatedSpdxElement": "SPDXRef-Package-ultragraph-0.8.8",
238274
"relationshipType": "DEPENDS_ON",
239-
"spdxElementId": "SPDXRef-Package-getrandom-0.3.3"
275+
"spdxElementId": "SPDXRef-Package-deep--causality-0.11.7"
240276
},
241277
{
242-
"relatedSpdxElement": "SPDXRef-Package-ultragraph-0.8.7",
278+
"relatedSpdxElement": "SPDXRef-Package-deep--causality--haft-0.2.1",
243279
"relationshipType": "DEPENDS_ON",
244-
"spdxElementId": "SPDXRef-Package-deep--causality-0.11.4"
280+
"spdxElementId": "SPDXRef-Package-deep--causality--tensor-0.1.6"
281+
},
282+
{
283+
"relatedSpdxElement": "SPDXRef-Package-deep--causality--ast-0.1.0",
284+
"relationshipType": "DEPENDS_ON",
285+
"spdxElementId": "SPDXRef-Package-deep--causality--uncertain-0.3.3"
245286
},
246287
{
247288
"relatedSpdxElement": "SPDXRef-Package-wasip2-1.0.1-plus-wasi-0.2.4",
248289
"relationshipType": "DEPENDS_ON",
249-
"spdxElementId": "SPDXRef-Package-wasi-0.14.7-plus-wasi-0.2.4"
290+
"spdxElementId": "SPDXRef-Package-getrandom-0.3.4"
250291
},
251292
{
252293
"relatedSpdxElement": "SPDXRef-Package-wit-bindgen-0.46.0",
253294
"relationshipType": "DEPENDS_ON",
254295
"spdxElementId": "SPDXRef-Package-wasip2-1.0.1-plus-wasi-0.2.4"
255296
},
256297
{
257-
"relatedSpdxElement": "SPDXRef-Package-libc-0.2.175",
298+
"relatedSpdxElement": "SPDXRef-Package-deep--causality--num-0.1.5",
258299
"relationshipType": "DEPENDS_ON",
259-
"spdxElementId": "SPDXRef-Package-getrandom-0.3.3"
300+
"spdxElementId": "SPDXRef-Package-deep--causality--rand-0.1.3"
260301
},
261302
{
262-
"relatedSpdxElement": "SPDXRef-Package-deep--causality-0.11.4",
263-
"relationshipType": "GENERATED_FROM",
264-
"spdxElementId": "SPDXRef-File-deep_causality"
265-
},
266-
{
267-
"relatedSpdxElement": "SPDXRef-Package-r-efi-5.3.0",
303+
"relatedSpdxElement": "SPDXRef-Package-deep--causality--num-0.1.5",
268304
"relationshipType": "DEPENDS_ON",
269-
"spdxElementId": "SPDXRef-Package-getrandom-0.3.3"
305+
"spdxElementId": "SPDXRef-Package-deep--causality--uncertain-0.3.3"
270306
}
271307
],
272308
"spdxVersion": "SPDX-2.3"

deep_causality/sbom.spdx.json.sha

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1 @@
1-
ecd565081e20f46f29ed21ab476963de373517e49354af9028874843895c70e1 deep_causality/sbom.spdx.json
1+
4d10ada99a1ddfbac046d492467d35ee9c122e9cd93675bb536f52db1eb6ecdc deep_causality/sbom.spdx.json

0 commit comments

Comments
 (0)