Skip to content

Commit 6256c5d

Browse files
committed
update sbom
1 parent c5768b9 commit 6256c5d

File tree

1 file changed

+110
-63
lines changed

1 file changed

+110
-63
lines changed

sbom/sbom.cdx.json

Lines changed: 110 additions & 63 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,10 @@
11
{
22
"bomFormat": "CycloneDX",
33
"specVersion": "1.6",
4-
"serialNumber": "urn:uuid:82b3e71c-544c-4701-938b-68a8a410f653",
4+
"serialNumber": "urn:uuid:72227cea-41d7-4fa4-9ee8-01b8a35baed7",
55
"version": 1,
66
"metadata": {
7-
"timestamp": "2025-11-06T07:38:38Z",
7+
"timestamp": "2025-11-12T10:03:19Z",
88
"lifecycles": [
99
{
1010
"phase": "build"
@@ -37,13 +37,6 @@
3737
"type": "application",
3838
"name": "compliantkubernetes-apps",
3939
"version": "latest",
40-
"licenses": [
41-
{
42-
"license": {
43-
"id": "Apache-2.0"
44-
}
45-
}
46-
],
4740
"purl": "pkg:generic/compliantkubernetes-apps@latest",
4841
"properties": [
4942
{
@@ -315,13 +308,13 @@
315308
}
316309
},
317310
{
318-
"bom-ref": "pkg:helm/common@2.30.0",
311+
"bom-ref": "pkg:helm/common@2.31.3",
319312
"type": "library",
320313
"supplier": {
321314
"name": "Broadcom, Inc. All Rights Reserved."
322315
},
323316
"name": "common",
324-
"version": "2.30.0",
317+
"version": "2.31.3",
325318
"description": "A Library Helm Chart for grouping common logic between bitnami charts. This chart is not deployable by itself.",
326319
"licenses": [
327320
{
@@ -330,7 +323,38 @@
330323
}
331324
}
332325
],
333-
"purl": "pkg:helm/common@2.30.0",
326+
"purl": "pkg:helm/common@2.31.3",
327+
"properties": [
328+
{
329+
"name": "Elastisys evaluation",
330+
"value": "Not evaluated"
331+
}
332+
],
333+
"evidence": {
334+
"occurrences": [
335+
{
336+
"location": "helmfile.d/upstream/bitnami/thanos/charts/minio/charts/common"
337+
}
338+
]
339+
}
340+
},
341+
{
342+
"bom-ref": "pkg:helm/common@2.31.4",
343+
"type": "library",
344+
"supplier": {
345+
"name": "Broadcom, Inc. All Rights Reserved."
346+
},
347+
"name": "common",
348+
"version": "2.31.4",
349+
"description": "A Library Helm Chart for grouping common logic between bitnami charts. This chart is not deployable by itself.",
350+
"licenses": [
351+
{
352+
"license": {
353+
"id": "Apache-2.0"
354+
}
355+
}
356+
],
357+
"purl": "pkg:helm/common@2.31.4",
334358
"properties": [
335359
{
336360
"name": "Elastisys evaluation",
@@ -1766,13 +1790,13 @@
17661790
}
17671791
},
17681792
{
1769-
"bom-ref": "pkg:helm/minio@15.0.5",
1793+
"bom-ref": "pkg:helm/minio@17.0.19",
17701794
"type": "library",
17711795
"supplier": {
17721796
"name": "Broadcom, Inc. All Rights Reserved."
17731797
},
17741798
"name": "minio",
1775-
"version": "15.0.5",
1799+
"version": "17.0.19",
17761800
"description": "MinIO(R) is an object storage server, compatible with Amazon S3 cloud storage service, mainly used for storing unstructured data (such as photos, videos, log files, etc.).",
17771801
"licenses": [
17781802
{
@@ -1781,7 +1805,7 @@
17811805
}
17821806
}
17831807
],
1784-
"purl": "pkg:helm/minio@15.0.5",
1808+
"purl": "pkg:helm/minio@17.0.19",
17851809
"properties": [
17861810
{
17871811
"name": "Elastisys evaluation",
@@ -2602,13 +2626,13 @@
26022626
}
26032627
},
26042628
{
2605-
"bom-ref": "pkg:helm/thanos@15.13.1",
2629+
"bom-ref": "pkg:helm/thanos@17.3.1",
26062630
"type": "library",
26072631
"supplier": {
26082632
"name": "Broadcom, Inc. All Rights Reserved."
26092633
},
26102634
"name": "thanos",
2611-
"version": "15.13.1",
2635+
"version": "17.3.1",
26122636
"description": "Thanos is a highly available metrics system that can be added on top of existing Prometheus deployments, providing a global query view across all Prometheus installations.",
26132637
"licenses": [
26142638
{
@@ -2617,7 +2641,7 @@
26172641
}
26182642
}
26192643
],
2620-
"purl": "pkg:helm/thanos@15.13.1",
2644+
"purl": "pkg:helm/thanos@17.3.1",
26212645
"properties": [
26222646
{
26232647
"name": "Elastisys evaluation",
@@ -2898,48 +2922,59 @@
28982922
"purl": "pkg:oci/bitnami/kubectl@1.30.2"
28992923
},
29002924
{
2901-
"bom-ref": "pkg:oci/bitnami/minio-client@2025.2.21-debian-12-r0",
2925+
"bom-ref": "pkg:oci/bitnami/minio-client@2025.7.21-debian-12-r1",
29022926
"type": "container",
29032927
"supplier": {
29042928
"name": "bitnami"
29052929
},
29062930
"name": "bitnami/minio-client",
2907-
"version": "2025.2.21-debian-12-r0",
2908-
"cpe": "cpe:2.3:a:bitnami:minio-client:2025.2.21:*:*:*:*:*:*:*",
2909-
"purl": "pkg:oci/bitnami/minio-client@2025.2.21-debian-12-r0"
2931+
"version": "2025.7.21-debian-12-r1",
2932+
"cpe": "cpe:2.3:a:bitnami:minio-client:2025.7.21:*:*:*:*:*:*:*",
2933+
"purl": "pkg:oci/bitnami/minio-client@2025.7.21-debian-12-r1"
29102934
},
29112935
{
2912-
"bom-ref": "pkg:oci/bitnami/minio@2025.2.28-debian-12-r0",
2936+
"bom-ref": "pkg:oci/bitnami/minio-object-browser@2.0.2-debian-12-r2",
2937+
"type": "container",
2938+
"supplier": {
2939+
"name": "bitnami"
2940+
},
2941+
"name": "bitnami/minio-object-browser",
2942+
"version": "2.0.2-debian-12-r2",
2943+
"cpe": "cpe:2.3:a:bitnami:minio-object-browser:2.0.2:*:*:*:*:*:*:*",
2944+
"purl": "pkg:oci/bitnami/minio-object-browser@2.0.2-debian-12-r2"
2945+
},
2946+
{
2947+
"bom-ref": "pkg:oci/bitnami/minio@2025.7.23-debian-12-r2",
29132948
"type": "container",
29142949
"supplier": {
29152950
"name": "bitnami"
29162951
},
29172952
"name": "bitnami/minio",
2918-
"version": "2025.2.28-debian-12-r0",
2919-
"cpe": "cpe:2.3:a:bitnami:minio:2025.2.28:*:*:*:*:*:*:*",
2920-
"purl": "pkg:oci/bitnami/minio@2025.2.28-debian-12-r0"
2953+
"version": "2025.7.23-debian-12-r2",
2954+
"cpe": "cpe:2.3:a:bitnami:minio:2025.7.23:*:*:*:*:*:*:*",
2955+
"purl": "pkg:oci/bitnami/minio@2025.7.23-debian-12-r2"
29212956
},
29222957
{
2923-
"bom-ref": "pkg:oci/bitnami/os-shell@12-debian-12-r39",
2958+
"bom-ref": "pkg:oci/bitnami/os-shell@12-debian-12-r50",
29242959
"type": "container",
29252960
"supplier": {
29262961
"name": "bitnami"
29272962
},
29282963
"name": "bitnami/os-shell",
2929-
"version": "12-debian-12-r39",
2964+
"version": "12-debian-12-r50",
29302965
"cpe": "cpe:2.3:a:bitnami:os-shell:12:*:*:*:*:*:*:*",
2931-
"purl": "pkg:oci/bitnami/os-shell@12-debian-12-r39"
2966+
"purl": "pkg:oci/bitnami/os-shell@12-debian-12-r50"
29322967
},
29332968
{
2934-
"bom-ref": "pkg:oci/bitnami/thanos@0.37.2-debian-12-r8",
2969+
"bom-ref": "pkg:oci/bitnami/thanos@0.39.2-debian-12-r2",
29352970
"type": "container",
29362971
"supplier": {
29372972
"name": "bitnami"
29382973
},
29392974
"name": "bitnami/thanos",
2940-
"version": "0.37.2-debian-12-r8",
2941-
"cpe": "cpe:2.3:a:bitnami:thanos:0.37.2:*:*:*:*:*:*:*",
2942-
"purl": "pkg:oci/bitnami/thanos@0.37.2-debian-12-r8"
2975+
"version": "0.39.2-debian-12-r2",
2976+
"cpe": "cpe:2.3:a:bitnami:thanos:0.39.2:*:*:*:*:*:*:*",
2977+
"purl": "pkg:oci/bitnami/thanos@0.39.2-debian-12-r2"
29432978
},
29442979
{
29452980
"bom-ref": "pkg:oci/brancz/kube-rbac-proxy@v0.19.1",
@@ -3129,15 +3164,15 @@
31293164
"purl": "pkg:oci/elastisys/bitnami/kubectl@1.32.4?repository_url=ghcr.io"
31303165
},
31313166
{
3132-
"bom-ref": "pkg:oci/elastisys/bitnami/thanos@0.37.2-debian-12-r8?repository_url=ghcr.io",
3167+
"bom-ref": "pkg:oci/elastisys/bitnami/thanos@0.39.2-debian-12-r2?repository_url=ghcr.io",
31333168
"type": "container",
31343169
"supplier": {
31353170
"name": "elastisys"
31363171
},
31373172
"name": "ghcr.io/elastisys/bitnami/thanos",
3138-
"version": "0.37.2-debian-12-r8",
3139-
"cpe": "cpe:2.3:a:elastisys:thanos:0.37.2:*:*:*:*:*:*:*",
3140-
"purl": "pkg:oci/elastisys/bitnami/thanos@0.37.2-debian-12-r8?repository_url=ghcr.io"
3173+
"version": "0.39.2-debian-12-r2",
3174+
"cpe": "cpe:2.3:a:elastisys:thanos:0.39.2:*:*:*:*:*:*:*",
3175+
"purl": "pkg:oci/elastisys/bitnami/thanos@0.39.2-debian-12-r2?repository_url=ghcr.io"
31413176
},
31423177
{
31433178
"bom-ref": "pkg:oci/elastisys/calico-accountant@0.1.6-ck8s3?repository_url=ghcr.io",
@@ -4306,7 +4341,7 @@
43064341
"pkg:helm/cert-manager@v1.18.3",
43074342
"pkg:helm/cilium-default-deny@0.1.0",
43084343
"pkg:helm/cluster-admin-rbac@0.1.0",
4309-
"pkg:helm/common@2.30.0",
4344+
"pkg:helm/common@2.31.4",
43104345
"pkg:helm/crds@0.0.0",
43114346
"pkg:helm/crds@3.3.6",
43124347
"pkg:helm/crossplane-packages@0.1.0",
@@ -4353,7 +4388,7 @@
43534388
"pkg:helm/letsencrypt@0.1.0",
43544389
"pkg:helm/log-manager@0.1.0",
43554390
"pkg:helm/metrics-server@3.12.1",
4356-
"pkg:helm/minio@15.0.5",
4391+
"pkg:helm/minio@17.0.19",
43574392
"pkg:helm/minio@5.0.14",
43584393
"pkg:helm/namespaces@0.1.1",
43594394
"pkg:helm/networkpolicy-generator@0.1.0",
@@ -4380,7 +4415,7 @@
43804415
"pkg:helm/tekton-pipelines@0.1.0",
43814416
"pkg:helm/thanos-ingress-secret@0.1.0",
43824417
"pkg:helm/thanos-ruler@0.1.0",
4383-
"pkg:helm/thanos@15.13.1",
4418+
"pkg:helm/thanos@17.3.1",
43844419
"pkg:helm/tigera-operator@v3.26.4",
43854420
"pkg:helm/trivy-operator@0.31.0",
43864421
"pkg:helm/user-crds@0.1.0",
@@ -4437,9 +4472,15 @@
44374472
]
44384473
},
44394474
{
4440-
"ref": "pkg:helm/common@2.30.0",
4475+
"ref": "pkg:helm/common@2.31.3",
44414476
"dependsOn": [
4442-
"pkg:oci/elastisys/bitnami/thanos@0.37.2-debian-12-r8?repository_url=ghcr.io"
4477+
"pkg:oci/elastisys/bitnami/thanos@0.39.2-debian-12-r2?repository_url=ghcr.io"
4478+
]
4479+
},
4480+
{
4481+
"ref": "pkg:helm/common@2.31.4",
4482+
"dependsOn": [
4483+
"pkg:oci/elastisys/bitnami/thanos@0.39.2-debian-12-r2?repository_url=ghcr.io"
44434484
]
44444485
},
44454486
{
@@ -4895,13 +4936,14 @@
48954936
]
48964937
},
48974938
{
4898-
"ref": "pkg:helm/minio@15.0.5",
4939+
"ref": "pkg:helm/minio@17.0.19",
48994940
"dependsOn": [
4900-
"pkg:helm/common@2.30.0",
4901-
"pkg:oci/bitnami/minio-client@2025.2.21-debian-12-r0",
4902-
"pkg:oci/bitnami/minio@2025.2.28-debian-12-r0",
4903-
"pkg:oci/bitnami/os-shell@12-debian-12-r39",
4904-
"pkg:oci/elastisys/bitnami/thanos@0.37.2-debian-12-r8?repository_url=ghcr.io"
4941+
"pkg:helm/common@2.31.3",
4942+
"pkg:oci/bitnami/minio-client@2025.7.21-debian-12-r1",
4943+
"pkg:oci/bitnami/minio-object-browser@2.0.2-debian-12-r2",
4944+
"pkg:oci/bitnami/minio@2025.7.23-debian-12-r2",
4945+
"pkg:oci/bitnami/os-shell@12-debian-12-r50",
4946+
"pkg:oci/elastisys/bitnami/thanos@0.39.2-debian-12-r2?repository_url=ghcr.io"
49054947
]
49064948
},
49074949
{
@@ -5083,25 +5125,26 @@
50835125
{
50845126
"ref": "pkg:helm/thanos-ingress-secret@0.1.0",
50855127
"dependsOn": [
5086-
"pkg:oci/elastisys/bitnami/thanos@0.37.2-debian-12-r8?repository_url=ghcr.io"
5128+
"pkg:oci/elastisys/bitnami/thanos@0.39.2-debian-12-r2?repository_url=ghcr.io"
50875129
]
50885130
},
50895131
{
50905132
"ref": "pkg:helm/thanos-ruler@0.1.0",
50915133
"dependsOn": [
5092-
"pkg:oci/elastisys/bitnami/thanos@0.37.2-debian-12-r8?repository_url=ghcr.io"
5134+
"pkg:oci/elastisys/bitnami/thanos@0.39.2-debian-12-r2?repository_url=ghcr.io"
50935135
]
50945136
},
50955137
{
5096-
"ref": "pkg:helm/thanos@15.13.1",
5138+
"ref": "pkg:helm/thanos@17.3.1",
50975139
"dependsOn": [
5098-
"pkg:helm/common@2.30.0",
5099-
"pkg:helm/minio@15.0.5",
5100-
"pkg:oci/bitnami/minio-client@2025.2.21-debian-12-r0",
5101-
"pkg:oci/bitnami/minio@2025.2.28-debian-12-r0",
5102-
"pkg:oci/bitnami/os-shell@12-debian-12-r39",
5103-
"pkg:oci/bitnami/thanos@0.37.2-debian-12-r8",
5104-
"pkg:oci/elastisys/bitnami/thanos@0.37.2-debian-12-r8?repository_url=ghcr.io"
5140+
"pkg:helm/common@2.31.4",
5141+
"pkg:helm/minio@17.0.19",
5142+
"pkg:oci/bitnami/minio-client@2025.7.21-debian-12-r1",
5143+
"pkg:oci/bitnami/minio-object-browser@2.0.2-debian-12-r2",
5144+
"pkg:oci/bitnami/minio@2025.7.23-debian-12-r2",
5145+
"pkg:oci/bitnami/os-shell@12-debian-12-r50",
5146+
"pkg:oci/bitnami/thanos@0.39.2-debian-12-r2",
5147+
"pkg:oci/elastisys/bitnami/thanos@0.39.2-debian-12-r2?repository_url=ghcr.io"
51055148
]
51065149
},
51075150
{
@@ -5179,19 +5222,23 @@
51795222
"dependsOn": []
51805223
},
51815224
{
5182-
"ref": "pkg:oci/bitnami/minio-client@2025.2.21-debian-12-r0",
5225+
"ref": "pkg:oci/bitnami/minio-client@2025.7.21-debian-12-r1",
5226+
"dependsOn": []
5227+
},
5228+
{
5229+
"ref": "pkg:oci/bitnami/minio-object-browser@2.0.2-debian-12-r2",
51835230
"dependsOn": []
51845231
},
51855232
{
5186-
"ref": "pkg:oci/bitnami/minio@2025.2.28-debian-12-r0",
5233+
"ref": "pkg:oci/bitnami/minio@2025.7.23-debian-12-r2",
51875234
"dependsOn": []
51885235
},
51895236
{
5190-
"ref": "pkg:oci/bitnami/os-shell@12-debian-12-r39",
5237+
"ref": "pkg:oci/bitnami/os-shell@12-debian-12-r50",
51915238
"dependsOn": []
51925239
},
51935240
{
5194-
"ref": "pkg:oci/bitnami/thanos@0.37.2-debian-12-r8",
5241+
"ref": "pkg:oci/bitnami/thanos@0.39.2-debian-12-r2",
51955242
"dependsOn": []
51965243
},
51975244
{
@@ -5263,7 +5310,7 @@
52635310
"dependsOn": []
52645311
},
52655312
{
5266-
"ref": "pkg:oci/elastisys/bitnami/thanos@0.37.2-debian-12-r8?repository_url=ghcr.io",
5313+
"ref": "pkg:oci/elastisys/bitnami/thanos@0.39.2-debian-12-r2?repository_url=ghcr.io",
52675314
"dependsOn": []
52685315
},
52695316
{

0 commit comments

Comments
 (0)