Skip to content

Commit 13a0a50

Browse files
chore: update SBOM for Python 3.11 (#4360)
Co-authored-by: GitHub <[email protected]>
1 parent 657fc13 commit 13a0a50

File tree

2 files changed

+61
-68
lines changed

2 files changed

+61
-68
lines changed

sbom/cve-bin-tool-py3.11.json

Lines changed: 33 additions & 39 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:14e467ca-a313-4558-bdb0-c00a572295aa",
5+
"serialNumber": "urn:uuid:0756c440-35f1-4087-a1d1-b2150d425fe2",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2024-08-12T00:35:13Z",
8+
"timestamp": "2024-08-19T00:34:30Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -74,7 +74,7 @@
7474
"type": "library",
7575
"bom-ref": "2-aiohttp",
7676
"name": "aiohttp",
77-
"version": "3.10.3",
77+
"version": "3.10.4",
7878
"description": "Async http client/server framework (asyncio)",
7979
"licenses": [
8080
{
@@ -87,12 +87,12 @@
8787
],
8888
"externalReferences": [
8989
{
90-
"url": "https://pypi.org/project/aiohttp/3.10.3",
90+
"url": "https://pypi.org/project/aiohttp/3.10.4",
9191
"type": "distribution",
9292
"comment": "Download location for component"
9393
}
9494
],
95-
"purl": "pkg:pypi/[email protected].3",
95+
"purl": "pkg:pypi/[email protected].4",
9696
"properties": [
9797
{
9898
"name": "language",
@@ -108,7 +108,7 @@
108108
"type": "library",
109109
"bom-ref": "3-aiohappyeyeballs",
110110
"name": "aiohappyeyeballs",
111-
"version": "2.3.5",
111+
"version": "2.3.7",
112112
"supplier": {
113113
"name": "J. Nick Koston",
114114
"contact": [
@@ -117,31 +117,25 @@
117117
}
118118
]
119119
},
120-
"cpe": "cpe:2.3:a:j._nick_koston:aiohappyeyeballs:2.3.5:*:*:*:*:*:*:*",
120+
"cpe": "cpe:2.3:a:j._nick_koston:aiohappyeyeballs:2.3.7:*:*:*:*:*:*:*",
121121
"description": "Happy Eyeballs for asyncio",
122-
"hashes": [
123-
{
124-
"alg": "SHA-1",
125-
"content": "01595bbda3380154cc4e72702a1f82502a15940a"
126-
}
127-
],
128122
"licenses": [
129123
{
130124
"license": {
131-
"id": "Python-2.0",
132-
"url": "https://opensource.org/licenses/Python-2.0",
125+
"id": "Python-2.0.1",
126+
"url": "https://www.python.org/download/releases/2.0.1/license/",
133127
"acknowledgement": "concluded"
134128
}
135129
}
136130
],
137131
"externalReferences": [
138132
{
139-
"url": "https://pypi.org/project/aiohappyeyeballs/2.3.5",
133+
"url": "https://pypi.org/project/aiohappyeyeballs/2.3.7",
140134
"type": "distribution",
141135
"comment": "Download location for component"
142136
}
143137
],
144-
"purl": "pkg:pypi/[email protected].5",
138+
"purl": "pkg:pypi/[email protected].7",
145139
"properties": [
146140
{
147141
"name": "language",
@@ -445,7 +439,7 @@
445439
"type": "library",
446440
"bom-ref": "11-soupsieve",
447441
"name": "soupsieve",
448-
"version": "2.5",
442+
"version": "2.6",
449443
"supplier": {
450444
"name": "Isaac Muse",
451445
"contact": [
@@ -454,22 +448,16 @@
454448
}
455449
]
456450
},
457-
"cpe": "cpe:2.3:a:isaac_muse:soupsieve:2.5:*:*:*:*:*:*:*",
451+
"cpe": "cpe:2.3:a:isaac_muse:soupsieve:2.6:*:*:*:*:*:*:*",
458452
"description": "A modern CSS selector implementation for Beautiful Soup.",
459-
"hashes": [
460-
{
461-
"alg": "SHA-1",
462-
"content": "51ec317ada7e34f70fad6bfddaef8a2cfac1aebd"
463-
}
464-
],
465453
"externalReferences": [
466454
{
467-
"url": "https://pypi.org/project/soupsieve/2.5",
455+
"url": "https://pypi.org/project/soupsieve/2.6",
468456
"type": "distribution",
469457
"comment": "Download location for component"
470458
}
471459
],
472-
"purl": "pkg:pypi/soupsieve@2.5",
460+
"purl": "pkg:pypi/soupsieve@2.6",
473461
"properties": [
474462
{
475463
"name": "language",
@@ -989,7 +977,7 @@
989977
"type": "library",
990978
"bom-ref": "23-cachetools",
991979
"name": "cachetools",
992-
"version": "5.4.0",
980+
"version": "5.5.0",
993981
"supplier": {
994982
"name": "Thomas Kemmer",
995983
"contact": [
@@ -998,7 +986,7 @@
998986
}
999987
]
1000988
},
1001-
"cpe": "cpe:2.3:a:thomas_kemmer:cachetools:5.4.0:*:*:*:*:*:*:*",
989+
"cpe": "cpe:2.3:a:thomas_kemmer:cachetools:5.5.0:*:*:*:*:*:*:*",
1002990
"description": "Extensible memoizing collections and decorators",
1003991
"licenses": [
1004992
{
@@ -1011,12 +999,12 @@
1011999
],
10121000
"externalReferences": [
10131001
{
1014-
"url": "https://pypi.org/project/cachetools/5.4.0",
1002+
"url": "https://pypi.org/project/cachetools/5.5.0",
10151003
"type": "distribution",
10161004
"comment": "Download location for component"
10171005
}
10181006
],
1019-
"purl": "pkg:pypi/cachetools@5.4.0",
1007+
"purl": "pkg:pypi/cachetools@5.5.0",
10201008
"properties": [
10211009
{
10221010
"name": "language",
@@ -2035,7 +2023,7 @@
20352023
"type": "library",
20362024
"bom-ref": "47-lib4sbom",
20372025
"name": "lib4sbom",
2038-
"version": "0.7.2",
2026+
"version": "0.7.3",
20392027
"supplier": {
20402028
"name": "Anthony Harrison",
20412029
"contact": [
@@ -2044,7 +2032,7 @@
20442032
}
20452033
]
20462034
},
2047-
"cpe": "cpe:2.3:a:anthony_harrison:lib4sbom:0.7.2:*:*:*:*:*:*:*",
2035+
"cpe": "cpe:2.3:a:anthony_harrison:lib4sbom:0.7.3:*:*:*:*:*:*:*",
20482036
"description": "Software Bill of Material (SBOM) generator and consumer library",
20492037
"licenses": [
20502038
{
@@ -2057,12 +2045,12 @@
20572045
],
20582046
"externalReferences": [
20592047
{
2060-
"url": "https://pypi.org/project/lib4sbom/0.7.2",
2048+
"url": "https://pypi.org/project/lib4sbom/0.7.3",
20612049
"type": "distribution",
20622050
"comment": "Download location for component"
20632051
}
20642052
],
2065-
"purl": "pkg:pypi/[email protected].2",
2053+
"purl": "pkg:pypi/[email protected].3",
20662054
"properties": [
20672055
{
20682056
"name": "language",
@@ -2274,6 +2262,12 @@
22742262
},
22752263
"cpe": "cpe:2.3:a:the_purl_authors:packageurl-python:0.15.6:*:*:*:*:*:*:*",
22762264
"description": "A purl aka. Package URL parser and builder",
2265+
"hashes": [
2266+
{
2267+
"alg": "SHA-1",
2268+
"content": "14a11b50ab723796888133d3722b5b3e2845b084"
2269+
}
2270+
],
22772271
"licenses": [
22782272
{
22792273
"license": {
@@ -2871,7 +2865,7 @@
28712865
"type": "library",
28722866
"bom-ref": "66-setuptools",
28732867
"name": "setuptools",
2874-
"version": "72.1.0",
2868+
"version": "72.2.0",
28752869
"supplier": {
28762870
"name": "Python Packaging Authority",
28772871
"contact": [
@@ -2880,16 +2874,16 @@
28802874
}
28812875
]
28822876
},
2883-
"cpe": "cpe:2.3:a:python_packaging_authority:setuptools:72.1.0:*:*:*:*:*:*:*",
2877+
"cpe": "cpe:2.3:a:python_packaging_authority:setuptools:72.2.0:*:*:*:*:*:*:*",
28842878
"description": "Easily download, build, install, upgrade, and uninstall Python packages",
28852879
"externalReferences": [
28862880
{
2887-
"url": "https://pypi.org/project/setuptools/72.1.0",
2881+
"url": "https://pypi.org/project/setuptools/72.2.0",
28882882
"type": "distribution",
28892883
"comment": "Download location for component"
28902884
}
28912885
],
2892-
"purl": "pkg:pypi/setuptools@72.1.0",
2886+
"purl": "pkg:pypi/setuptools@72.2.0",
28932887
"properties": [
28942888
{
28952889
"name": "language",

sbom/cve-bin-tool-py3.11.spdx

Lines changed: 28 additions & 29 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-351dc84d-37d7-42cd-a685-641ac1848762
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-471104ff-c261-42ef-b302-6f8b05985844
66
LicenseListVersion: 3.22
77
Creator: Tool: sbom4python-0.11.1
8-
Created: 2024-08-12T00:34:00Z
8+
Created: 2024-08-19T00:33:22Z
99
CreatorComment: <text>This document has been automatically generated.</text>
1010
#####
1111

@@ -26,33 +26,32 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.3.1.dev0:*:*:
2626

2727
PackageName: aiohttp
2828
SPDXID: SPDXRef-Package-2-aiohttp
29-
PackageVersion: 3.10.3
29+
PackageVersion: 3.10.4
3030
PrimaryPackagePurpose: LIBRARY
3131
PackageSupplier: NOASSERTION
32-
PackageDownloadLocation: https://pypi.org/project/aiohttp/3.10.3
32+
PackageDownloadLocation: https://pypi.org/project/aiohttp/3.10.4
3333
FilesAnalyzed: false
3434
PackageLicenseDeclared: NOASSERTION
3535
PackageLicenseConcluded: Apache-2.0
3636
PackageLicenseComments: <text>aiohttp declares Apache 2 which is not currently a valid SPDX License identifier or expression.</text>
3737
PackageCopyrightText: NOASSERTION
3838
PackageSummary: <text>Async http client/server framework (asyncio)</text>
39-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].3
39+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].4
4040
#####
4141

4242
PackageName: aiohappyeyeballs
4343
SPDXID: SPDXRef-Package-3-aiohappyeyeballs
44-
PackageVersion: 2.3.5
44+
PackageVersion: 2.3.7
4545
PrimaryPackagePurpose: LIBRARY
4646
PackageSupplier: Organization: J. Nick Koston ([email protected])
47-
PackageDownloadLocation: https://pypi.org/project/aiohappyeyeballs/2.3.5
47+
PackageDownloadLocation: https://pypi.org/project/aiohappyeyeballs/2.3.7
4848
FilesAnalyzed: false
49-
PackageChecksum: SHA1: 01595bbda3380154cc4e72702a1f82502a15940a
50-
PackageLicenseDeclared: Python-2.0
51-
PackageLicenseConcluded: Python-2.0
49+
PackageLicenseDeclared: Python-2.0.1
50+
PackageLicenseConcluded: Python-2.0.1
5251
PackageCopyrightText: NOASSERTION
5352
PackageSummary: <text>Happy Eyeballs for asyncio</text>
54-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].5
55-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:j._nick_koston:aiohappyeyeballs:2.3.5:*:*:*:*:*:*:*
53+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].7
54+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:j._nick_koston:aiohappyeyeballs:2.3.7:*:*:*:*:*:*:*
5655
#####
5756

5857
PackageName: aiosignal
@@ -167,18 +166,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:leonard_richardson:beautifulsoup4:4.12
167166

168167
PackageName: soupsieve
169168
SPDXID: SPDXRef-Package-11-soupsieve
170-
PackageVersion: 2.5
169+
PackageVersion: 2.6
171170
PrimaryPackagePurpose: LIBRARY
172171
PackageSupplier: Person: Isaac Muse ([email protected])
173-
PackageDownloadLocation: https://pypi.org/project/soupsieve/2.5
172+
PackageDownloadLocation: https://pypi.org/project/soupsieve/2.6
174173
FilesAnalyzed: false
175-
PackageChecksum: SHA1: 51ec317ada7e34f70fad6bfddaef8a2cfac1aebd
176174
PackageLicenseDeclared: NOASSERTION
177175
PackageLicenseConcluded: NOASSERTION
178176
PackageCopyrightText: NOASSERTION
179177
PackageSummary: <text>A modern CSS selector implementation for Beautiful Soup.</text>
180-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/soupsieve@2.5
181-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:isaac_muse:soupsieve:2.5:*:*:*:*:*:*:*
178+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/soupsieve@2.6
179+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:isaac_muse:soupsieve:2.6:*:*:*:*:*:*:*
182180
#####
183181

184182
PackageName: cvss
@@ -361,17 +359,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_cloud_platform:google-auth:2.17
361359

362360
PackageName: cachetools
363361
SPDXID: SPDXRef-Package-23-cachetools
364-
PackageVersion: 5.4.0
362+
PackageVersion: 5.5.0
365363
PrimaryPackagePurpose: LIBRARY
366364
PackageSupplier: Person: Thomas Kemmer ([email protected])
367-
PackageDownloadLocation: https://pypi.org/project/cachetools/5.4.0
365+
PackageDownloadLocation: https://pypi.org/project/cachetools/5.5.0
368366
FilesAnalyzed: false
369367
PackageLicenseDeclared: MIT
370368
PackageLicenseConcluded: MIT
371369
PackageCopyrightText: NOASSERTION
372370
PackageSummary: <text>Extensible memoizing collections and decorators</text>
373-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/cachetools@5.4.0
374-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:thomas_kemmer:cachetools:5.4.0:*:*:*:*:*:*:*
371+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/cachetools@5.5.0
372+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:thomas_kemmer:cachetools:5.5.0:*:*:*:*:*:*:*
375373
#####
376374

377375
PackageName: pyasn1-modules
@@ -741,17 +739,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.20.0:*:*:*:*:*
741739

742740
PackageName: lib4sbom
743741
SPDXID: SPDXRef-Package-47-lib4sbom
744-
PackageVersion: 0.7.2
742+
PackageVersion: 0.7.3
745743
PrimaryPackagePurpose: LIBRARY
746744
PackageSupplier: Person: Anthony Harrison ([email protected])
747-
PackageDownloadLocation: https://pypi.org/project/lib4sbom/0.7.2
745+
PackageDownloadLocation: https://pypi.org/project/lib4sbom/0.7.3
748746
FilesAnalyzed: false
749747
PackageLicenseDeclared: Apache-2.0
750748
PackageLicenseConcluded: Apache-2.0
751749
PackageCopyrightText: NOASSERTION
752750
PackageSummary: <text>Software Bill of Material (SBOM) generator and consumer library</text>
753-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].2
754-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:anthony_harrison:lib4sbom:0.7.2:*:*:*:*:*:*:*
751+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].3
752+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:anthony_harrison:lib4sbom:0.7.3:*:*:*:*:*:*:*
755753
#####
756754

757755
PackageName: pyyaml
@@ -825,6 +823,7 @@ PrimaryPackagePurpose: LIBRARY
825823
PackageSupplier: Person: the purl authors
826824
PackageDownloadLocation: https://pypi.org/project/packageurl-python/0.15.6
827825
FilesAnalyzed: false
826+
PackageChecksum: SHA1: 14a11b50ab723796888133d3722b5b3e2845b084
828827
PackageLicenseDeclared: MIT
829828
PackageLicenseConcluded: MIT
830829
PackageCopyrightText: NOASSERTION
@@ -1039,17 +1038,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:sean_ross:rpmfile:2.1.0:*:*:*:*:*:*:*
10391038

10401039
PackageName: setuptools
10411040
SPDXID: SPDXRef-Package-66-setuptools
1042-
PackageVersion: 72.1.0
1041+
PackageVersion: 72.2.0
10431042
PrimaryPackagePurpose: LIBRARY
10441043
PackageSupplier: Organization: Python Packaging Authority ([email protected])
1045-
PackageDownloadLocation: https://pypi.org/project/setuptools/72.1.0
1044+
PackageDownloadLocation: https://pypi.org/project/setuptools/72.2.0
10461045
FilesAnalyzed: false
10471046
PackageLicenseDeclared: NOASSERTION
10481047
PackageLicenseConcluded: NOASSERTION
10491048
PackageCopyrightText: NOASSERTION
10501049
PackageSummary: <text>Easily download, build, install, upgrade, and uninstall Python packages</text>
1051-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/setuptools@72.1.0
1052-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:python_packaging_authority:setuptools:72.1.0:*:*:*:*:*:*:*
1050+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/setuptools@72.2.0
1051+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:python_packaging_authority:setuptools:72.2.0:*:*:*:*:*:*:*
10531052
#####
10541053

10551054
PackageName: xmlschema

0 commit comments

Comments
 (0)