Skip to content

Commit 3f45816

Browse files
chore: update SBOM for Python 3.8 (#4009)
Co-authored-by: GitHub <[email protected]>
1 parent 7540d03 commit 3f45816

File tree

2 files changed

+20
-27
lines changed

2 files changed

+20
-27
lines changed

sbom/cve-bin-tool-py3.8.json

Lines changed: 10 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.5.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.5",
5-
"serialNumber": "urn:uuid:92d57349-21cb-4df6-8619-bf73673c69ad",
5+
"serialNumber": "urn:uuid:5c954ebf-4bb9-4c1c-a196-01f5616d7939",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2024-04-01T00:29:58Z",
8+
"timestamp": "2024-04-08T00:27:58Z",
99
"tools": {
1010
"components": [
1111
{
@@ -2795,7 +2795,7 @@
27952795
"type": "library",
27962796
"bom-ref": "66-typing-extensions",
27972797
"name": "typing-extensions",
2798-
"version": "4.10.0",
2798+
"version": "4.11.0",
27992799
"supplier": {
28002800
"name": "Guido van Jukka ukasz Michael",
28012801
"contact": [
@@ -2804,22 +2804,16 @@
28042804
}
28052805
]
28062806
},
2807-
"cpe": "cpe:2.3:a:guido_van_jukka_ukasz_michael:typing-extensions:4.10.0:*:*:*:*:*:*:*",
2807+
"cpe": "cpe:2.3:a:guido_van_jukka_ukasz_michael:typing-extensions:4.11.0:*:*:*:*:*:*:*",
28082808
"description": "Backported and Experimental Type Hints for Python 3.8+",
2809-
"hashes": [
2810-
{
2811-
"alg": "SHA-1",
2812-
"content": "06b23e3f05fd0f929dbaea17ae51621dcc8434ab"
2813-
}
2814-
],
28152809
"externalReferences": [
28162810
{
2817-
"url": "https://pypi.org/project/typing_extensions/4.10.0",
2811+
"url": "https://pypi.org/project/typing_extensions/4.11.0",
28182812
"type": "distribution",
28192813
"comment": "Download location for component"
28202814
}
28212815
],
2822-
"purl": "pkg:pypi/typing-extensions@4.10.0",
2816+
"purl": "pkg:pypi/typing-extensions@4.11.0",
28232817
"properties": [
28242818
{
28252819
"name": "language",
@@ -2925,7 +2919,7 @@
29252919
"type": "library",
29262920
"bom-ref": "69-xmlschema",
29272921
"name": "xmlschema",
2928-
"version": "3.2.0",
2922+
"version": "3.2.1",
29292923
"supplier": {
29302924
"name": "Davide Brunato",
29312925
"contact": [
@@ -2934,7 +2928,7 @@
29342928
}
29352929
]
29362930
},
2937-
"cpe": "cpe:2.3:a:davide_brunato:xmlschema:3.2.0:*:*:*:*:*:*:*",
2931+
"cpe": "cpe:2.3:a:davide_brunato:xmlschema:3.2.1:*:*:*:*:*:*:*",
29382932
"description": "An XML Schema validator and decoder",
29392933
"licenses": [
29402934
{
@@ -2946,12 +2940,12 @@
29462940
],
29472941
"externalReferences": [
29482942
{
2949-
"url": "https://pypi.org/project/xmlschema/3.2.0",
2943+
"url": "https://pypi.org/project/xmlschema/3.2.1",
29502944
"type": "distribution",
29512945
"comment": "Download location for component"
29522946
}
29532947
],
2954-
"purl": "pkg:pypi/[email protected].0",
2948+
"purl": "pkg:pypi/[email protected].1",
29552949
"properties": [
29562950
{
29572951
"name": "language",

sbom/cve-bin-tool-py3.8.spdx

Lines changed: 10 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-4c83f10e-5529-4cc8-95c9-409f552f3d19
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-a228b5bf-0565-4e04-b688-0865d0c12357
66
LicenseListVersion: 3.22
77
Creator: Tool: sbom4python-0.10.4
8-
Created: 2024-04-01T00:28:30Z
8+
Created: 2024-04-08T00:26:37Z
99
CreatorComment: <text>This document has been automatically generated.</text>
1010
#####
1111

@@ -1042,18 +1042,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:georg_brandl:pygments:2.17.2:*:*:*:*:*
10421042

10431043
PackageName: typing-extensions
10441044
SPDXID: SPDXRef-Package-66-typing-extensions
1045-
PackageVersion: 4.10.0
1045+
PackageVersion: 4.11.0
10461046
PrimaryPackagePurpose: LIBRARY
10471047
PackageSupplier: Organization: Guido van Jukka ukasz Michael ([email protected])
1048-
PackageDownloadLocation: https://pypi.org/project/typing_extensions/4.10.0
1048+
PackageDownloadLocation: https://pypi.org/project/typing_extensions/4.11.0
10491049
FilesAnalyzed: false
1050-
PackageChecksum: SHA1: 06b23e3f05fd0f929dbaea17ae51621dcc8434ab
10511050
PackageLicenseDeclared: NOASSERTION
10521051
PackageLicenseConcluded: NOASSERTION
10531052
PackageCopyrightText: NOASSERTION
10541053
PackageSummary: <text>Backported and Experimental Type Hints for Python 3.8+</text>
1055-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/typing-extensions@4.10.0
1056-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:guido_van_jukka_ukasz_michael:typing-extensions:4.10.0:*:*:*:*:*:*:*
1054+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/typing-extensions@4.11.0
1055+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:guido_van_jukka_ukasz_michael:typing-extensions:4.11.0:*:*:*:*:*:*:*
10571056
#####
10581057

10591058
PackageName: rpmfile
@@ -1089,17 +1088,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:william_pearson:toml:0.10.2:*:*:*:*:*:
10891088

10901089
PackageName: xmlschema
10911090
SPDXID: SPDXRef-Package-69-xmlschema
1092-
PackageVersion: 3.2.0
1091+
PackageVersion: 3.2.1
10931092
PrimaryPackagePurpose: LIBRARY
10941093
PackageSupplier: Person: Davide Brunato ([email protected])
1095-
PackageDownloadLocation: https://pypi.org/project/xmlschema/3.2.0
1094+
PackageDownloadLocation: https://pypi.org/project/xmlschema/3.2.1
10961095
FilesAnalyzed: false
10971096
PackageLicenseDeclared: MIT
10981097
PackageLicenseConcluded: MIT
10991098
PackageCopyrightText: NOASSERTION
11001099
PackageSummary: <text>An XML Schema validator and decoder</text>
1101-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].0
1102-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:davide_brunato:xmlschema:3.2.0:*:*:*:*:*:*:*
1100+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].1
1101+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:davide_brunato:xmlschema:3.2.1:*:*:*:*:*:*:*
11031102
#####
11041103

11051104
PackageName: elementpath

0 commit comments

Comments
 (0)