Skip to content

Commit acefaca

Browse files
chore: update SBOM for Python 3.11 (#3571)
Co-authored-by: GitHub <[email protected]>
1 parent f42aa53 commit acefaca

File tree

2 files changed

+44
-44
lines changed

2 files changed

+44
-44
lines changed

sbom/cve-bin-tool-py3.11.json

Lines changed: 22 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.5.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.5",
5-
"serialNumber": "urn:uuid:71a49ade-e8ea-4cfb-917a-86225833fa76",
5+
"serialNumber": "urn:uuid:2611a013-0254-4305-85bc-2e7f1a844d1f",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2023-12-04T00:26:50Z",
8+
"timestamp": "2023-12-11T00:26:51Z",
99
"tools": {
1010
"components": [
1111
{
@@ -246,7 +246,7 @@
246246
"type": "library",
247247
"bom-ref": "7-yarl",
248248
"name": "yarl",
249-
"version": "1.9.3",
249+
"version": "1.9.4",
250250
"supplier": {
251251
"name": "Andrew Svetlov",
252252
"contact": [
@@ -255,7 +255,7 @@
255255
}
256256
]
257257
},
258-
"cpe": "cpe:2.3:a:andrew_svetlov:yarl:1.9.3:*:*:*:*:*:*:*",
258+
"cpe": "cpe:2.3:a:andrew_svetlov:yarl:1.9.4:*:*:*:*:*:*:*",
259259
"description": "Yet another URL library",
260260
"licenses": [
261261
{
@@ -267,12 +267,12 @@
267267
],
268268
"externalReferences": [
269269
{
270-
"url": "https://pypi.org/project/yarl/1.9.3",
270+
"url": "https://pypi.org/project/yarl/1.9.4",
271271
"type": "distribution",
272272
"comment": "Download location for component"
273273
}
274274
],
275-
"purl": "pkg:pypi/[email protected].3",
275+
"purl": "pkg:pypi/[email protected].4",
276276
"properties": [
277277
{
278278
"name": "language",
@@ -542,7 +542,7 @@
542542
"type": "library",
543543
"bom-ref": "15-argcomplete",
544544
"name": "argcomplete",
545-
"version": "3.1.6",
545+
"version": "3.2.1",
546546
"supplier": {
547547
"name": "Andrey Kislyuk",
548548
"contact": [
@@ -551,7 +551,7 @@
551551
}
552552
]
553553
},
554-
"cpe": "cpe:2.3:a:andrey_kislyuk:argcomplete:3.1.6:*:*:*:*:*:*:*",
554+
"cpe": "cpe:2.3:a:andrey_kislyuk:argcomplete:3.2.1:*:*:*:*:*:*:*",
555555
"description": "Bash tab completion for argparse",
556556
"licenses": [
557557
{
@@ -563,12 +563,12 @@
563563
],
564564
"externalReferences": [
565565
{
566-
"url": "https://pypi.org/project/argcomplete/3.1.6",
566+
"url": "https://pypi.org/project/argcomplete/3.2.1",
567567
"type": "distribution",
568568
"comment": "Download location for component"
569569
}
570570
],
571-
"purl": "pkg:pypi/argcomplete@3.1.6",
571+
"purl": "pkg:pypi/argcomplete@3.2.1",
572572
"properties": [
573573
{
574574
"name": "language",
@@ -1326,7 +1326,7 @@
13261326
"type": "library",
13271327
"bom-ref": "35-google-auth",
13281328
"name": "google-auth",
1329-
"version": "2.24.0",
1329+
"version": "2.25.2",
13301330
"supplier": {
13311331
"name": "Google Cloud Platform",
13321332
"contact": [
@@ -1335,7 +1335,7 @@
13351335
}
13361336
]
13371337
},
1338-
"cpe": "cpe:2.3:a:google_cloud_platform:google-auth:2.24.0:*:*:*:*:*:*:*",
1338+
"cpe": "cpe:2.3:a:google_cloud_platform:google-auth:2.25.2:*:*:*:*:*:*:*",
13391339
"description": "Google Authentication Library",
13401340
"licenses": [
13411341
{
@@ -1347,12 +1347,12 @@
13471347
],
13481348
"externalReferences": [
13491349
{
1350-
"url": "https://pypi.org/project/google-auth/2.24.0",
1350+
"url": "https://pypi.org/project/google-auth/2.25.2",
13511351
"type": "distribution",
13521352
"comment": "Download location for component"
13531353
}
13541354
],
1355-
"purl": "pkg:pypi/google-auth@2.24.0",
1355+
"purl": "pkg:pypi/google-auth@2.25.2",
13561356
"properties": [
13571357
{
13581358
"name": "language",
@@ -1585,11 +1585,11 @@
15851585
"type": "library",
15861586
"bom-ref": "42-referencing",
15871587
"name": "referencing",
1588-
"version": "0.31.1",
1588+
"version": "0.32.0",
15891589
"supplier": {
15901590
"name": "Julian Berman"
15911591
},
1592-
"cpe": "cpe:2.3:a:julian_berman:referencing:0.31.1:*:*:*:*:*:*:*",
1592+
"cpe": "cpe:2.3:a:julian_berman:referencing:0.32.0:*:*:*:*:*:*:*",
15931593
"description": "JSON Referencing + Python",
15941594
"licenses": [
15951595
{
@@ -1601,12 +1601,12 @@
16011601
],
16021602
"externalReferences": [
16031603
{
1604-
"url": "https://pypi.org/project/referencing/0.31.1",
1604+
"url": "https://pypi.org/project/referencing/0.32.0",
16051605
"type": "distribution",
16061606
"comment": "Download location for component"
16071607
}
16081608
],
1609-
"purl": "pkg:pypi/referencing@0.31.1",
1609+
"purl": "pkg:pypi/referencing@0.32.0",
16101610
"properties": [
16111611
{
16121612
"name": "language",
@@ -1769,11 +1769,11 @@
17691769
"type": "library",
17701770
"bom-ref": "47-packageurl-python",
17711771
"name": "packageurl-python",
1772-
"version": "0.11.2",
1772+
"version": "0.12.0",
17731773
"supplier": {
17741774
"name": "the purl authors"
17751775
},
1776-
"cpe": "cpe:2.3:a:the_purl_authors:packageurl-python:0.11.2:*:*:*:*:*:*:*",
1776+
"cpe": "cpe:2.3:a:the_purl_authors:packageurl-python:0.12.0:*:*:*:*:*:*:*",
17771777
"description": "A purl aka. Package URL parser and builder",
17781778
"licenses": [
17791779
{
@@ -1785,12 +1785,12 @@
17851785
],
17861786
"externalReferences": [
17871787
{
1788-
"url": "https://pypi.org/project/packageurl-python/0.11.2",
1788+
"url": "https://pypi.org/project/packageurl-python/0.12.0",
17891789
"type": "distribution",
17901790
"comment": "Download location for component"
17911791
}
17921792
],
1793-
"purl": "pkg:pypi/packageurl-python@0.11.2",
1793+
"purl": "pkg:pypi/packageurl-python@0.12.0",
17941794
"properties": [
17951795
{
17961796
"name": "language",

sbom/cve-bin-tool-py3.11.spdx

Lines changed: 22 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-a5fee435-b502-47c2-bfb7-f15ddbde470d
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-623585a8-860e-4dfc-9821-a22cb79b0092
66
LicenseListVersion: 3.22
77
Creator: Tool: sbom4python-0.10.1
8-
Created: 2023-12-04T00:25:50Z
8+
Created: 2023-12-11T00:25:54Z
99
CreatorComment: <text>This document has been automatically generated.</text>
1010
#####
1111

@@ -101,17 +101,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrew_svetlov:multidict:6.0.4:*:*:*:*
101101

102102
PackageName: yarl
103103
SPDXID: SPDXRef-Package-7-yarl
104-
PackageVersion: 1.9.3
104+
PackageVersion: 1.9.4
105105
PrimaryPackagePurpose: LIBRARY
106106
PackageSupplier: Person: Andrew Svetlov ([email protected])
107-
PackageDownloadLocation: https://pypi.org/project/yarl/1.9.3
107+
PackageDownloadLocation: https://pypi.org/project/yarl/1.9.4
108108
FilesAnalyzed: false
109109
PackageLicenseDeclared: Apache-2.0
110110
PackageLicenseConcluded: Apache-2.0
111111
PackageCopyrightText: NOASSERTION
112112
PackageSummary: <text>Yet another URL library</text>
113-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].3
114-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrew_svetlov:yarl:1.9.3:*:*:*:*:*:*:*
113+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].4
114+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrew_svetlov:yarl:1.9.4:*:*:*:*:*:*:*
115115
#####
116116

117117
PackageName: idna
@@ -225,18 +225,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_inc.:gsutil:5.27:*:*:*:*:*:*:*
225225

226226
PackageName: argcomplete
227227
SPDXID: SPDXRef-Package-15-argcomplete
228-
PackageVersion: 3.1.6
228+
PackageVersion: 3.2.1
229229
PrimaryPackagePurpose: LIBRARY
230230
PackageSupplier: Person: Andrey Kislyuk ([email protected])
231-
PackageDownloadLocation: https://pypi.org/project/argcomplete/3.1.6
231+
PackageDownloadLocation: https://pypi.org/project/argcomplete/3.2.1
232232
FilesAnalyzed: false
233233
PackageLicenseDeclared: NOASSERTION
234234
PackageLicenseConcluded: Apache-2.0
235235
PackageLicenseComments: <text>argcomplete declares Apache Software License which is not currently a valid SPDX License identifier or expression.</text>
236236
PackageCopyrightText: NOASSERTION
237237
PackageSummary: <text>Bash tab completion for argparse</text>
238-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/argcomplete@3.1.6
239-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_kislyuk:argcomplete:3.1.6:*:*:*:*:*:*:*
238+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/argcomplete@3.2.1
239+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_kislyuk:argcomplete:3.2.1:*:*:*:*:*:*:*
240240
#####
241241

242242
PackageName: crcmod
@@ -535,18 +535,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:craig_citro:google-apitools:0.5.32:*:*
535535

536536
PackageName: google-auth
537537
SPDXID: SPDXRef-Package-35-google-auth
538-
PackageVersion: 2.24.0
538+
PackageVersion: 2.25.2
539539
PrimaryPackagePurpose: LIBRARY
540540
PackageSupplier: Organization: Google Cloud Platform ([email protected])
541-
PackageDownloadLocation: https://pypi.org/project/google-auth/2.24.0
541+
PackageDownloadLocation: https://pypi.org/project/google-auth/2.25.2
542542
FilesAnalyzed: false
543543
PackageLicenseDeclared: NOASSERTION
544544
PackageLicenseConcluded: Apache-2.0
545545
PackageLicenseComments: <text>google-auth declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
546546
PackageCopyrightText: NOASSERTION
547547
PackageSummary: <text>Google Authentication Library</text>
548-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/google-auth@2.24.0
549-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_cloud_platform:google-auth:2.24.0:*:*:*:*:*:*:*
548+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/google-auth@2.25.2
549+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_cloud_platform:google-auth:2.25.2:*:*:*:*:*:*:*
550550
#####
551551

552552
PackageName: cachetools
@@ -641,17 +641,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:jsonschema-specification
641641

642642
PackageName: referencing
643643
SPDXID: SPDXRef-Package-42-referencing
644-
PackageVersion: 0.31.1
644+
PackageVersion: 0.32.0
645645
PrimaryPackagePurpose: LIBRARY
646646
PackageSupplier: Person: Julian Berman
647-
PackageDownloadLocation: https://pypi.org/project/referencing/0.31.1
647+
PackageDownloadLocation: https://pypi.org/project/referencing/0.32.0
648648
FilesAnalyzed: false
649649
PackageLicenseDeclared: MIT
650650
PackageLicenseConcluded: MIT
651651
PackageCopyrightText: NOASSERTION
652652
PackageSummary: <text>JSON Referencing + Python</text>
653-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/referencing@0.31.1
654-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:referencing:0.31.1:*:*:*:*:*:*:*
653+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/referencing@0.32.0
654+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:referencing:0.32.0:*:*:*:*:*:*:*
655655
#####
656656

657657
PackageName: rpds-py
@@ -717,17 +717,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:raphael_barrois:semantic-version:2.10.
717717

718718
PackageName: packageurl-python
719719
SPDXID: SPDXRef-Package-47-packageurl-python
720-
PackageVersion: 0.11.2
720+
PackageVersion: 0.12.0
721721
PrimaryPackagePurpose: LIBRARY
722722
PackageSupplier: Person: the purl authors
723-
PackageDownloadLocation: https://pypi.org/project/packageurl-python/0.11.2
723+
PackageDownloadLocation: https://pypi.org/project/packageurl-python/0.12.0
724724
FilesAnalyzed: false
725725
PackageLicenseDeclared: MIT
726726
PackageLicenseConcluded: MIT
727727
PackageCopyrightText: NOASSERTION
728728
PackageSummary: <text>A purl aka. Package URL parser and builder</text>
729-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/packageurl-python@0.11.2
730-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_purl_authors:packageurl-python:0.11.2:*:*:*:*:*:*:*
729+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/packageurl-python@0.12.0
730+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_purl_authors:packageurl-python:0.12.0:*:*:*:*:*:*:*
731731
#####
732732

733733
PackageName: packaging

0 commit comments

Comments
 (0)