Skip to content

Commit d3d3892

Browse files
github-actions[bot]web-flow
authored andcommitted
chore: update SBOM for Python 3.10 (intel#3729)
Co-authored-by: GitHub <[email protected]>
1 parent f1d2528 commit d3d3892

File tree

2 files changed

+56
-52
lines changed

2 files changed

+56
-52
lines changed

sbom/cve-bin-tool-py3.10.json

Lines changed: 35 additions & 32 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.5.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.5",
5-
"serialNumber": "urn:uuid:c700a6f1-9bd1-4cdc-bd37-9399ed85c2ba",
5+
"serialNumber": "urn:uuid:055a78b9-2a63-4e07-bb1b-ebb33387923e",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2024-01-09T17:40:33Z",
8+
"timestamp": "2024-01-15T00:28:56Z",
99
"tools": {
1010
"components": [
1111
{
@@ -1400,6 +1400,12 @@
14001400
},
14011401
"cpe": "cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:41.0.7:*:*:*:*:*:*:*",
14021402
"description": "cryptography is a package which provides cryptographic recipes and primitives to Python developers.",
1403+
"hashes": [
1404+
{
1405+
"alg": "SHA-1",
1406+
"content": "4054596afc6f2b6cfcc54f56c35c34e0e429cb66"
1407+
}
1408+
],
14031409
"licenses": [
14041410
{
14051411
"expression": "Apache-2.0 OR BSD-3-Clause"
@@ -1628,7 +1634,7 @@
16281634
"type": "library",
16291635
"bom-ref": "36-google-auth",
16301636
"name": "google-auth",
1631-
"version": "2.26.1",
1637+
"version": "2.26.2",
16321638
"supplier": {
16331639
"name": "Google Cloud Platform",
16341640
"contact": [
@@ -1637,7 +1643,7 @@
16371643
}
16381644
]
16391645
},
1640-
"cpe": "cpe:2.3:a:google_cloud_platform:google-auth:2.26.1:*:*:*:*:*:*:*",
1646+
"cpe": "cpe:2.3:a:google_cloud_platform:google-auth:2.26.2:*:*:*:*:*:*:*",
16411647
"description": "Google Authentication Library",
16421648
"licenses": [
16431649
{
@@ -1649,12 +1655,12 @@
16491655
],
16501656
"externalReferences": [
16511657
{
1652-
"url": "https://pypi.org/project/google-auth/2.26.1",
1658+
"url": "https://pypi.org/project/google-auth/2.26.2",
16531659
"type": "distribution",
16541660
"comment": "Download location for component"
16551661
}
16561662
],
1657-
"purl": "pkg:pypi/[email protected].1",
1663+
"purl": "pkg:pypi/[email protected].2",
16581664
"properties": [
16591665
{
16601666
"name": "language",
@@ -1774,23 +1780,8 @@
17741780
"type": "library",
17751781
"bom-ref": "39-jinja2",
17761782
"name": "jinja2",
1777-
"version": "3.1.2",
1778-
"supplier": {
1779-
"name": "Armin Ronacher",
1780-
"contact": [
1781-
{
1782-
"email": "[email protected]"
1783-
}
1784-
]
1785-
},
1786-
"cpe": "cpe:2.3:a:armin_ronacher:jinja2:3.1.2:*:*:*:*:*:*:*",
1783+
"version": "3.1.3",
17871784
"description": "A very fast and expressive template engine.",
1788-
"hashes": [
1789-
{
1790-
"alg": "SHA-1",
1791-
"content": "b08cd4bc64bb980df86ed2876978ae5735572280"
1792-
}
1793-
],
17941785
"licenses": [
17951786
{
17961787
"license": {
@@ -1801,12 +1792,12 @@
18011792
],
18021793
"externalReferences": [
18031794
{
1804-
"url": "https://pypi.org/project/Jinja2/3.1.2",
1795+
"url": "https://pypi.org/project/Jinja2/3.1.3",
18051796
"type": "distribution",
18061797
"comment": "Download location for component"
18071798
}
18081799
],
1809-
"purl": "pkg:pypi/[email protected].2",
1800+
"purl": "pkg:pypi/[email protected].3",
18101801
"properties": [
18111802
{
18121803
"name": "language",
@@ -1984,11 +1975,11 @@
19841975
"type": "library",
19851976
"bom-ref": "44-rpds-py",
19861977
"name": "rpds-py",
1987-
"version": "0.16.2",
1978+
"version": "0.17.1",
19881979
"supplier": {
19891980
"name": "Julian Berman"
19901981
},
1991-
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.16.2:*:*:*:*:*:*:*",
1982+
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.17.1:*:*:*:*:*:*:*",
19921983
"description": "Python bindings to Rust's persistent data structures (rpds)",
19931984
"licenses": [
19941985
{
@@ -2000,12 +1991,12 @@
20001991
],
20011992
"externalReferences": [
20021993
{
2003-
"url": "https://pypi.org/project/rpds-py/0.16.2",
1994+
"url": "https://pypi.org/project/rpds-py/0.17.1",
20041995
"type": "distribution",
20051996
"comment": "Download location for component"
20061997
}
20071998
],
2008-
"purl": "pkg:pypi/rpds-py@0.16.2",
1999+
"purl": "pkg:pypi/rpds-py@0.17.1",
20092000
"properties": [
20102001
{
20112002
"name": "language",
@@ -2169,6 +2160,12 @@
21692160
},
21702161
"cpe": "cpe:2.3:a:the_purl_authors:packageurl-python:0.13.4:*:*:*:*:*:*:*",
21712162
"description": "A purl aka. Package URL parser and builder",
2163+
"hashes": [
2164+
{
2165+
"alg": "SHA-1",
2166+
"content": "f7f41b89a941278e8f76c0aad3a9409c6583eda8"
2167+
}
2168+
],
21722169
"licenses": [
21732170
{
21742171
"license": {
@@ -2701,6 +2698,12 @@
27012698
},
27022699
"cpe": "cpe:2.3:a:georg_brandl:pygments:2.17.2:*:*:*:*:*:*:*",
27032700
"description": "Pygments is a syntax highlighting package written in Python.",
2701+
"hashes": [
2702+
{
2703+
"alg": "SHA-1",
2704+
"content": "ee30ce132ae252bd72f3a74c86d9314a2214d0b4"
2705+
}
2706+
],
27042707
"licenses": [
27052708
{
27062709
"license": {
@@ -2822,7 +2825,7 @@
28222825
"type": "library",
28232826
"bom-ref": "63-xmlschema",
28242827
"name": "xmlschema",
2825-
"version": "3.0.0",
2828+
"version": "3.0.1",
28262829
"supplier": {
28272830
"name": "Davide Brunato",
28282831
"contact": [
@@ -2831,7 +2834,7 @@
28312834
}
28322835
]
28332836
},
2834-
"cpe": "cpe:2.3:a:davide_brunato:xmlschema:3.0.0:*:*:*:*:*:*:*",
2837+
"cpe": "cpe:2.3:a:davide_brunato:xmlschema:3.0.1:*:*:*:*:*:*:*",
28352838
"description": "An XML Schema validator and decoder",
28362839
"licenses": [
28372840
{
@@ -2843,12 +2846,12 @@
28432846
],
28442847
"externalReferences": [
28452848
{
2846-
"url": "https://pypi.org/project/xmlschema/3.0.0",
2849+
"url": "https://pypi.org/project/xmlschema/3.0.1",
28472850
"type": "distribution",
28482851
"comment": "Download location for component"
28492852
}
28502853
],
2851-
"purl": "pkg:pypi/[email protected].0",
2854+
"purl": "pkg:pypi/[email protected].1",
28522855
"properties": [
28532856
{
28542857
"name": "language",

sbom/cve-bin-tool-py3.10.spdx

Lines changed: 21 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-33aa23be-5a3e-4536-a2d5-a1135a9c2e46
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-23ce7aee-b65e-4e50-8505-e69ea92226c9
66
LicenseListVersion: 3.22
77
Creator: Tool: sbom4python-0.10.3
8-
Created: 2024-01-09T17:39:00Z
8+
Created: 2024-01-15T00:27:22Z
99
CreatorComment: <text>This document has been automatically generated.</text>
1010
#####
1111

@@ -497,6 +497,7 @@ PrimaryPackagePurpose: LIBRARY
497497
PackageSupplier: Organization: The Python Cryptographic Authority and individual contributors ([email protected])
498498
PackageDownloadLocation: https://pypi.org/project/cryptography/41.0.7
499499
FilesAnalyzed: false
500+
PackageChecksum: SHA1: 4054596afc6f2b6cfcc54f56c35c34e0e429cb66
500501
PackageLicenseDeclared: Apache-2.0 OR BSD-3-Clause
501502
PackageLicenseConcluded: Apache-2.0 OR BSD-3-Clause
502503
PackageCopyrightText: NOASSERTION
@@ -573,18 +574,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:craig_citro:google-apitools:0.5.32:*:*
573574

574575
PackageName: google-auth
575576
SPDXID: SPDXRef-Package-36-google-auth
576-
PackageVersion: 2.26.1
577+
PackageVersion: 2.26.2
577578
PrimaryPackagePurpose: LIBRARY
578579
PackageSupplier: Organization: Google Cloud Platform ([email protected])
579-
PackageDownloadLocation: https://pypi.org/project/google-auth/2.26.1
580+
PackageDownloadLocation: https://pypi.org/project/google-auth/2.26.2
580581
FilesAnalyzed: false
581582
PackageLicenseDeclared: NOASSERTION
582583
PackageLicenseConcluded: Apache-2.0
583584
PackageLicenseComments: <text>google-auth declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
584585
PackageCopyrightText: NOASSERTION
585586
PackageSummary: <text>Google Authentication Library</text>
586-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].1
587-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_cloud_platform:google-auth:2.26.1:*:*:*:*:*:*:*
587+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].2
588+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_cloud_platform:google-auth:2.26.2:*:*:*:*:*:*:*
588589
#####
589590

590591
PackageName: cachetools
@@ -622,18 +623,16 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:ori_livneh:monotonic:1.6:*:*:*:*:*:*:*
622623

623624
PackageName: jinja2
624625
SPDXID: SPDXRef-Package-39-jinja2
625-
PackageVersion: 3.1.2
626+
PackageVersion: 3.1.3
626627
PrimaryPackagePurpose: LIBRARY
627-
PackageSupplier: Person: Armin Ronacher ([email protected])
628-
PackageDownloadLocation: https://pypi.org/project/Jinja2/3.1.2
628+
PackageSupplier: NOASSERTION
629+
PackageDownloadLocation: https://pypi.org/project/Jinja2/3.1.3
629630
FilesAnalyzed: false
630-
PackageChecksum: SHA1: b08cd4bc64bb980df86ed2876978ae5735572280
631631
PackageLicenseDeclared: BSD-3-Clause
632632
PackageLicenseConcluded: BSD-3-Clause
633633
PackageCopyrightText: NOASSERTION
634634
PackageSummary: <text>A very fast and expressive template engine.</text>
635-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected]
636-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:armin_ronacher:jinja2:3.1.2:*:*:*:*:*:*:*
635+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected]
637636
#####
638637

639638
PackageName: markupsafe
@@ -700,17 +699,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:referencing:0.32.1:*:*:*
700699

701700
PackageName: rpds-py
702701
SPDXID: SPDXRef-Package-44-rpds-py
703-
PackageVersion: 0.16.2
702+
PackageVersion: 0.17.1
704703
PrimaryPackagePurpose: LIBRARY
705704
PackageSupplier: Person: Julian Berman
706-
PackageDownloadLocation: https://pypi.org/project/rpds-py/0.16.2
705+
PackageDownloadLocation: https://pypi.org/project/rpds-py/0.17.1
707706
FilesAnalyzed: false
708707
PackageLicenseDeclared: MIT
709708
PackageLicenseConcluded: MIT
710709
PackageCopyrightText: NOASSERTION
711710
PackageSummary: <text>Python bindings to Rust's persistent data structures (rpds)</text>
712-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rpds-py@0.16.2
713-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.16.2:*:*:*:*:*:*:*
711+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rpds-py@0.17.1
712+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.17.1:*:*:*:*:*:*:*
714713
#####
715714

716715
PackageName: lib4sbom
@@ -768,6 +767,7 @@ PrimaryPackagePurpose: LIBRARY
768767
PackageSupplier: Person: the purl authors
769768
PackageDownloadLocation: https://pypi.org/project/packageurl-python/0.13.4
770769
FilesAnalyzed: false
770+
PackageChecksum: SHA1: f7f41b89a941278e8f76c0aad3a9409c6583eda8
771771
PackageLicenseDeclared: MIT
772772
PackageLicenseConcluded: MIT
773773
PackageCopyrightText: NOASSERTION
@@ -959,6 +959,7 @@ PrimaryPackagePurpose: LIBRARY
959959
PackageSupplier: Person: Georg Brandl ([email protected])
960960
PackageDownloadLocation: https://pypi.org/project/Pygments/2.17.2
961961
FilesAnalyzed: false
962+
PackageChecksum: SHA1: ee30ce132ae252bd72f3a74c86d9314a2214d0b4
962963
PackageLicenseDeclared: BSD-2-Clause
963964
PackageLicenseConcluded: BSD-2-Clause
964965
PackageCopyrightText: NOASSERTION
@@ -1000,17 +1001,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:william_pearson:toml:0.10.2:*:*:*:*:*:
10001001

10011002
PackageName: xmlschema
10021003
SPDXID: SPDXRef-Package-63-xmlschema
1003-
PackageVersion: 3.0.0
1004+
PackageVersion: 3.0.1
10041005
PrimaryPackagePurpose: LIBRARY
10051006
PackageSupplier: Person: Davide Brunato ([email protected])
1006-
PackageDownloadLocation: https://pypi.org/project/xmlschema/3.0.0
1007+
PackageDownloadLocation: https://pypi.org/project/xmlschema/3.0.1
10071008
FilesAnalyzed: false
10081009
PackageLicenseDeclared: MIT
10091010
PackageLicenseConcluded: MIT
10101011
PackageCopyrightText: NOASSERTION
10111012
PackageSummary: <text>An XML Schema validator and decoder</text>
1012-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].0
1013-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:davide_brunato:xmlschema:3.0.0:*:*:*:*:*:*:*
1013+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].1
1014+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:davide_brunato:xmlschema:3.0.1:*:*:*:*:*:*:*
10141015
#####
10151016

10161017
PackageName: elementpath

0 commit comments

Comments
 (0)