Skip to content

Commit dbbb1a3

Browse files
github-actions[bot]web-flow
authored andcommitted
chore: update SBOM for Python 3.11 (intel#3688)
Co-authored-by: GitHub <[email protected]>
1 parent 893cfa3 commit dbbb1a3

File tree

2 files changed

+55
-62
lines changed

2 files changed

+55
-62
lines changed

sbom/cve-bin-tool-py3.11.json

Lines changed: 30 additions & 36 deletions
Original file line numberDiff line numberDiff line change
@@ -2,15 +2,15 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.5.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.5",
5-
"serialNumber": "urn:uuid:04ec1dd8-d2ec-44b9-ba93-cee74b34cc8e",
5+
"serialNumber": "urn:uuid:3276bc0a-d0c8-4c99-95f1-c47bc965e860",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2023-12-25T00:30:14Z",
8+
"timestamp": "2024-01-04T20:02:20Z",
99
"tools": {
1010
"components": [
1111
{
1212
"name": "sbom4python",
13-
"version": "0.10.2",
13+
"version": "0.10.3",
1414
"type": "application"
1515
}
1616
]
@@ -196,7 +196,7 @@
196196
"type": "library",
197197
"bom-ref": "5-attrs",
198198
"name": "attrs",
199-
"version": "23.1.0",
199+
"version": "23.2.0",
200200
"supplier": {
201201
"name": "Hynek Schlawack",
202202
"contact": [
@@ -205,22 +205,16 @@
205205
}
206206
]
207207
},
208-
"cpe": "cpe:2.3:a:hynek_schlawack:attrs:23.1.0:*:*:*:*:*:*:*",
208+
"cpe": "cpe:2.3:a:hynek_schlawack:attrs:23.2.0:*:*:*:*:*:*:*",
209209
"description": "Classes Without Boilerplate",
210-
"hashes": [
211-
{
212-
"alg": "SHA-1",
213-
"content": "1e2f6f9cac5cc60f0adab051c14adf09ffe39155"
214-
}
215-
],
216210
"externalReferences": [
217211
{
218-
"url": "https://pypi.org/project/attrs/23.1.0",
212+
"url": "https://pypi.org/project/attrs/23.2.0",
219213
"type": "distribution",
220214
"comment": "Download location for component"
221215
}
222216
],
223-
"purl": "pkg:pypi/attrs@23.1.0",
217+
"purl": "pkg:pypi/attrs@23.2.0",
224218
"properties": [
225219
{
226220
"name": "language",
@@ -1302,6 +1296,12 @@
13021296
},
13031297
"cpe": "cpe:2.3:a:the_pyopenssl_developers:pyopenssl:23.3.0:*:*:*:*:*:*:*",
13041298
"description": "Python wrapper module around the OpenSSL library",
1299+
"hashes": [
1300+
{
1301+
"alg": "SHA-1",
1302+
"content": "5ba8ce10ed7c318e57516a7ec8447cbb5626d3f9"
1303+
}
1304+
],
13051305
"licenses": [
13061306
{
13071307
"license": {
@@ -1576,7 +1576,7 @@
15761576
"type": "library",
15771577
"bom-ref": "35-google-auth",
15781578
"name": "google-auth",
1579-
"version": "2.25.2",
1579+
"version": "2.26.1",
15801580
"supplier": {
15811581
"name": "Google Cloud Platform",
15821582
"contact": [
@@ -1585,7 +1585,7 @@
15851585
}
15861586
]
15871587
},
1588-
"cpe": "cpe:2.3:a:google_cloud_platform:google-auth:2.25.2:*:*:*:*:*:*:*",
1588+
"cpe": "cpe:2.3:a:google_cloud_platform:google-auth:2.26.1:*:*:*:*:*:*:*",
15891589
"description": "Google Authentication Library",
15901590
"licenses": [
15911591
{
@@ -1597,12 +1597,12 @@
15971597
],
15981598
"externalReferences": [
15991599
{
1600-
"url": "https://pypi.org/project/google-auth/2.25.2",
1600+
"url": "https://pypi.org/project/google-auth/2.26.1",
16011601
"type": "distribution",
16021602
"comment": "Download location for component"
16031603
}
16041604
],
1605-
"purl": "pkg:pypi/google-auth@2.25.2",
1605+
"purl": "pkg:pypi/google-auth@2.26.1",
16061606
"properties": [
16071607
{
16081608
"name": "language",
@@ -1852,16 +1852,16 @@
18521852
"type": "library",
18531853
"bom-ref": "41-jsonschema-specifications",
18541854
"name": "jsonschema-specifications",
1855-
"version": "2023.11.2",
1855+
"version": "2023.12.1",
18561856
"supplier": {
18571857
"name": "Julian Berman"
18581858
},
1859-
"cpe": "cpe:2.3:a:julian_berman:jsonschema-specifications:2023.11.2:*:*:*:*:*:*:*",
1859+
"cpe": "cpe:2.3:a:julian_berman:jsonschema-specifications:2023.12.1:*:*:*:*:*:*:*",
18601860
"description": "The JSON Schema meta-schemas and vocabularies, exposed as a Registry",
18611861
"hashes": [
18621862
{
18631863
"alg": "SHA-1",
1864-
"content": "a2fec386cdb2ed38041ccbfff0fc3e8a566997a3"
1864+
"content": "544e0ff86850af1c6d9e533c4b58b76c59542a76"
18651865
}
18661866
],
18671867
"licenses": [
@@ -1874,12 +1874,12 @@
18741874
],
18751875
"externalReferences": [
18761876
{
1877-
"url": "https://pypi.org/project/jsonschema-specifications/2023.11.2",
1877+
"url": "https://pypi.org/project/jsonschema-specifications/2023.12.1",
18781878
"type": "distribution",
18791879
"comment": "Download location for component"
18801880
}
18811881
],
1882-
"purl": "pkg:pypi/jsonschema-specifications@2023.11.2",
1882+
"purl": "pkg:pypi/jsonschema-specifications@2023.12.1",
18831883
"properties": [
18841884
{
18851885
"name": "language",
@@ -1938,11 +1938,11 @@
19381938
"type": "library",
19391939
"bom-ref": "43-rpds-py",
19401940
"name": "rpds-py",
1941-
"version": "0.15.2",
1941+
"version": "0.16.2",
19421942
"supplier": {
19431943
"name": "Julian Berman"
19441944
},
1945-
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.15.2:*:*:*:*:*:*:*",
1945+
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.16.2:*:*:*:*:*:*:*",
19461946
"description": "Python bindings to Rust's persistent data structures (rpds)",
19471947
"licenses": [
19481948
{
@@ -1954,12 +1954,12 @@
19541954
],
19551955
"externalReferences": [
19561956
{
1957-
"url": "https://pypi.org/project/rpds-py/0.15.2",
1957+
"url": "https://pypi.org/project/rpds-py/0.16.2",
19581958
"type": "distribution",
19591959
"comment": "Download location for component"
19601960
}
19611961
],
1962-
"purl": "pkg:pypi/rpds-py@0.15.2",
1962+
"purl": "pkg:pypi/rpds-py@0.16.2",
19631963
"properties": [
19641964
{
19651965
"name": "language",
@@ -1975,7 +1975,7 @@
19751975
"type": "library",
19761976
"bom-ref": "44-lib4sbom",
19771977
"name": "lib4sbom",
1978-
"version": "0.5.4",
1978+
"version": "0.6.1",
19791979
"supplier": {
19801980
"name": "Anthony Harrison",
19811981
"contact": [
@@ -1984,14 +1984,8 @@
19841984
}
19851985
]
19861986
},
1987-
"cpe": "cpe:2.3:a:anthony_harrison:lib4sbom:0.5.4:*:*:*:*:*:*:*",
1987+
"cpe": "cpe:2.3:a:anthony_harrison:lib4sbom:0.6.1:*:*:*:*:*:*:*",
19881988
"description": "Software Bill of Material (SBOM) generator and consumer library",
1989-
"hashes": [
1990-
{
1991-
"alg": "SHA-1",
1992-
"content": "3de23e3f3b32c08f9bf8231e2765a06ebb82dc80"
1993-
}
1994-
],
19951989
"licenses": [
19961990
{
19971991
"license": {
@@ -2002,12 +1996,12 @@
20021996
],
20031997
"externalReferences": [
20041998
{
2005-
"url": "https://pypi.org/project/lib4sbom/0.5.4",
1999+
"url": "https://pypi.org/project/lib4sbom/0.6.1",
20062000
"type": "distribution",
20072001
"comment": "Download location for component"
20082002
}
20092003
],
2010-
"purl": "pkg:pypi/lib4sbom@0.5.4",
2004+
"purl": "pkg:pypi/lib4sbom@0.6.1",
20112005
"properties": [
20122006
{
20132007
"name": "language",

sbom/cve-bin-tool-py3.11.spdx

Lines changed: 25 additions & 26 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-f1f34e30-f49a-4f73-90bd-80e0bdc889b9
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-6bb28944-b0e3-45eb-9feb-dc60bec1512c
66
LicenseListVersion: 3.22
7-
Creator: Tool: sbom4python-0.10.2
8-
Created: 2023-12-25T00:28:34Z
7+
Creator: Tool: sbom4python-0.10.3
8+
Created: 2024-01-04T20:00:41Z
99
CreatorComment: <text>This document has been automatically generated.</text>
1010
#####
1111

@@ -73,18 +73,17 @@ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected]
7373

7474
PackageName: attrs
7575
SPDXID: SPDXRef-Package-5-attrs
76-
PackageVersion: 23.1.0
76+
PackageVersion: 23.2.0
7777
PrimaryPackagePurpose: LIBRARY
7878
PackageSupplier: Person: Hynek Schlawack ([email protected])
79-
PackageDownloadLocation: https://pypi.org/project/attrs/23.1.0
79+
PackageDownloadLocation: https://pypi.org/project/attrs/23.2.0
8080
FilesAnalyzed: false
81-
PackageChecksum: SHA1: 1e2f6f9cac5cc60f0adab051c14adf09ffe39155
8281
PackageLicenseDeclared: NOASSERTION
8382
PackageLicenseConcluded: NOASSERTION
8483
PackageCopyrightText: NOASSERTION
8584
PackageSummary: <text>Classes Without Boilerplate</text>
86-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/attrs@23.1.0
87-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:hynek_schlawack:attrs:23.1.0:*:*:*:*:*:*:*
85+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/attrs@23.2.0
86+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:hynek_schlawack:attrs:23.2.0:*:*:*:*:*:*:*
8887
#####
8988

9089
PackageName: multidict
@@ -464,6 +463,7 @@ PrimaryPackagePurpose: LIBRARY
464463
PackageSupplier: Organization: The pyOpenSSL developers ([email protected])
465464
PackageDownloadLocation: https://pypi.org/project/pyOpenSSL/23.3.0
466465
FilesAnalyzed: false
466+
PackageChecksum: SHA1: 5ba8ce10ed7c318e57516a7ec8447cbb5626d3f9
467467
PackageLicenseDeclared: NOASSERTION
468468
PackageLicenseConcluded: Apache-2.0
469469
PackageLicenseComments: <text>pyOpenSSL declares Apache License, Version 2.0 which is not currently a valid SPDX License identifier or expression.</text>
@@ -556,18 +556,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:craig_citro:google-apitools:0.5.32:*:*
556556

557557
PackageName: google-auth
558558
SPDXID: SPDXRef-Package-35-google-auth
559-
PackageVersion: 2.25.2
559+
PackageVersion: 2.26.1
560560
PrimaryPackagePurpose: LIBRARY
561561
PackageSupplier: Organization: Google Cloud Platform ([email protected])
562-
PackageDownloadLocation: https://pypi.org/project/google-auth/2.25.2
562+
PackageDownloadLocation: https://pypi.org/project/google-auth/2.26.1
563563
FilesAnalyzed: false
564564
PackageLicenseDeclared: NOASSERTION
565565
PackageLicenseConcluded: Apache-2.0
566566
PackageLicenseComments: <text>google-auth declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
567567
PackageCopyrightText: NOASSERTION
568568
PackageSummary: <text>Google Authentication Library</text>
569-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/google-auth@2.25.2
570-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_cloud_platform:google-auth:2.25.2:*:*:*:*:*:*:*
569+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/google-auth@2.26.1
570+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_cloud_platform:google-auth:2.26.1:*:*:*:*:*:*:*
571571
#####
572572

573573
PackageName: cachetools
@@ -652,18 +652,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:jsonschema:4.20.0:*:*:*:
652652

653653
PackageName: jsonschema-specifications
654654
SPDXID: SPDXRef-Package-41-jsonschema-specifications
655-
PackageVersion: 2023.11.2
655+
PackageVersion: 2023.12.1
656656
PrimaryPackagePurpose: LIBRARY
657657
PackageSupplier: Person: Julian Berman
658-
PackageDownloadLocation: https://pypi.org/project/jsonschema-specifications/2023.11.2
658+
PackageDownloadLocation: https://pypi.org/project/jsonschema-specifications/2023.12.1
659659
FilesAnalyzed: false
660-
PackageChecksum: SHA1: a2fec386cdb2ed38041ccbfff0fc3e8a566997a3
660+
PackageChecksum: SHA1: 544e0ff86850af1c6d9e533c4b58b76c59542a76
661661
PackageLicenseDeclared: MIT
662662
PackageLicenseConcluded: MIT
663663
PackageCopyrightText: NOASSERTION
664664
PackageSummary: <text>The JSON Schema meta-schemas and vocabularies, exposed as a Registry</text>
665-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/jsonschema-specifications@2023.11.2
666-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:jsonschema-specifications:2023.11.2:*:*:*:*:*:*:*
665+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/jsonschema-specifications@2023.12.1
666+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:jsonschema-specifications:2023.12.1:*:*:*:*:*:*:*
667667
#####
668668

669669
PackageName: referencing
@@ -684,33 +684,32 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:referencing:0.32.0:*:*:*
684684

685685
PackageName: rpds-py
686686
SPDXID: SPDXRef-Package-43-rpds-py
687-
PackageVersion: 0.15.2
687+
PackageVersion: 0.16.2
688688
PrimaryPackagePurpose: LIBRARY
689689
PackageSupplier: Person: Julian Berman
690-
PackageDownloadLocation: https://pypi.org/project/rpds-py/0.15.2
690+
PackageDownloadLocation: https://pypi.org/project/rpds-py/0.16.2
691691
FilesAnalyzed: false
692692
PackageLicenseDeclared: MIT
693693
PackageLicenseConcluded: MIT
694694
PackageCopyrightText: NOASSERTION
695695
PackageSummary: <text>Python bindings to Rust's persistent data structures (rpds)</text>
696-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rpds-py@0.15.2
697-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.15.2:*:*:*:*:*:*:*
696+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rpds-py@0.16.2
697+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.16.2:*:*:*:*:*:*:*
698698
#####
699699

700700
PackageName: lib4sbom
701701
SPDXID: SPDXRef-Package-44-lib4sbom
702-
PackageVersion: 0.5.4
702+
PackageVersion: 0.6.1
703703
PrimaryPackagePurpose: LIBRARY
704704
PackageSupplier: Person: Anthony Harrison ([email protected])
705-
PackageDownloadLocation: https://pypi.org/project/lib4sbom/0.5.4
705+
PackageDownloadLocation: https://pypi.org/project/lib4sbom/0.6.1
706706
FilesAnalyzed: false
707-
PackageChecksum: SHA1: 3de23e3f3b32c08f9bf8231e2765a06ebb82dc80
708707
PackageLicenseDeclared: Apache-2.0
709708
PackageLicenseConcluded: Apache-2.0
710709
PackageCopyrightText: NOASSERTION
711710
PackageSummary: <text>Software Bill of Material (SBOM) generator and consumer library</text>
712-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/lib4sbom@0.5.4
713-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:anthony_harrison:lib4sbom:0.5.4:*:*:*:*:*:*:*
711+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/lib4sbom@0.6.1
712+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:anthony_harrison:lib4sbom:0.6.1:*:*:*:*:*:*:*
714713
#####
715714

716715
PackageName: pyyaml

0 commit comments

Comments
 (0)