Skip to content

Commit 010697d

Browse files
chore: update SBOM for Python 3.10 (#4118)
Co-authored-by: GitHub <[email protected]>
1 parent 12bee2b commit 010697d

File tree

2 files changed

+43
-50
lines changed

2 files changed

+43
-50
lines changed

sbom/cve-bin-tool-py3.10.json

Lines changed: 24 additions & 30 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:d2fdc99c-7d87-42c4-89a0-9274b36f0f25",
5+
"serialNumber": "urn:uuid:f7285934-6771-420a-9951-5901142b3594",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2024-05-06T00:28:30Z",
8+
"timestamp": "2024-05-13T00:28:49Z",
99
"tools": {
1010
"components": [
1111
{
@@ -483,6 +483,12 @@
483483
},
484484
"cpe": "cpe:2.3:a:stanislav_red_hat_product_security:cvss:3.1:*:*:*:*:*:*:*",
485485
"description": "CVSS2/3/4 library with interactive calculator for Python 2 and Python 3",
486+
"hashes": [
487+
{
488+
"alg": "SHA-1",
489+
"content": "e4cf69bea6bcfa1cbc38dca13b9ec8bf3363a475"
490+
}
491+
],
486492
"licenses": [
487493
{
488494
"license": {
@@ -652,7 +658,7 @@
652658
"type": "library",
653659
"bom-ref": "16-gsutil",
654660
"name": "gsutil",
655-
"version": "5.28",
661+
"version": "5.29",
656662
"supplier": {
657663
"name": "Google Inc .",
658664
"contact": [
@@ -661,7 +667,7 @@
661667
}
662668
]
663669
},
664-
"cpe": "cpe:2.3:a:google_inc.:gsutil:5.28:*:*:*:*:*:*:*",
670+
"cpe": "cpe:2.3:a:google_inc.:gsutil:5.29:*:*:*:*:*:*:*",
665671
"description": "A command line tool for interacting with cloud storage services.",
666672
"licenses": [
667673
{
@@ -673,12 +679,12 @@
673679
],
674680
"externalReferences": [
675681
{
676-
"url": "https://pypi.org/project/gsutil/5.28",
682+
"url": "https://pypi.org/project/gsutil/5.29",
677683
"type": "distribution",
678684
"comment": "Download location for component"
679685
}
680686
],
681-
"purl": "pkg:pypi/gsutil@5.28",
687+
"purl": "pkg:pypi/gsutil@5.29",
682688
"properties": [
683689
{
684690
"name": "language",
@@ -1514,7 +1520,7 @@
15141520
"type": "library",
15151521
"bom-ref": "35-cryptography",
15161522
"name": "cryptography",
1517-
"version": "42.0.6",
1523+
"version": "42.0.7",
15181524
"supplier": {
15191525
"name": "The Python Cryptographic Authority and individual contributors",
15201526
"contact": [
@@ -1523,7 +1529,7 @@
15231529
}
15241530
]
15251531
},
1526-
"cpe": "cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:42.0.6:*:*:*:*:*:*:*",
1532+
"cpe": "cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:42.0.7:*:*:*:*:*:*:*",
15271533
"description": "cryptography is a package which provides cryptographic recipes and primitives to Python developers.",
15281534
"licenses": [
15291535
{
@@ -1532,12 +1538,12 @@
15321538
],
15331539
"externalReferences": [
15341540
{
1535-
"url": "https://pypi.org/project/cryptography/42.0.6",
1541+
"url": "https://pypi.org/project/cryptography/42.0.7",
15361542
"type": "distribution",
15371543
"comment": "Download location for component"
15381544
}
15391545
],
1540-
"purl": "pkg:pypi/[email protected].6",
1546+
"purl": "pkg:pypi/[email protected].7",
15411547
"properties": [
15421548
{
15431549
"name": "language",
@@ -1820,12 +1826,6 @@
18201826
"name": "markupsafe",
18211827
"version": "2.1.5",
18221828
"description": "Safely add untrusted strings to HTML/XML markup.",
1823-
"hashes": [
1824-
{
1825-
"alg": "SHA-1",
1826-
"content": "fbba4acd0312826cec9cfe18371c7df07962cb65"
1827-
}
1828-
],
18291829
"licenses": [
18301830
{
18311831
"license": {
@@ -1966,11 +1966,11 @@
19661966
"type": "library",
19671967
"bom-ref": "46-rpds-py",
19681968
"name": "rpds-py",
1969-
"version": "0.18.0",
1969+
"version": "0.18.1",
19701970
"supplier": {
19711971
"name": "Julian Berman"
19721972
},
1973-
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.18.0:*:*:*:*:*:*:*",
1973+
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.18.1:*:*:*:*:*:*:*",
19741974
"description": "Python bindings to Rust's persistent data structures (rpds)",
19751975
"licenses": [
19761976
{
@@ -1982,12 +1982,12 @@
19821982
],
19831983
"externalReferences": [
19841984
{
1985-
"url": "https://pypi.org/project/rpds-py/0.18.0",
1985+
"url": "https://pypi.org/project/rpds-py/0.18.1",
19861986
"type": "distribution",
19871987
"comment": "Download location for component"
19881988
}
19891989
],
1990-
"purl": "pkg:pypi/[email protected].0",
1990+
"purl": "pkg:pypi/[email protected].1",
19911991
"properties": [
19921992
{
19931993
"name": "language",
@@ -2266,7 +2266,7 @@
22662266
"type": "library",
22672267
"bom-ref": "53-tenacity",
22682268
"name": "tenacity",
2269-
"version": "8.2.3",
2269+
"version": "8.3.0",
22702270
"supplier": {
22712271
"name": "Julien Danjou",
22722272
"contact": [
@@ -2275,14 +2275,8 @@
22752275
}
22762276
]
22772277
},
2278-
"cpe": "cpe:2.3:a:julien_danjou:tenacity:8.2.3:*:*:*:*:*:*:*",
2278+
"cpe": "cpe:2.3:a:julien_danjou:tenacity:8.3.0:*:*:*:*:*:*:*",
22792279
"description": "Retry code until it succeeds",
2280-
"hashes": [
2281-
{
2282-
"alg": "SHA-1",
2283-
"content": "41ed2420cda8ab7650a39900451099f4730266c3"
2284-
}
2285-
],
22862280
"licenses": [
22872281
{
22882282
"license": {
@@ -2293,12 +2287,12 @@
22932287
],
22942288
"externalReferences": [
22952289
{
2296-
"url": "https://pypi.org/project/tenacity/8.2.3",
2290+
"url": "https://pypi.org/project/tenacity/8.3.0",
22972291
"type": "distribution",
22982292
"comment": "Download location for component"
22992293
}
23002294
],
2301-
"purl": "pkg:pypi/tenacity@8.2.3",
2295+
"purl": "pkg:pypi/tenacity@8.3.0",
23022296
"properties": [
23032297
{
23042298
"name": "language",

sbom/cve-bin-tool-py3.10.spdx

Lines changed: 19 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-e55ebc57-b76a-458c-95c3-ac8d39a01d6f
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-7ebf2507-d2e7-4da3-966b-3116faa0d6c1
66
LicenseListVersion: 3.22
77
Creator: Tool: sbom4python-0.10.4
8-
Created: 2024-05-06T00:26:49Z
8+
Created: 2024-05-13T00:27:18Z
99
CreatorComment: <text>This document has been automatically generated.</text>
1010
#####
1111

@@ -189,6 +189,7 @@ PrimaryPackagePurpose: LIBRARY
189189
PackageSupplier: Organization: Stanislav Red Hat Product Security ([email protected])
190190
PackageDownloadLocation: https://pypi.org/project/cvss/3.1
191191
FilesAnalyzed: false
192+
PackageChecksum: SHA1: e4cf69bea6bcfa1cbc38dca13b9ec8bf3363a475
192193
PackageLicenseDeclared: NOASSERTION
193194
PackageLicenseConcluded: LGPL-3.0-or-later
194195
PackageLicenseComments: <text>cvss declares LGPLv3+ which is not currently a valid SPDX License identifier or expression.</text>
@@ -249,18 +250,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:tomas_aparicio:filetype:1.2.0:*:*:*:*:
249250

250251
PackageName: gsutil
251252
SPDXID: SPDXRef-Package-16-gsutil
252-
PackageVersion: 5.28
253+
PackageVersion: 5.29
253254
PrimaryPackagePurpose: LIBRARY
254255
PackageSupplier: Person: Google Inc. ([email protected])
255-
PackageDownloadLocation: https://pypi.org/project/gsutil/5.28
256+
PackageDownloadLocation: https://pypi.org/project/gsutil/5.29
256257
FilesAnalyzed: false
257258
PackageLicenseDeclared: NOASSERTION
258259
PackageLicenseConcluded: Apache-2.0
259260
PackageLicenseComments: <text>gsutil declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
260261
PackageCopyrightText: NOASSERTION
261262
PackageSummary: <text>A command line tool for interacting with cloud storage services.</text>
262-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/gsutil@5.28
263-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_inc.:gsutil:5.28:*:*:*:*:*:*:*
263+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/gsutil@5.29
264+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_inc.:gsutil:5.29:*:*:*:*:*:*:*
264265
#####
265266

266267
PackageName: argcomplete
@@ -557,17 +558,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_pyopenssl_developers:pyopenssl:24.
557558

558559
PackageName: cryptography
559560
SPDXID: SPDXRef-Package-35-cryptography
560-
PackageVersion: 42.0.6
561+
PackageVersion: 42.0.7
561562
PrimaryPackagePurpose: LIBRARY
562563
PackageSupplier: Organization: The Python Cryptographic Authority and individual contributors ([email protected])
563-
PackageDownloadLocation: https://pypi.org/project/cryptography/42.0.6
564+
PackageDownloadLocation: https://pypi.org/project/cryptography/42.0.7
564565
FilesAnalyzed: false
565566
PackageLicenseDeclared: Apache-2.0 OR BSD-3-Clause
566567
PackageLicenseConcluded: Apache-2.0 OR BSD-3-Clause
567568
PackageCopyrightText: NOASSERTION
568569
PackageSummary: <text>cryptography is a package which provides cryptographic recipes and primitives to Python developers.</text>
569-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].6
570-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:42.0.6:*:*:*:*:*:*:*
570+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].7
571+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:42.0.7:*:*:*:*:*:*:*
571572
#####
572573

573574
PackageName: cffi
@@ -673,7 +674,6 @@ PrimaryPackagePurpose: LIBRARY
673674
PackageSupplier: NOASSERTION
674675
PackageDownloadLocation: https://pypi.org/project/MarkupSafe/2.1.5
675676
FilesAnalyzed: false
676-
PackageChecksum: SHA1: fbba4acd0312826cec9cfe18371c7df07962cb65
677677
PackageLicenseDeclared: BSD-3-Clause
678678
PackageLicenseConcluded: BSD-3-Clause
679679
PackageCopyrightText: NOASSERTION
@@ -729,17 +729,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:referencing:0.35.1:*:*:*
729729

730730
PackageName: rpds-py
731731
SPDXID: SPDXRef-Package-46-rpds-py
732-
PackageVersion: 0.18.0
732+
PackageVersion: 0.18.1
733733
PrimaryPackagePurpose: LIBRARY
734734
PackageSupplier: Person: Julian Berman
735-
PackageDownloadLocation: https://pypi.org/project/rpds-py/0.18.0
735+
PackageDownloadLocation: https://pypi.org/project/rpds-py/0.18.1
736736
FilesAnalyzed: false
737737
PackageLicenseDeclared: MIT
738738
PackageLicenseConcluded: MIT
739739
PackageCopyrightText: NOASSERTION
740740
PackageSummary: <text>Python bindings to Rust's persistent data structures (rpds)</text>
741-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].0
742-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.18.0:*:*:*:*:*:*:*
741+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].1
742+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.18.1:*:*:*:*:*:*:*
743743
#####
744744

745745
PackageName: lib4sbom
@@ -839,19 +839,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:5.22.0:*:*:*:*:*:*:*
839839

840840
PackageName: tenacity
841841
SPDXID: SPDXRef-Package-53-tenacity
842-
PackageVersion: 8.2.3
842+
PackageVersion: 8.3.0
843843
PrimaryPackagePurpose: LIBRARY
844844
PackageSupplier: Person: Julien Danjou ([email protected])
845-
PackageDownloadLocation: https://pypi.org/project/tenacity/8.2.3
845+
PackageDownloadLocation: https://pypi.org/project/tenacity/8.3.0
846846
FilesAnalyzed: false
847-
PackageChecksum: SHA1: 41ed2420cda8ab7650a39900451099f4730266c3
848847
PackageLicenseDeclared: NOASSERTION
849848
PackageLicenseConcluded: Apache-2.0
850849
PackageLicenseComments: <text>tenacity declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
851850
PackageCopyrightText: NOASSERTION
852851
PackageSummary: <text>Retry code until it succeeds</text>
853-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/tenacity@8.2.3
854-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julien_danjou:tenacity:8.2.3:*:*:*:*:*:*:*
852+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/tenacity@8.3.0
853+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julien_danjou:tenacity:8.3.0:*:*:*:*:*:*:*
855854
#####
856855

857856
PackageName: python-gnupg

0 commit comments

Comments
 (0)