Skip to content

Commit 3162e92

Browse files
web-flowgithub-actions[bot]
authored andcommitted
chore: update SBOM for Python 3.9
1 parent 234f8ea commit 3162e92

File tree

2 files changed

+43
-50
lines changed

2 files changed

+43
-50
lines changed

sbom/cve-bin-tool-py3.9.json

Lines changed: 24 additions & 30 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:56c5c5f1-72d5-4d37-921d-7e5fa7e38ab0",
5+
"serialNumber": "urn:uuid:6b8040ba-91ea-45e2-b48e-cf3f925e08dd",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2024-05-06T00:28:19Z",
8+
"timestamp": "2024-05-13T00:29:02Z",
99
"tools": {
1010
"components": [
1111
{
@@ -483,6 +483,12 @@
483483
},
484484
"cpe": "cpe:2.3:a:stanislav_red_hat_product_security:cvss:3.1:*:*:*:*:*:*:*",
485485
"description": "CVSS2/3/4 library with interactive calculator for Python 2 and Python 3",
486+
"hashes": [
487+
{
488+
"alg": "SHA-1",
489+
"content": "e4cf69bea6bcfa1cbc38dca13b9ec8bf3363a475"
490+
}
491+
],
486492
"licenses": [
487493
{
488494
"license": {
@@ -652,7 +658,7 @@
652658
"type": "library",
653659
"bom-ref": "16-gsutil",
654660
"name": "gsutil",
655-
"version": "5.28",
661+
"version": "5.29",
656662
"supplier": {
657663
"name": "Google Inc .",
658664
"contact": [
@@ -661,7 +667,7 @@
661667
}
662668
]
663669
},
664-
"cpe": "cpe:2.3:a:google_inc.:gsutil:5.28:*:*:*:*:*:*:*",
670+
"cpe": "cpe:2.3:a:google_inc.:gsutil:5.29:*:*:*:*:*:*:*",
665671
"description": "A command line tool for interacting with cloud storage services.",
666672
"licenses": [
667673
{
@@ -673,12 +679,12 @@
673679
],
674680
"externalReferences": [
675681
{
676-
"url": "https://pypi.org/project/gsutil/5.28",
682+
"url": "https://pypi.org/project/gsutil/5.29",
677683
"type": "distribution",
678684
"comment": "Download location for component"
679685
}
680686
],
681-
"purl": "pkg:pypi/gsutil@5.28",
687+
"purl": "pkg:pypi/gsutil@5.29",
682688
"properties": [
683689
{
684690
"name": "language",
@@ -1514,7 +1520,7 @@
15141520
"type": "library",
15151521
"bom-ref": "35-cryptography",
15161522
"name": "cryptography",
1517-
"version": "42.0.6",
1523+
"version": "42.0.7",
15181524
"supplier": {
15191525
"name": "The Python Cryptographic Authority and individual contributors",
15201526
"contact": [
@@ -1523,7 +1529,7 @@
15231529
}
15241530
]
15251531
},
1526-
"cpe": "cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:42.0.6:*:*:*:*:*:*:*",
1532+
"cpe": "cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:42.0.7:*:*:*:*:*:*:*",
15271533
"description": "cryptography is a package which provides cryptographic recipes and primitives to Python developers.",
15281534
"licenses": [
15291535
{
@@ -1532,12 +1538,12 @@
15321538
],
15331539
"externalReferences": [
15341540
{
1535-
"url": "https://pypi.org/project/cryptography/42.0.6",
1541+
"url": "https://pypi.org/project/cryptography/42.0.7",
15361542
"type": "distribution",
15371543
"comment": "Download location for component"
15381544
}
15391545
],
1540-
"purl": "pkg:pypi/[email protected].6",
1546+
"purl": "pkg:pypi/[email protected].7",
15411547
"properties": [
15421548
{
15431549
"name": "language",
@@ -1900,12 +1906,6 @@
19001906
"name": "markupsafe",
19011907
"version": "2.1.5",
19021908
"description": "Safely add untrusted strings to HTML/XML markup.",
1903-
"hashes": [
1904-
{
1905-
"alg": "SHA-1",
1906-
"content": "fbba4acd0312826cec9cfe18371c7df07962cb65"
1907-
}
1908-
],
19091909
"licenses": [
19101910
{
19111911
"license": {
@@ -2046,11 +2046,11 @@
20462046
"type": "library",
20472047
"bom-ref": "48-rpds-py",
20482048
"name": "rpds-py",
2049-
"version": "0.18.0",
2049+
"version": "0.18.1",
20502050
"supplier": {
20512051
"name": "Julian Berman"
20522052
},
2053-
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.18.0:*:*:*:*:*:*:*",
2053+
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.18.1:*:*:*:*:*:*:*",
20542054
"description": "Python bindings to Rust's persistent data structures (rpds)",
20552055
"licenses": [
20562056
{
@@ -2062,12 +2062,12 @@
20622062
],
20632063
"externalReferences": [
20642064
{
2065-
"url": "https://pypi.org/project/rpds-py/0.18.0",
2065+
"url": "https://pypi.org/project/rpds-py/0.18.1",
20662066
"type": "distribution",
20672067
"comment": "Download location for component"
20682068
}
20692069
],
2070-
"purl": "pkg:pypi/[email protected].0",
2070+
"purl": "pkg:pypi/[email protected].1",
20712071
"properties": [
20722072
{
20732073
"name": "language",
@@ -2346,7 +2346,7 @@
23462346
"type": "library",
23472347
"bom-ref": "55-tenacity",
23482348
"name": "tenacity",
2349-
"version": "8.2.3",
2349+
"version": "8.3.0",
23502350
"supplier": {
23512351
"name": "Julien Danjou",
23522352
"contact": [
@@ -2355,14 +2355,8 @@
23552355
}
23562356
]
23572357
},
2358-
"cpe": "cpe:2.3:a:julien_danjou:tenacity:8.2.3:*:*:*:*:*:*:*",
2358+
"cpe": "cpe:2.3:a:julien_danjou:tenacity:8.3.0:*:*:*:*:*:*:*",
23592359
"description": "Retry code until it succeeds",
2360-
"hashes": [
2361-
{
2362-
"alg": "SHA-1",
2363-
"content": "41ed2420cda8ab7650a39900451099f4730266c3"
2364-
}
2365-
],
23662360
"licenses": [
23672361
{
23682362
"license": {
@@ -2373,12 +2367,12 @@
23732367
],
23742368
"externalReferences": [
23752369
{
2376-
"url": "https://pypi.org/project/tenacity/8.2.3",
2370+
"url": "https://pypi.org/project/tenacity/8.3.0",
23772371
"type": "distribution",
23782372
"comment": "Download location for component"
23792373
}
23802374
],
2381-
"purl": "pkg:pypi/tenacity@8.2.3",
2375+
"purl": "pkg:pypi/tenacity@8.3.0",
23822376
"properties": [
23832377
{
23842378
"name": "language",

sbom/cve-bin-tool-py3.9.spdx

Lines changed: 19 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-146f1efc-97ef-4b16-b568-084fa08abc52
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-f75310d1-b81b-40c2-930d-22699181394d
66
LicenseListVersion: 3.22
77
Creator: Tool: sbom4python-0.10.4
8-
Created: 2024-05-06T00:26:45Z
8+
Created: 2024-05-13T00:27:25Z
99
CreatorComment: <text>This document has been automatically generated.</text>
1010
#####
1111

@@ -189,6 +189,7 @@ PrimaryPackagePurpose: LIBRARY
189189
PackageSupplier: Organization: Stanislav Red Hat Product Security ([email protected])
190190
PackageDownloadLocation: https://pypi.org/project/cvss/3.1
191191
FilesAnalyzed: false
192+
PackageChecksum: SHA1: e4cf69bea6bcfa1cbc38dca13b9ec8bf3363a475
192193
PackageLicenseDeclared: NOASSERTION
193194
PackageLicenseConcluded: LGPL-3.0-or-later
194195
PackageLicenseComments: <text>cvss declares LGPLv3+ which is not currently a valid SPDX License identifier or expression.</text>
@@ -249,18 +250,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:tomas_aparicio:filetype:1.2.0:*:*:*:*:
249250

250251
PackageName: gsutil
251252
SPDXID: SPDXRef-Package-16-gsutil
252-
PackageVersion: 5.28
253+
PackageVersion: 5.29
253254
PrimaryPackagePurpose: LIBRARY
254255
PackageSupplier: Person: Google Inc. ([email protected])
255-
PackageDownloadLocation: https://pypi.org/project/gsutil/5.28
256+
PackageDownloadLocation: https://pypi.org/project/gsutil/5.29
256257
FilesAnalyzed: false
257258
PackageLicenseDeclared: NOASSERTION
258259
PackageLicenseConcluded: Apache-2.0
259260
PackageLicenseComments: <text>gsutil declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
260261
PackageCopyrightText: NOASSERTION
261262
PackageSummary: <text>A command line tool for interacting with cloud storage services.</text>
262-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/gsutil@5.28
263-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_inc.:gsutil:5.28:*:*:*:*:*:*:*
263+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/gsutil@5.29
264+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_inc.:gsutil:5.29:*:*:*:*:*:*:*
264265
#####
265266

266267
PackageName: argcomplete
@@ -557,17 +558,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_pyopenssl_developers:pyopenssl:24.
557558

558559
PackageName: cryptography
559560
SPDXID: SPDXRef-Package-35-cryptography
560-
PackageVersion: 42.0.6
561+
PackageVersion: 42.0.7
561562
PrimaryPackagePurpose: LIBRARY
562563
PackageSupplier: Organization: The Python Cryptographic Authority and individual contributors ([email protected])
563-
PackageDownloadLocation: https://pypi.org/project/cryptography/42.0.6
564+
PackageDownloadLocation: https://pypi.org/project/cryptography/42.0.7
564565
FilesAnalyzed: false
565566
PackageLicenseDeclared: Apache-2.0 OR BSD-3-Clause
566567
PackageLicenseConcluded: Apache-2.0 OR BSD-3-Clause
567568
PackageCopyrightText: NOASSERTION
568569
PackageSummary: <text>cryptography is a package which provides cryptographic recipes and primitives to Python developers.</text>
569-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].6
570-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:42.0.6:*:*:*:*:*:*:*
570+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].7
571+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:42.0.7:*:*:*:*:*:*:*
571572
#####
572573

573574
PackageName: cffi
@@ -705,7 +706,6 @@ PrimaryPackagePurpose: LIBRARY
705706
PackageSupplier: NOASSERTION
706707
PackageDownloadLocation: https://pypi.org/project/MarkupSafe/2.1.5
707708
FilesAnalyzed: false
708-
PackageChecksum: SHA1: fbba4acd0312826cec9cfe18371c7df07962cb65
709709
PackageLicenseDeclared: BSD-3-Clause
710710
PackageLicenseConcluded: BSD-3-Clause
711711
PackageCopyrightText: NOASSERTION
@@ -761,17 +761,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:referencing:0.35.1:*:*:*
761761

762762
PackageName: rpds-py
763763
SPDXID: SPDXRef-Package-48-rpds-py
764-
PackageVersion: 0.18.0
764+
PackageVersion: 0.18.1
765765
PrimaryPackagePurpose: LIBRARY
766766
PackageSupplier: Person: Julian Berman
767-
PackageDownloadLocation: https://pypi.org/project/rpds-py/0.18.0
767+
PackageDownloadLocation: https://pypi.org/project/rpds-py/0.18.1
768768
FilesAnalyzed: false
769769
PackageLicenseDeclared: MIT
770770
PackageLicenseConcluded: MIT
771771
PackageCopyrightText: NOASSERTION
772772
PackageSummary: <text>Python bindings to Rust's persistent data structures (rpds)</text>
773-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].0
774-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.18.0:*:*:*:*:*:*:*
773+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].1
774+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.18.1:*:*:*:*:*:*:*
775775
#####
776776

777777
PackageName: lib4sbom
@@ -871,19 +871,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:5.22.0:*:*:*:*:*:*:*
871871

872872
PackageName: tenacity
873873
SPDXID: SPDXRef-Package-55-tenacity
874-
PackageVersion: 8.2.3
874+
PackageVersion: 8.3.0
875875
PrimaryPackagePurpose: LIBRARY
876876
PackageSupplier: Person: Julien Danjou ([email protected])
877-
PackageDownloadLocation: https://pypi.org/project/tenacity/8.2.3
877+
PackageDownloadLocation: https://pypi.org/project/tenacity/8.3.0
878878
FilesAnalyzed: false
879-
PackageChecksum: SHA1: 41ed2420cda8ab7650a39900451099f4730266c3
880879
PackageLicenseDeclared: NOASSERTION
881880
PackageLicenseConcluded: Apache-2.0
882881
PackageLicenseComments: <text>tenacity declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
883882
PackageCopyrightText: NOASSERTION
884883
PackageSummary: <text>Retry code until it succeeds</text>
885-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/tenacity@8.2.3
886-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julien_danjou:tenacity:8.2.3:*:*:*:*:*:*:*
884+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/tenacity@8.3.0
885+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julien_danjou:tenacity:8.3.0:*:*:*:*:*:*:*
887886
#####
888887

889888
PackageName: python-gnupg

0 commit comments

Comments
 (0)