Skip to content

Commit 52a3f76

Browse files
chore: update SBOM for Python 3.11 (#4064)
Co-authored-by: GitHub <[email protected]>
1 parent ff7949a commit 52a3f76

File tree

2 files changed

+34
-48
lines changed

2 files changed

+34
-48
lines changed

sbom/cve-bin-tool-py3.11.json

Lines changed: 17 additions & 29 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.5.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.5",
5-
"serialNumber": "urn:uuid:fa92daaf-b6b6-4b4d-8d0a-02f5be3d2743",
5+
"serialNumber": "urn:uuid:a724c9fa-1450-4ee9-90df-ea70f46028f5",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2024-04-15T02:43:05Z",
8+
"timestamp": "2024-04-22T00:27:30Z",
99
"tools": {
1010
"components": [
1111
{
@@ -26,7 +26,7 @@
2626
"type": "application",
2727
"bom-ref": "1-cve-bin-tool",
2828
"name": "cve-bin-tool",
29-
"version": "3.3",
29+
"version": "3.3.1.dev0",
3030
"supplier": {
3131
"name": "Terri Oda",
3232
"contact": [
@@ -35,14 +35,8 @@
3535
}
3636
]
3737
},
38-
"cpe": "cpe:2.3:a:terri_oda:cve-bin-tool:3.3:*:*:*:*:*:*:*",
38+
"cpe": "cpe:2.3:a:terri_oda:cve-bin-tool:3.3.1.dev0:*:*:*:*:*:*:*",
3939
"description": "CVE Binary Checker Tool",
40-
"hashes": [
41-
{
42-
"alg": "SHA-1",
43-
"content": "83e30ee0f640bce7a20d4346c85873d359c05d1f"
44-
}
45-
],
4640
"licenses": [
4741
{
4842
"license": {
@@ -53,12 +47,12 @@
5347
],
5448
"externalReferences": [
5549
{
56-
"url": "https://pypi.org/project/cve-bin-tool/3.3",
50+
"url": "https://pypi.org/project/cve-bin-tool/3.3.1.dev0",
5751
"type": "distribution",
5852
"comment": "Download location for component"
5953
}
6054
],
61-
"purl": "pkg:pypi/[email protected]",
55+
"purl": "pkg:pypi/[email protected].1.dev0",
6256
"properties": [
6357
{
6458
"name": "language",
@@ -74,7 +68,7 @@
7468
"type": "library",
7569
"bom-ref": "2-aiohttp",
7670
"name": "aiohttp",
77-
"version": "3.9.4",
71+
"version": "3.9.5",
7872
"description": "Async http client/server framework (asyncio)",
7973
"licenses": [
8074
{
@@ -86,12 +80,12 @@
8680
],
8781
"externalReferences": [
8882
{
89-
"url": "https://pypi.org/project/aiohttp/3.9.4",
83+
"url": "https://pypi.org/project/aiohttp/3.9.5",
9084
"type": "distribution",
9185
"comment": "Download location for component"
9286
}
9387
],
94-
"purl": "pkg:pypi/[email protected].4",
88+
"purl": "pkg:pypi/[email protected].5",
9589
"properties": [
9690
{
9791
"name": "language",
@@ -2119,7 +2113,7 @@
21192113
"type": "library",
21202114
"bom-ref": "50-plotly",
21212115
"name": "plotly",
2122-
"version": "5.20.0",
2116+
"version": "5.21.0",
21232117
"supplier": {
21242118
"name": "Chris P",
21252119
"contact": [
@@ -2128,14 +2122,8 @@
21282122
}
21292123
]
21302124
},
2131-
"cpe": "cpe:2.3:a:chris_p:plotly:5.20.0:*:*:*:*:*:*:*",
2125+
"cpe": "cpe:2.3:a:chris_p:plotly:5.21.0:*:*:*:*:*:*:*",
21322126
"description": "An open-source, interactive data visualization library for Python",
2133-
"hashes": [
2134-
{
2135-
"alg": "SHA-1",
2136-
"content": "9335a34ca77399a597a72420f73e947217d3d410"
2137-
}
2138-
],
21392127
"licenses": [
21402128
{
21412129
"license": {
@@ -2146,12 +2134,12 @@
21462134
],
21472135
"externalReferences": [
21482136
{
2149-
"url": "https://pypi.org/project/plotly/5.20.0",
2137+
"url": "https://pypi.org/project/plotly/5.21.0",
21502138
"type": "distribution",
21512139
"comment": "Download location for component"
21522140
}
21532141
],
2154-
"purl": "pkg:pypi/plotly@5.20.0",
2142+
"purl": "pkg:pypi/plotly@5.21.0",
21552143
"properties": [
21562144
{
21572145
"name": "language",
@@ -2647,7 +2635,7 @@
26472635
"type": "library",
26482636
"bom-ref": "62-xmlschema",
26492637
"name": "xmlschema",
2650-
"version": "3.2.1",
2638+
"version": "3.3.0",
26512639
"supplier": {
26522640
"name": "Davide Brunato",
26532641
"contact": [
@@ -2656,7 +2644,7 @@
26562644
}
26572645
]
26582646
},
2659-
"cpe": "cpe:2.3:a:davide_brunato:xmlschema:3.2.1:*:*:*:*:*:*:*",
2647+
"cpe": "cpe:2.3:a:davide_brunato:xmlschema:3.3.0:*:*:*:*:*:*:*",
26602648
"description": "An XML Schema validator and decoder",
26612649
"licenses": [
26622650
{
@@ -2668,12 +2656,12 @@
26682656
],
26692657
"externalReferences": [
26702658
{
2671-
"url": "https://pypi.org/project/xmlschema/3.2.1",
2659+
"url": "https://pypi.org/project/xmlschema/3.3.0",
26722660
"type": "distribution",
26732661
"comment": "Download location for component"
26742662
}
26752663
],
2676-
"purl": "pkg:pypi/xmlschema@3.2.1",
2664+
"purl": "pkg:pypi/xmlschema@3.3.0",
26772665
"properties": [
26782666
{
26792667
"name": "language",

sbom/cve-bin-tool-py3.11.spdx

Lines changed: 17 additions & 19 deletions
Original file line numberDiff line numberDiff line change
@@ -2,42 +2,41 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-2bb412b6-9cd4-4fea-848c-dea1256fc8ee
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-82f58543-22bd-4a27-9870-1027bc4a581b
66
LicenseListVersion: 3.22
77
Creator: Tool: sbom4python-0.10.4
8-
Created: 2024-04-15T02:41:53Z
8+
Created: 2024-04-22T00:26:28Z
99
CreatorComment: <text>This document has been automatically generated.</text>
1010
#####
1111

1212
PackageName: cve-bin-tool
1313
SPDXID: SPDXRef-Package-1-cve-bin-tool
14-
PackageVersion: 3.3
14+
PackageVersion: 3.3.1.dev0
1515
PrimaryPackagePurpose: APPLICATION
1616
PackageSupplier: Person: Terri Oda ([email protected])
17-
PackageDownloadLocation: https://pypi.org/project/cve-bin-tool/3.3
17+
PackageDownloadLocation: https://pypi.org/project/cve-bin-tool/3.3.1.dev0
1818
FilesAnalyzed: false
19-
PackageChecksum: SHA1: 83e30ee0f640bce7a20d4346c85873d359c05d1f
2019
PackageLicenseDeclared: GPL-3.0-or-later
2120
PackageLicenseConcluded: GPL-3.0-or-later
2221
PackageCopyrightText: NOASSERTION
2322
PackageSummary: <text>CVE Binary Checker Tool</text>
24-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected]
25-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.3:*:*:*:*:*:*:*
23+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].1.dev0
24+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.3.1.dev0:*:*:*:*:*:*:*
2625
#####
2726

2827
PackageName: aiohttp
2928
SPDXID: SPDXRef-Package-2-aiohttp
30-
PackageVersion: 3.9.4
29+
PackageVersion: 3.9.5
3130
PrimaryPackagePurpose: LIBRARY
3231
PackageSupplier: NOASSERTION
33-
PackageDownloadLocation: https://pypi.org/project/aiohttp/3.9.4
32+
PackageDownloadLocation: https://pypi.org/project/aiohttp/3.9.5
3433
FilesAnalyzed: false
3534
PackageLicenseDeclared: NOASSERTION
3635
PackageLicenseConcluded: Apache-2.0
3736
PackageLicenseComments: <text>aiohttp declares Apache 2 which is not currently a valid SPDX License identifier or expression.</text>
3837
PackageCopyrightText: NOASSERTION
3938
PackageSummary: <text>Async http client/server framework (asyncio)</text>
40-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].4
39+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].5
4140
#####
4241

4342
PackageName: aiosignal
@@ -788,18 +787,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:donald_stufft:packaging:24.0:*:*:*:*:*
788787

789788
PackageName: plotly
790789
SPDXID: SPDXRef-Package-50-plotly
791-
PackageVersion: 5.20.0
790+
PackageVersion: 5.21.0
792791
PrimaryPackagePurpose: LIBRARY
793792
PackageSupplier: Person: Chris P ([email protected])
794-
PackageDownloadLocation: https://pypi.org/project/plotly/5.20.0
793+
PackageDownloadLocation: https://pypi.org/project/plotly/5.21.0
795794
FilesAnalyzed: false
796-
PackageChecksum: SHA1: 9335a34ca77399a597a72420f73e947217d3d410
797795
PackageLicenseDeclared: MIT
798796
PackageLicenseConcluded: MIT
799797
PackageCopyrightText: NOASSERTION
800798
PackageSummary: <text>An open-source, interactive data visualization library for Python</text>
801-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/plotly@5.20.0
802-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:5.20.0:*:*:*:*:*:*:*
799+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/plotly@5.21.0
800+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:5.21.0:*:*:*:*:*:*:*
803801
#####
804802

805803
PackageName: tenacity
@@ -979,17 +977,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:sean_ross:rpmfile:2.0.0:*:*:*:*:*:*:*
979977

980978
PackageName: xmlschema
981979
SPDXID: SPDXRef-Package-62-xmlschema
982-
PackageVersion: 3.2.1
980+
PackageVersion: 3.3.0
983981
PrimaryPackagePurpose: LIBRARY
984982
PackageSupplier: Person: Davide Brunato ([email protected])
985-
PackageDownloadLocation: https://pypi.org/project/xmlschema/3.2.1
983+
PackageDownloadLocation: https://pypi.org/project/xmlschema/3.3.0
986984
FilesAnalyzed: false
987985
PackageLicenseDeclared: MIT
988986
PackageLicenseConcluded: MIT
989987
PackageCopyrightText: NOASSERTION
990988
PackageSummary: <text>An XML Schema validator and decoder</text>
991-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/xmlschema@3.2.1
992-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:davide_brunato:xmlschema:3.2.1:*:*:*:*:*:*:*
989+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/xmlschema@3.3.0
990+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:davide_brunato:xmlschema:3.3.0:*:*:*:*:*:*:*
993991
#####
994992

995993
PackageName: elementpath

0 commit comments

Comments
 (0)