Skip to content

Commit 610251a

Browse files
web-flowgithub-actions[bot]
authored andcommitted
chore: update SBOM for Python 3.9
1 parent 8610ceb commit 610251a

File tree

2 files changed

+34
-48
lines changed

2 files changed

+34
-48
lines changed

sbom/cve-bin-tool-py3.9.json

Lines changed: 17 additions & 29 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.5.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.5",
5-
"serialNumber": "urn:uuid:86bfebc8-cd04-4c9a-98d8-90930122e373",
5+
"serialNumber": "urn:uuid:62d51421-c5d5-4db5-a60b-f0ced871055c",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2024-04-15T02:43:08Z",
8+
"timestamp": "2024-04-22T00:27:44Z",
99
"tools": {
1010
"components": [
1111
{
@@ -26,7 +26,7 @@
2626
"type": "application",
2727
"bom-ref": "1-cve-bin-tool",
2828
"name": "cve-bin-tool",
29-
"version": "3.3",
29+
"version": "3.3.1.dev0",
3030
"supplier": {
3131
"name": "Terri Oda",
3232
"contact": [
@@ -35,14 +35,8 @@
3535
}
3636
]
3737
},
38-
"cpe": "cpe:2.3:a:terri_oda:cve-bin-tool:3.3:*:*:*:*:*:*:*",
38+
"cpe": "cpe:2.3:a:terri_oda:cve-bin-tool:3.3.1.dev0:*:*:*:*:*:*:*",
3939
"description": "CVE Binary Checker Tool",
40-
"hashes": [
41-
{
42-
"alg": "SHA-1",
43-
"content": "83e30ee0f640bce7a20d4346c85873d359c05d1f"
44-
}
45-
],
4640
"licenses": [
4741
{
4842
"license": {
@@ -53,12 +47,12 @@
5347
],
5448
"externalReferences": [
5549
{
56-
"url": "https://pypi.org/project/cve-bin-tool/3.3",
50+
"url": "https://pypi.org/project/cve-bin-tool/3.3.1.dev0",
5751
"type": "distribution",
5852
"comment": "Download location for component"
5953
}
6054
],
61-
"purl": "pkg:pypi/[email protected]",
55+
"purl": "pkg:pypi/[email protected].1.dev0",
6256
"properties": [
6357
{
6458
"name": "language",
@@ -74,7 +68,7 @@
7468
"type": "library",
7569
"bom-ref": "2-aiohttp",
7670
"name": "aiohttp",
77-
"version": "3.9.4",
71+
"version": "3.9.5",
7872
"description": "Async http client/server framework (asyncio)",
7973
"licenses": [
8074
{
@@ -86,12 +80,12 @@
8680
],
8781
"externalReferences": [
8882
{
89-
"url": "https://pypi.org/project/aiohttp/3.9.4",
83+
"url": "https://pypi.org/project/aiohttp/3.9.5",
9084
"type": "distribution",
9185
"comment": "Download location for component"
9286
}
9387
],
94-
"purl": "pkg:pypi/[email protected].4",
88+
"purl": "pkg:pypi/[email protected].5",
9589
"properties": [
9690
{
9791
"name": "language",
@@ -2235,7 +2229,7 @@
22352229
"type": "library",
22362230
"bom-ref": "53-plotly",
22372231
"name": "plotly",
2238-
"version": "5.20.0",
2232+
"version": "5.21.0",
22392233
"supplier": {
22402234
"name": "Chris P",
22412235
"contact": [
@@ -2244,14 +2238,8 @@
22442238
}
22452239
]
22462240
},
2247-
"cpe": "cpe:2.3:a:chris_p:plotly:5.20.0:*:*:*:*:*:*:*",
2241+
"cpe": "cpe:2.3:a:chris_p:plotly:5.21.0:*:*:*:*:*:*:*",
22482242
"description": "An open-source, interactive data visualization library for Python",
2249-
"hashes": [
2250-
{
2251-
"alg": "SHA-1",
2252-
"content": "9335a34ca77399a597a72420f73e947217d3d410"
2253-
}
2254-
],
22552243
"licenses": [
22562244
{
22572245
"license": {
@@ -2262,12 +2250,12 @@
22622250
],
22632251
"externalReferences": [
22642252
{
2265-
"url": "https://pypi.org/project/plotly/5.20.0",
2253+
"url": "https://pypi.org/project/plotly/5.21.0",
22662254
"type": "distribution",
22672255
"comment": "Download location for component"
22682256
}
22692257
],
2270-
"purl": "pkg:pypi/plotly@5.20.0",
2258+
"purl": "pkg:pypi/plotly@5.21.0",
22712259
"properties": [
22722260
{
22732261
"name": "language",
@@ -2811,7 +2799,7 @@
28112799
"type": "library",
28122800
"bom-ref": "66-xmlschema",
28132801
"name": "xmlschema",
2814-
"version": "3.2.1",
2802+
"version": "3.3.0",
28152803
"supplier": {
28162804
"name": "Davide Brunato",
28172805
"contact": [
@@ -2820,7 +2808,7 @@
28202808
}
28212809
]
28222810
},
2823-
"cpe": "cpe:2.3:a:davide_brunato:xmlschema:3.2.1:*:*:*:*:*:*:*",
2811+
"cpe": "cpe:2.3:a:davide_brunato:xmlschema:3.3.0:*:*:*:*:*:*:*",
28242812
"description": "An XML Schema validator and decoder",
28252813
"licenses": [
28262814
{
@@ -2832,12 +2820,12 @@
28322820
],
28332821
"externalReferences": [
28342822
{
2835-
"url": "https://pypi.org/project/xmlschema/3.2.1",
2823+
"url": "https://pypi.org/project/xmlschema/3.3.0",
28362824
"type": "distribution",
28372825
"comment": "Download location for component"
28382826
}
28392827
],
2840-
"purl": "pkg:pypi/xmlschema@3.2.1",
2828+
"purl": "pkg:pypi/xmlschema@3.3.0",
28412829
"properties": [
28422830
{
28432831
"name": "language",

sbom/cve-bin-tool-py3.9.spdx

Lines changed: 17 additions & 19 deletions
Original file line numberDiff line numberDiff line change
@@ -2,42 +2,41 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-07124c73-1f18-4124-ac1c-c53724579633
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-9c42dfff-8156-4a69-bdf7-6143efc1f04a
66
LicenseListVersion: 3.22
77
Creator: Tool: sbom4python-0.10.4
8-
Created: 2024-04-15T02:41:52Z
8+
Created: 2024-04-22T00:26:31Z
99
CreatorComment: <text>This document has been automatically generated.</text>
1010
#####
1111

1212
PackageName: cve-bin-tool
1313
SPDXID: SPDXRef-Package-1-cve-bin-tool
14-
PackageVersion: 3.3
14+
PackageVersion: 3.3.1.dev0
1515
PrimaryPackagePurpose: APPLICATION
1616
PackageSupplier: Person: Terri Oda ([email protected])
17-
PackageDownloadLocation: https://pypi.org/project/cve-bin-tool/3.3
17+
PackageDownloadLocation: https://pypi.org/project/cve-bin-tool/3.3.1.dev0
1818
FilesAnalyzed: false
19-
PackageChecksum: SHA1: 83e30ee0f640bce7a20d4346c85873d359c05d1f
2019
PackageLicenseDeclared: GPL-3.0-or-later
2120
PackageLicenseConcluded: GPL-3.0-or-later
2221
PackageCopyrightText: NOASSERTION
2322
PackageSummary: <text>CVE Binary Checker Tool</text>
24-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected]
25-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.3:*:*:*:*:*:*:*
23+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].1.dev0
24+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.3.1.dev0:*:*:*:*:*:*:*
2625
#####
2726

2827
PackageName: aiohttp
2928
SPDXID: SPDXRef-Package-2-aiohttp
30-
PackageVersion: 3.9.4
29+
PackageVersion: 3.9.5
3130
PrimaryPackagePurpose: LIBRARY
3231
PackageSupplier: NOASSERTION
33-
PackageDownloadLocation: https://pypi.org/project/aiohttp/3.9.4
32+
PackageDownloadLocation: https://pypi.org/project/aiohttp/3.9.5
3433
FilesAnalyzed: false
3534
PackageLicenseDeclared: NOASSERTION
3635
PackageLicenseConcluded: Apache-2.0
3736
PackageLicenseComments: <text>aiohttp declares Apache 2 which is not currently a valid SPDX License identifier or expression.</text>
3837
PackageCopyrightText: NOASSERTION
3938
PackageSummary: <text>Async http client/server framework (asyncio)</text>
40-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].4
39+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].5
4140
#####
4241

4342
PackageName: aiosignal
@@ -835,18 +834,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:donald_stufft:packaging:24.0:*:*:*:*:*
835834

836835
PackageName: plotly
837836
SPDXID: SPDXRef-Package-53-plotly
838-
PackageVersion: 5.20.0
837+
PackageVersion: 5.21.0
839838
PrimaryPackagePurpose: LIBRARY
840839
PackageSupplier: Person: Chris P ([email protected])
841-
PackageDownloadLocation: https://pypi.org/project/plotly/5.20.0
840+
PackageDownloadLocation: https://pypi.org/project/plotly/5.21.0
842841
FilesAnalyzed: false
843-
PackageChecksum: SHA1: 9335a34ca77399a597a72420f73e947217d3d410
844842
PackageLicenseDeclared: MIT
845843
PackageLicenseConcluded: MIT
846844
PackageCopyrightText: NOASSERTION
847845
PackageSummary: <text>An open-source, interactive data visualization library for Python</text>
848-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/plotly@5.20.0
849-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:5.20.0:*:*:*:*:*:*:*
846+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/plotly@5.21.0
847+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:5.21.0:*:*:*:*:*:*:*
850848
#####
851849

852850
PackageName: tenacity
@@ -1042,17 +1040,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:william_pearson:toml:0.10.2:*:*:*:*:*:
10421040

10431041
PackageName: xmlschema
10441042
SPDXID: SPDXRef-Package-66-xmlschema
1045-
PackageVersion: 3.2.1
1043+
PackageVersion: 3.3.0
10461044
PrimaryPackagePurpose: LIBRARY
10471045
PackageSupplier: Person: Davide Brunato ([email protected])
1048-
PackageDownloadLocation: https://pypi.org/project/xmlschema/3.2.1
1046+
PackageDownloadLocation: https://pypi.org/project/xmlschema/3.3.0
10491047
FilesAnalyzed: false
10501048
PackageLicenseDeclared: MIT
10511049
PackageLicenseConcluded: MIT
10521050
PackageCopyrightText: NOASSERTION
10531051
PackageSummary: <text>An XML Schema validator and decoder</text>
1054-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/xmlschema@3.2.1
1055-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:davide_brunato:xmlschema:3.2.1:*:*:*:*:*:*:*
1052+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/xmlschema@3.3.0
1053+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:davide_brunato:xmlschema:3.3.0:*:*:*:*:*:*:*
10561054
#####
10571055

10581056
PackageName: elementpath

0 commit comments

Comments
 (0)