Skip to content

Commit 6d1a590

Browse files
authored
chore: update SBOM for Python 3.8
1 parent 3816c72 commit 6d1a590

File tree

2 files changed

+44
-44
lines changed

2 files changed

+44
-44
lines changed

sbom/cve-bin-tool-py3.8.json

Lines changed: 22 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.4.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.4",
5-
"serialNumber": "urn:uuid8422fb83-076d-48df-a378-970954b2c07a",
5+
"serialNumber": "urn:uuidb9b09cec-54df-4f21-b7b2-20fe19b3b8bd",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2023-05-22T00:27:20Z",
8+
"timestamp": "2023-05-29T00:27:22Z",
99
"tools": [
1010
{
1111
"name": "sbom4python",
@@ -1377,7 +1377,7 @@
13771377
"type": "library",
13781378
"bom-ref": "37-google-auth",
13791379
"name": "google-auth",
1380-
"version": "2.18.1",
1380+
"version": "2.19.0",
13811381
"supplier": {
13821382
"name": "Google Cloud Platform",
13831383
"contact": [
@@ -1386,7 +1386,7 @@
13861386
}
13871387
]
13881388
},
1389-
"cpe": "cpe:2.3:a:google_cloud_platform:google-auth:2.18.1:*:*:*:*:*:*:*",
1389+
"cpe": "cpe:2.3:a:google_cloud_platform:google-auth:2.19.0:*:*:*:*:*:*:*",
13901390
"description": "Google Authentication Library",
13911391
"licenses": [
13921392
{
@@ -1403,12 +1403,12 @@
14031403
"comment": "Home page for project"
14041404
},
14051405
{
1406-
"url": "https://pypi.org/project/google-auth/2.18.1",
1406+
"url": "https://pypi.org/project/google-auth/2.19.0",
14071407
"type": "distribution",
14081408
"comment": "Download location for component"
14091409
}
14101410
],
1411-
"purl": "pkg:pypi/google-auth@2.18.1",
1411+
"purl": "pkg:pypi/google-auth@2.19.0",
14121412
"properties": [
14131413
{
14141414
"name": "License Comments",
@@ -1420,7 +1420,7 @@
14201420
"type": "library",
14211421
"bom-ref": "38-cachetools",
14221422
"name": "cachetools",
1423-
"version": "5.3.0",
1423+
"version": "5.3.1",
14241424
"supplier": {
14251425
"name": "Thomas Kemmer",
14261426
"contact": [
@@ -1429,7 +1429,7 @@
14291429
}
14301430
]
14311431
},
1432-
"cpe": "cpe:2.3:a:thomas_kemmer:cachetools:5.3.0:*:*:*:*:*:*:*",
1432+
"cpe": "cpe:2.3:a:thomas_kemmer:cachetools:5.3.1:*:*:*:*:*:*:*",
14331433
"description": "Extensible memoizing collections and decorators",
14341434
"licenses": [
14351435
{
@@ -1446,18 +1446,18 @@
14461446
"comment": "Home page for project"
14471447
},
14481448
{
1449-
"url": "https://pypi.org/project/cachetools/5.3.0",
1449+
"url": "https://pypi.org/project/cachetools/5.3.1",
14501450
"type": "distribution",
14511451
"comment": "Download location for component"
14521452
}
14531453
],
1454-
"purl": "pkg:pypi/[email protected].0"
1454+
"purl": "pkg:pypi/[email protected].1"
14551455
},
14561456
{
14571457
"type": "library",
14581458
"bom-ref": "39-urllib3",
14591459
"name": "urllib3",
1460-
"version": "1.26.15",
1460+
"version": "1.26.16",
14611461
"supplier": {
14621462
"name": "Andrey Petrov",
14631463
"contact": [
@@ -1466,7 +1466,7 @@
14661466
}
14671467
]
14681468
},
1469-
"cpe": "cpe:2.3:a:andrey_petrov:urllib3:1.26.15:*:*:*:*:*:*:*",
1469+
"cpe": "cpe:2.3:a:andrey_petrov:urllib3:1.26.16:*:*:*:*:*:*:*",
14701470
"description": "HTTP library with thread-safe connection pooling, file post, and more.",
14711471
"licenses": [
14721472
{
@@ -1483,12 +1483,12 @@
14831483
"comment": "Home page for project"
14841484
},
14851485
{
1486-
"url": "https://pypi.org/project/urllib3/1.26.15",
1486+
"url": "https://pypi.org/project/urllib3/1.26.16",
14871487
"type": "distribution",
14881488
"comment": "Download location for component"
14891489
}
14901490
],
1491-
"purl": "pkg:pypi/[email protected].15"
1491+
"purl": "pkg:pypi/[email protected].16"
14921492
},
14931493
{
14941494
"type": "library",
@@ -2030,7 +2030,7 @@
20302030
"type": "library",
20312031
"bom-ref": "55-requests",
20322032
"name": "requests",
2033-
"version": "2.30.0",
2033+
"version": "2.31.0",
20342034
"supplier": {
20352035
"name": "Kenneth Reitz",
20362036
"contact": [
@@ -2039,7 +2039,7 @@
20392039
}
20402040
]
20412041
},
2042-
"cpe": "cpe:2.3:a:kenneth_reitz:requests:2.30.0:*:*:*:*:*:*:*",
2042+
"cpe": "cpe:2.3:a:kenneth_reitz:requests:2.31.0:*:*:*:*:*:*:*",
20432043
"description": "Python HTTP for Humans.",
20442044
"licenses": [
20452045
{
@@ -2056,12 +2056,12 @@
20562056
"comment": "Home page for project"
20572057
},
20582058
{
2059-
"url": "https://pypi.org/project/requests/2.30.0",
2059+
"url": "https://pypi.org/project/requests/2.31.0",
20602060
"type": "distribution",
20612061
"comment": "Download location for component"
20622062
}
20632063
],
2064-
"purl": "pkg:pypi/requests@2.30.0",
2064+
"purl": "pkg:pypi/requests@2.31.0",
20652065
"properties": [
20662066
{
20672067
"name": "License Comments",
@@ -2227,7 +2227,7 @@
22272227
"type": "library",
22282228
"bom-ref": "61-typing-extensions",
22292229
"name": "typing-extensions",
2230-
"version": "4.5.0",
2230+
"version": "4.6.2",
22312231
"supplier": {
22322232
"name": "Guido van Jukka ukasz Michael",
22332233
"contact": [
@@ -2236,16 +2236,16 @@
22362236
}
22372237
]
22382238
},
2239-
"cpe": "cpe:2.3:a:guido_van_jukka_ukasz_michael:typing-extensions:4.5.0:*:*:*:*:*:*:*",
2239+
"cpe": "cpe:2.3:a:guido_van_jukka_ukasz_michael:typing-extensions:4.6.2:*:*:*:*:*:*:*",
22402240
"description": "Backported and Experimental Type Hints for Python 3.7+",
22412241
"externalReferences": [
22422242
{
2243-
"url": "https://pypi.org/project/typing_extensions/4.5.0",
2243+
"url": "https://pypi.org/project/typing_extensions/4.6.2",
22442244
"type": "distribution",
22452245
"comment": "Download location for component"
22462246
}
22472247
],
2248-
"purl": "pkg:pypi/typing-extensions@4.5.0"
2248+
"purl": "pkg:pypi/typing-extensions@4.6.2"
22492249
},
22502250
{
22512251
"type": "library",

sbom/cve-bin-tool-py3.8.spdx

Lines changed: 22 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-3d7ad60e-d4e3-403e-bdc1-2f59271e305d
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-24d84485-8943-44a4-9776-b41bfc9b7686
66
LicenseListVersion: 3.20
77
Creator: Tool: sbom4python-0.9.1
8-
Created: 2023-05-22T00:25:58Z
8+
Created: 2023-05-29T00:25:56Z
99
CreatorComment: <text>This document has been automatically generated.</text>
1010
#####
1111

@@ -599,51 +599,51 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:craig_citro:google-apitools:0.5.32:*:*
599599

600600
PackageName: google-auth
601601
SPDXID: SPDXRef-Package-37-google-auth
602-
PackageVersion: 2.18.1
602+
PackageVersion: 2.19.0
603603
PrimaryPackagePurpose: LIBRARY
604604
PackageSupplier: Organization: Google Cloud Platform ([email protected])
605-
PackageDownloadLocation: https://pypi.org/project/google-auth/2.18.1
605+
PackageDownloadLocation: https://pypi.org/project/google-auth/2.19.0
606606
FilesAnalyzed: false
607607
PackageHomePage: https://github.com/googleapis/google-auth-library-python
608608
PackageLicenseDeclared: NOASSERTION
609609
PackageLicenseConcluded: Apache-2.0
610610
PackageLicenseComments: <text>google-auth declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
611611
PackageCopyrightText: NOASSERTION
612612
PackageSummary: <text>Google Authentication Library</text>
613-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/google-auth@2.18.1
614-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_cloud_platform:google-auth:2.18.1:*:*:*:*:*:*:*
613+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/google-auth@2.19.0
614+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_cloud_platform:google-auth:2.19.0:*:*:*:*:*:*:*
615615
#####
616616

617617
PackageName: cachetools
618618
SPDXID: SPDXRef-Package-38-cachetools
619-
PackageVersion: 5.3.0
619+
PackageVersion: 5.3.1
620620
PrimaryPackagePurpose: LIBRARY
621621
PackageSupplier: Person: Thomas Kemmer ([email protected])
622-
PackageDownloadLocation: https://pypi.org/project/cachetools/5.3.0
622+
PackageDownloadLocation: https://pypi.org/project/cachetools/5.3.1
623623
FilesAnalyzed: false
624624
PackageHomePage: https://github.com/tkem/cachetools/
625625
PackageLicenseDeclared: MIT
626626
PackageLicenseConcluded: MIT
627627
PackageCopyrightText: NOASSERTION
628628
PackageSummary: <text>Extensible memoizing collections and decorators</text>
629-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].0
630-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:thomas_kemmer:cachetools:5.3.0:*:*:*:*:*:*:*
629+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].1
630+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:thomas_kemmer:cachetools:5.3.1:*:*:*:*:*:*:*
631631
#####
632632

633633
PackageName: urllib3
634634
SPDXID: SPDXRef-Package-39-urllib3
635-
PackageVersion: 1.26.15
635+
PackageVersion: 1.26.16
636636
PrimaryPackagePurpose: LIBRARY
637637
PackageSupplier: Person: Andrey Petrov ([email protected])
638-
PackageDownloadLocation: https://pypi.org/project/urllib3/1.26.15
638+
PackageDownloadLocation: https://pypi.org/project/urllib3/1.26.16
639639
FilesAnalyzed: false
640640
PackageHomePage: https://urllib3.readthedocs.io/
641641
PackageLicenseDeclared: MIT
642642
PackageLicenseConcluded: MIT
643643
PackageCopyrightText: NOASSERTION
644644
PackageSummary: <text>HTTP library with thread-safe connection pooling, file post, and more.</text>
645-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].15
646-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_petrov:urllib3:1.26.15:*:*:*:*:*:*:*
645+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].16
646+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_petrov:urllib3:1.26.16:*:*:*:*:*:*:*
647647
#####
648648

649649
PackageName: monotonic
@@ -891,19 +891,19 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julien_danjou:tenacity:8.2.2:*:*:*:*:*
891891

892892
PackageName: requests
893893
SPDXID: SPDXRef-Package-55-requests
894-
PackageVersion: 2.30.0
894+
PackageVersion: 2.31.0
895895
PrimaryPackagePurpose: LIBRARY
896896
PackageSupplier: Person: Kenneth Reitz ([email protected])
897-
PackageDownloadLocation: https://pypi.org/project/requests/2.30.0
897+
PackageDownloadLocation: https://pypi.org/project/requests/2.31.0
898898
FilesAnalyzed: false
899899
PackageHomePage: https://requests.readthedocs.io
900900
PackageLicenseDeclared: NOASSERTION
901901
PackageLicenseConcluded: Apache-2.0
902902
PackageLicenseComments: <text>requests declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
903903
PackageCopyrightText: NOASSERTION
904904
PackageSummary: <text>Python HTTP for Humans.</text>
905-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/requests@2.30.0
906-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:requests:2.30.0:*:*:*:*:*:*:*
905+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/requests@2.31.0
906+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:requests:2.31.0:*:*:*:*:*:*:*
907907
#####
908908

909909
PackageName: certifi
@@ -985,17 +985,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:georg_brandl:pygments:2.15.1:*:*:*:*:*
985985

986986
PackageName: typing-extensions
987987
SPDXID: SPDXRef-Package-61-typing-extensions
988-
PackageVersion: 4.5.0
988+
PackageVersion: 4.6.2
989989
PrimaryPackagePurpose: LIBRARY
990990
PackageSupplier: Organization: Guido van Jukka ukasz Michael ([email protected])
991-
PackageDownloadLocation: https://pypi.org/project/typing_extensions/4.5.0
991+
PackageDownloadLocation: https://pypi.org/project/typing_extensions/4.6.2
992992
FilesAnalyzed: false
993993
PackageLicenseDeclared: NOASSERTION
994994
PackageLicenseConcluded: NOASSERTION
995995
PackageCopyrightText: NOASSERTION
996996
PackageSummary: <text>Backported and Experimental Type Hints for Python 3.7+</text>
997-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/typing-extensions@4.5.0
998-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:guido_van_jukka_ukasz_michael:typing-extensions:4.5.0:*:*:*:*:*:*:*
997+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/typing-extensions@4.6.2
998+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:guido_van_jukka_ukasz_michael:typing-extensions:4.6.2:*:*:*:*:*:*:*
999999
#####
10001000

10011001
PackageName: rpmfile

0 commit comments

Comments
 (0)