Skip to content

Commit 76cc230

Browse files
web-flowgithub-actions[bot]
authored andcommitted
chore: update SBOM for Python 3.11
1 parent 234f8ea commit 76cc230

File tree

2 files changed

+43
-50
lines changed

2 files changed

+43
-50
lines changed

sbom/cve-bin-tool-py3.11.json

Lines changed: 24 additions & 30 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:3d92dd3f-a250-4a6d-b2fd-ff03869a74f5",
5+
"serialNumber": "urn:uuid:8fc2ac9b-6e8a-43fe-bce6-727f3ac89875",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2024-05-06T00:28:01Z",
8+
"timestamp": "2024-05-13T00:28:35Z",
99
"tools": {
1010
"components": [
1111
{
@@ -435,6 +435,12 @@
435435
},
436436
"cpe": "cpe:2.3:a:stanislav_red_hat_product_security:cvss:3.1:*:*:*:*:*:*:*",
437437
"description": "CVSS2/3/4 library with interactive calculator for Python 2 and Python 3",
438+
"hashes": [
439+
{
440+
"alg": "SHA-1",
441+
"content": "e4cf69bea6bcfa1cbc38dca13b9ec8bf3363a475"
442+
}
443+
],
438444
"licenses": [
439445
{
440446
"license": {
@@ -604,7 +610,7 @@
604610
"type": "library",
605611
"bom-ref": "15-gsutil",
606612
"name": "gsutil",
607-
"version": "5.28",
613+
"version": "5.29",
608614
"supplier": {
609615
"name": "Google Inc .",
610616
"contact": [
@@ -613,7 +619,7 @@
613619
}
614620
]
615621
},
616-
"cpe": "cpe:2.3:a:google_inc.:gsutil:5.28:*:*:*:*:*:*:*",
622+
"cpe": "cpe:2.3:a:google_inc.:gsutil:5.29:*:*:*:*:*:*:*",
617623
"description": "A command line tool for interacting with cloud storage services.",
618624
"licenses": [
619625
{
@@ -625,12 +631,12 @@
625631
],
626632
"externalReferences": [
627633
{
628-
"url": "https://pypi.org/project/gsutil/5.28",
634+
"url": "https://pypi.org/project/gsutil/5.29",
629635
"type": "distribution",
630636
"comment": "Download location for component"
631637
}
632638
],
633-
"purl": "pkg:pypi/gsutil@5.28",
639+
"purl": "pkg:pypi/gsutil@5.29",
634640
"properties": [
635641
{
636642
"name": "language",
@@ -1466,7 +1472,7 @@
14661472
"type": "library",
14671473
"bom-ref": "34-cryptography",
14681474
"name": "cryptography",
1469-
"version": "42.0.6",
1475+
"version": "42.0.7",
14701476
"supplier": {
14711477
"name": "The Python Cryptographic Authority and individual contributors",
14721478
"contact": [
@@ -1475,7 +1481,7 @@
14751481
}
14761482
]
14771483
},
1478-
"cpe": "cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:42.0.6:*:*:*:*:*:*:*",
1484+
"cpe": "cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:42.0.7:*:*:*:*:*:*:*",
14791485
"description": "cryptography is a package which provides cryptographic recipes and primitives to Python developers.",
14801486
"licenses": [
14811487
{
@@ -1484,12 +1490,12 @@
14841490
],
14851491
"externalReferences": [
14861492
{
1487-
"url": "https://pypi.org/project/cryptography/42.0.6",
1493+
"url": "https://pypi.org/project/cryptography/42.0.7",
14881494
"type": "distribution",
14891495
"comment": "Download location for component"
14901496
}
14911497
],
1492-
"purl": "pkg:pypi/[email protected].6",
1498+
"purl": "pkg:pypi/[email protected].7",
14931499
"properties": [
14941500
{
14951501
"name": "language",
@@ -1772,12 +1778,6 @@
17721778
"name": "markupsafe",
17731779
"version": "2.1.5",
17741780
"description": "Safely add untrusted strings to HTML/XML markup.",
1775-
"hashes": [
1776-
{
1777-
"alg": "SHA-1",
1778-
"content": "fbba4acd0312826cec9cfe18371c7df07962cb65"
1779-
}
1780-
],
17811781
"licenses": [
17821782
{
17831783
"license": {
@@ -1918,11 +1918,11 @@
19181918
"type": "library",
19191919
"bom-ref": "45-rpds-py",
19201920
"name": "rpds-py",
1921-
"version": "0.18.0",
1921+
"version": "0.18.1",
19221922
"supplier": {
19231923
"name": "Julian Berman"
19241924
},
1925-
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.18.0:*:*:*:*:*:*:*",
1925+
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.18.1:*:*:*:*:*:*:*",
19261926
"description": "Python bindings to Rust's persistent data structures (rpds)",
19271927
"licenses": [
19281928
{
@@ -1934,12 +1934,12 @@
19341934
],
19351935
"externalReferences": [
19361936
{
1937-
"url": "https://pypi.org/project/rpds-py/0.18.0",
1937+
"url": "https://pypi.org/project/rpds-py/0.18.1",
19381938
"type": "distribution",
19391939
"comment": "Download location for component"
19401940
}
19411941
],
1942-
"purl": "pkg:pypi/[email protected].0",
1942+
"purl": "pkg:pypi/[email protected].1",
19431943
"properties": [
19441944
{
19451945
"name": "language",
@@ -2218,7 +2218,7 @@
22182218
"type": "library",
22192219
"bom-ref": "52-tenacity",
22202220
"name": "tenacity",
2221-
"version": "8.2.3",
2221+
"version": "8.3.0",
22222222
"supplier": {
22232223
"name": "Julien Danjou",
22242224
"contact": [
@@ -2227,14 +2227,8 @@
22272227
}
22282228
]
22292229
},
2230-
"cpe": "cpe:2.3:a:julien_danjou:tenacity:8.2.3:*:*:*:*:*:*:*",
2230+
"cpe": "cpe:2.3:a:julien_danjou:tenacity:8.3.0:*:*:*:*:*:*:*",
22312231
"description": "Retry code until it succeeds",
2232-
"hashes": [
2233-
{
2234-
"alg": "SHA-1",
2235-
"content": "41ed2420cda8ab7650a39900451099f4730266c3"
2236-
}
2237-
],
22382232
"licenses": [
22392233
{
22402234
"license": {
@@ -2245,12 +2239,12 @@
22452239
],
22462240
"externalReferences": [
22472241
{
2248-
"url": "https://pypi.org/project/tenacity/8.2.3",
2242+
"url": "https://pypi.org/project/tenacity/8.3.0",
22492243
"type": "distribution",
22502244
"comment": "Download location for component"
22512245
}
22522246
],
2253-
"purl": "pkg:pypi/tenacity@8.2.3",
2247+
"purl": "pkg:pypi/tenacity@8.3.0",
22542248
"properties": [
22552249
{
22562250
"name": "language",

sbom/cve-bin-tool-py3.11.spdx

Lines changed: 19 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-81dc583c-21c5-4aa5-bb6a-0782b82641e9
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-955978f6-8abe-4894-a787-b8e0b16a0b30
66
LicenseListVersion: 3.22
77
Creator: Tool: sbom4python-0.10.4
8-
Created: 2024-05-06T00:26:39Z
8+
Created: 2024-05-13T00:27:14Z
99
CreatorComment: <text>This document has been automatically generated.</text>
1010
#####
1111

@@ -172,6 +172,7 @@ PrimaryPackagePurpose: LIBRARY
172172
PackageSupplier: Organization: Stanislav Red Hat Product Security ([email protected])
173173
PackageDownloadLocation: https://pypi.org/project/cvss/3.1
174174
FilesAnalyzed: false
175+
PackageChecksum: SHA1: e4cf69bea6bcfa1cbc38dca13b9ec8bf3363a475
175176
PackageLicenseDeclared: NOASSERTION
176177
PackageLicenseConcluded: LGPL-3.0-or-later
177178
PackageLicenseComments: <text>cvss declares LGPLv3+ which is not currently a valid SPDX License identifier or expression.</text>
@@ -232,18 +233,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:tomas_aparicio:filetype:1.2.0:*:*:*:*:
232233

233234
PackageName: gsutil
234235
SPDXID: SPDXRef-Package-15-gsutil
235-
PackageVersion: 5.28
236+
PackageVersion: 5.29
236237
PrimaryPackagePurpose: LIBRARY
237238
PackageSupplier: Person: Google Inc. ([email protected])
238-
PackageDownloadLocation: https://pypi.org/project/gsutil/5.28
239+
PackageDownloadLocation: https://pypi.org/project/gsutil/5.29
239240
FilesAnalyzed: false
240241
PackageLicenseDeclared: NOASSERTION
241242
PackageLicenseConcluded: Apache-2.0
242243
PackageLicenseComments: <text>gsutil declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
243244
PackageCopyrightText: NOASSERTION
244245
PackageSummary: <text>A command line tool for interacting with cloud storage services.</text>
245-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/gsutil@5.28
246-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_inc.:gsutil:5.28:*:*:*:*:*:*:*
246+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/gsutil@5.29
247+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_inc.:gsutil:5.29:*:*:*:*:*:*:*
247248
#####
248249

249250
PackageName: argcomplete
@@ -540,17 +541,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_pyopenssl_developers:pyopenssl:24.
540541

541542
PackageName: cryptography
542543
SPDXID: SPDXRef-Package-34-cryptography
543-
PackageVersion: 42.0.6
544+
PackageVersion: 42.0.7
544545
PrimaryPackagePurpose: LIBRARY
545546
PackageSupplier: Organization: The Python Cryptographic Authority and individual contributors ([email protected])
546-
PackageDownloadLocation: https://pypi.org/project/cryptography/42.0.6
547+
PackageDownloadLocation: https://pypi.org/project/cryptography/42.0.7
547548
FilesAnalyzed: false
548549
PackageLicenseDeclared: Apache-2.0 OR BSD-3-Clause
549550
PackageLicenseConcluded: Apache-2.0 OR BSD-3-Clause
550551
PackageCopyrightText: NOASSERTION
551552
PackageSummary: <text>cryptography is a package which provides cryptographic recipes and primitives to Python developers.</text>
552-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].6
553-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:42.0.6:*:*:*:*:*:*:*
553+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].7
554+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:42.0.7:*:*:*:*:*:*:*
554555
#####
555556

556557
PackageName: cffi
@@ -656,7 +657,6 @@ PrimaryPackagePurpose: LIBRARY
656657
PackageSupplier: NOASSERTION
657658
PackageDownloadLocation: https://pypi.org/project/MarkupSafe/2.1.5
658659
FilesAnalyzed: false
659-
PackageChecksum: SHA1: fbba4acd0312826cec9cfe18371c7df07962cb65
660660
PackageLicenseDeclared: BSD-3-Clause
661661
PackageLicenseConcluded: BSD-3-Clause
662662
PackageCopyrightText: NOASSERTION
@@ -712,17 +712,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:referencing:0.35.1:*:*:*
712712

713713
PackageName: rpds-py
714714
SPDXID: SPDXRef-Package-45-rpds-py
715-
PackageVersion: 0.18.0
715+
PackageVersion: 0.18.1
716716
PrimaryPackagePurpose: LIBRARY
717717
PackageSupplier: Person: Julian Berman
718-
PackageDownloadLocation: https://pypi.org/project/rpds-py/0.18.0
718+
PackageDownloadLocation: https://pypi.org/project/rpds-py/0.18.1
719719
FilesAnalyzed: false
720720
PackageLicenseDeclared: MIT
721721
PackageLicenseConcluded: MIT
722722
PackageCopyrightText: NOASSERTION
723723
PackageSummary: <text>Python bindings to Rust's persistent data structures (rpds)</text>
724-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].0
725-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.18.0:*:*:*:*:*:*:*
724+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].1
725+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.18.1:*:*:*:*:*:*:*
726726
#####
727727

728728
PackageName: lib4sbom
@@ -822,19 +822,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:5.22.0:*:*:*:*:*:*:*
822822

823823
PackageName: tenacity
824824
SPDXID: SPDXRef-Package-52-tenacity
825-
PackageVersion: 8.2.3
825+
PackageVersion: 8.3.0
826826
PrimaryPackagePurpose: LIBRARY
827827
PackageSupplier: Person: Julien Danjou ([email protected])
828-
PackageDownloadLocation: https://pypi.org/project/tenacity/8.2.3
828+
PackageDownloadLocation: https://pypi.org/project/tenacity/8.3.0
829829
FilesAnalyzed: false
830-
PackageChecksum: SHA1: 41ed2420cda8ab7650a39900451099f4730266c3
831830
PackageLicenseDeclared: NOASSERTION
832831
PackageLicenseConcluded: Apache-2.0
833832
PackageLicenseComments: <text>tenacity declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
834833
PackageCopyrightText: NOASSERTION
835834
PackageSummary: <text>Retry code until it succeeds</text>
836-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/tenacity@8.2.3
837-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julien_danjou:tenacity:8.2.3:*:*:*:*:*:*:*
835+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/tenacity@8.3.0
836+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julien_danjou:tenacity:8.3.0:*:*:*:*:*:*:*
838837
#####
839838

840839
PackageName: python-gnupg

0 commit comments

Comments
 (0)