Skip to content

Commit 7c92123

Browse files
authored
chore: update SBOM for Python 3.10
1 parent 3816c72 commit 7c92123

File tree

2 files changed

+36
-36
lines changed

2 files changed

+36
-36
lines changed

sbom/cve-bin-tool-py3.10.json

Lines changed: 18 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.4.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.4",
5-
"serialNumber": "urn:uuidd5330715-93f3-4862-a632-a32a97c64c94",
5+
"serialNumber": "urn:uuid4a7b46e0-061d-4124-81c9-34a5a5a2e7cb",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2023-05-22T00:27:52Z",
8+
"timestamp": "2023-05-29T00:26:41Z",
99
"tools": [
1010
{
1111
"name": "sbom4python",
@@ -1377,7 +1377,7 @@
13771377
"type": "library",
13781378
"bom-ref": "37-google-auth",
13791379
"name": "google-auth",
1380-
"version": "2.18.1",
1380+
"version": "2.19.0",
13811381
"supplier": {
13821382
"name": "Google Cloud Platform",
13831383
"contact": [
@@ -1386,7 +1386,7 @@
13861386
}
13871387
]
13881388
},
1389-
"cpe": "cpe:2.3:a:google_cloud_platform:google-auth:2.18.1:*:*:*:*:*:*:*",
1389+
"cpe": "cpe:2.3:a:google_cloud_platform:google-auth:2.19.0:*:*:*:*:*:*:*",
13901390
"description": "Google Authentication Library",
13911391
"licenses": [
13921392
{
@@ -1403,12 +1403,12 @@
14031403
"comment": "Home page for project"
14041404
},
14051405
{
1406-
"url": "https://pypi.org/project/google-auth/2.18.1",
1406+
"url": "https://pypi.org/project/google-auth/2.19.0",
14071407
"type": "distribution",
14081408
"comment": "Download location for component"
14091409
}
14101410
],
1411-
"purl": "pkg:pypi/google-auth@2.18.1",
1411+
"purl": "pkg:pypi/google-auth@2.19.0",
14121412
"properties": [
14131413
{
14141414
"name": "License Comments",
@@ -1420,7 +1420,7 @@
14201420
"type": "library",
14211421
"bom-ref": "38-cachetools",
14221422
"name": "cachetools",
1423-
"version": "5.3.0",
1423+
"version": "5.3.1",
14241424
"supplier": {
14251425
"name": "Thomas Kemmer",
14261426
"contact": [
@@ -1429,7 +1429,7 @@
14291429
}
14301430
]
14311431
},
1432-
"cpe": "cpe:2.3:a:thomas_kemmer:cachetools:5.3.0:*:*:*:*:*:*:*",
1432+
"cpe": "cpe:2.3:a:thomas_kemmer:cachetools:5.3.1:*:*:*:*:*:*:*",
14331433
"description": "Extensible memoizing collections and decorators",
14341434
"licenses": [
14351435
{
@@ -1446,18 +1446,18 @@
14461446
"comment": "Home page for project"
14471447
},
14481448
{
1449-
"url": "https://pypi.org/project/cachetools/5.3.0",
1449+
"url": "https://pypi.org/project/cachetools/5.3.1",
14501450
"type": "distribution",
14511451
"comment": "Download location for component"
14521452
}
14531453
],
1454-
"purl": "pkg:pypi/[email protected].0"
1454+
"purl": "pkg:pypi/[email protected].1"
14551455
},
14561456
{
14571457
"type": "library",
14581458
"bom-ref": "39-urllib3",
14591459
"name": "urllib3",
1460-
"version": "1.26.15",
1460+
"version": "1.26.16",
14611461
"supplier": {
14621462
"name": "Andrey Petrov",
14631463
"contact": [
@@ -1466,7 +1466,7 @@
14661466
}
14671467
]
14681468
},
1469-
"cpe": "cpe:2.3:a:andrey_petrov:urllib3:1.26.15:*:*:*:*:*:*:*",
1469+
"cpe": "cpe:2.3:a:andrey_petrov:urllib3:1.26.16:*:*:*:*:*:*:*",
14701470
"description": "HTTP library with thread-safe connection pooling, file post, and more.",
14711471
"licenses": [
14721472
{
@@ -1483,12 +1483,12 @@
14831483
"comment": "Home page for project"
14841484
},
14851485
{
1486-
"url": "https://pypi.org/project/urllib3/1.26.15",
1486+
"url": "https://pypi.org/project/urllib3/1.26.16",
14871487
"type": "distribution",
14881488
"comment": "Download location for component"
14891489
}
14901490
],
1491-
"purl": "pkg:pypi/[email protected].15"
1491+
"purl": "pkg:pypi/[email protected].16"
14921492
},
14931493
{
14941494
"type": "library",
@@ -1914,7 +1914,7 @@
19141914
"type": "library",
19151915
"bom-ref": "51-requests",
19161916
"name": "requests",
1917-
"version": "2.30.0",
1917+
"version": "2.31.0",
19181918
"supplier": {
19191919
"name": "Kenneth Reitz",
19201920
"contact": [
@@ -1923,7 +1923,7 @@
19231923
}
19241924
]
19251925
},
1926-
"cpe": "cpe:2.3:a:kenneth_reitz:requests:2.30.0:*:*:*:*:*:*:*",
1926+
"cpe": "cpe:2.3:a:kenneth_reitz:requests:2.31.0:*:*:*:*:*:*:*",
19271927
"description": "Python HTTP for Humans.",
19281928
"licenses": [
19291929
{
@@ -1940,12 +1940,12 @@
19401940
"comment": "Home page for project"
19411941
},
19421942
{
1943-
"url": "https://pypi.org/project/requests/2.30.0",
1943+
"url": "https://pypi.org/project/requests/2.31.0",
19441944
"type": "distribution",
19451945
"comment": "Download location for component"
19461946
}
19471947
],
1948-
"purl": "pkg:pypi/requests@2.30.0",
1948+
"purl": "pkg:pypi/requests@2.31.0",
19491949
"properties": [
19501950
{
19511951
"name": "License Comments",

sbom/cve-bin-tool-py3.10.spdx

Lines changed: 18 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-5af86c52-6745-4b5c-b59e-cc5edf5a1ee1
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-4ce50d6b-1019-46e9-9b17-6b5a58868221
66
LicenseListVersion: 3.20
77
Creator: Tool: sbom4python-0.9.1
8-
Created: 2023-05-22T00:26:22Z
8+
Created: 2023-05-29T00:25:32Z
99
CreatorComment: <text>This document has been automatically generated.</text>
1010
#####
1111

@@ -599,51 +599,51 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:craig_citro:google-apitools:0.5.32:*:*
599599

600600
PackageName: google-auth
601601
SPDXID: SPDXRef-Package-37-google-auth
602-
PackageVersion: 2.18.1
602+
PackageVersion: 2.19.0
603603
PrimaryPackagePurpose: LIBRARY
604604
PackageSupplier: Organization: Google Cloud Platform ([email protected])
605-
PackageDownloadLocation: https://pypi.org/project/google-auth/2.18.1
605+
PackageDownloadLocation: https://pypi.org/project/google-auth/2.19.0
606606
FilesAnalyzed: false
607607
PackageHomePage: https://github.com/googleapis/google-auth-library-python
608608
PackageLicenseDeclared: NOASSERTION
609609
PackageLicenseConcluded: Apache-2.0
610610
PackageLicenseComments: <text>google-auth declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
611611
PackageCopyrightText: NOASSERTION
612612
PackageSummary: <text>Google Authentication Library</text>
613-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/google-auth@2.18.1
614-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_cloud_platform:google-auth:2.18.1:*:*:*:*:*:*:*
613+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/google-auth@2.19.0
614+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_cloud_platform:google-auth:2.19.0:*:*:*:*:*:*:*
615615
#####
616616

617617
PackageName: cachetools
618618
SPDXID: SPDXRef-Package-38-cachetools
619-
PackageVersion: 5.3.0
619+
PackageVersion: 5.3.1
620620
PrimaryPackagePurpose: LIBRARY
621621
PackageSupplier: Person: Thomas Kemmer ([email protected])
622-
PackageDownloadLocation: https://pypi.org/project/cachetools/5.3.0
622+
PackageDownloadLocation: https://pypi.org/project/cachetools/5.3.1
623623
FilesAnalyzed: false
624624
PackageHomePage: https://github.com/tkem/cachetools/
625625
PackageLicenseDeclared: MIT
626626
PackageLicenseConcluded: MIT
627627
PackageCopyrightText: NOASSERTION
628628
PackageSummary: <text>Extensible memoizing collections and decorators</text>
629-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].0
630-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:thomas_kemmer:cachetools:5.3.0:*:*:*:*:*:*:*
629+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].1
630+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:thomas_kemmer:cachetools:5.3.1:*:*:*:*:*:*:*
631631
#####
632632

633633
PackageName: urllib3
634634
SPDXID: SPDXRef-Package-39-urllib3
635-
PackageVersion: 1.26.15
635+
PackageVersion: 1.26.16
636636
PrimaryPackagePurpose: LIBRARY
637637
PackageSupplier: Person: Andrey Petrov ([email protected])
638-
PackageDownloadLocation: https://pypi.org/project/urllib3/1.26.15
638+
PackageDownloadLocation: https://pypi.org/project/urllib3/1.26.16
639639
FilesAnalyzed: false
640640
PackageHomePage: https://urllib3.readthedocs.io/
641641
PackageLicenseDeclared: MIT
642642
PackageLicenseConcluded: MIT
643643
PackageCopyrightText: NOASSERTION
644644
PackageSummary: <text>HTTP library with thread-safe connection pooling, file post, and more.</text>
645-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].15
646-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_petrov:urllib3:1.26.15:*:*:*:*:*:*:*
645+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].16
646+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_petrov:urllib3:1.26.16:*:*:*:*:*:*:*
647647
#####
648648

649649
PackageName: monotonic
@@ -827,19 +827,19 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julien_danjou:tenacity:8.2.2:*:*:*:*:*
827827

828828
PackageName: requests
829829
SPDXID: SPDXRef-Package-51-requests
830-
PackageVersion: 2.30.0
830+
PackageVersion: 2.31.0
831831
PrimaryPackagePurpose: LIBRARY
832832
PackageSupplier: Person: Kenneth Reitz ([email protected])
833-
PackageDownloadLocation: https://pypi.org/project/requests/2.30.0
833+
PackageDownloadLocation: https://pypi.org/project/requests/2.31.0
834834
FilesAnalyzed: false
835835
PackageHomePage: https://requests.readthedocs.io
836836
PackageLicenseDeclared: NOASSERTION
837837
PackageLicenseConcluded: Apache-2.0
838838
PackageLicenseComments: <text>requests declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
839839
PackageCopyrightText: NOASSERTION
840840
PackageSummary: <text>Python HTTP for Humans.</text>
841-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/requests@2.30.0
842-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:requests:2.30.0:*:*:*:*:*:*:*
841+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/requests@2.31.0
842+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:requests:2.31.0:*:*:*:*:*:*:*
843843
#####
844844

845845
PackageName: certifi

0 commit comments

Comments
 (0)