Skip to content

Commit 9dbcbf2

Browse files
chore: update SBOM for Python 3.8 (#4068)
Co-authored-by: GitHub <[email protected]>
1 parent 8610ceb commit 9dbcbf2

File tree

2 files changed

+34
-48
lines changed

2 files changed

+34
-48
lines changed

sbom/cve-bin-tool-py3.8.json

Lines changed: 17 additions & 29 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.5.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.5",
5-
"serialNumber": "urn:uuid:6e6f45f6-34e7-40b9-9f6b-bedf9e571dc1",
5+
"serialNumber": "urn:uuid:3011e948-50cd-43d1-a1c6-42af9dba80ba",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2024-04-15T02:43:38Z",
8+
"timestamp": "2024-04-22T00:28:09Z",
99
"tools": {
1010
"components": [
1111
{
@@ -26,7 +26,7 @@
2626
"type": "application",
2727
"bom-ref": "1-cve-bin-tool",
2828
"name": "cve-bin-tool",
29-
"version": "3.3",
29+
"version": "3.3.1.dev0",
3030
"supplier": {
3131
"name": "Terri Oda",
3232
"contact": [
@@ -35,14 +35,8 @@
3535
}
3636
]
3737
},
38-
"cpe": "cpe:2.3:a:terri_oda:cve-bin-tool:3.3:*:*:*:*:*:*:*",
38+
"cpe": "cpe:2.3:a:terri_oda:cve-bin-tool:3.3.1.dev0:*:*:*:*:*:*:*",
3939
"description": "CVE Binary Checker Tool",
40-
"hashes": [
41-
{
42-
"alg": "SHA-1",
43-
"content": "83e30ee0f640bce7a20d4346c85873d359c05d1f"
44-
}
45-
],
4640
"licenses": [
4741
{
4842
"license": {
@@ -53,12 +47,12 @@
5347
],
5448
"externalReferences": [
5549
{
56-
"url": "https://pypi.org/project/cve-bin-tool/3.3",
50+
"url": "https://pypi.org/project/cve-bin-tool/3.3.1.dev0",
5751
"type": "distribution",
5852
"comment": "Download location for component"
5953
}
6054
],
61-
"purl": "pkg:pypi/[email protected]",
55+
"purl": "pkg:pypi/[email protected].1.dev0",
6256
"properties": [
6357
{
6458
"name": "language",
@@ -74,7 +68,7 @@
7468
"type": "library",
7569
"bom-ref": "2-aiohttp",
7670
"name": "aiohttp",
77-
"version": "3.9.4",
71+
"version": "3.9.5",
7872
"description": "Async http client/server framework (asyncio)",
7973
"licenses": [
8074
{
@@ -86,12 +80,12 @@
8680
],
8781
"externalReferences": [
8882
{
89-
"url": "https://pypi.org/project/aiohttp/3.9.4",
83+
"url": "https://pypi.org/project/aiohttp/3.9.5",
9084
"type": "distribution",
9185
"comment": "Download location for component"
9286
}
9387
],
94-
"purl": "pkg:pypi/[email protected].4",
88+
"purl": "pkg:pypi/[email protected].5",
9589
"properties": [
9690
{
9791
"name": "language",
@@ -2303,7 +2297,7 @@
23032297
"type": "library",
23042298
"bom-ref": "55-plotly",
23052299
"name": "plotly",
2306-
"version": "5.20.0",
2300+
"version": "5.21.0",
23072301
"supplier": {
23082302
"name": "Chris P",
23092303
"contact": [
@@ -2312,14 +2306,8 @@
23122306
}
23132307
]
23142308
},
2315-
"cpe": "cpe:2.3:a:chris_p:plotly:5.20.0:*:*:*:*:*:*:*",
2309+
"cpe": "cpe:2.3:a:chris_p:plotly:5.21.0:*:*:*:*:*:*:*",
23162310
"description": "An open-source, interactive data visualization library for Python",
2317-
"hashes": [
2318-
{
2319-
"alg": "SHA-1",
2320-
"content": "9335a34ca77399a597a72420f73e947217d3d410"
2321-
}
2322-
],
23232311
"licenses": [
23242312
{
23252313
"license": {
@@ -2330,12 +2318,12 @@
23302318
],
23312319
"externalReferences": [
23322320
{
2333-
"url": "https://pypi.org/project/plotly/5.20.0",
2321+
"url": "https://pypi.org/project/plotly/5.21.0",
23342322
"type": "distribution",
23352323
"comment": "Download location for component"
23362324
}
23372325
],
2338-
"purl": "pkg:pypi/plotly@5.20.0",
2326+
"purl": "pkg:pypi/plotly@5.21.0",
23392327
"properties": [
23402328
{
23412329
"name": "language",
@@ -2913,7 +2901,7 @@
29132901
"type": "library",
29142902
"bom-ref": "69-xmlschema",
29152903
"name": "xmlschema",
2916-
"version": "3.2.1",
2904+
"version": "3.3.0",
29172905
"supplier": {
29182906
"name": "Davide Brunato",
29192907
"contact": [
@@ -2922,7 +2910,7 @@
29222910
}
29232911
]
29242912
},
2925-
"cpe": "cpe:2.3:a:davide_brunato:xmlschema:3.2.1:*:*:*:*:*:*:*",
2913+
"cpe": "cpe:2.3:a:davide_brunato:xmlschema:3.3.0:*:*:*:*:*:*:*",
29262914
"description": "An XML Schema validator and decoder",
29272915
"licenses": [
29282916
{
@@ -2934,12 +2922,12 @@
29342922
],
29352923
"externalReferences": [
29362924
{
2937-
"url": "https://pypi.org/project/xmlschema/3.2.1",
2925+
"url": "https://pypi.org/project/xmlschema/3.3.0",
29382926
"type": "distribution",
29392927
"comment": "Download location for component"
29402928
}
29412929
],
2942-
"purl": "pkg:pypi/xmlschema@3.2.1",
2930+
"purl": "pkg:pypi/xmlschema@3.3.0",
29432931
"properties": [
29442932
{
29452933
"name": "language",

sbom/cve-bin-tool-py3.8.spdx

Lines changed: 17 additions & 19 deletions
Original file line numberDiff line numberDiff line change
@@ -2,42 +2,41 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-b3e3bf6c-56dc-407e-86d7-d92b04fc5218
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-a059f2f9-c142-41b3-b870-0e0c0f91d08b
66
LicenseListVersion: 3.22
77
Creator: Tool: sbom4python-0.10.4
8-
Created: 2024-04-15T02:42:07Z
8+
Created: 2024-04-22T00:26:48Z
99
CreatorComment: <text>This document has been automatically generated.</text>
1010
#####
1111

1212
PackageName: cve-bin-tool
1313
SPDXID: SPDXRef-Package-1-cve-bin-tool
14-
PackageVersion: 3.3
14+
PackageVersion: 3.3.1.dev0
1515
PrimaryPackagePurpose: APPLICATION
1616
PackageSupplier: Person: Terri Oda ([email protected])
17-
PackageDownloadLocation: https://pypi.org/project/cve-bin-tool/3.3
17+
PackageDownloadLocation: https://pypi.org/project/cve-bin-tool/3.3.1.dev0
1818
FilesAnalyzed: false
19-
PackageChecksum: SHA1: 83e30ee0f640bce7a20d4346c85873d359c05d1f
2019
PackageLicenseDeclared: GPL-3.0-or-later
2120
PackageLicenseConcluded: GPL-3.0-or-later
2221
PackageCopyrightText: NOASSERTION
2322
PackageSummary: <text>CVE Binary Checker Tool</text>
24-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected]
25-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.3:*:*:*:*:*:*:*
23+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].1.dev0
24+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.3.1.dev0:*:*:*:*:*:*:*
2625
#####
2726

2827
PackageName: aiohttp
2928
SPDXID: SPDXRef-Package-2-aiohttp
30-
PackageVersion: 3.9.4
29+
PackageVersion: 3.9.5
3130
PrimaryPackagePurpose: LIBRARY
3231
PackageSupplier: NOASSERTION
33-
PackageDownloadLocation: https://pypi.org/project/aiohttp/3.9.4
32+
PackageDownloadLocation: https://pypi.org/project/aiohttp/3.9.5
3433
FilesAnalyzed: false
3534
PackageLicenseDeclared: NOASSERTION
3635
PackageLicenseConcluded: Apache-2.0
3736
PackageLicenseComments: <text>aiohttp declares Apache 2 which is not currently a valid SPDX License identifier or expression.</text>
3837
PackageCopyrightText: NOASSERTION
3938
PackageSummary: <text>Async http client/server framework (asyncio)</text>
40-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].4
39+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].5
4140
#####
4241

4342
PackageName: aiosignal
@@ -865,18 +864,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:donald_stufft:packaging:24.0:*:*:*:*:*
865864

866865
PackageName: plotly
867866
SPDXID: SPDXRef-Package-55-plotly
868-
PackageVersion: 5.20.0
867+
PackageVersion: 5.21.0
869868
PrimaryPackagePurpose: LIBRARY
870869
PackageSupplier: Person: Chris P ([email protected])
871-
PackageDownloadLocation: https://pypi.org/project/plotly/5.20.0
870+
PackageDownloadLocation: https://pypi.org/project/plotly/5.21.0
872871
FilesAnalyzed: false
873-
PackageChecksum: SHA1: 9335a34ca77399a597a72420f73e947217d3d410
874872
PackageLicenseDeclared: MIT
875873
PackageLicenseConcluded: MIT
876874
PackageCopyrightText: NOASSERTION
877875
PackageSummary: <text>An open-source, interactive data visualization library for Python</text>
878-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/plotly@5.20.0
879-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:5.20.0:*:*:*:*:*:*:*
876+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/plotly@5.21.0
877+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:5.21.0:*:*:*:*:*:*:*
880878
#####
881879

882880
PackageName: tenacity
@@ -1087,17 +1085,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:william_pearson:toml:0.10.2:*:*:*:*:*:
10871085

10881086
PackageName: xmlschema
10891087
SPDXID: SPDXRef-Package-69-xmlschema
1090-
PackageVersion: 3.2.1
1088+
PackageVersion: 3.3.0
10911089
PrimaryPackagePurpose: LIBRARY
10921090
PackageSupplier: Person: Davide Brunato ([email protected])
1093-
PackageDownloadLocation: https://pypi.org/project/xmlschema/3.2.1
1091+
PackageDownloadLocation: https://pypi.org/project/xmlschema/3.3.0
10941092
FilesAnalyzed: false
10951093
PackageLicenseDeclared: MIT
10961094
PackageLicenseConcluded: MIT
10971095
PackageCopyrightText: NOASSERTION
10981096
PackageSummary: <text>An XML Schema validator and decoder</text>
1099-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/xmlschema@3.2.1
1100-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:davide_brunato:xmlschema:3.2.1:*:*:*:*:*:*:*
1097+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/xmlschema@3.3.0
1098+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:davide_brunato:xmlschema:3.3.0:*:*:*:*:*:*:*
11011099
#####
11021100

11031101
PackageName: elementpath

0 commit comments

Comments
 (0)