Skip to content

Commit a85edb2

Browse files
chore: update SBOM for Python 3.12 (#4658)
Co-authored-by: GitHub <[email protected]>
1 parent 5b40882 commit a85edb2

File tree

2 files changed

+51
-33
lines changed

2 files changed

+51
-33
lines changed

sbom/cve-bin-tool-py3.12.json

Lines changed: 34 additions & 19 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:ba7deb33-60bc-4e5d-aa41-b59969aae9d5",
5+
"serialNumber": "urn:uuid:a96614bc-e99f-48ba-9bfe-beea6e6e2028",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2024-12-23T00:36:39Z",
8+
"timestamp": "2024-12-30T00:36:13Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -246,6 +246,12 @@
246246
"name": "aiosignal",
247247
"version": "1.3.2",
248248
"description": "aiosignal: a list of registered asynchronous callbacks",
249+
"hashes": [
250+
{
251+
"alg": "SHA-256",
252+
"content": "45cde58e409a301715980c2b01d0c28bdde3770d8290b5eb2173759d9acb31a5"
253+
}
254+
],
249255
"licenses": [
250256
{
251257
"license": {
@@ -295,7 +301,7 @@
295301
"properties": [
296302
{
297303
"name": "release_date",
298-
"value": "2024-11-30T18:43:39Z"
304+
"value": "2024-12-13T17:10:38Z"
299305
},
300306
{
301307
"name": "language",
@@ -4166,21 +4172,21 @@
41664172
"type": "library",
41674173
"bom-ref": "66-charset-normalizer",
41684174
"name": "charset-normalizer",
4169-
"version": "3.4.0",
4175+
"version": "3.4.1",
41704176
"supplier": {
4171-
"name": "Ahmed TAHRI",
4177+
"name": "Ahmed R .",
41724178
"contact": [
41734179
{
41744180
"email": "[email protected]"
41754181
}
41764182
]
41774183
},
4178-
"cpe": "cpe:2.3:a:ahmed_tahri:charset-normalizer:3.4.0:*:*:*:*:*:*:*",
4184+
"cpe": "cpe:2.3:a:ahmed_r.:charset-normalizer:3.4.1:*:*:*:*:*:*:*",
41794185
"description": "The Real First Universal Charset Detector. Open, modern and actively maintained alternative to Chardet.",
41804186
"hashes": [
41814187
{
41824188
"alg": "SHA-256",
4183-
"content": "4f9fc98dad6c2eaa32fc3af1417d95b5e3d08aff968df0cd320066def971f9a6"
4189+
"content": "91b36a978b5ae0ee86c394f5a54d6ef44db1de0815eb43de826d41d21e4af3de"
41844190
}
41854191
],
41864192
"licenses": [
@@ -4194,29 +4200,32 @@
41944200
],
41954201
"externalReferences": [
41964202
{
4197-
"url": "https://github.com/Ousret/charset_normalizer",
4198-
"type": "website",
4199-
"comment": "Home page for project"
4200-
},
4201-
{
4202-
"url": "https://pypi.org/project/charset-normalizer/3.4.0/#files",
4203+
"url": "https://pypi.org/project/charset-normalizer/3.4.1/#files",
42034204
"type": "distribution",
42044205
"comment": "Download location for component"
42054206
},
42064207
{
4207-
"url": "https://github.com/Ousret/charset_normalizer/issues",
4208-
"type": "issue-tracker"
4208+
"url": "https://github.com/jawah/charset_normalizer/blob/master/CHANGELOG.md",
4209+
"type": "log"
42094210
},
42104211
{
4211-
"url": "https://charset-normalizer.readthedocs.io/en/latest",
4212+
"url": "https://charset-normalizer.readthedocs.io/",
42124213
"type": "documentation"
4214+
},
4215+
{
4216+
"url": "https://github.com/jawah/charset_normalizer",
4217+
"type": "vcs"
4218+
},
4219+
{
4220+
"url": "https://github.com/jawah/charset_normalizer/issues",
4221+
"type": "issue-tracker"
42134222
}
42144223
],
4215-
"purl": "pkg:pypi/[email protected].0",
4224+
"purl": "pkg:pypi/[email protected].1",
42164225
"properties": [
42174226
{
42184227
"name": "release_date",
4219-
"value": "2024-10-09T07:38:02Z"
4228+
"value": "2024-12-24T18:09:43Z"
42204229
},
42214230
{
42224231
"name": "language",
@@ -4243,6 +4252,12 @@
42434252
},
42444253
"cpe": "cpe:2.3:a:andrey_petrov:urllib3:2.3.0:*:*:*:*:*:*:*",
42454254
"description": "HTTP library with thread-safe connection pooling, file post, and more.",
4255+
"hashes": [
4256+
{
4257+
"alg": "SHA-256",
4258+
"content": "1cee9ad369867bfdbbb48b7dd50374c0967a0bb7710050facf0dd6911440e3df"
4259+
}
4260+
],
42464261
"externalReferences": [
42474262
{
42484263
"url": "https://pypi.org/project/urllib3/2.3.0/#files",
@@ -4270,7 +4285,7 @@
42704285
"properties": [
42714286
{
42724287
"name": "release_date",
4273-
"value": "2024-10-09T07:38:02Z"
4288+
"value": "2024-12-22T07:47:28Z"
42744289
},
42754290
{
42764291
"name": "language",

sbom/cve-bin-tool-py3.12.spdx

Lines changed: 17 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-60dfe3c5-3476-48bd-b46c-8ac18237082c
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-a67a67da-e7ea-41be-8157-ee7e9237e8b6
66
LicenseListVersion: 3.25
77
Creator: Tool: sbom4python-0.12.1
8-
Created: 2024-12-23T00:36:31Z
8+
Created: 2024-12-30T00:36:05Z
99
CreatorComment: <text>This document has been automatically generated.</text>
1010
#####
1111

@@ -82,12 +82,13 @@ PackageSupplier: NOASSERTION
8282
PackageDownloadLocation: https://pypi.org/project/aiosignal/1.3.2/#files
8383
FilesAnalyzed: false
8484
PackageHomePage: https://github.com/aio-libs/aiosignal
85+
PackageChecksum: SHA256: 45cde58e409a301715980c2b01d0c28bdde3770d8290b5eb2173759d9acb31a5
8586
PackageLicenseDeclared: NOASSERTION
8687
PackageLicenseConcluded: Apache-2.0
8788
PackageLicenseComments: <text>aiosignal declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
8889
PackageCopyrightText: NOASSERTION
8990
PackageSummary: <text>aiosignal: a list of registered asynchronous callbacks</text>
90-
ReleaseDate: 2024-11-30T18:43:39Z
91+
ReleaseDate: 2024-12-13T17:10:38Z
9192
ExternalRef: OTHER other https://gitter.im/aio-libs/Lobby
9293
ExternalRef: OTHER build-system https://github.com/aio-libs/aiosignal/actions
9394
ExternalRef: OTHER other https://codecov.io/github/aio-libs/aiosignal
@@ -1370,22 +1371,23 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:requests:2.32.3:*:*:*:*:
13701371

13711372
PackageName: charset-normalizer
13721373
SPDXID: SPDXRef-66-charset-normalizer
1373-
PackageVersion: 3.4.0
1374+
PackageVersion: 3.4.1
13741375
PrimaryPackagePurpose: LIBRARY
1375-
PackageSupplier: Person: Ahmed TAHRI ([email protected])
1376-
PackageDownloadLocation: https://pypi.org/project/charset-normalizer/3.4.0/#files
1376+
PackageSupplier: Organization: Ahmed R. ([email protected])
1377+
PackageDownloadLocation: https://pypi.org/project/charset-normalizer/3.4.1/#files
13771378
FilesAnalyzed: false
1378-
PackageHomePage: https://github.com/Ousret/charset_normalizer
1379-
PackageChecksum: SHA256: 4f9fc98dad6c2eaa32fc3af1417d95b5e3d08aff968df0cd320066def971f9a6
1379+
PackageChecksum: SHA256: 91b36a978b5ae0ee86c394f5a54d6ef44db1de0815eb43de826d41d21e4af3de
13801380
PackageLicenseDeclared: MIT
13811381
PackageLicenseConcluded: MIT
13821382
PackageCopyrightText: NOASSERTION
13831383
PackageSummary: <text>The Real First Universal Charset Detector. Open, modern and actively maintained alternative to Chardet.</text>
1384-
ReleaseDate: 2024-10-09T07:38:02Z
1385-
ExternalRef: OTHER issue-tracker https://github.com/Ousret/charset_normalizer/issues
1386-
ExternalRef: OTHER documentation https://charset-normalizer.readthedocs.io/en/latest
1387-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected]
1388-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:ahmed_tahri:charset-normalizer:3.4.0:*:*:*:*:*:*:*
1384+
ReleaseDate: 2024-12-24T18:09:43Z
1385+
ExternalRef: OTHER log https://github.com/jawah/charset_normalizer/blob/master/CHANGELOG.md
1386+
ExternalRef: OTHER documentation https://charset-normalizer.readthedocs.io/
1387+
ExternalRef: OTHER vcs https://github.com/jawah/charset_normalizer
1388+
ExternalRef: OTHER issue-tracker https://github.com/jawah/charset_normalizer/issues
1389+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected]
1390+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:ahmed_r.:charset-normalizer:3.4.1:*:*:*:*:*:*:*
13891391
#####
13901392

13911393
PackageName: urllib3
@@ -1395,11 +1397,12 @@ PrimaryPackagePurpose: LIBRARY
13951397
PackageSupplier: Person: Andrey Petrov ([email protected])
13961398
PackageDownloadLocation: https://pypi.org/project/urllib3/2.3.0/#files
13971399
FilesAnalyzed: false
1400+
PackageChecksum: SHA256: 1cee9ad369867bfdbbb48b7dd50374c0967a0bb7710050facf0dd6911440e3df
13981401
PackageLicenseDeclared: NOASSERTION
13991402
PackageLicenseConcluded: NOASSERTION
14001403
PackageCopyrightText: NOASSERTION
14011404
PackageSummary: <text>HTTP library with thread-safe connection pooling, file post, and more.</text>
1402-
ReleaseDate: 2024-10-09T07:38:02Z
1405+
ReleaseDate: 2024-12-22T07:47:28Z
14031406
ExternalRef: OTHER log https://github.com/urllib3/urllib3/blob/main/CHANGES.rst
14041407
ExternalRef: OTHER documentation https://urllib3.readthedocs.io
14051408
ExternalRef: OTHER vcs https://github.com/urllib3/urllib3

0 commit comments

Comments
 (0)