Skip to content

Commit b4c371b

Browse files
chore: update SBOM for Python 3.9 (#4528)
Co-authored-by: GitHub <[email protected]>
1 parent bbed296 commit b4c371b

File tree

2 files changed

+49
-53
lines changed

2 files changed

+49
-53
lines changed

sbom/cve-bin-tool-py3.9.json

Lines changed: 27 additions & 31 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:446914dd-c18a-4e5a-8c75-a21664d12eb9",
5+
"serialNumber": "urn:uuid:fad70535-a2c6-4cf6-84b8-75bf196560b4",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2024-10-21T00:38:06Z",
8+
"timestamp": "2024-10-28T00:40:22Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -129,6 +129,12 @@
129129
},
130130
"cpe": "cpe:2.3:a:j._nick_koston:aiohappyeyeballs:2.4.3:*:*:*:*:*:*:*",
131131
"description": "Happy Eyeballs for asyncio",
132+
"hashes": [
133+
{
134+
"alg": "SHA-1",
135+
"content": "e3519bbebf2069eee0aff0dfde50689c742ba97f"
136+
}
137+
],
132138
"licenses": [
133139
{
134140
"license": {
@@ -215,7 +221,7 @@
215221
"type": "library",
216222
"bom-ref": "5-frozenlist",
217223
"name": "frozenlist",
218-
"version": "1.4.1",
224+
"version": "1.5.0",
219225
"description": "A list-like structure which implements collections.abc.MutableSequence",
220226
"licenses": [
221227
{
@@ -233,12 +239,12 @@
233239
"comment": "Home page for project"
234240
},
235241
{
236-
"url": "https://pypi.org/project/frozenlist/1.4.1/#files",
242+
"url": "https://pypi.org/project/frozenlist/1.5.0/#files",
237243
"type": "distribution",
238244
"comment": "Download location for component"
239245
}
240246
],
241-
"purl": "pkg:pypi/frozenlist@1.4.1",
247+
"purl": "pkg:pypi/frozenlist@1.5.0",
242248
"properties": [
243249
{
244250
"name": "language",
@@ -247,10 +253,6 @@
247253
{
248254
"name": "python_version",
249255
"value": "3.9.20"
250-
},
251-
{
252-
"name": "package_release_date",
253-
"value": "2023-12-15T08:40:29.000Z"
254256
}
255257
]
256258
},
@@ -432,7 +434,7 @@
432434
"type": "library",
433435
"bom-ref": "10-yarl",
434436
"name": "yarl",
435-
"version": "1.15.5",
437+
"version": "1.16.0",
436438
"supplier": {
437439
"name": "Andrew Svetlov",
438440
"contact": [
@@ -441,7 +443,7 @@
441443
}
442444
]
443445
},
444-
"cpe": "cpe:2.3:a:andrew_svetlov:yarl:1.15.5:*:*:*:*:*:*:*",
446+
"cpe": "cpe:2.3:a:andrew_svetlov:yarl:1.16.0:*:*:*:*:*:*:*",
445447
"description": "Yet another URL library",
446448
"licenses": [
447449
{
@@ -459,12 +461,12 @@
459461
"comment": "Home page for project"
460462
},
461463
{
462-
"url": "https://pypi.org/project/yarl/1.15.5/#files",
464+
"url": "https://pypi.org/project/yarl/1.16.0/#files",
463465
"type": "distribution",
464466
"comment": "Download location for component"
465467
}
466468
],
467-
"purl": "pkg:pypi/yarl@1.15.5",
469+
"purl": "pkg:pypi/yarl@1.16.0",
468470
"properties": [
469471
{
470472
"name": "language",
@@ -2775,18 +2777,12 @@
27752777
"type": "library",
27762778
"bom-ref": "57-packageurl-python",
27772779
"name": "packageurl-python",
2778-
"version": "0.15.6",
2780+
"version": "0.16.0",
27792781
"supplier": {
27802782
"name": "the purl authors"
27812783
},
2782-
"cpe": "cpe:2.3:a:the_purl_authors:packageurl-python:0.15.6:*:*:*:*:*:*:*",
2784+
"cpe": "cpe:2.3:a:the_purl_authors:packageurl-python:0.16.0:*:*:*:*:*:*:*",
27832785
"description": "A purl aka. Package URL parser and builder",
2784-
"hashes": [
2785-
{
2786-
"alg": "SHA-1",
2787-
"content": "14a11b50ab723796888133d3722b5b3e2845b084"
2788-
}
2789-
],
27902786
"licenses": [
27912787
{
27922788
"license": {
@@ -2803,12 +2799,12 @@
28032799
"comment": "Home page for project"
28042800
},
28052801
{
2806-
"url": "https://pypi.org/project/packageurl-python/0.15.6/#files",
2802+
"url": "https://pypi.org/project/packageurl-python/0.16.0/#files",
28072803
"type": "distribution",
28082804
"comment": "Download location for component"
28092805
}
28102806
],
2811-
"purl": "pkg:pypi/packageurl-python@0.15.6",
2807+
"purl": "pkg:pypi/packageurl-python@0.16.0",
28122808
"properties": [
28132809
{
28142810
"name": "language",
@@ -2824,7 +2820,7 @@
28242820
"type": "library",
28252821
"bom-ref": "58-rich",
28262822
"name": "rich",
2827-
"version": "13.9.2",
2823+
"version": "13.9.3",
28282824
"supplier": {
28292825
"name": "Will McGugan",
28302826
"contact": [
@@ -2833,7 +2829,7 @@
28332829
}
28342830
]
28352831
},
2836-
"cpe": "cpe:2.3:a:will_mcgugan:rich:13.9.2:*:*:*:*:*:*:*",
2832+
"cpe": "cpe:2.3:a:will_mcgugan:rich:13.9.3:*:*:*:*:*:*:*",
28372833
"description": "Render rich text, tables, progress bars, syntax highlighting, markdown and more to the terminal",
28382834
"licenses": [
28392835
{
@@ -2851,12 +2847,12 @@
28512847
"comment": "Home page for project"
28522848
},
28532849
{
2854-
"url": "https://pypi.org/project/rich/13.9.2/#files",
2850+
"url": "https://pypi.org/project/rich/13.9.3/#files",
28552851
"type": "distribution",
28562852
"comment": "Download location for component"
28572853
}
28582854
],
2859-
"purl": "pkg:pypi/[email protected].2",
2855+
"purl": "pkg:pypi/[email protected].3",
28602856
"properties": [
28612857
{
28622858
"name": "language",
@@ -3590,7 +3586,7 @@
35903586
"type": "library",
35913587
"bom-ref": "74-elementpath",
35923588
"name": "elementpath",
3593-
"version": "4.5.0",
3589+
"version": "4.6.0",
35943590
"supplier": {
35953591
"name": "Davide Brunato",
35963592
"contact": [
@@ -3599,7 +3595,7 @@
35993595
}
36003596
]
36013597
},
3602-
"cpe": "cpe:2.3:a:davide_brunato:elementpath:4.5.0:*:*:*:*:*:*:*",
3598+
"cpe": "cpe:2.3:a:davide_brunato:elementpath:4.6.0:*:*:*:*:*:*:*",
36033599
"description": "XPath 1.0/2.0/3.0/3.1 parsers and selectors for ElementTree and lxml",
36043600
"licenses": [
36053601
{
@@ -3617,12 +3613,12 @@
36173613
"comment": "Home page for project"
36183614
},
36193615
{
3620-
"url": "https://pypi.org/project/elementpath/4.5.0/#files",
3616+
"url": "https://pypi.org/project/elementpath/4.6.0/#files",
36213617
"type": "distribution",
36223618
"comment": "Download location for component"
36233619
}
36243620
],
3625-
"purl": "pkg:pypi/elementpath@4.5.0",
3621+
"purl": "pkg:pypi/elementpath@4.6.0",
36263622
"properties": [
36273623
{
36283624
"name": "language",

sbom/cve-bin-tool-py3.9.spdx

Lines changed: 22 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-fb473dd3-9d06-4045-8446-8b94d55b0135
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-eb859755-2df3-4cff-8f13-6688d449550c
66
LicenseListVersion: 3.22
77
Creator: Tool: sbom4python-0.11.3
8-
Created: 2024-10-21T00:37:14Z
8+
Created: 2024-10-28T00:39:33Z
99
CreatorComment: <text>This document has been automatically generated.</text>
1010
#####
1111

@@ -49,6 +49,7 @@ PackageSupplier: Organization: J. Nick Koston ([email protected])
4949
PackageDownloadLocation: https://pypi.org/project/aiohappyeyeballs/2.4.3/#files
5050
FilesAnalyzed: false
5151
PackageHomePage: https://github.com/aio-libs/aiohappyeyeballs
52+
PackageChecksum: SHA1: e3519bbebf2069eee0aff0dfde50689c742ba97f
5253
PackageLicenseDeclared: PSF-2.0
5354
PackageLicenseConcluded: PSF-2.0
5455
PackageCopyrightText: NOASSERTION
@@ -76,18 +77,18 @@ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected]
7677

7778
PackageName: frozenlist
7879
SPDXID: SPDXRef-5-frozenlist
79-
PackageVersion: 1.4.1
80+
PackageVersion: 1.5.0
8081
PrimaryPackagePurpose: LIBRARY
8182
PackageSupplier: NOASSERTION
82-
PackageDownloadLocation: https://pypi.org/project/frozenlist/1.4.1/#files
83+
PackageDownloadLocation: https://pypi.org/project/frozenlist/1.5.0/#files
8384
FilesAnalyzed: false
8485
PackageHomePage: https://github.com/aio-libs/frozenlist
8586
PackageLicenseDeclared: NOASSERTION
8687
PackageLicenseConcluded: Apache-2.0
8788
PackageLicenseComments: <text>frozenlist declares Apache 2 which is not currently a valid SPDX License identifier or expression.</text>
8889
PackageCopyrightText: NOASSERTION
8990
PackageSummary: <text>A list-like structure which implements collections.abc.MutableSequence</text>
90-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/frozenlist@1.4.1
91+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/frozenlist@1.5.0
9192
#####
9293

9394
PackageName: async-timeout
@@ -157,18 +158,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:guido_van_jukka_ukasz_michael:typing-e
157158

158159
PackageName: yarl
159160
SPDXID: SPDXRef-10-yarl
160-
PackageVersion: 1.15.5
161+
PackageVersion: 1.16.0
161162
PrimaryPackagePurpose: LIBRARY
162163
PackageSupplier: Person: Andrew Svetlov ([email protected])
163-
PackageDownloadLocation: https://pypi.org/project/yarl/1.15.5/#files
164+
PackageDownloadLocation: https://pypi.org/project/yarl/1.16.0/#files
164165
FilesAnalyzed: false
165166
PackageHomePage: https://github.com/aio-libs/yarl
166167
PackageLicenseDeclared: Apache-2.0
167168
PackageLicenseConcluded: Apache-2.0
168169
PackageCopyrightText: NOASSERTION
169170
PackageSummary: <text>Yet another URL library</text>
170-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/yarl@1.15.5
171-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrew_svetlov:yarl:1.15.5:*:*:*:*:*:*:*
171+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/yarl@1.16.0
172+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrew_svetlov:yarl:1.16.0:*:*:*:*:*:*:*
172173
#####
173174

174175
PackageName: idna
@@ -945,35 +946,34 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:anthony_harrison:csaf-tool:0.3.2:*:*:*
945946

946947
PackageName: packageurl-python
947948
SPDXID: SPDXRef-57-packageurl-python
948-
PackageVersion: 0.15.6
949+
PackageVersion: 0.16.0
949950
PrimaryPackagePurpose: LIBRARY
950951
PackageSupplier: Person: the purl authors
951-
PackageDownloadLocation: https://pypi.org/project/packageurl-python/0.15.6/#files
952+
PackageDownloadLocation: https://pypi.org/project/packageurl-python/0.16.0/#files
952953
FilesAnalyzed: false
953954
PackageHomePage: https://github.com/package-url/packageurl-python
954-
PackageChecksum: SHA1: 14a11b50ab723796888133d3722b5b3e2845b084
955955
PackageLicenseDeclared: MIT
956956
PackageLicenseConcluded: MIT
957957
PackageCopyrightText: NOASSERTION
958958
PackageSummary: <text>A purl aka. Package URL parser and builder</text>
959-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/packageurl-python@0.15.6
960-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_purl_authors:packageurl-python:0.15.6:*:*:*:*:*:*:*
959+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/packageurl-python@0.16.0
960+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_purl_authors:packageurl-python:0.16.0:*:*:*:*:*:*:*
961961
#####
962962

963963
PackageName: rich
964964
SPDXID: SPDXRef-58-rich
965-
PackageVersion: 13.9.2
965+
PackageVersion: 13.9.3
966966
PrimaryPackagePurpose: LIBRARY
967967
PackageSupplier: Person: Will McGugan ([email protected])
968-
PackageDownloadLocation: https://pypi.org/project/rich/13.9.2/#files
968+
PackageDownloadLocation: https://pypi.org/project/rich/13.9.3/#files
969969
FilesAnalyzed: false
970970
PackageHomePage: https://github.com/Textualize/rich
971971
PackageLicenseDeclared: MIT
972972
PackageLicenseConcluded: MIT
973973
PackageCopyrightText: NOASSERTION
974974
PackageSummary: <text>Render rich text, tables, progress bars, syntax highlighting, markdown and more to the terminal</text>
975-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].2
976-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:will_mcgugan:rich:13.9.2:*:*:*:*:*:*:*
975+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].3
976+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:will_mcgugan:rich:13.9.3:*:*:*:*:*:*:*
977977
#####
978978

979979
PackageName: markdown-it-py
@@ -1224,18 +1224,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:davide_brunato:xmlschema:3.4.2:*:*:*:*
12241224

12251225
PackageName: elementpath
12261226
SPDXID: SPDXRef-74-elementpath
1227-
PackageVersion: 4.5.0
1227+
PackageVersion: 4.6.0
12281228
PrimaryPackagePurpose: LIBRARY
12291229
PackageSupplier: Person: Davide Brunato ([email protected])
1230-
PackageDownloadLocation: https://pypi.org/project/elementpath/4.5.0/#files
1230+
PackageDownloadLocation: https://pypi.org/project/elementpath/4.6.0/#files
12311231
FilesAnalyzed: false
12321232
PackageHomePage: https://github.com/sissaschool/elementpath
12331233
PackageLicenseDeclared: MIT
12341234
PackageLicenseConcluded: MIT
12351235
PackageCopyrightText: NOASSERTION
12361236
PackageSummary: <text>XPath 1.0/2.0/3.0/3.1 parsers and selectors for ElementTree and lxml</text>
1237-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/elementpath@4.5.0
1238-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:davide_brunato:elementpath:4.5.0:*:*:*:*:*:*:*
1237+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/elementpath@4.6.0
1238+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:davide_brunato:elementpath:4.6.0:*:*:*:*:*:*:*
12391239
#####
12401240

12411241
PackageName: zstandard

0 commit comments

Comments
 (0)