Skip to content

Commit c4c2334

Browse files
authored
chore: update SBOM for Python 3.10
1 parent 92d27dc commit c4c2334

File tree

2 files changed

+36
-36
lines changed

2 files changed

+36
-36
lines changed

sbom/cve-bin-tool-py3.10.json

Lines changed: 18 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.4.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.4",
5-
"serialNumber": "urn:uuida3d53afb-2d70-4c03-9ecf-07b223bcbea4",
5+
"serialNumber": "urn:uuidd5330715-93f3-4862-a632-a32a97c64c94",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2023-05-15T00:31:35Z",
8+
"timestamp": "2023-05-22T00:27:52Z",
99
"tools": [
1010
{
1111
"name": "sbom4python",
@@ -23,7 +23,7 @@
2323
"type": "application",
2424
"bom-ref": "1-cve-bin-tool",
2525
"name": "cve-bin-tool",
26-
"version": "3.2.1rc0",
26+
"version": "3.2.1",
2727
"supplier": {
2828
"name": "Terri Oda",
2929
"contact": [
@@ -32,7 +32,7 @@
3232
}
3333
]
3434
},
35-
"cpe": "cpe:2.3:a:terri_oda:cve-bin-tool:3.2.1rc0:*:*:*:*:*:*:*",
35+
"cpe": "cpe:2.3:a:terri_oda:cve-bin-tool:3.2.1:*:*:*:*:*:*:*",
3636
"description": "CVE Binary Checker Tool",
3737
"licenses": [
3838
{
@@ -49,12 +49,12 @@
4949
"comment": "Home page for project"
5050
},
5151
{
52-
"url": "https://pypi.org/project/cve-bin-tool/3.2.1rc0",
52+
"url": "https://pypi.org/project/cve-bin-tool/3.2.1",
5353
"type": "distribution",
5454
"comment": "Download location for component"
5555
}
5656
],
57-
"purl": "pkg:pypi/[email protected].1rc0"
57+
"purl": "pkg:pypi/[email protected].1"
5858
},
5959
{
6060
"type": "library",
@@ -547,7 +547,7 @@
547547
"type": "library",
548548
"bom-ref": "16-gsutil",
549549
"name": "gsutil",
550-
"version": "5.23",
550+
"version": "5.24",
551551
"supplier": {
552552
"name": "Google Inc.",
553553
"contact": [
@@ -556,7 +556,7 @@
556556
}
557557
]
558558
},
559-
"cpe": "cpe:2.3:a:google_inc.:gsutil:5.23:*:*:*:*:*:*:*",
559+
"cpe": "cpe:2.3:a:google_inc.:gsutil:5.24:*:*:*:*:*:*:*",
560560
"description": "A command line tool for interacting with cloud storage services.",
561561
"licenses": [
562562
{
@@ -573,12 +573,12 @@
573573
"comment": "Home page for project"
574574
},
575575
{
576-
"url": "https://pypi.org/project/gsutil/5.23",
576+
"url": "https://pypi.org/project/gsutil/5.24",
577577
"type": "distribution",
578578
"comment": "Download location for component"
579579
}
580580
],
581-
"purl": "pkg:pypi/gsutil@5.23",
581+
"purl": "pkg:pypi/gsutil@5.24",
582582
"properties": [
583583
{
584584
"name": "License Comments",
@@ -1377,7 +1377,7 @@
13771377
"type": "library",
13781378
"bom-ref": "37-google-auth",
13791379
"name": "google-auth",
1380-
"version": "2.18.0",
1380+
"version": "2.18.1",
13811381
"supplier": {
13821382
"name": "Google Cloud Platform",
13831383
"contact": [
@@ -1386,7 +1386,7 @@
13861386
}
13871387
]
13881388
},
1389-
"cpe": "cpe:2.3:a:google_cloud_platform:google-auth:2.18.0:*:*:*:*:*:*:*",
1389+
"cpe": "cpe:2.3:a:google_cloud_platform:google-auth:2.18.1:*:*:*:*:*:*:*",
13901390
"description": "Google Authentication Library",
13911391
"licenses": [
13921392
{
@@ -1403,12 +1403,12 @@
14031403
"comment": "Home page for project"
14041404
},
14051405
{
1406-
"url": "https://pypi.org/project/google-auth/2.18.0",
1406+
"url": "https://pypi.org/project/google-auth/2.18.1",
14071407
"type": "distribution",
14081408
"comment": "Download location for component"
14091409
}
14101410
],
1411-
"purl": "pkg:pypi/[email protected].0",
1411+
"purl": "pkg:pypi/[email protected].1",
14121412
"properties": [
14131413
{
14141414
"name": "License Comments",
@@ -2185,7 +2185,7 @@
21852185
"type": "library",
21862186
"bom-ref": "59-xmlschema",
21872187
"name": "xmlschema",
2188-
"version": "2.2.3",
2188+
"version": "2.3.0",
21892189
"supplier": {
21902190
"name": "Davide Brunato",
21912191
"contact": [
@@ -2194,7 +2194,7 @@
21942194
}
21952195
]
21962196
},
2197-
"cpe": "cpe:2.3:a:davide_brunato:xmlschema:2.2.3:*:*:*:*:*:*:*",
2197+
"cpe": "cpe:2.3:a:davide_brunato:xmlschema:2.3.0:*:*:*:*:*:*:*",
21982198
"description": "An XML Schema validator and decoder",
21992199
"licenses": [
22002200
{
@@ -2211,12 +2211,12 @@
22112211
"comment": "Home page for project"
22122212
},
22132213
{
2214-
"url": "https://pypi.org/project/xmlschema/2.2.3",
2214+
"url": "https://pypi.org/project/xmlschema/2.3.0",
22152215
"type": "distribution",
22162216
"comment": "Download location for component"
22172217
}
22182218
],
2219-
"purl": "pkg:pypi/xmlschema@2.2.3"
2219+
"purl": "pkg:pypi/xmlschema@2.3.0"
22202220
},
22212221
{
22222222
"type": "library",

sbom/cve-bin-tool-py3.10.spdx

Lines changed: 18 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -2,27 +2,27 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-ed06be93-71a5-4810-ad58-f1451132b770
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-5af86c52-6745-4b5c-b59e-cc5edf5a1ee1
66
LicenseListVersion: 3.20
77
Creator: Tool: sbom4python-0.9.1
8-
Created: 2023-05-15T00:30:22Z
8+
Created: 2023-05-22T00:26:22Z
99
CreatorComment: <text>This document has been automatically generated.</text>
1010
#####
1111

1212
PackageName: cve-bin-tool
1313
SPDXID: SPDXRef-Package-1-cve-bin-tool
14-
PackageVersion: 3.2.1rc0
14+
PackageVersion: 3.2.1
1515
PrimaryPackagePurpose: APPLICATION
1616
PackageSupplier: Person: Terri Oda ([email protected])
17-
PackageDownloadLocation: https://pypi.org/project/cve-bin-tool/3.2.1rc0
17+
PackageDownloadLocation: https://pypi.org/project/cve-bin-tool/3.2.1
1818
FilesAnalyzed: false
1919
PackageHomePage: https://github.com/intel/cve-bin-tool
2020
PackageLicenseDeclared: GPL-3.0-or-later
2121
PackageLicenseConcluded: GPL-3.0-or-later
2222
PackageCopyrightText: NOASSERTION
2323
PackageSummary: <text>CVE Binary Checker Tool</text>
24-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].1rc0
25-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.2.1rc0:*:*:*:*:*:*:*
24+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].1
25+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.2.1:*:*:*:*:*:*:*
2626
#####
2727

2828
PackageName: aiohttp
@@ -252,19 +252,19 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:nir_cohen:distro:1.8.0:*:*:*:*:*:*:*
252252

253253
PackageName: gsutil
254254
SPDXID: SPDXRef-Package-16-gsutil
255-
PackageVersion: 5.23
255+
PackageVersion: 5.24
256256
PrimaryPackagePurpose: LIBRARY
257257
PackageSupplier: Person: Google Inc. ([email protected])
258-
PackageDownloadLocation: https://pypi.org/project/gsutil/5.23
258+
PackageDownloadLocation: https://pypi.org/project/gsutil/5.24
259259
FilesAnalyzed: false
260260
PackageHomePage: https://cloud.google.com/storage/docs/gsutil
261261
PackageLicenseDeclared: NOASSERTION
262262
PackageLicenseConcluded: Apache-2.0
263263
PackageLicenseComments: <text>gsutil declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
264264
PackageCopyrightText: NOASSERTION
265265
PackageSummary: <text>A command line tool for interacting with cloud storage services.</text>
266-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/gsutil@5.23
267-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_inc.:gsutil:5.23:*:*:*:*:*:*:*
266+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/gsutil@5.24
267+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_inc.:gsutil:5.24:*:*:*:*:*:*:*
268268
#####
269269

270270
PackageName: argcomplete
@@ -599,19 +599,19 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:craig_citro:google-apitools:0.5.32:*:*
599599

600600
PackageName: google-auth
601601
SPDXID: SPDXRef-Package-37-google-auth
602-
PackageVersion: 2.18.0
602+
PackageVersion: 2.18.1
603603
PrimaryPackagePurpose: LIBRARY
604604
PackageSupplier: Organization: Google Cloud Platform ([email protected])
605-
PackageDownloadLocation: https://pypi.org/project/google-auth/2.18.0
605+
PackageDownloadLocation: https://pypi.org/project/google-auth/2.18.1
606606
FilesAnalyzed: false
607607
PackageHomePage: https://github.com/googleapis/google-auth-library-python
608608
PackageLicenseDeclared: NOASSERTION
609609
PackageLicenseConcluded: Apache-2.0
610610
PackageLicenseComments: <text>google-auth declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
611611
PackageCopyrightText: NOASSERTION
612612
PackageSummary: <text>Google Authentication Library</text>
613-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].0
614-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_cloud_platform:google-auth:2.18.0:*:*:*:*:*:*:*
613+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].1
614+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_cloud_platform:google-auth:2.18.1:*:*:*:*:*:*:*
615615
#####
616616

617617
PackageName: cachetools
@@ -953,18 +953,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:william_pearson:toml:0.10.2:*:*:*:*:*:
953953

954954
PackageName: xmlschema
955955
SPDXID: SPDXRef-Package-59-xmlschema
956-
PackageVersion: 2.2.3
956+
PackageVersion: 2.3.0
957957
PrimaryPackagePurpose: LIBRARY
958958
PackageSupplier: Person: Davide Brunato ([email protected])
959-
PackageDownloadLocation: https://pypi.org/project/xmlschema/2.2.3
959+
PackageDownloadLocation: https://pypi.org/project/xmlschema/2.3.0
960960
FilesAnalyzed: false
961961
PackageHomePage: https://github.com/sissaschool/xmlschema
962962
PackageLicenseDeclared: MIT
963963
PackageLicenseConcluded: MIT
964964
PackageCopyrightText: NOASSERTION
965965
PackageSummary: <text>An XML Schema validator and decoder</text>
966-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/xmlschema@2.2.3
967-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:davide_brunato:xmlschema:2.2.3:*:*:*:*:*:*:*
966+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/xmlschema@2.3.0
967+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:davide_brunato:xmlschema:2.3.0:*:*:*:*:*:*:*
968968
#####
969969

970970
PackageName: elementpath

0 commit comments

Comments
 (0)