Skip to content

Commit d68cee3

Browse files
chore: update SBOM for Python 3.10 (#3621)
Co-authored-by: GitHub <[email protected]>
1 parent 3947866 commit d68cee3

File tree

2 files changed

+46
-62
lines changed

2 files changed

+46
-62
lines changed

sbom/cve-bin-tool-py3.10.json

Lines changed: 21 additions & 37 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.5.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.5",
5-
"serialNumber": "urn:uuid:9d4b0c1e-1f41-466b-9562-6dfb28a23baa",
5+
"serialNumber": "urn:uuid:71cf7a87-d95b-45ce-9395-edd4cf653670",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2023-12-11T00:27:30Z",
8+
"timestamp": "2023-12-18T00:27:17Z",
99
"tools": {
1010
"components": [
1111
{
@@ -65,10 +65,6 @@
6565
"bom-ref": "2-aiohttp",
6666
"name": "aiohttp",
6767
"version": "3.9.1",
68-
"supplier": {
69-
"name": "NOASSERTION"
70-
},
71-
"cpe": "cpe:/a:NOASSERTION:aiohttp:3.9.1",
7268
"description": "Async http client/server framework (asyncio)",
7369
"licenses": [
7470
{
@@ -102,10 +98,6 @@
10298
"bom-ref": "3-aiosignal",
10399
"name": "aiosignal",
104100
"version": "1.3.1",
105-
"supplier": {
106-
"name": "NOASSERTION"
107-
},
108-
"cpe": "cpe:/a:NOASSERTION:aiosignal:1.3.1",
109101
"licenses": [
110102
{
111103
"license": {
@@ -137,11 +129,7 @@
137129
"type": "library",
138130
"bom-ref": "4-frozenlist",
139131
"name": "frozenlist",
140-
"version": "1.4.0",
141-
"supplier": {
142-
"name": "NOASSERTION"
143-
},
144-
"cpe": "cpe:/a:NOASSERTION:frozenlist:1.4.0",
132+
"version": "1.4.1",
145133
"description": "A list-like structure which implements collections.abc.MutableSequence",
146134
"licenses": [
147135
{
@@ -153,12 +141,12 @@
153141
],
154142
"externalReferences": [
155143
{
156-
"url": "https://pypi.org/project/frozenlist/1.4.0",
144+
"url": "https://pypi.org/project/frozenlist/1.4.1",
157145
"type": "distribution",
158146
"comment": "Download location for component"
159147
}
160148
],
161-
"purl": "pkg:pypi/[email protected].0",
149+
"purl": "pkg:pypi/[email protected].1",
162150
"properties": [
163151
{
164152
"name": "language",
@@ -1529,10 +1517,6 @@
15291517
"bom-ref": "40-markupsafe",
15301518
"name": "markupsafe",
15311519
"version": "2.1.3",
1532-
"supplier": {
1533-
"name": "NOASSERTION"
1534-
},
1535-
"cpe": "cpe:/a:NOASSERTION:markupsafe:2.1.3",
15361520
"description": "Safely add untrusted strings to HTML/XML markup.",
15371521
"licenses": [
15381522
{
@@ -1660,11 +1644,11 @@
16601644
"type": "library",
16611645
"bom-ref": "44-rpds-py",
16621646
"name": "rpds-py",
1663-
"version": "0.13.2",
1647+
"version": "0.15.2",
16641648
"supplier": {
16651649
"name": "Julian Berman"
16661650
},
1667-
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.13.2:*:*:*:*:*:*:*",
1651+
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.15.2:*:*:*:*:*:*:*",
16681652
"description": "Python bindings to Rust's persistent data structures (rpds)",
16691653
"licenses": [
16701654
{
@@ -1676,12 +1660,12 @@
16761660
],
16771661
"externalReferences": [
16781662
{
1679-
"url": "https://pypi.org/project/rpds-py/0.13.2",
1663+
"url": "https://pypi.org/project/rpds-py/0.15.2",
16801664
"type": "distribution",
16811665
"comment": "Download location for component"
16821666
}
16831667
],
1684-
"purl": "pkg:pypi/rpds-py@0.13.2",
1668+
"purl": "pkg:pypi/rpds-py@0.15.2",
16851669
"properties": [
16861670
{
16871671
"name": "language",
@@ -1693,7 +1677,7 @@
16931677
"type": "library",
16941678
"bom-ref": "45-lib4sbom",
16951679
"name": "lib4sbom",
1696-
"version": "0.5.3",
1680+
"version": "0.5.4",
16971681
"supplier": {
16981682
"name": "Anthony Harrison",
16991683
"contact": [
@@ -1702,7 +1686,7 @@
17021686
}
17031687
]
17041688
},
1705-
"cpe": "cpe:2.3:a:anthony_harrison:lib4sbom:0.5.3:*:*:*:*:*:*:*",
1689+
"cpe": "cpe:2.3:a:anthony_harrison:lib4sbom:0.5.4:*:*:*:*:*:*:*",
17061690
"description": "Software Bill of Material (SBOM) generator and consumer library",
17071691
"licenses": [
17081692
{
@@ -1714,12 +1698,12 @@
17141698
],
17151699
"externalReferences": [
17161700
{
1717-
"url": "https://pypi.org/project/lib4sbom/0.5.3",
1701+
"url": "https://pypi.org/project/lib4sbom/0.5.4",
17181702
"type": "distribution",
17191703
"comment": "Download location for component"
17201704
}
17211705
],
1722-
"purl": "pkg:pypi/[email protected].3",
1706+
"purl": "pkg:pypi/[email protected].4",
17231707
"properties": [
17241708
{
17251709
"name": "language",
@@ -1811,11 +1795,11 @@
18111795
"type": "library",
18121796
"bom-ref": "48-packageurl-python",
18131797
"name": "packageurl-python",
1814-
"version": "0.12.0",
1798+
"version": "0.13.1",
18151799
"supplier": {
18161800
"name": "the purl authors"
18171801
},
1818-
"cpe": "cpe:2.3:a:the_purl_authors:packageurl-python:0.12.0:*:*:*:*:*:*:*",
1802+
"cpe": "cpe:2.3:a:the_purl_authors:packageurl-python:0.13.1:*:*:*:*:*:*:*",
18191803
"description": "A purl aka. Package URL parser and builder",
18201804
"licenses": [
18211805
{
@@ -1827,12 +1811,12 @@
18271811
],
18281812
"externalReferences": [
18291813
{
1830-
"url": "https://pypi.org/project/packageurl-python/0.12.0",
1814+
"url": "https://pypi.org/project/packageurl-python/0.13.1",
18311815
"type": "distribution",
18321816
"comment": "Download location for component"
18331817
}
18341818
],
1835-
"purl": "pkg:pypi/packageurl-python@0.12.0",
1819+
"purl": "pkg:pypi/packageurl-python@0.13.1",
18361820
"properties": [
18371821
{
18381822
"name": "language",
@@ -1954,7 +1938,7 @@
19541938
"type": "library",
19551939
"bom-ref": "52-python-gnupg",
19561940
"name": "python-gnupg",
1957-
"version": "0.5.1",
1941+
"version": "0.5.2",
19581942
"supplier": {
19591943
"name": "Vinay Sajip",
19601944
"contact": [
@@ -1963,7 +1947,7 @@
19631947
}
19641948
]
19651949
},
1966-
"cpe": "cpe:2.3:a:vinay_sajip:python-gnupg:0.5.1:*:*:*:*:*:*:*",
1950+
"cpe": "cpe:2.3:a:vinay_sajip:python-gnupg:0.5.2:*:*:*:*:*:*:*",
19671951
"description": "A wrapper for the Gnu Privacy Guard (GPG or GnuPG)",
19681952
"licenses": [
19691953
{
@@ -1975,12 +1959,12 @@
19751959
],
19761960
"externalReferences": [
19771961
{
1978-
"url": "https://pypi.org/project/python-gnupg/0.5.1",
1962+
"url": "https://pypi.org/project/python-gnupg/0.5.2",
19791963
"type": "distribution",
19801964
"comment": "Download location for component"
19811965
}
19821966
],
1983-
"purl": "pkg:pypi/[email protected].1",
1967+
"purl": "pkg:pypi/[email protected].2",
19841968
"properties": [
19851969
{
19861970
"name": "language",

sbom/cve-bin-tool-py3.10.spdx

Lines changed: 25 additions & 25 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-4992f648-3aa3-4c7e-9862-6074ba2c3ba2
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-87588567-0852-4721-937b-f64990b706a8
66
LicenseListVersion: 3.22
77
Creator: Tool: sbom4python-0.10.1
8-
Created: 2023-12-11T00:26:28Z
8+
Created: 2023-12-18T00:26:14Z
99
CreatorComment: <text>This document has been automatically generated.</text>
1010
#####
1111

@@ -28,7 +28,7 @@ PackageName: aiohttp
2828
SPDXID: SPDXRef-Package-2-aiohttp
2929
PackageVersion: 3.9.1
3030
PrimaryPackagePurpose: LIBRARY
31-
PackageSupplier: Organization: NOASSERTION
31+
PackageSupplier: NOASSERTION
3232
PackageDownloadLocation: https://pypi.org/project/aiohttp/3.9.1
3333
FilesAnalyzed: false
3434
PackageLicenseDeclared: NOASSERTION
@@ -43,7 +43,7 @@ PackageName: aiosignal
4343
SPDXID: SPDXRef-Package-3-aiosignal
4444
PackageVersion: 1.3.1
4545
PrimaryPackagePurpose: LIBRARY
46-
PackageSupplier: Organization: NOASSERTION
46+
PackageSupplier: NOASSERTION
4747
PackageDownloadLocation: https://pypi.org/project/aiosignal/1.3.1
4848
FilesAnalyzed: false
4949
PackageLicenseDeclared: NOASSERTION
@@ -55,17 +55,17 @@ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected]
5555

5656
PackageName: frozenlist
5757
SPDXID: SPDXRef-Package-4-frozenlist
58-
PackageVersion: 1.4.0
58+
PackageVersion: 1.4.1
5959
PrimaryPackagePurpose: LIBRARY
60-
PackageSupplier: Organization: NOASSERTION
61-
PackageDownloadLocation: https://pypi.org/project/frozenlist/1.4.0
60+
PackageSupplier: NOASSERTION
61+
PackageDownloadLocation: https://pypi.org/project/frozenlist/1.4.1
6262
FilesAnalyzed: false
6363
PackageLicenseDeclared: NOASSERTION
6464
PackageLicenseConcluded: Apache-2.0
6565
PackageLicenseComments: <text>frozenlist declares Apache 2 which is not currently a valid SPDX License identifier or expression.</text>
6666
PackageCopyrightText: NOASSERTION
6767
PackageSummary: <text>A list-like structure which implements collections.abc.MutableSequence</text>
68-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].0
68+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].1
6969
#####
7070

7171
PackageName: async-timeout
@@ -615,7 +615,7 @@ PackageName: markupsafe
615615
SPDXID: SPDXRef-Package-40-markupsafe
616616
PackageVersion: 2.1.3
617617
PrimaryPackagePurpose: LIBRARY
618-
PackageSupplier: Organization: NOASSERTION
618+
PackageSupplier: NOASSERTION
619619
PackageDownloadLocation: https://pypi.org/project/MarkupSafe/2.1.3
620620
FilesAnalyzed: false
621621
PackageLicenseDeclared: BSD-3-Clause
@@ -672,32 +672,32 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:referencing:0.32.0:*:*:*
672672

673673
PackageName: rpds-py
674674
SPDXID: SPDXRef-Package-44-rpds-py
675-
PackageVersion: 0.13.2
675+
PackageVersion: 0.15.2
676676
PrimaryPackagePurpose: LIBRARY
677677
PackageSupplier: Person: Julian Berman
678-
PackageDownloadLocation: https://pypi.org/project/rpds-py/0.13.2
678+
PackageDownloadLocation: https://pypi.org/project/rpds-py/0.15.2
679679
FilesAnalyzed: false
680680
PackageLicenseDeclared: MIT
681681
PackageLicenseConcluded: MIT
682682
PackageCopyrightText: NOASSERTION
683683
PackageSummary: <text>Python bindings to Rust's persistent data structures (rpds)</text>
684-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rpds-py@0.13.2
685-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.13.2:*:*:*:*:*:*:*
684+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rpds-py@0.15.2
685+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.15.2:*:*:*:*:*:*:*
686686
#####
687687

688688
PackageName: lib4sbom
689689
SPDXID: SPDXRef-Package-45-lib4sbom
690-
PackageVersion: 0.5.3
690+
PackageVersion: 0.5.4
691691
PrimaryPackagePurpose: LIBRARY
692692
PackageSupplier: Person: Anthony Harrison ([email protected])
693-
PackageDownloadLocation: https://pypi.org/project/lib4sbom/0.5.3
693+
PackageDownloadLocation: https://pypi.org/project/lib4sbom/0.5.4
694694
FilesAnalyzed: false
695695
PackageLicenseDeclared: Apache-2.0
696696
PackageLicenseConcluded: Apache-2.0
697697
PackageCopyrightText: NOASSERTION
698698
PackageSummary: <text>Software Bill of Material (SBOM) generator and consumer library</text>
699-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].3
700-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:anthony_harrison:lib4sbom:0.5.3:*:*:*:*:*:*:*
699+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].4
700+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:anthony_harrison:lib4sbom:0.5.4:*:*:*:*:*:*:*
701701
#####
702702

703703
PackageName: pyyaml
@@ -733,17 +733,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:raphael_barrois:semantic-version:2.10.
733733

734734
PackageName: packageurl-python
735735
SPDXID: SPDXRef-Package-48-packageurl-python
736-
PackageVersion: 0.12.0
736+
PackageVersion: 0.13.1
737737
PrimaryPackagePurpose: LIBRARY
738738
PackageSupplier: Person: the purl authors
739-
PackageDownloadLocation: https://pypi.org/project/packageurl-python/0.12.0
739+
PackageDownloadLocation: https://pypi.org/project/packageurl-python/0.13.1
740740
FilesAnalyzed: false
741741
PackageLicenseDeclared: MIT
742742
PackageLicenseConcluded: MIT
743743
PackageCopyrightText: NOASSERTION
744744
PackageSummary: <text>A purl aka. Package URL parser and builder</text>
745-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/packageurl-python@0.12.0
746-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_purl_authors:packageurl-python:0.12.0:*:*:*:*:*:*:*
745+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/packageurl-python@0.13.1
746+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_purl_authors:packageurl-python:0.13.1:*:*:*:*:*:*:*
747747
#####
748748

749749
PackageName: packaging
@@ -794,18 +794,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julien_danjou:tenacity:8.2.3:*:*:*:*:*
794794

795795
PackageName: python-gnupg
796796
SPDXID: SPDXRef-Package-52-python-gnupg
797-
PackageVersion: 0.5.1
797+
PackageVersion: 0.5.2
798798
PrimaryPackagePurpose: LIBRARY
799799
PackageSupplier: Person: Vinay Sajip ([email protected])
800-
PackageDownloadLocation: https://pypi.org/project/python-gnupg/0.5.1
800+
PackageDownloadLocation: https://pypi.org/project/python-gnupg/0.5.2
801801
FilesAnalyzed: false
802802
PackageLicenseDeclared: NOASSERTION
803803
PackageLicenseConcluded: BSD-3-Clause
804804
PackageLicenseComments: <text>python-gnupg declares BSD which is not currently a valid SPDX License identifier or expression.</text>
805805
PackageCopyrightText: NOASSERTION
806806
PackageSummary: <text>A wrapper for the Gnu Privacy Guard (GPG or GnuPG)</text>
807-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].1
808-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:vinay_sajip:python-gnupg:0.5.1:*:*:*:*:*:*:*
807+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].2
808+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:vinay_sajip:python-gnupg:0.5.2:*:*:*:*:*:*:*
809809
#####
810810

811811
PackageName: requests

0 commit comments

Comments
 (0)