Skip to content

Commit e4b3fd3

Browse files
chore: update SBOM for Python 3.12 (#4583)
Co-authored-by: GitHub <[email protected]>
1 parent 44516c0 commit e4b3fd3

File tree

2 files changed

+72
-32
lines changed

2 files changed

+72
-32
lines changed

sbom/cve-bin-tool-py3.12.json

Lines changed: 55 additions & 17 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:b68a2b85-9212-4889-b7b2-84f3edf441ff",
5+
"serialNumber": "urn:uuid:a061e09a-b4f0-449a-bc41-098f3ead640a",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2024-11-18T00:38:25Z",
8+
"timestamp": "2024-11-25T00:37:29Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -79,7 +79,7 @@
7979
"type": "library",
8080
"bom-ref": "2-aiohttp",
8181
"name": "aiohttp",
82-
"version": "3.11.2",
82+
"version": "3.11.7",
8383
"description": "Async http client/server framework (asyncio)",
8484
"licenses": [
8585
{
@@ -97,12 +97,12 @@
9797
"comment": "Home page for project"
9898
},
9999
{
100-
"url": "https://pypi.org/project/aiohttp/3.11.2/#files",
100+
"url": "https://pypi.org/project/aiohttp/3.11.7/#files",
101101
"type": "distribution",
102102
"comment": "Download location for component"
103103
}
104104
],
105-
"purl": "pkg:pypi/[email protected].2",
105+
"purl": "pkg:pypi/[email protected].7",
106106
"properties": [
107107
{
108108
"name": "language",
@@ -111,6 +111,10 @@
111111
{
112112
"name": "python_version",
113113
"value": "3.12.7"
114+
},
115+
{
116+
"name": "package_release_date",
117+
"value": "2024-11-21T15:42:26.000Z"
114118
}
115119
]
116120
},
@@ -375,6 +379,12 @@
375379
},
376380
"cpe": "cpe:2.3:a:andrew_svetlov:propcache:0.2.0:*:*:*:*:*:*:*",
377381
"description": "Accelerated property cache",
382+
"hashes": [
383+
{
384+
"alg": "SHA-1",
385+
"content": "f157b0a7b0b3a3c755764b9f03f4d90c43ee5cda"
386+
}
387+
],
378388
"licenses": [
379389
{
380390
"license": {
@@ -416,7 +426,7 @@
416426
"type": "library",
417427
"bom-ref": "9-yarl",
418428
"name": "yarl",
419-
"version": "1.17.2",
429+
"version": "1.18.0",
420430
"supplier": {
421431
"name": "Andrew Svetlov",
422432
"contact": [
@@ -425,7 +435,7 @@
425435
}
426436
]
427437
},
428-
"cpe": "cpe:2.3:a:andrew_svetlov:yarl:1.17.2:*:*:*:*:*:*:*",
438+
"cpe": "cpe:2.3:a:andrew_svetlov:yarl:1.18.0:*:*:*:*:*:*:*",
429439
"description": "Yet another URL library",
430440
"licenses": [
431441
{
@@ -443,12 +453,12 @@
443453
"comment": "Home page for project"
444454
},
445455
{
446-
"url": "https://pypi.org/project/yarl/1.17.2/#files",
456+
"url": "https://pypi.org/project/yarl/1.18.0/#files",
447457
"type": "distribution",
448458
"comment": "Download location for component"
449459
}
450460
],
451-
"purl": "pkg:pypi/yarl@1.17.2",
461+
"purl": "pkg:pypi/yarl@1.18.0",
452462
"properties": [
453463
{
454464
"name": "language",
@@ -457,6 +467,10 @@
457467
{
458468
"name": "python_version",
459469
"value": "3.12.7"
470+
},
471+
{
472+
"name": "package_release_date",
473+
"value": "2024-11-21T15:02:50.000Z"
460474
}
461475
]
462476
},
@@ -1938,6 +1952,10 @@
19381952
{
19391953
"name": "python_version",
19401954
"value": "3.12.7"
1955+
},
1956+
{
1957+
"name": "package_release_date",
1958+
"value": "2024-09-04T20:43:30.000Z"
19411959
}
19421960
]
19431961
},
@@ -2705,6 +2723,10 @@
27052723
{
27062724
"name": "python_version",
27072725
"value": "3.12.7"
2726+
},
2727+
{
2728+
"name": "package_release_date",
2729+
"value": "2024-06-12T20:10:06.000Z"
27082730
}
27092731
]
27102732
},
@@ -2718,6 +2740,12 @@
27182740
},
27192741
"cpe": "cpe:2.3:a:the_purl_authors:packageurl-python:0.16.0:*:*:*:*:*:*:*",
27202742
"description": "A purl aka. Package URL parser and builder",
2743+
"hashes": [
2744+
{
2745+
"alg": "SHA-1",
2746+
"content": "9155d4173e4c1f29a345de86c280ab783c837882"
2747+
}
2748+
],
27212749
"licenses": [
27222750
{
27232751
"license": {
@@ -2748,6 +2776,10 @@
27482776
{
27492777
"name": "python_version",
27502778
"value": "3.12.7"
2779+
},
2780+
{
2781+
"name": "package_release_date",
2782+
"value": "2024-10-22T05:51:23.000Z"
27512783
}
27522784
]
27532785
},
@@ -2980,6 +3012,12 @@
29803012
},
29813013
"cpe": "cpe:2.3:a:donald_stufft:packaging:24.2:*:*:*:*:*:*:*",
29823014
"description": "Core utilities for Python packages",
3015+
"hashes": [
3016+
{
3017+
"alg": "SHA-1",
3018+
"content": "d8e3b31b734926ebbcaff654279f6855a73e052f"
3019+
}
3020+
],
29833021
"externalReferences": [
29843022
{
29853023
"url": "https://pypi.org/project/packaging/24.2/#files",
@@ -3439,7 +3477,7 @@
34393477
"type": "library",
34403478
"bom-ref": "67-setuptools",
34413479
"name": "setuptools",
3442-
"version": "75.5.0",
3480+
"version": "75.6.0",
34433481
"supplier": {
34443482
"name": "Python Packaging Authority",
34453483
"contact": [
@@ -3448,16 +3486,16 @@
34483486
}
34493487
]
34503488
},
3451-
"cpe": "cpe:2.3:a:python_packaging_authority:setuptools:75.5.0:*:*:*:*:*:*:*",
3489+
"cpe": "cpe:2.3:a:python_packaging_authority:setuptools:75.6.0:*:*:*:*:*:*:*",
34523490
"description": "Easily download, build, install, upgrade, and uninstall Python packages",
34533491
"externalReferences": [
34543492
{
3455-
"url": "https://pypi.org/project/setuptools/75.5.0/#files",
3493+
"url": "https://pypi.org/project/setuptools/75.6.0/#files",
34563494
"type": "distribution",
34573495
"comment": "Download location for component"
34583496
}
34593497
],
3460-
"purl": "pkg:pypi/setuptools@75.5.0",
3498+
"purl": "pkg:pypi/setuptools@75.6.0",
34613499
"properties": [
34623500
{
34633501
"name": "language",
@@ -3466,10 +3504,6 @@
34663504
{
34673505
"name": "python_version",
34683506
"value": "3.12.7"
3469-
},
3470-
{
3471-
"name": "package_release_date",
3472-
"value": "2024-11-13T11:22:04.000Z"
34733507
}
34743508
]
34753509
},
@@ -3570,6 +3604,10 @@
35703604
{
35713605
"name": "python_version",
35723606
"value": "3.12.7"
3607+
},
3608+
{
3609+
"name": "package_release_date",
3610+
"value": "2024-10-27T21:52:58.000Z"
35733611
}
35743612
]
35753613
},

sbom/cve-bin-tool-py3.12.spdx

Lines changed: 17 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-babbb628-7d9c-4a26-8587-854eedfee7d8
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-36045916-f900-49d4-8e22-5885aa0e310b
66
LicenseListVersion: 3.22
77
Creator: Tool: sbom4python-0.11.3
8-
Created: 2024-11-18T00:37:38Z
8+
Created: 2024-11-25T00:36:48Z
99
CreatorComment: <text>This document has been automatically generated.</text>
1010
#####
1111

@@ -27,18 +27,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.4:*:*:*:*:*:*
2727

2828
PackageName: aiohttp
2929
SPDXID: SPDXRef-2-aiohttp
30-
PackageVersion: 3.11.2
30+
PackageVersion: 3.11.7
3131
PrimaryPackagePurpose: LIBRARY
3232
PackageSupplier: NOASSERTION
33-
PackageDownloadLocation: https://pypi.org/project/aiohttp/3.11.2/#files
33+
PackageDownloadLocation: https://pypi.org/project/aiohttp/3.11.7/#files
3434
FilesAnalyzed: false
3535
PackageHomePage: https://github.com/aio-libs/aiohttp
36-
PackageLicenseDeclared: NOASSERTION
36+
PackageLicenseDeclared: Apache-2.0
3737
PackageLicenseConcluded: Apache-2.0
38-
PackageLicenseComments: <text>aiohttp declares Apache 2 which is not currently a valid SPDX License identifier or expression.</text>
3938
PackageCopyrightText: NOASSERTION
4039
PackageSummary: <text>Async http client/server framework (asyncio)</text>
41-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].2
40+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].7
4241
#####
4342

4443
PackageName: aiohappyeyeballs
@@ -132,6 +131,7 @@ PackageSupplier: Person: Andrew Svetlov ([email protected])
132131
PackageDownloadLocation: https://pypi.org/project/propcache/0.2.0/#files
133132
FilesAnalyzed: false
134133
PackageHomePage: https://github.com/aio-libs/propcache
134+
PackageChecksum: SHA1: f157b0a7b0b3a3c755764b9f03f4d90c43ee5cda
135135
PackageLicenseDeclared: Apache-2.0
136136
PackageLicenseConcluded: Apache-2.0
137137
PackageCopyrightText: NOASSERTION
@@ -142,18 +142,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrew_svetlov:propcache:0.2.0:*:*:*:*
142142

143143
PackageName: yarl
144144
SPDXID: SPDXRef-9-yarl
145-
PackageVersion: 1.17.2
145+
PackageVersion: 1.18.0
146146
PrimaryPackagePurpose: LIBRARY
147147
PackageSupplier: Person: Andrew Svetlov ([email protected])
148-
PackageDownloadLocation: https://pypi.org/project/yarl/1.17.2/#files
148+
PackageDownloadLocation: https://pypi.org/project/yarl/1.18.0/#files
149149
FilesAnalyzed: false
150150
PackageHomePage: https://github.com/aio-libs/yarl
151151
PackageLicenseDeclared: Apache-2.0
152152
PackageLicenseConcluded: Apache-2.0
153153
PackageCopyrightText: NOASSERTION
154154
PackageSummary: <text>Yet another URL library</text>
155-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/yarl@1.17.2
156-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrew_svetlov:yarl:1.17.2:*:*:*:*:*:*:*
155+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/yarl@1.18.0
156+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrew_svetlov:yarl:1.18.0:*:*:*:*:*:*:*
157157
#####
158158

159159
PackageName: idna
@@ -893,6 +893,7 @@ PackageSupplier: Person: the purl authors
893893
PackageDownloadLocation: https://pypi.org/project/packageurl-python/0.16.0/#files
894894
FilesAnalyzed: false
895895
PackageHomePage: https://github.com/package-url/packageurl-python
896+
PackageChecksum: SHA1: 9155d4173e4c1f29a345de86c280ab783c837882
896897
PackageLicenseDeclared: MIT
897898
PackageLicenseConcluded: MIT
898899
PackageCopyrightText: NOASSERTION
@@ -976,6 +977,7 @@ PrimaryPackagePurpose: LIBRARY
976977
PackageSupplier: Person: Donald Stufft ([email protected])
977978
PackageDownloadLocation: https://pypi.org/project/packaging/24.2/#files
978979
FilesAnalyzed: false
980+
PackageChecksum: SHA1: d8e3b31b734926ebbcaff654279f6855a73e052f
979981
PackageLicenseDeclared: NOASSERTION
980982
PackageLicenseConcluded: NOASSERTION
981983
PackageCopyrightText: NOASSERTION
@@ -1120,17 +1122,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:sean_ross:rpmfile:2.1.0:*:*:*:*:*:*:*
11201122

11211123
PackageName: setuptools
11221124
SPDXID: SPDXRef-67-setuptools
1123-
PackageVersion: 75.5.0
1125+
PackageVersion: 75.6.0
11241126
PrimaryPackagePurpose: LIBRARY
11251127
PackageSupplier: Organization: Python Packaging Authority ([email protected])
1126-
PackageDownloadLocation: https://pypi.org/project/setuptools/75.5.0/#files
1128+
PackageDownloadLocation: https://pypi.org/project/setuptools/75.6.0/#files
11271129
FilesAnalyzed: false
11281130
PackageLicenseDeclared: NOASSERTION
11291131
PackageLicenseConcluded: NOASSERTION
11301132
PackageCopyrightText: NOASSERTION
11311133
PackageSummary: <text>Easily download, build, install, upgrade, and uninstall Python packages</text>
1132-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/setuptools@75.5.0
1133-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:python_packaging_authority:setuptools:75.5.0:*:*:*:*:*:*:*
1134+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/setuptools@75.6.0
1135+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:python_packaging_authority:setuptools:75.6.0:*:*:*:*:*:*:*
11341136
#####
11351137

11361138
PackageName: xmlschema

0 commit comments

Comments
 (0)