Skip to content

Commit f42aa53

Browse files
chore: update SBOM for Python 3.8 (#3572)
Co-authored-by: GitHub <[email protected]>
1 parent faba2b8 commit f42aa53

File tree

2 files changed

+52
-52
lines changed

2 files changed

+52
-52
lines changed

sbom/cve-bin-tool-py3.8.json

Lines changed: 26 additions & 26 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.5.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.5",
5-
"serialNumber": "urn:uuid:63b6ddf0-0f47-4d29-9bc7-d74d55620fb5",
5+
"serialNumber": "urn:uuid:dbe81473-bc6a-4f42-83b0-111ae79f8a5d",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2023-12-04T00:27:26Z",
8+
"timestamp": "2023-12-11T00:27:25Z",
99
"tools": {
1010
"components": [
1111
{
@@ -288,7 +288,7 @@
288288
"type": "library",
289289
"bom-ref": "8-yarl",
290290
"name": "yarl",
291-
"version": "1.9.3",
291+
"version": "1.9.4",
292292
"supplier": {
293293
"name": "Andrew Svetlov",
294294
"contact": [
@@ -297,7 +297,7 @@
297297
}
298298
]
299299
},
300-
"cpe": "cpe:2.3:a:andrew_svetlov:yarl:1.9.3:*:*:*:*:*:*:*",
300+
"cpe": "cpe:2.3:a:andrew_svetlov:yarl:1.9.4:*:*:*:*:*:*:*",
301301
"description": "Yet another URL library",
302302
"licenses": [
303303
{
@@ -309,12 +309,12 @@
309309
],
310310
"externalReferences": [
311311
{
312-
"url": "https://pypi.org/project/yarl/1.9.3",
312+
"url": "https://pypi.org/project/yarl/1.9.4",
313313
"type": "distribution",
314314
"comment": "Download location for component"
315315
}
316316
],
317-
"purl": "pkg:pypi/[email protected].3",
317+
"purl": "pkg:pypi/[email protected].4",
318318
"properties": [
319319
{
320320
"name": "language",
@@ -584,7 +584,7 @@
584584
"type": "library",
585585
"bom-ref": "16-argcomplete",
586586
"name": "argcomplete",
587-
"version": "3.1.6",
587+
"version": "3.2.1",
588588
"supplier": {
589589
"name": "Andrey Kislyuk",
590590
"contact": [
@@ -593,7 +593,7 @@
593593
}
594594
]
595595
},
596-
"cpe": "cpe:2.3:a:andrey_kislyuk:argcomplete:3.1.6:*:*:*:*:*:*:*",
596+
"cpe": "cpe:2.3:a:andrey_kislyuk:argcomplete:3.2.1:*:*:*:*:*:*:*",
597597
"description": "Bash tab completion for argparse",
598598
"licenses": [
599599
{
@@ -605,12 +605,12 @@
605605
],
606606
"externalReferences": [
607607
{
608-
"url": "https://pypi.org/project/argcomplete/3.1.6",
608+
"url": "https://pypi.org/project/argcomplete/3.2.1",
609609
"type": "distribution",
610610
"comment": "Download location for component"
611611
}
612612
],
613-
"purl": "pkg:pypi/argcomplete@3.1.6",
613+
"purl": "pkg:pypi/argcomplete@3.2.1",
614614
"properties": [
615615
{
616616
"name": "language",
@@ -1368,7 +1368,7 @@
13681368
"type": "library",
13691369
"bom-ref": "36-google-auth",
13701370
"name": "google-auth",
1371-
"version": "2.24.0",
1371+
"version": "2.25.2",
13721372
"supplier": {
13731373
"name": "Google Cloud Platform",
13741374
"contact": [
@@ -1377,7 +1377,7 @@
13771377
}
13781378
]
13791379
},
1380-
"cpe": "cpe:2.3:a:google_cloud_platform:google-auth:2.24.0:*:*:*:*:*:*:*",
1380+
"cpe": "cpe:2.3:a:google_cloud_platform:google-auth:2.25.2:*:*:*:*:*:*:*",
13811381
"description": "Google Authentication Library",
13821382
"licenses": [
13831383
{
@@ -1389,12 +1389,12 @@
13891389
],
13901390
"externalReferences": [
13911391
{
1392-
"url": "https://pypi.org/project/google-auth/2.24.0",
1392+
"url": "https://pypi.org/project/google-auth/2.25.2",
13931393
"type": "distribution",
13941394
"comment": "Download location for component"
13951395
}
13961396
],
1397-
"purl": "pkg:pypi/google-auth@2.24.0",
1397+
"purl": "pkg:pypi/google-auth@2.25.2",
13981398
"properties": [
13991399
{
14001400
"name": "language",
@@ -1717,11 +1717,11 @@
17171717
"type": "library",
17181718
"bom-ref": "46-referencing",
17191719
"name": "referencing",
1720-
"version": "0.31.1",
1720+
"version": "0.32.0",
17211721
"supplier": {
17221722
"name": "Julian Berman"
17231723
},
1724-
"cpe": "cpe:2.3:a:julian_berman:referencing:0.31.1:*:*:*:*:*:*:*",
1724+
"cpe": "cpe:2.3:a:julian_berman:referencing:0.32.0:*:*:*:*:*:*:*",
17251725
"description": "JSON Referencing + Python",
17261726
"licenses": [
17271727
{
@@ -1733,12 +1733,12 @@
17331733
],
17341734
"externalReferences": [
17351735
{
1736-
"url": "https://pypi.org/project/referencing/0.31.1",
1736+
"url": "https://pypi.org/project/referencing/0.32.0",
17371737
"type": "distribution",
17381738
"comment": "Download location for component"
17391739
}
17401740
],
1741-
"purl": "pkg:pypi/referencing@0.31.1",
1741+
"purl": "pkg:pypi/referencing@0.32.0",
17421742
"properties": [
17431743
{
17441744
"name": "language",
@@ -1931,11 +1931,11 @@
19311931
"type": "library",
19321932
"bom-ref": "52-packageurl-python",
19331933
"name": "packageurl-python",
1934-
"version": "0.11.2",
1934+
"version": "0.12.0",
19351935
"supplier": {
19361936
"name": "the purl authors"
19371937
},
1938-
"cpe": "cpe:2.3:a:the_purl_authors:packageurl-python:0.11.2:*:*:*:*:*:*:*",
1938+
"cpe": "cpe:2.3:a:the_purl_authors:packageurl-python:0.12.0:*:*:*:*:*:*:*",
19391939
"description": "A purl aka. Package URL parser and builder",
19401940
"licenses": [
19411941
{
@@ -1947,12 +1947,12 @@
19471947
],
19481948
"externalReferences": [
19491949
{
1950-
"url": "https://pypi.org/project/packageurl-python/0.11.2",
1950+
"url": "https://pypi.org/project/packageurl-python/0.12.0",
19511951
"type": "distribution",
19521952
"comment": "Download location for component"
19531953
}
19541954
],
1955-
"purl": "pkg:pypi/packageurl-python@0.11.2",
1955+
"purl": "pkg:pypi/packageurl-python@0.12.0",
19561956
"properties": [
19571957
{
19581958
"name": "language",
@@ -2400,7 +2400,7 @@
24002400
"type": "library",
24012401
"bom-ref": "65-typing-extensions",
24022402
"name": "typing-extensions",
2403-
"version": "4.8.0",
2403+
"version": "4.9.0",
24042404
"supplier": {
24052405
"name": "Guido van Jukka ukasz Michael",
24062406
"contact": [
@@ -2409,16 +2409,16 @@
24092409
}
24102410
]
24112411
},
2412-
"cpe": "cpe:2.3:a:guido_van_jukka_ukasz_michael:typing-extensions:4.8.0:*:*:*:*:*:*:*",
2412+
"cpe": "cpe:2.3:a:guido_van_jukka_ukasz_michael:typing-extensions:4.9.0:*:*:*:*:*:*:*",
24132413
"description": "Backported and Experimental Type Hints for Python 3.8+",
24142414
"externalReferences": [
24152415
{
2416-
"url": "https://pypi.org/project/typing_extensions/4.8.0",
2416+
"url": "https://pypi.org/project/typing_extensions/4.9.0",
24172417
"type": "distribution",
24182418
"comment": "Download location for component"
24192419
}
24202420
],
2421-
"purl": "pkg:pypi/typing-extensions@4.8.0",
2421+
"purl": "pkg:pypi/typing-extensions@4.9.0",
24222422
"properties": [
24232423
{
24242424
"name": "language",

sbom/cve-bin-tool-py3.8.spdx

Lines changed: 26 additions & 26 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-c97adb49-cd97-4afa-abfa-56c2f899134b
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-8f6dc0e5-f734-4e02-b567-528c334f2968
66
LicenseListVersion: 3.22
77
Creator: Tool: sbom4python-0.10.1
8-
Created: 2023-12-04T00:26:07Z
8+
Created: 2023-12-11T00:26:12Z
99
CreatorComment: <text>This document has been automatically generated.</text>
1010
#####
1111

@@ -117,17 +117,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrew_svetlov:multidict:6.0.4:*:*:*:*
117117

118118
PackageName: yarl
119119
SPDXID: SPDXRef-Package-8-yarl
120-
PackageVersion: 1.9.3
120+
PackageVersion: 1.9.4
121121
PrimaryPackagePurpose: LIBRARY
122122
PackageSupplier: Person: Andrew Svetlov ([email protected])
123-
PackageDownloadLocation: https://pypi.org/project/yarl/1.9.3
123+
PackageDownloadLocation: https://pypi.org/project/yarl/1.9.4
124124
FilesAnalyzed: false
125125
PackageLicenseDeclared: Apache-2.0
126126
PackageLicenseConcluded: Apache-2.0
127127
PackageCopyrightText: NOASSERTION
128128
PackageSummary: <text>Yet another URL library</text>
129-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].3
130-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrew_svetlov:yarl:1.9.3:*:*:*:*:*:*:*
129+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].4
130+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrew_svetlov:yarl:1.9.4:*:*:*:*:*:*:*
131131
#####
132132

133133
PackageName: idna
@@ -241,18 +241,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_inc.:gsutil:5.27:*:*:*:*:*:*:*
241241

242242
PackageName: argcomplete
243243
SPDXID: SPDXRef-Package-16-argcomplete
244-
PackageVersion: 3.1.6
244+
PackageVersion: 3.2.1
245245
PrimaryPackagePurpose: LIBRARY
246246
PackageSupplier: Person: Andrey Kislyuk ([email protected])
247-
PackageDownloadLocation: https://pypi.org/project/argcomplete/3.1.6
247+
PackageDownloadLocation: https://pypi.org/project/argcomplete/3.2.1
248248
FilesAnalyzed: false
249249
PackageLicenseDeclared: NOASSERTION
250250
PackageLicenseConcluded: Apache-2.0
251251
PackageLicenseComments: <text>argcomplete declares Apache Software License which is not currently a valid SPDX License identifier or expression.</text>
252252
PackageCopyrightText: NOASSERTION
253253
PackageSummary: <text>Bash tab completion for argparse</text>
254-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/argcomplete@3.1.6
255-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_kislyuk:argcomplete:3.1.6:*:*:*:*:*:*:*
254+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/argcomplete@3.2.1
255+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_kislyuk:argcomplete:3.2.1:*:*:*:*:*:*:*
256256
#####
257257

258258
PackageName: crcmod
@@ -551,18 +551,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:craig_citro:google-apitools:0.5.32:*:*
551551

552552
PackageName: google-auth
553553
SPDXID: SPDXRef-Package-36-google-auth
554-
PackageVersion: 2.24.0
554+
PackageVersion: 2.25.2
555555
PrimaryPackagePurpose: LIBRARY
556556
PackageSupplier: Organization: Google Cloud Platform ([email protected])
557-
PackageDownloadLocation: https://pypi.org/project/google-auth/2.24.0
557+
PackageDownloadLocation: https://pypi.org/project/google-auth/2.25.2
558558
FilesAnalyzed: false
559559
PackageLicenseDeclared: NOASSERTION
560560
PackageLicenseConcluded: Apache-2.0
561561
PackageLicenseComments: <text>google-auth declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
562562
PackageCopyrightText: NOASSERTION
563563
PackageSummary: <text>Google Authentication Library</text>
564-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/google-auth@2.24.0
565-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_cloud_platform:google-auth:2.24.0:*:*:*:*:*:*:*
564+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/google-auth@2.25.2
565+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_cloud_platform:google-auth:2.25.2:*:*:*:*:*:*:*
566566
#####
567567

568568
PackageName: cachetools
@@ -702,17 +702,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:jsonschema-specification
702702

703703
PackageName: referencing
704704
SPDXID: SPDXRef-Package-46-referencing
705-
PackageVersion: 0.31.1
705+
PackageVersion: 0.32.0
706706
PrimaryPackagePurpose: LIBRARY
707707
PackageSupplier: Person: Julian Berman
708-
PackageDownloadLocation: https://pypi.org/project/referencing/0.31.1
708+
PackageDownloadLocation: https://pypi.org/project/referencing/0.32.0
709709
FilesAnalyzed: false
710710
PackageLicenseDeclared: MIT
711711
PackageLicenseConcluded: MIT
712712
PackageCopyrightText: NOASSERTION
713713
PackageSummary: <text>JSON Referencing + Python</text>
714-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/referencing@0.31.1
715-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:referencing:0.31.1:*:*:*:*:*:*:*
714+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/referencing@0.32.0
715+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:referencing:0.32.0:*:*:*:*:*:*:*
716716
#####
717717

718718
PackageName: rpds-py
@@ -793,17 +793,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:raphael_barrois:semantic-version:2.10.
793793

794794
PackageName: packageurl-python
795795
SPDXID: SPDXRef-Package-52-packageurl-python
796-
PackageVersion: 0.11.2
796+
PackageVersion: 0.12.0
797797
PrimaryPackagePurpose: LIBRARY
798798
PackageSupplier: Person: the purl authors
799-
PackageDownloadLocation: https://pypi.org/project/packageurl-python/0.11.2
799+
PackageDownloadLocation: https://pypi.org/project/packageurl-python/0.12.0
800800
FilesAnalyzed: false
801801
PackageLicenseDeclared: MIT
802802
PackageLicenseConcluded: MIT
803803
PackageCopyrightText: NOASSERTION
804804
PackageSummary: <text>A purl aka. Package URL parser and builder</text>
805-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/packageurl-python@0.11.2
806-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_purl_authors:packageurl-python:0.11.2:*:*:*:*:*:*:*
805+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/packageurl-python@0.12.0
806+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_purl_authors:packageurl-python:0.12.0:*:*:*:*:*:*:*
807807
#####
808808

809809
PackageName: packaging
@@ -991,17 +991,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:georg_brandl:pygments:2.17.2:*:*:*:*:*
991991

992992
PackageName: typing-extensions
993993
SPDXID: SPDXRef-Package-65-typing-extensions
994-
PackageVersion: 4.8.0
994+
PackageVersion: 4.9.0
995995
PrimaryPackagePurpose: LIBRARY
996996
PackageSupplier: Organization: Guido van Jukka ukasz Michael ([email protected])
997-
PackageDownloadLocation: https://pypi.org/project/typing_extensions/4.8.0
997+
PackageDownloadLocation: https://pypi.org/project/typing_extensions/4.9.0
998998
FilesAnalyzed: false
999999
PackageLicenseDeclared: NOASSERTION
10001000
PackageLicenseConcluded: NOASSERTION
10011001
PackageCopyrightText: NOASSERTION
10021002
PackageSummary: <text>Backported and Experimental Type Hints for Python 3.8+</text>
1003-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/typing-extensions@4.8.0
1004-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:guido_van_jukka_ukasz_michael:typing-extensions:4.8.0:*:*:*:*:*:*:*
1003+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/typing-extensions@4.9.0
1004+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:guido_van_jukka_ukasz_michael:typing-extensions:4.9.0:*:*:*:*:*:*:*
10051005
#####
10061006

10071007
PackageName: rpmfile

0 commit comments

Comments
 (0)