Skip to content

Commit f85ca13

Browse files
chore: update SBOM for Python 3.11 (#2569)
Co-authored-by: GitHub <[email protected]>
1 parent 11ce0c9 commit f85ca13

File tree

2 files changed

+94
-72
lines changed

2 files changed

+94
-72
lines changed

sbom/cve-bin-tool-py3.11.json

Lines changed: 46 additions & 39 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.4.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.4",
5-
"serialNumber": "urn:uuida1a94d53-e5d0-44d7-8823-365618603cf3",
5+
"serialNumber": "urn:uuid2bccd5d8-fa96-41ad-b2da-d4d601ff39f2",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2023-01-16T00:27:40Z",
8+
"timestamp": "2023-01-23T00:26:10Z",
99
"tools": [
1010
{
1111
"name": "sbom4python",
@@ -561,9 +561,9 @@
561561
"type": "library",
562562
"bom-ref": "38-cachetools",
563563
"name": "cachetools",
564-
"version": "5.2.1",
564+
"version": "5.3.0",
565565
"author": "Thomas Kemmer",
566-
"cpe": "cpe:/a:thomas_kemmer:cachetools:5.2.1",
566+
"cpe": "cpe:/a:thomas_kemmer:cachetools:5.3.0",
567567
"licenses": [
568568
{
569569
"license": {
@@ -572,7 +572,7 @@
572572
}
573573
}
574574
],
575-
"purl": "pkg:pypi/cachetools@5.2.1"
575+
"purl": "pkg:pypi/cachetools@5.3.0"
576576
},
577577
{
578578
"type": "library",
@@ -604,9 +604,9 @@
604604
"type": "library",
605605
"bom-ref": "41-markupsafe",
606606
"name": "markupsafe",
607-
"version": "2.1.1",
607+
"version": "2.1.2",
608608
"author": "Armin Ronacher",
609-
"cpe": "cpe:/a:armin_ronacher:markupsafe:2.1.1",
609+
"cpe": "cpe:/a:armin_ronacher:markupsafe:2.1.2",
610610
"licenses": [
611611
{
612612
"license": {
@@ -615,7 +615,7 @@
615615
}
616616
}
617617
],
618-
"purl": "pkg:pypi/[email protected].1"
618+
"purl": "pkg:pypi/[email protected].2"
619619
},
620620
{
621621
"type": "library",
@@ -766,9 +766,9 @@
766766
"type": "library",
767767
"bom-ref": "51-rich",
768768
"name": "rich",
769-
"version": "13.1.0",
769+
"version": "13.2.0",
770770
"author": "Will McGugan",
771-
"cpe": "cpe:/a:will_mcgugan:rich:13.1.0",
771+
"cpe": "cpe:/a:will_mcgugan:rich:13.2.0",
772772
"licenses": [
773773
{
774774
"license": {
@@ -777,28 +777,29 @@
777777
}
778778
}
779779
],
780-
"purl": "pkg:pypi/rich@13.1.0"
780+
"purl": "pkg:pypi/rich@13.2.0"
781781
},
782782
{
783783
"type": "library",
784-
"bom-ref": "52-commonmark",
785-
"name": "commonmark",
786-
"version": "0.9.1",
787-
"author": "Bibek Kafle Roland Shoemaker",
788-
"cpe": "cpe:/a:bibek_kafle_roland_shoemaker:commonmark:0.9.1",
789-
"licenses": [
790-
{
791-
"license": {
792-
"id": "BSD-3-Clause",
793-
"url": "https://opensource.org/licenses/BSD-3-Clause"
794-
}
795-
}
796-
],
797-
"purl": "pkg:pypi/[email protected]"
784+
"bom-ref": "52-markdown-it-py",
785+
"name": "markdown-it-py",
786+
"version": "2.1.0",
787+
"author": "Chris Sewell",
788+
"cpe": "cpe:/a:chris_sewell:markdown-it-py:2.1.0",
789+
"purl": "pkg:pypi/[email protected]"
790+
},
791+
{
792+
"type": "library",
793+
"bom-ref": "53-mdurl",
794+
"name": "mdurl",
795+
"version": "0.1.2",
796+
"author": "Taneli Hukkinen",
797+
"cpe": "cpe:/a:taneli_hukkinen:mdurl:0.1.2",
798+
"purl": "pkg:pypi/[email protected]"
798799
},
799800
{
800801
"type": "library",
801-
"bom-ref": "53-pygments",
802+
"bom-ref": "54-pygments",
802803
"name": "pygments",
803804
"version": "2.14.0",
804805
"author": "Georg Brandl",
@@ -815,7 +816,7 @@
815816
},
816817
{
817818
"type": "library",
818-
"bom-ref": "54-rpmfile",
819+
"bom-ref": "55-rpmfile",
819820
"name": "rpmfile",
820821
"version": "1.0.8",
821822
"author": "Sean Ross",
@@ -832,7 +833,7 @@
832833
},
833834
{
834835
"type": "library",
835-
"bom-ref": "55-toml",
836+
"bom-ref": "56-toml",
836837
"name": "toml",
837838
"version": "0.10.2",
838839
"author": "William Pearson",
@@ -849,7 +850,7 @@
849850
},
850851
{
851852
"type": "library",
852-
"bom-ref": "56-xmlschema",
853+
"bom-ref": "57-xmlschema",
853854
"name": "xmlschema",
854855
"version": "2.1.1",
855856
"author": "Davide Brunato",
@@ -866,7 +867,7 @@
866867
},
867868
{
868869
"type": "library",
869-
"bom-ref": "57-elementpath",
870+
"bom-ref": "58-elementpath",
870871
"name": "elementpath",
871872
"version": "3.0.2",
872873
"author": "Davide Brunato",
@@ -883,7 +884,7 @@
883884
},
884885
{
885886
"type": "library",
886-
"bom-ref": "58-zstandard",
887+
"bom-ref": "59-zstandard",
887888
"name": "zstandard",
888889
"version": "0.19.0",
889890
"author": "Gregory Szorc",
@@ -908,11 +909,11 @@
908909
"47-pyyaml",
909910
"48-requests",
910911
"51-rich",
911-
"54-rpmfile",
912-
"55-toml",
912+
"55-rpmfile",
913+
"56-toml",
913914
"50-urllib3",
914-
"56-xmlschema",
915-
"58-zstandard"
915+
"57-xmlschema",
916+
"59-zstandard"
916917
]
917918
},
918919
{
@@ -1089,14 +1090,20 @@
10891090
{
10901091
"ref": "51-rich",
10911092
"dependsOn": [
1092-
"52-commonmark",
1093-
"53-pygments"
1093+
"52-markdown-it-py",
1094+
"54-pygments"
1095+
]
1096+
},
1097+
{
1098+
"ref": "52-markdown-it-py",
1099+
"dependsOn": [
1100+
"53-mdurl"
10941101
]
10951102
},
10961103
{
1097-
"ref": "56-xmlschema",
1104+
"ref": "57-xmlschema",
10981105
"dependsOn": [
1099-
"57-elementpath"
1106+
"58-elementpath"
11001107
]
11011108
}
11021109
]

sbom/cve-bin-tool-py3.11.spdx

Lines changed: 48 additions & 33 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.2
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/cve-bin-tool-4a88a599-2f17-4548-978a-1d925135b726
5+
DocumentNamespace: http://spdx.org/spdxdocs/cve-bin-tool-417e9044-1bc1-4980-aee1-720c2dc7775d
66
LicenseListVersion: 3.18
77
Creator: Tool: sbom4python-0.7.0
8-
Created: 2023-01-16T00:26:25Z
8+
Created: 2023-01-23T00:25:02Z
99
CreatorComment: <text>This document has been automatically generated.</text>
1010
#####
1111

@@ -527,15 +527,15 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_cloud_platform:google-auth:2.16
527527
PackageName: cachetools
528528
SPDXID: SPDXRef-Package-38-cachetools
529529
PackageSupplier: Person: Thomas Kemmer ([email protected])
530-
PackageVersion: 5.2.1
530+
PackageVersion: 5.3.0
531531
PackageDownloadLocation: NOASSERTION
532532
FilesAnalyzed: false
533533
##### Reported license MIT
534534
PackageLicenseConcluded: MIT
535535
PackageLicenseDeclared: MIT
536536
PackageCopyrightText: NOASSERTION
537-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/cachetools@5.2.1
538-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:thomas_kemmer:cachetools:5.2.1:*:*:*:*:*:*:*
537+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/cachetools@5.3.0
538+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:thomas_kemmer:cachetools:5.3.0:*:*:*:*:*:*:*
539539
#####
540540

541541
PackageName: monotonic
@@ -569,15 +569,15 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:armin_ronacher:jinja2:3.1.2:*:*:*:*:*:
569569
PackageName: markupsafe
570570
SPDXID: SPDXRef-Package-41-markupsafe
571571
PackageSupplier: Person: Armin Ronacher ([email protected])
572-
PackageVersion: 2.1.1
572+
PackageVersion: 2.1.2
573573
PackageDownloadLocation: NOASSERTION
574574
FilesAnalyzed: false
575575
##### Reported license BSD-3-Clause
576576
PackageLicenseConcluded: BSD-3-Clause
577577
PackageLicenseDeclared: BSD-3-Clause
578578
PackageCopyrightText: NOASSERTION
579-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].1
580-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:armin_ronacher:markupsafe:2.1.1:*:*:*:*:*:*:*
579+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].2
580+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:armin_ronacher:markupsafe:2.1.2:*:*:*:*:*:*:*
581581
#####
582582

583583
PackageName: jsonschema
@@ -709,33 +709,47 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_petrov:urllib3:1.26.14:*:*:*:*:
709709
PackageName: rich
710710
SPDXID: SPDXRef-Package-51-rich
711711
PackageSupplier: Person: Will McGugan ([email protected])
712-
PackageVersion: 13.1.0
712+
PackageVersion: 13.2.0
713713
PackageDownloadLocation: NOASSERTION
714714
FilesAnalyzed: false
715715
##### Reported license MIT
716716
PackageLicenseConcluded: MIT
717717
PackageLicenseDeclared: MIT
718718
PackageCopyrightText: NOASSERTION
719-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rich@13.1.0
720-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:will_mcgugan:rich:13.1.0:*:*:*:*:*:*:*
719+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rich@13.2.0
720+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:will_mcgugan:rich:13.2.0:*:*:*:*:*:*:*
721721
#####
722722

723-
PackageName: commonmark
724-
SPDXID: SPDXRef-Package-52-commonmark
725-
PackageSupplier: Organization: Bibek Kafle Roland Shoemaker (rolandshoemaker@gmail.com)
726-
PackageVersion: 0.9.1
723+
PackageName: markdown-it-py
724+
SPDXID: SPDXRef-Package-52-markdown-it-py
725+
PackageSupplier: Person: Chris Sewell (chrisj_sewell@hotmail.com)
726+
PackageVersion: 2.1.0
727727
PackageDownloadLocation: NOASSERTION
728728
FilesAnalyzed: false
729-
##### Reported license BSD-3-Clause
730-
PackageLicenseConcluded: BSD-3-Clause
731-
PackageLicenseDeclared: BSD-3-Clause
729+
##### Reported license
730+
PackageLicenseConcluded: NOASSERTION
731+
PackageLicenseDeclared: NOASSERTION
732+
PackageCopyrightText: NOASSERTION
733+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected]
734+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_sewell:markdown-it-py:2.1.0:*:*:*:*:*:*:*
735+
#####
736+
737+
PackageName: mdurl
738+
SPDXID: SPDXRef-Package-53-mdurl
739+
PackageSupplier: Person: Taneli Hukkinen ([email protected])
740+
PackageVersion: 0.1.2
741+
PackageDownloadLocation: NOASSERTION
742+
FilesAnalyzed: false
743+
##### Reported license
744+
PackageLicenseConcluded: NOASSERTION
745+
PackageLicenseDeclared: NOASSERTION
732746
PackageCopyrightText: NOASSERTION
733-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/commonmark@0.9.1
734-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:bibek_kafle_roland_shoemaker:commonmark:0.9.1:*:*:*:*:*:*:*
747+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/mdurl@0.1.2
748+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:taneli_hukkinen:mdurl:0.1.2:*:*:*:*:*:*:*
735749
#####
736750

737751
PackageName: pygments
738-
SPDXID: SPDXRef-Package-53-pygments
752+
SPDXID: SPDXRef-Package-54-pygments
739753
PackageSupplier: Person: Georg Brandl ([email protected])
740754
PackageVersion: 2.14.0
741755
PackageDownloadLocation: NOASSERTION
@@ -749,7 +763,7 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:georg_brandl:pygments:2.14.0:*:*:*:*:*
749763
#####
750764

751765
PackageName: rpmfile
752-
SPDXID: SPDXRef-Package-54-rpmfile
766+
SPDXID: SPDXRef-Package-55-rpmfile
753767
PackageSupplier: Person: Sean Ross ([email protected])
754768
PackageVersion: 1.0.8
755769
PackageDownloadLocation: NOASSERTION
@@ -763,7 +777,7 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:sean_ross:rpmfile:1.0.8:*:*:*:*:*:*:*
763777
#####
764778

765779
PackageName: toml
766-
SPDXID: SPDXRef-Package-55-toml
780+
SPDXID: SPDXRef-Package-56-toml
767781
PackageSupplier: Person: William Pearson ([email protected])
768782
PackageVersion: 0.10.2
769783
PackageDownloadLocation: NOASSERTION
@@ -777,7 +791,7 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:william_pearson:toml:0.10.2:*:*:*:*:*:
777791
#####
778792

779793
PackageName: xmlschema
780-
SPDXID: SPDXRef-Package-56-xmlschema
794+
SPDXID: SPDXRef-Package-57-xmlschema
781795
PackageSupplier: Person: Davide Brunato ([email protected])
782796
PackageVersion: 2.1.1
783797
PackageDownloadLocation: NOASSERTION
@@ -791,7 +805,7 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:davide_brunato:xmlschema:2.1.1:*:*:*:*
791805
#####
792806

793807
PackageName: elementpath
794-
SPDXID: SPDXRef-Package-57-elementpath
808+
SPDXID: SPDXRef-Package-58-elementpath
795809
PackageSupplier: Person: Davide Brunato ([email protected])
796810
PackageVersion: 3.0.2
797811
PackageDownloadLocation: NOASSERTION
@@ -805,7 +819,7 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:davide_brunato:elementpath:3.0.2:*:*:*
805819
#####
806820

807821
PackageName: zstandard
808-
SPDXID: SPDXRef-Package-58-zstandard
822+
SPDXID: SPDXRef-Package-59-zstandard
809823
PackageSupplier: Person: Gregory Szorc ([email protected])
810824
PackageVersion: 0.19.0
811825
PackageDownloadLocation: NOASSERTION
@@ -831,10 +845,10 @@ Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-47-pyyam
831845
Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-48-requests
832846
Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-50-urllib3
833847
Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-51-rich
834-
Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-54-rpmfile
835-
Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-55-toml
836-
Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-56-xmlschema
837-
Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-58-zstandard
848+
Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-55-rpmfile
849+
Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-56-toml
850+
Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-57-xmlschema
851+
Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-59-zstandard
838852
Relationship: SPDXRef-Package-11-beautifulsoup4 DEPENDS_ON SPDXRef-Package-12-soupsieve
839853
Relationship: SPDXRef-Package-16-gsutil DEPENDS_ON SPDXRef-Package-17-argcomplete
840854
Relationship: SPDXRef-Package-16-gsutil DEPENDS_ON SPDXRef-Package-18-crcmod
@@ -894,8 +908,9 @@ Relationship: SPDXRef-Package-48-requests DEPENDS_ON SPDXRef-Package-10-idna
894908
Relationship: SPDXRef-Package-48-requests DEPENDS_ON SPDXRef-Package-49-certifi
895909
Relationship: SPDXRef-Package-48-requests DEPENDS_ON SPDXRef-Package-50-urllib3
896910
Relationship: SPDXRef-Package-48-requests DEPENDS_ON SPDXRef-Package-7-charset-normalizer
897-
Relationship: SPDXRef-Package-51-rich DEPENDS_ON SPDXRef-Package-52-commonmark
898-
Relationship: SPDXRef-Package-51-rich DEPENDS_ON SPDXRef-Package-53-pygments
899-
Relationship: SPDXRef-Package-56-xmlschema DEPENDS_ON SPDXRef-Package-57-elementpath
911+
Relationship: SPDXRef-Package-51-rich DEPENDS_ON SPDXRef-Package-52-markdown-it-py
912+
Relationship: SPDXRef-Package-51-rich DEPENDS_ON SPDXRef-Package-54-pygments
913+
Relationship: SPDXRef-Package-52-markdown-it-py DEPENDS_ON SPDXRef-Package-53-mdurl
914+
Relationship: SPDXRef-Package-57-xmlschema DEPENDS_ON SPDXRef-Package-58-elementpath
900915
Relationship: SPDXRef-Package-9-yarl DEPENDS_ON SPDXRef-Package-10-idna
901916
Relationship: SPDXRef-Package-9-yarl DEPENDS_ON SPDXRef-Package-8-multidict

0 commit comments

Comments
 (0)