Skip to content

Commit fe1d174

Browse files
authored
chore: update SBOM for Python 3.10
1 parent ef38dba commit fe1d174

File tree

2 files changed

+52
-52
lines changed

2 files changed

+52
-52
lines changed

sbom/cve-bin-tool-py3.10.json

Lines changed: 26 additions & 26 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.5.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.5",
5-
"serialNumber": "urn:uuid:bb0b8982-7878-46ff-96c7-fc5dab4eec83",
5+
"serialNumber": "urn:uuid:6baa9a42-0ae2-43de-ae54-80a7c7975217",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2023-11-27T00:26:26Z",
8+
"timestamp": "2023-12-04T00:26:42Z",
99
"tools": {
1010
"components": [
1111
{
@@ -26,7 +26,7 @@
2626
"type": "application",
2727
"bom-ref": "1-cve-bin-tool",
2828
"name": "cve-bin-tool",
29-
"version": "3.2.2.dev0",
29+
"version": "3.3a0",
3030
"supplier": {
3131
"name": "Terri Oda",
3232
"contact": [
@@ -35,7 +35,7 @@
3535
}
3636
]
3737
},
38-
"cpe": "cpe:2.3:a:terri_oda:cve-bin-tool:3.2.2.dev0:*:*:*:*:*:*:*",
38+
"cpe": "cpe:2.3:a:terri_oda:cve-bin-tool:3.3a0:*:*:*:*:*:*:*",
3939
"description": "CVE Binary Checker Tool",
4040
"licenses": [
4141
{
@@ -47,12 +47,12 @@
4747
],
4848
"externalReferences": [
4949
{
50-
"url": "https://pypi.org/project/cve-bin-tool/3.2.2.dev0",
50+
"url": "https://pypi.org/project/cve-bin-tool/3.3a0",
5151
"type": "distribution",
5252
"comment": "Download location for component"
5353
}
5454
],
55-
"purl": "pkg:pypi/cve-bin-tool@3.2.2.dev0",
55+
"purl": "pkg:pypi/cve-bin-tool@3.3a0",
5656
"properties": [
5757
{
5858
"name": "language",
@@ -1173,7 +1173,7 @@
11731173
"type": "library",
11741174
"bom-ref": "31-cryptography",
11751175
"name": "cryptography",
1176-
"version": "41.0.5",
1176+
"version": "41.0.7",
11771177
"supplier": {
11781178
"name": "The Python Cryptographic Authority and individual contributors",
11791179
"contact": [
@@ -1182,7 +1182,7 @@
11821182
}
11831183
]
11841184
},
1185-
"cpe": "cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:41.0.5:*:*:*:*:*:*:*",
1185+
"cpe": "cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:41.0.7:*:*:*:*:*:*:*",
11861186
"description": "cryptography is a package which provides cryptographic recipes and primitives to Python developers.",
11871187
"licenses": [
11881188
{
@@ -1191,12 +1191,12 @@
11911191
],
11921192
"externalReferences": [
11931193
{
1194-
"url": "https://pypi.org/project/cryptography/41.0.5",
1194+
"url": "https://pypi.org/project/cryptography/41.0.7",
11951195
"type": "distribution",
11961196
"comment": "Download location for component"
11971197
}
11981198
],
1199-
"purl": "pkg:pypi/[email protected].5",
1199+
"purl": "pkg:pypi/[email protected].7",
12001200
"properties": [
12011201
{
12021202
"name": "language",
@@ -1368,7 +1368,7 @@
13681368
"type": "library",
13691369
"bom-ref": "36-google-auth",
13701370
"name": "google-auth",
1371-
"version": "2.23.4",
1371+
"version": "2.24.0",
13721372
"supplier": {
13731373
"name": "Google Cloud Platform",
13741374
"contact": [
@@ -1377,7 +1377,7 @@
13771377
}
13781378
]
13791379
},
1380-
"cpe": "cpe:2.3:a:google_cloud_platform:google-auth:2.23.4:*:*:*:*:*:*:*",
1380+
"cpe": "cpe:2.3:a:google_cloud_platform:google-auth:2.24.0:*:*:*:*:*:*:*",
13811381
"description": "Google Authentication Library",
13821382
"licenses": [
13831383
{
@@ -1389,12 +1389,12 @@
13891389
],
13901390
"externalReferences": [
13911391
{
1392-
"url": "https://pypi.org/project/google-auth/2.23.4",
1392+
"url": "https://pypi.org/project/google-auth/2.24.0",
13931393
"type": "distribution",
13941394
"comment": "Download location for component"
13951395
}
13961396
],
1397-
"purl": "pkg:pypi/google-auth@2.23.4",
1397+
"purl": "pkg:pypi/google-auth@2.24.0",
13981398
"properties": [
13991399
{
14001400
"name": "language",
@@ -1594,11 +1594,11 @@
15941594
"type": "library",
15951595
"bom-ref": "42-jsonschema-specifications",
15961596
"name": "jsonschema-specifications",
1597-
"version": "2023.11.1",
1597+
"version": "2023.11.2",
15981598
"supplier": {
15991599
"name": "Julian Berman"
16001600
},
1601-
"cpe": "cpe:2.3:a:julian_berman:jsonschema-specifications:2023.11.1:*:*:*:*:*:*:*",
1601+
"cpe": "cpe:2.3:a:julian_berman:jsonschema-specifications:2023.11.2:*:*:*:*:*:*:*",
16021602
"description": "The JSON Schema meta-schemas and vocabularies, exposed as a Registry",
16031603
"licenses": [
16041604
{
@@ -1610,12 +1610,12 @@
16101610
],
16111611
"externalReferences": [
16121612
{
1613-
"url": "https://pypi.org/project/jsonschema-specifications/2023.11.1",
1613+
"url": "https://pypi.org/project/jsonschema-specifications/2023.11.2",
16141614
"type": "distribution",
16151615
"comment": "Download location for component"
16161616
}
16171617
],
1618-
"purl": "pkg:pypi/[email protected].1",
1618+
"purl": "pkg:pypi/[email protected].2",
16191619
"properties": [
16201620
{
16211621
"name": "language",
@@ -1627,11 +1627,11 @@
16271627
"type": "library",
16281628
"bom-ref": "43-referencing",
16291629
"name": "referencing",
1630-
"version": "0.31.0",
1630+
"version": "0.31.1",
16311631
"supplier": {
16321632
"name": "Julian Berman"
16331633
},
1634-
"cpe": "cpe:2.3:a:julian_berman:referencing:0.31.0:*:*:*:*:*:*:*",
1634+
"cpe": "cpe:2.3:a:julian_berman:referencing:0.31.1:*:*:*:*:*:*:*",
16351635
"description": "JSON Referencing + Python",
16361636
"licenses": [
16371637
{
@@ -1643,12 +1643,12 @@
16431643
],
16441644
"externalReferences": [
16451645
{
1646-
"url": "https://pypi.org/project/referencing/0.31.0",
1646+
"url": "https://pypi.org/project/referencing/0.31.1",
16471647
"type": "distribution",
16481648
"comment": "Download location for component"
16491649
}
16501650
],
1651-
"purl": "pkg:pypi/[email protected].0",
1651+
"purl": "pkg:pypi/[email protected].1",
16521652
"properties": [
16531653
{
16541654
"name": "language",
@@ -1660,11 +1660,11 @@
16601660
"type": "library",
16611661
"bom-ref": "44-rpds-py",
16621662
"name": "rpds-py",
1663-
"version": "0.13.1",
1663+
"version": "0.13.2",
16641664
"supplier": {
16651665
"name": "Julian Berman"
16661666
},
1667-
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.13.1:*:*:*:*:*:*:*",
1667+
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.13.2:*:*:*:*:*:*:*",
16681668
"description": "Python bindings to Rust's persistent data structures (rpds)",
16691669
"licenses": [
16701670
{
@@ -1676,12 +1676,12 @@
16761676
],
16771677
"externalReferences": [
16781678
{
1679-
"url": "https://pypi.org/project/rpds-py/0.13.1",
1679+
"url": "https://pypi.org/project/rpds-py/0.13.2",
16801680
"type": "distribution",
16811681
"comment": "Download location for component"
16821682
}
16831683
],
1684-
"purl": "pkg:pypi/[email protected].1",
1684+
"purl": "pkg:pypi/[email protected].2",
16851685
"properties": [
16861686
{
16871687
"name": "language",

sbom/cve-bin-tool-py3.10.spdx

Lines changed: 26 additions & 26 deletions
Original file line numberDiff line numberDiff line change
@@ -2,26 +2,26 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-ab06f588-e314-40f5-ae47-5ec7bb254f31
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-0628dc5c-a9ba-4bef-85a5-0bff8ab02543
66
LicenseListVersion: 3.22
77
Creator: Tool: sbom4python-0.10.1
8-
Created: 2023-11-27T00:25:26Z
8+
Created: 2023-12-04T00:25:42Z
99
CreatorComment: <text>This document has been automatically generated.</text>
1010
#####
1111

1212
PackageName: cve-bin-tool
1313
SPDXID: SPDXRef-Package-1-cve-bin-tool
14-
PackageVersion: 3.2.2.dev0
14+
PackageVersion: 3.3a0
1515
PrimaryPackagePurpose: APPLICATION
1616
PackageSupplier: Person: Terri Oda ([email protected])
17-
PackageDownloadLocation: https://pypi.org/project/cve-bin-tool/3.2.2.dev0
17+
PackageDownloadLocation: https://pypi.org/project/cve-bin-tool/3.3a0
1818
FilesAnalyzed: false
1919
PackageLicenseDeclared: GPL-3.0-or-later
2020
PackageLicenseConcluded: GPL-3.0-or-later
2121
PackageCopyrightText: NOASSERTION
2222
PackageSummary: <text>CVE Binary Checker Tool</text>
23-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/cve-bin-tool@3.2.2.dev0
24-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.2.2.dev0:*:*:*:*:*:*:*
23+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/cve-bin-tool@3.3a0
24+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.3a0:*:*:*:*:*:*:*
2525
#####
2626

2727
PackageName: aiohttp
@@ -474,17 +474,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_pyopenssl_developers:pyopenssl:23.
474474

475475
PackageName: cryptography
476476
SPDXID: SPDXRef-Package-31-cryptography
477-
PackageVersion: 41.0.5
477+
PackageVersion: 41.0.7
478478
PrimaryPackagePurpose: LIBRARY
479479
PackageSupplier: Organization: The Python Cryptographic Authority and individual contributors ([email protected])
480-
PackageDownloadLocation: https://pypi.org/project/cryptography/41.0.5
480+
PackageDownloadLocation: https://pypi.org/project/cryptography/41.0.7
481481
FilesAnalyzed: false
482482
PackageLicenseDeclared: Apache-2.0 OR BSD-3-Clause
483483
PackageLicenseConcluded: Apache-2.0 OR BSD-3-Clause
484484
PackageCopyrightText: NOASSERTION
485485
PackageSummary: <text>cryptography is a package which provides cryptographic recipes and primitives to Python developers.</text>
486-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].5
487-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:41.0.5:*:*:*:*:*:*:*
486+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].7
487+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:41.0.7:*:*:*:*:*:*:*
488488
#####
489489

490490
PackageName: cffi
@@ -551,18 +551,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:craig_citro:google-apitools:0.5.32:*:*
551551

552552
PackageName: google-auth
553553
SPDXID: SPDXRef-Package-36-google-auth
554-
PackageVersion: 2.23.4
554+
PackageVersion: 2.24.0
555555
PrimaryPackagePurpose: LIBRARY
556556
PackageSupplier: Organization: Google Cloud Platform ([email protected])
557-
PackageDownloadLocation: https://pypi.org/project/google-auth/2.23.4
557+
PackageDownloadLocation: https://pypi.org/project/google-auth/2.24.0
558558
FilesAnalyzed: false
559559
PackageLicenseDeclared: NOASSERTION
560560
PackageLicenseConcluded: Apache-2.0
561561
PackageLicenseComments: <text>google-auth declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
562562
PackageCopyrightText: NOASSERTION
563563
PackageSummary: <text>Google Authentication Library</text>
564-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/google-auth@2.23.4
565-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_cloud_platform:google-auth:2.23.4:*:*:*:*:*:*:*
564+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/google-auth@2.24.0
565+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_cloud_platform:google-auth:2.24.0:*:*:*:*:*:*:*
566566
#####
567567

568568
PackageName: cachetools
@@ -642,47 +642,47 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:jsonschema:4.20.0:*:*:*:
642642

643643
PackageName: jsonschema-specifications
644644
SPDXID: SPDXRef-Package-42-jsonschema-specifications
645-
PackageVersion: 2023.11.1
645+
PackageVersion: 2023.11.2
646646
PrimaryPackagePurpose: LIBRARY
647647
PackageSupplier: Person: Julian Berman
648-
PackageDownloadLocation: https://pypi.org/project/jsonschema-specifications/2023.11.1
648+
PackageDownloadLocation: https://pypi.org/project/jsonschema-specifications/2023.11.2
649649
FilesAnalyzed: false
650650
PackageLicenseDeclared: MIT
651651
PackageLicenseConcluded: MIT
652652
PackageCopyrightText: NOASSERTION
653653
PackageSummary: <text>The JSON Schema meta-schemas and vocabularies, exposed as a Registry</text>
654-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].1
655-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:jsonschema-specifications:2023.11.1:*:*:*:*:*:*:*
654+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].2
655+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:jsonschema-specifications:2023.11.2:*:*:*:*:*:*:*
656656
#####
657657

658658
PackageName: referencing
659659
SPDXID: SPDXRef-Package-43-referencing
660-
PackageVersion: 0.31.0
660+
PackageVersion: 0.31.1
661661
PrimaryPackagePurpose: LIBRARY
662662
PackageSupplier: Person: Julian Berman
663-
PackageDownloadLocation: https://pypi.org/project/referencing/0.31.0
663+
PackageDownloadLocation: https://pypi.org/project/referencing/0.31.1
664664
FilesAnalyzed: false
665665
PackageLicenseDeclared: MIT
666666
PackageLicenseConcluded: MIT
667667
PackageCopyrightText: NOASSERTION
668668
PackageSummary: <text>JSON Referencing + Python</text>
669-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].0
670-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:referencing:0.31.0:*:*:*:*:*:*:*
669+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].1
670+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:referencing:0.31.1:*:*:*:*:*:*:*
671671
#####
672672

673673
PackageName: rpds-py
674674
SPDXID: SPDXRef-Package-44-rpds-py
675-
PackageVersion: 0.13.1
675+
PackageVersion: 0.13.2
676676
PrimaryPackagePurpose: LIBRARY
677677
PackageSupplier: Person: Julian Berman
678-
PackageDownloadLocation: https://pypi.org/project/rpds-py/0.13.1
678+
PackageDownloadLocation: https://pypi.org/project/rpds-py/0.13.2
679679
FilesAnalyzed: false
680680
PackageLicenseDeclared: MIT
681681
PackageLicenseConcluded: MIT
682682
PackageCopyrightText: NOASSERTION
683683
PackageSummary: <text>Python bindings to Rust's persistent data structures (rpds)</text>
684-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].1
685-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.13.1:*:*:*:*:*:*:*
684+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].2
685+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.13.2:*:*:*:*:*:*:*
686686
#####
687687

688688
PackageName: lib4sbom

0 commit comments

Comments
 (0)