Skip to content

Commit 0efb0ba

Browse files
authored
chore: update SBOM for Python 3.8
1 parent 44b5e99 commit 0efb0ba

File tree

2 files changed

+52
-52
lines changed

2 files changed

+52
-52
lines changed

sbom/cve-bin-tool-py3.8.json

Lines changed: 26 additions & 26 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.5.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.5",
5-
"serialNumber": "urn:uuid:bd4dc772-3281-4b09-82cb-4c763a0777b2",
5+
"serialNumber": "urn:uuid:0d337128-8043-410a-958f-5b759eb2bc29",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2023-10-30T00:27:18Z",
8+
"timestamp": "2023-11-06T00:26:15Z",
99
"tools": {
1010
"components": [
1111
{
@@ -218,7 +218,7 @@
218218
"type": "library",
219219
"bom-ref": "7-charset-normalizer",
220220
"name": "charset-normalizer",
221-
"version": "3.3.1",
221+
"version": "3.3.2",
222222
"supplier": {
223223
"name": "Ahmed TAHRI",
224224
"contact": [
@@ -227,7 +227,7 @@
227227
}
228228
]
229229
},
230-
"cpe": "cpe:2.3:a:ahmed_tahri:charset-normalizer:3.3.1:*:*:*:*:*:*:*",
230+
"cpe": "cpe:2.3:a:ahmed_tahri:charset-normalizer:3.3.2:*:*:*:*:*:*:*",
231231
"description": "The Real First Universal Charset Detector. Open, modern and actively maintained alternative to Chardet.",
232232
"licenses": [
233233
{
@@ -239,12 +239,12 @@
239239
],
240240
"externalReferences": [
241241
{
242-
"url": "https://pypi.org/project/charset-normalizer/3.3.1",
242+
"url": "https://pypi.org/project/charset-normalizer/3.3.2",
243243
"type": "distribution",
244244
"comment": "Download location for component"
245245
}
246246
],
247-
"purl": "pkg:pypi/[email protected].1"
247+
"purl": "pkg:pypi/[email protected].2"
248248
},
249249
{
250250
"type": "library",
@@ -544,7 +544,7 @@
544544
"type": "library",
545545
"bom-ref": "17-argcomplete",
546546
"name": "argcomplete",
547-
"version": "3.1.2",
547+
"version": "3.1.4",
548548
"supplier": {
549549
"name": "Andrey Kislyuk",
550550
"contact": [
@@ -553,7 +553,7 @@
553553
}
554554
]
555555
},
556-
"cpe": "cpe:2.3:a:andrey_kislyuk:argcomplete:3.1.2:*:*:*:*:*:*:*",
556+
"cpe": "cpe:2.3:a:andrey_kislyuk:argcomplete:3.1.4:*:*:*:*:*:*:*",
557557
"description": "Bash tab completion for argparse",
558558
"licenses": [
559559
{
@@ -565,12 +565,12 @@
565565
],
566566
"externalReferences": [
567567
{
568-
"url": "https://pypi.org/project/argcomplete/3.1.2",
568+
"url": "https://pypi.org/project/argcomplete/3.1.4",
569569
"type": "distribution",
570570
"comment": "Download location for component"
571571
}
572572
],
573-
"purl": "pkg:pypi/[email protected].2",
573+
"purl": "pkg:pypi/[email protected].4",
574574
"properties": [
575575
{
576576
"name": "License Comments",
@@ -1228,7 +1228,7 @@
12281228
"type": "library",
12291229
"bom-ref": "37-google-auth",
12301230
"name": "google-auth",
1231-
"version": "2.23.3",
1231+
"version": "2.23.4",
12321232
"supplier": {
12331233
"name": "Google Cloud Platform",
12341234
"contact": [
@@ -1237,7 +1237,7 @@
12371237
}
12381238
]
12391239
},
1240-
"cpe": "cpe:2.3:a:google_cloud_platform:google-auth:2.23.3:*:*:*:*:*:*:*",
1240+
"cpe": "cpe:2.3:a:google_cloud_platform:google-auth:2.23.4:*:*:*:*:*:*:*",
12411241
"description": "Google Authentication Library",
12421242
"licenses": [
12431243
{
@@ -1249,12 +1249,12 @@
12491249
],
12501250
"externalReferences": [
12511251
{
1252-
"url": "https://pypi.org/project/google-auth/2.23.3",
1252+
"url": "https://pypi.org/project/google-auth/2.23.4",
12531253
"type": "distribution",
12541254
"comment": "Download location for component"
12551255
}
12561256
],
1257-
"purl": "pkg:pypi/[email protected].3",
1257+
"purl": "pkg:pypi/[email protected].4",
12581258
"properties": [
12591259
{
12601260
"name": "License Comments",
@@ -1467,11 +1467,11 @@
14671467
"type": "library",
14681468
"bom-ref": "45-jsonschema",
14691469
"name": "jsonschema",
1470-
"version": "4.19.1",
1470+
"version": "4.19.2",
14711471
"supplier": {
14721472
"name": "Julian Berman"
14731473
},
1474-
"cpe": "cpe:2.3:a:julian_berman:jsonschema:4.19.1:*:*:*:*:*:*:*",
1474+
"cpe": "cpe:2.3:a:julian_berman:jsonschema:4.19.2:*:*:*:*:*:*:*",
14751475
"description": "An implementation of JSON Schema validation for Python",
14761476
"licenses": [
14771477
{
@@ -1483,12 +1483,12 @@
14831483
],
14841484
"externalReferences": [
14851485
{
1486-
"url": "https://pypi.org/project/jsonschema/4.19.1",
1486+
"url": "https://pypi.org/project/jsonschema/4.19.2",
14871487
"type": "distribution",
14881488
"comment": "Download location for component"
14891489
}
14901490
],
1491-
"purl": "pkg:pypi/[email protected].1"
1491+
"purl": "pkg:pypi/[email protected].2"
14921492
},
14931493
{
14941494
"type": "library",
@@ -1548,11 +1548,11 @@
15481548
"type": "library",
15491549
"bom-ref": "48-rpds-py",
15501550
"name": "rpds-py",
1551-
"version": "0.10.6",
1551+
"version": "0.12.0",
15521552
"supplier": {
15531553
"name": "Julian Berman"
15541554
},
1555-
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.10.6:*:*:*:*:*:*:*",
1555+
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.12.0:*:*:*:*:*:*:*",
15561556
"description": "Python bindings to Rust's persistent data structures (rpds)",
15571557
"licenses": [
15581558
{
@@ -1564,12 +1564,12 @@
15641564
],
15651565
"externalReferences": [
15661566
{
1567-
"url": "https://pypi.org/project/rpds-py/0.10.6",
1567+
"url": "https://pypi.org/project/rpds-py/0.12.0",
15681568
"type": "distribution",
15691569
"comment": "Download location for component"
15701570
}
15711571
],
1572-
"purl": "pkg:pypi/rpds-py@0.10.6"
1572+
"purl": "pkg:pypi/rpds-py@0.12.0"
15731573
},
15741574
{
15751575
"type": "library",
@@ -2229,7 +2229,7 @@
22292229
"type": "library",
22302230
"bom-ref": "70-zstandard",
22312231
"name": "zstandard",
2232-
"version": "0.21.0",
2232+
"version": "0.22.0",
22332233
"supplier": {
22342234
"name": "Gregory Szorc",
22352235
"contact": [
@@ -2238,7 +2238,7 @@
22382238
}
22392239
]
22402240
},
2241-
"cpe": "cpe:2.3:a:gregory_szorc:zstandard:0.21.0:*:*:*:*:*:*:*",
2241+
"cpe": "cpe:2.3:a:gregory_szorc:zstandard:0.22.0:*:*:*:*:*:*:*",
22422242
"description": "Zstandard bindings for Python",
22432243
"licenses": [
22442244
{
@@ -2250,12 +2250,12 @@
22502250
],
22512251
"externalReferences": [
22522252
{
2253-
"url": "https://pypi.org/project/zstandard/0.21.0",
2253+
"url": "https://pypi.org/project/zstandard/0.22.0",
22542254
"type": "distribution",
22552255
"comment": "Download location for component"
22562256
}
22572257
],
2258-
"purl": "pkg:pypi/zstandard@0.21.0",
2258+
"purl": "pkg:pypi/zstandard@0.22.0",
22592259
"properties": [
22602260
{
22612261
"name": "License Comments",

sbom/cve-bin-tool-py3.8.spdx

Lines changed: 26 additions & 26 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-4a971d10-35e5-4f7d-a0f5-c0b1fb37a726
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-f51c8a98-01cc-461e-9cb6-719415e95c01
66
LicenseListVersion: 3.21
77
Creator: Tool: sbom4python-0.10.0
8-
Created: 2023-10-30T00:25:22Z
8+
Created: 2023-11-06T00:25:00Z
99
CreatorComment: <text>This document has been automatically generated.</text>
1010
#####
1111

@@ -101,17 +101,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:hynek_schlawack:attrs:23.1.0:*:*:*:*:*
101101

102102
PackageName: charset-normalizer
103103
SPDXID: SPDXRef-Package-7-charset-normalizer
104-
PackageVersion: 3.3.1
104+
PackageVersion: 3.3.2
105105
PrimaryPackagePurpose: LIBRARY
106106
PackageSupplier: Person: Ahmed TAHRI ([email protected])
107-
PackageDownloadLocation: https://pypi.org/project/charset-normalizer/3.3.1
107+
PackageDownloadLocation: https://pypi.org/project/charset-normalizer/3.3.2
108108
FilesAnalyzed: false
109109
PackageLicenseDeclared: MIT
110110
PackageLicenseConcluded: MIT
111111
PackageCopyrightText: NOASSERTION
112112
PackageSummary: <text>The Real First Universal Charset Detector. Open, modern and actively maintained alternative to Chardet.</text>
113-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].1
114-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:ahmed_tahri:charset-normalizer:3.3.1:*:*:*:*:*:*:*
113+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].2
114+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:ahmed_tahri:charset-normalizer:3.3.2:*:*:*:*:*:*:*
115115
#####
116116

117117
PackageName: multidict
@@ -256,18 +256,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_inc.:gsutil:5.27:*:*:*:*:*:*:*
256256

257257
PackageName: argcomplete
258258
SPDXID: SPDXRef-Package-17-argcomplete
259-
PackageVersion: 3.1.2
259+
PackageVersion: 3.1.4
260260
PrimaryPackagePurpose: LIBRARY
261261
PackageSupplier: Person: Andrey Kislyuk ([email protected])
262-
PackageDownloadLocation: https://pypi.org/project/argcomplete/3.1.2
262+
PackageDownloadLocation: https://pypi.org/project/argcomplete/3.1.4
263263
FilesAnalyzed: false
264264
PackageLicenseDeclared: NOASSERTION
265265
PackageLicenseConcluded: Apache-2.0
266266
PackageLicenseComments: <text>argcomplete declares Apache Software License which is not currently a valid SPDX License identifier or expression.</text>
267267
PackageCopyrightText: NOASSERTION
268268
PackageSummary: <text>Bash tab completion for argparse</text>
269-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].2
270-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_kislyuk:argcomplete:3.1.2:*:*:*:*:*:*:*
269+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].4
270+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_kislyuk:argcomplete:3.1.4:*:*:*:*:*:*:*
271271
#####
272272

273273
PackageName: crcmod
@@ -566,18 +566,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:craig_citro:google-apitools:0.5.32:*:*
566566

567567
PackageName: google-auth
568568
SPDXID: SPDXRef-Package-37-google-auth
569-
PackageVersion: 2.23.3
569+
PackageVersion: 2.23.4
570570
PrimaryPackagePurpose: LIBRARY
571571
PackageSupplier: Organization: Google Cloud Platform ([email protected])
572-
PackageDownloadLocation: https://pypi.org/project/google-auth/2.23.3
572+
PackageDownloadLocation: https://pypi.org/project/google-auth/2.23.4
573573
FilesAnalyzed: false
574574
PackageLicenseDeclared: NOASSERTION
575575
PackageLicenseConcluded: Apache-2.0
576576
PackageLicenseComments: <text>google-auth declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
577577
PackageCopyrightText: NOASSERTION
578578
PackageSummary: <text>Google Authentication Library</text>
579-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].3
580-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_cloud_platform:google-auth:2.23.3:*:*:*:*:*:*:*
579+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].4
580+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_cloud_platform:google-auth:2.23.4:*:*:*:*:*:*:*
581581
#####
582582

583583
PackageName: cachetools
@@ -687,17 +687,17 @@ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected]
687687

688688
PackageName: jsonschema
689689
SPDXID: SPDXRef-Package-45-jsonschema
690-
PackageVersion: 4.19.1
690+
PackageVersion: 4.19.2
691691
PrimaryPackagePurpose: LIBRARY
692692
PackageSupplier: Person: Julian Berman
693-
PackageDownloadLocation: https://pypi.org/project/jsonschema/4.19.1
693+
PackageDownloadLocation: https://pypi.org/project/jsonschema/4.19.2
694694
FilesAnalyzed: false
695695
PackageLicenseDeclared: MIT
696696
PackageLicenseConcluded: MIT
697697
PackageCopyrightText: NOASSERTION
698698
PackageSummary: <text>An implementation of JSON Schema validation for Python</text>
699-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].1
700-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:jsonschema:4.19.1:*:*:*:*:*:*:*
699+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].2
700+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:jsonschema:4.19.2:*:*:*:*:*:*:*
701701
#####
702702

703703
PackageName: jsonschema-specifications
@@ -732,17 +732,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:referencing:0.30.2:*:*:*
732732

733733
PackageName: rpds-py
734734
SPDXID: SPDXRef-Package-48-rpds-py
735-
PackageVersion: 0.10.6
735+
PackageVersion: 0.12.0
736736
PrimaryPackagePurpose: LIBRARY
737737
PackageSupplier: Person: Julian Berman
738-
PackageDownloadLocation: https://pypi.org/project/rpds-py/0.10.6
738+
PackageDownloadLocation: https://pypi.org/project/rpds-py/0.12.0
739739
FilesAnalyzed: false
740740
PackageLicenseDeclared: MIT
741741
PackageLicenseConcluded: MIT
742742
PackageCopyrightText: NOASSERTION
743743
PackageSummary: <text>Python bindings to Rust's persistent data structures (rpds)</text>
744-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rpds-py@0.10.6
745-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.10.6:*:*:*:*:*:*:*
744+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rpds-py@0.12.0
745+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.12.0:*:*:*:*:*:*:*
746746
#####
747747

748748
PackageName: pkgutil-resolve-name
@@ -1067,18 +1067,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:davide_brunato:elementpath:4.1.5:*:*:*
10671067

10681068
PackageName: zstandard
10691069
SPDXID: SPDXRef-Package-70-zstandard
1070-
PackageVersion: 0.21.0
1070+
PackageVersion: 0.22.0
10711071
PrimaryPackagePurpose: LIBRARY
10721072
PackageSupplier: Person: Gregory Szorc ([email protected])
1073-
PackageDownloadLocation: https://pypi.org/project/zstandard/0.21.0
1073+
PackageDownloadLocation: https://pypi.org/project/zstandard/0.22.0
10741074
FilesAnalyzed: false
10751075
PackageLicenseDeclared: NOASSERTION
10761076
PackageLicenseConcluded: BSD-3-Clause
10771077
PackageLicenseComments: <text>zstandard declares BSD which is not currently a valid SPDX License identifier or expression.</text>
10781078
PackageCopyrightText: NOASSERTION
10791079
PackageSummary: <text>Zstandard bindings for Python</text>
1080-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/zstandard@0.21.0
1081-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:gregory_szorc:zstandard:0.21.0:*:*:*:*:*:*:*
1080+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/zstandard@0.22.0
1081+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:gregory_szorc:zstandard:0.22.0:*:*:*:*:*:*:*
10821082
#####
10831083

10841084
Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-11-beautifulsoup4

0 commit comments

Comments
 (0)