Skip to content

Commit 7816fcf

Browse files
chore: update SBOM for Python 3.8 (#4120)
Co-authored-by: GitHub <[email protected]>
1 parent c7e2688 commit 7816fcf

File tree

2 files changed

+43
-50
lines changed

2 files changed

+43
-50
lines changed

sbom/cve-bin-tool-py3.8.json

Lines changed: 24 additions & 30 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:120bb2a5-fa0c-4b63-8098-1c048eeed9f3",
5+
"serialNumber": "urn:uuid:3178e3ea-d027-4327-a88b-1a6f2c9f1925",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2024-05-06T00:28:48Z",
8+
"timestamp": "2024-05-13T00:29:26Z",
99
"tools": {
1010
"components": [
1111
{
@@ -483,6 +483,12 @@
483483
},
484484
"cpe": "cpe:2.3:a:stanislav_red_hat_product_security:cvss:3.1:*:*:*:*:*:*:*",
485485
"description": "CVSS2/3/4 library with interactive calculator for Python 2 and Python 3",
486+
"hashes": [
487+
{
488+
"alg": "SHA-1",
489+
"content": "e4cf69bea6bcfa1cbc38dca13b9ec8bf3363a475"
490+
}
491+
],
486492
"licenses": [
487493
{
488494
"license": {
@@ -652,7 +658,7 @@
652658
"type": "library",
653659
"bom-ref": "16-gsutil",
654660
"name": "gsutil",
655-
"version": "5.28",
661+
"version": "5.29",
656662
"supplier": {
657663
"name": "Google Inc .",
658664
"contact": [
@@ -661,7 +667,7 @@
661667
}
662668
]
663669
},
664-
"cpe": "cpe:2.3:a:google_inc.:gsutil:5.28:*:*:*:*:*:*:*",
670+
"cpe": "cpe:2.3:a:google_inc.:gsutil:5.29:*:*:*:*:*:*:*",
665671
"description": "A command line tool for interacting with cloud storage services.",
666672
"licenses": [
667673
{
@@ -673,12 +679,12 @@
673679
],
674680
"externalReferences": [
675681
{
676-
"url": "https://pypi.org/project/gsutil/5.28",
682+
"url": "https://pypi.org/project/gsutil/5.29",
677683
"type": "distribution",
678684
"comment": "Download location for component"
679685
}
680686
],
681-
"purl": "pkg:pypi/gsutil@5.28",
687+
"purl": "pkg:pypi/gsutil@5.29",
682688
"properties": [
683689
{
684690
"name": "language",
@@ -1514,7 +1520,7 @@
15141520
"type": "library",
15151521
"bom-ref": "35-cryptography",
15161522
"name": "cryptography",
1517-
"version": "42.0.6",
1523+
"version": "42.0.7",
15181524
"supplier": {
15191525
"name": "The Python Cryptographic Authority and individual contributors",
15201526
"contact": [
@@ -1523,7 +1529,7 @@
15231529
}
15241530
]
15251531
},
1526-
"cpe": "cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:42.0.6:*:*:*:*:*:*:*",
1532+
"cpe": "cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:42.0.7:*:*:*:*:*:*:*",
15271533
"description": "cryptography is a package which provides cryptographic recipes and primitives to Python developers.",
15281534
"licenses": [
15291535
{
@@ -1532,12 +1538,12 @@
15321538
],
15331539
"externalReferences": [
15341540
{
1535-
"url": "https://pypi.org/project/cryptography/42.0.6",
1541+
"url": "https://pypi.org/project/cryptography/42.0.7",
15361542
"type": "distribution",
15371543
"comment": "Download location for component"
15381544
}
15391545
],
1540-
"purl": "pkg:pypi/[email protected].6",
1546+
"purl": "pkg:pypi/[email protected].7",
15411547
"properties": [
15421548
{
15431549
"name": "language",
@@ -1940,12 +1946,6 @@
19401946
"name": "markupsafe",
19411947
"version": "2.1.5",
19421948
"description": "Safely add untrusted strings to HTML/XML markup.",
1943-
"hashes": [
1944-
{
1945-
"alg": "SHA-1",
1946-
"content": "fbba4acd0312826cec9cfe18371c7df07962cb65"
1947-
}
1948-
],
19491949
"licenses": [
19501950
{
19511951
"license": {
@@ -2086,11 +2086,11 @@
20862086
"type": "library",
20872087
"bom-ref": "49-rpds-py",
20882088
"name": "rpds-py",
2089-
"version": "0.18.0",
2089+
"version": "0.18.1",
20902090
"supplier": {
20912091
"name": "Julian Berman"
20922092
},
2093-
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.18.0:*:*:*:*:*:*:*",
2093+
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.18.1:*:*:*:*:*:*:*",
20942094
"description": "Python bindings to Rust's persistent data structures (rpds)",
20952095
"licenses": [
20962096
{
@@ -2102,12 +2102,12 @@
21022102
],
21032103
"externalReferences": [
21042104
{
2105-
"url": "https://pypi.org/project/rpds-py/0.18.0",
2105+
"url": "https://pypi.org/project/rpds-py/0.18.1",
21062106
"type": "distribution",
21072107
"comment": "Download location for component"
21082108
}
21092109
],
2110-
"purl": "pkg:pypi/[email protected].0",
2110+
"purl": "pkg:pypi/[email protected].1",
21112111
"properties": [
21122112
{
21132113
"name": "language",
@@ -2420,7 +2420,7 @@
24202420
"type": "library",
24212421
"bom-ref": "57-tenacity",
24222422
"name": "tenacity",
2423-
"version": "8.2.3",
2423+
"version": "8.3.0",
24242424
"supplier": {
24252425
"name": "Julien Danjou",
24262426
"contact": [
@@ -2429,14 +2429,8 @@
24292429
}
24302430
]
24312431
},
2432-
"cpe": "cpe:2.3:a:julien_danjou:tenacity:8.2.3:*:*:*:*:*:*:*",
2432+
"cpe": "cpe:2.3:a:julien_danjou:tenacity:8.3.0:*:*:*:*:*:*:*",
24332433
"description": "Retry code until it succeeds",
2434-
"hashes": [
2435-
{
2436-
"alg": "SHA-1",
2437-
"content": "41ed2420cda8ab7650a39900451099f4730266c3"
2438-
}
2439-
],
24402434
"licenses": [
24412435
{
24422436
"license": {
@@ -2447,12 +2441,12 @@
24472441
],
24482442
"externalReferences": [
24492443
{
2450-
"url": "https://pypi.org/project/tenacity/8.2.3",
2444+
"url": "https://pypi.org/project/tenacity/8.3.0",
24512445
"type": "distribution",
24522446
"comment": "Download location for component"
24532447
}
24542448
],
2455-
"purl": "pkg:pypi/tenacity@8.2.3",
2449+
"purl": "pkg:pypi/tenacity@8.3.0",
24562450
"properties": [
24572451
{
24582452
"name": "language",

sbom/cve-bin-tool-py3.8.spdx

Lines changed: 19 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-e22d6ccd-3b1e-4723-801c-333cec52ae09
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-43ca30d9-07f7-4748-a669-8136d177492c
66
LicenseListVersion: 3.22
77
Creator: Tool: sbom4python-0.10.4
8-
Created: 2024-05-06T00:27:03Z
8+
Created: 2024-05-13T00:27:42Z
99
CreatorComment: <text>This document has been automatically generated.</text>
1010
#####
1111

@@ -189,6 +189,7 @@ PrimaryPackagePurpose: LIBRARY
189189
PackageSupplier: Organization: Stanislav Red Hat Product Security ([email protected])
190190
PackageDownloadLocation: https://pypi.org/project/cvss/3.1
191191
FilesAnalyzed: false
192+
PackageChecksum: SHA1: e4cf69bea6bcfa1cbc38dca13b9ec8bf3363a475
192193
PackageLicenseDeclared: NOASSERTION
193194
PackageLicenseConcluded: LGPL-3.0-or-later
194195
PackageLicenseComments: <text>cvss declares LGPLv3+ which is not currently a valid SPDX License identifier or expression.</text>
@@ -249,18 +250,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:tomas_aparicio:filetype:1.2.0:*:*:*:*:
249250

250251
PackageName: gsutil
251252
SPDXID: SPDXRef-Package-16-gsutil
252-
PackageVersion: 5.28
253+
PackageVersion: 5.29
253254
PrimaryPackagePurpose: LIBRARY
254255
PackageSupplier: Person: Google Inc. ([email protected])
255-
PackageDownloadLocation: https://pypi.org/project/gsutil/5.28
256+
PackageDownloadLocation: https://pypi.org/project/gsutil/5.29
256257
FilesAnalyzed: false
257258
PackageLicenseDeclared: NOASSERTION
258259
PackageLicenseConcluded: Apache-2.0
259260
PackageLicenseComments: <text>gsutil declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
260261
PackageCopyrightText: NOASSERTION
261262
PackageSummary: <text>A command line tool for interacting with cloud storage services.</text>
262-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/gsutil@5.28
263-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_inc.:gsutil:5.28:*:*:*:*:*:*:*
263+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/gsutil@5.29
264+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_inc.:gsutil:5.29:*:*:*:*:*:*:*
264265
#####
265266

266267
PackageName: argcomplete
@@ -557,17 +558,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_pyopenssl_developers:pyopenssl:24.
557558

558559
PackageName: cryptography
559560
SPDXID: SPDXRef-Package-35-cryptography
560-
PackageVersion: 42.0.6
561+
PackageVersion: 42.0.7
561562
PrimaryPackagePurpose: LIBRARY
562563
PackageSupplier: Organization: The Python Cryptographic Authority and individual contributors ([email protected])
563-
PackageDownloadLocation: https://pypi.org/project/cryptography/42.0.6
564+
PackageDownloadLocation: https://pypi.org/project/cryptography/42.0.7
564565
FilesAnalyzed: false
565566
PackageLicenseDeclared: Apache-2.0 OR BSD-3-Clause
566567
PackageLicenseConcluded: Apache-2.0 OR BSD-3-Clause
567568
PackageCopyrightText: NOASSERTION
568569
PackageSummary: <text>cryptography is a package which provides cryptographic recipes and primitives to Python developers.</text>
569-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].6
570-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:42.0.6:*:*:*:*:*:*:*
570+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].7
571+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:42.0.7:*:*:*:*:*:*:*
571572
#####
572573

573574
PackageName: cffi
@@ -721,7 +722,6 @@ PrimaryPackagePurpose: LIBRARY
721722
PackageSupplier: NOASSERTION
722723
PackageDownloadLocation: https://pypi.org/project/MarkupSafe/2.1.5
723724
FilesAnalyzed: false
724-
PackageChecksum: SHA1: fbba4acd0312826cec9cfe18371c7df07962cb65
725725
PackageLicenseDeclared: BSD-3-Clause
726726
PackageLicenseConcluded: BSD-3-Clause
727727
PackageCopyrightText: NOASSERTION
@@ -777,17 +777,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:referencing:0.35.1:*:*:*
777777

778778
PackageName: rpds-py
779779
SPDXID: SPDXRef-Package-49-rpds-py
780-
PackageVersion: 0.18.0
780+
PackageVersion: 0.18.1
781781
PrimaryPackagePurpose: LIBRARY
782782
PackageSupplier: Person: Julian Berman
783-
PackageDownloadLocation: https://pypi.org/project/rpds-py/0.18.0
783+
PackageDownloadLocation: https://pypi.org/project/rpds-py/0.18.1
784784
FilesAnalyzed: false
785785
PackageLicenseDeclared: MIT
786786
PackageLicenseConcluded: MIT
787787
PackageCopyrightText: NOASSERTION
788788
PackageSummary: <text>Python bindings to Rust's persistent data structures (rpds)</text>
789-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].0
790-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.18.0:*:*:*:*:*:*:*
789+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].1
790+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.18.1:*:*:*:*:*:*:*
791791
#####
792792

793793
PackageName: pkgutil-resolve-name
@@ -902,19 +902,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:5.22.0:*:*:*:*:*:*:*
902902

903903
PackageName: tenacity
904904
SPDXID: SPDXRef-Package-57-tenacity
905-
PackageVersion: 8.2.3
905+
PackageVersion: 8.3.0
906906
PrimaryPackagePurpose: LIBRARY
907907
PackageSupplier: Person: Julien Danjou ([email protected])
908-
PackageDownloadLocation: https://pypi.org/project/tenacity/8.2.3
908+
PackageDownloadLocation: https://pypi.org/project/tenacity/8.3.0
909909
FilesAnalyzed: false
910-
PackageChecksum: SHA1: 41ed2420cda8ab7650a39900451099f4730266c3
911910
PackageLicenseDeclared: NOASSERTION
912911
PackageLicenseConcluded: Apache-2.0
913912
PackageLicenseComments: <text>tenacity declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
914913
PackageCopyrightText: NOASSERTION
915914
PackageSummary: <text>Retry code until it succeeds</text>
916-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/tenacity@8.2.3
917-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julien_danjou:tenacity:8.2.3:*:*:*:*:*:*:*
915+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/tenacity@8.3.0
916+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julien_danjou:tenacity:8.3.0:*:*:*:*:*:*:*
918917
#####
919918

920919
PackageName: python-gnupg

0 commit comments

Comments
 (0)