Skip to content

Commit fbe2d13

Browse files
chore: update SBOM for Python 3.10 (#4229)
Co-authored-by: GitHub <[email protected]>
1 parent 4b9b959 commit fbe2d13

File tree

2 files changed

+19
-12
lines changed

2 files changed

+19
-12
lines changed

sbom/cve-bin-tool-py3.10.json

Lines changed: 12 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:b44cf216-911d-4108-a644-baac334f4065",
5+
"serialNumber": "urn:uuid:ffa389b8-77a3-45cc-af52-28b1c8cda666",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2024-06-24T00:29:18Z",
8+
"timestamp": "2024-07-01T00:32:05Z",
99
"tools": {
1010
"components": [
1111
{
@@ -2532,7 +2532,7 @@
25322532
"type": "library",
25332533
"bom-ref": "59-tenacity",
25342534
"name": "tenacity",
2535-
"version": "8.4.1",
2535+
"version": "8.4.2",
25362536
"supplier": {
25372537
"name": "Julien Danjou",
25382538
"contact": [
@@ -2541,7 +2541,7 @@
25412541
}
25422542
]
25432543
},
2544-
"cpe": "cpe:2.3:a:julien_danjou:tenacity:8.4.1:*:*:*:*:*:*:*",
2544+
"cpe": "cpe:2.3:a:julien_danjou:tenacity:8.4.2:*:*:*:*:*:*:*",
25452545
"description": "Retry code until it succeeds",
25462546
"licenses": [
25472547
{
@@ -2553,12 +2553,12 @@
25532553
],
25542554
"externalReferences": [
25552555
{
2556-
"url": "https://pypi.org/project/tenacity/8.4.1",
2556+
"url": "https://pypi.org/project/tenacity/8.4.2",
25572557
"type": "distribution",
25582558
"comment": "Download location for component"
25592559
}
25602560
],
2561-
"purl": "pkg:pypi/[email protected].1",
2561+
"purl": "pkg:pypi/[email protected].2",
25622562
"properties": [
25632563
{
25642564
"name": "language",
@@ -2943,6 +2943,12 @@
29432943
},
29442944
"cpe": "cpe:2.3:a:davide_brunato:elementpath:4.4.0:*:*:*:*:*:*:*",
29452945
"description": "XPath 1.0/2.0/3.0/3.1 parsers and selectors for ElementTree and lxml",
2946+
"hashes": [
2947+
{
2948+
"alg": "SHA-1",
2949+
"content": "004fca18366974c34193176bd3a356f711330ca0"
2950+
}
2951+
],
29462952
"licenses": [
29472953
{
29482954
"license": {

sbom/cve-bin-tool-py3.10.spdx

Lines changed: 7 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-0d31b14c-cf19-487e-bf40-0fee61c13105
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-b0fe606b-c617-4d22-be78-af0167648fc4
66
LicenseListVersion: 3.22
77
Creator: Tool: sbom4python-0.10.4
8-
Created: 2024-06-24T00:28:21Z
8+
Created: 2024-07-01T00:31:12Z
99
CreatorComment: <text>This document has been automatically generated.</text>
1010
#####
1111

@@ -934,18 +934,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:5.22.0:*:*:*:*:*:*:*
934934

935935
PackageName: tenacity
936936
SPDXID: SPDXRef-Package-59-tenacity
937-
PackageVersion: 8.4.1
937+
PackageVersion: 8.4.2
938938
PrimaryPackagePurpose: LIBRARY
939939
PackageSupplier: Person: Julien Danjou ([email protected])
940-
PackageDownloadLocation: https://pypi.org/project/tenacity/8.4.1
940+
PackageDownloadLocation: https://pypi.org/project/tenacity/8.4.2
941941
FilesAnalyzed: false
942942
PackageLicenseDeclared: NOASSERTION
943943
PackageLicenseConcluded: Apache-2.0
944944
PackageLicenseComments: <text>tenacity declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
945945
PackageCopyrightText: NOASSERTION
946946
PackageSummary: <text>Retry code until it succeeds</text>
947-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].1
948-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julien_danjou:tenacity:8.4.1:*:*:*:*:*:*:*
947+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].2
948+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julien_danjou:tenacity:8.4.2:*:*:*:*:*:*:*
949949
#####
950950

951951
PackageName: python-gnupg
@@ -1081,6 +1081,7 @@ PrimaryPackagePurpose: LIBRARY
10811081
PackageSupplier: Person: Davide Brunato ([email protected])
10821082
PackageDownloadLocation: https://pypi.org/project/elementpath/4.4.0
10831083
FilesAnalyzed: false
1084+
PackageChecksum: SHA1: 004fca18366974c34193176bd3a356f711330ca0
10841085
PackageLicenseDeclared: MIT
10851086
PackageLicenseConcluded: MIT
10861087
PackageCopyrightText: NOASSERTION

0 commit comments

Comments
 (0)