diff --git a/sbom/cve-bin-tool-py3.8.json b/sbom/cve-bin-tool-py3.8.json
index 0b18a29331..0e78ff1b1d 100644
--- a/sbom/cve-bin-tool-py3.8.json
+++ b/sbom/cve-bin-tool-py3.8.json
@@ -2,10 +2,10 @@
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
"bomFormat": "CycloneDX",
"specVersion": "1.6",
- "serialNumber": "urn:uuid:05549142-5d45-4ceb-b2b7-b95ca4fb9e53",
+ "serialNumber": "urn:uuid:98b04938-ce5b-4df5-9d99-2eacbcb84cc3",
"version": 1,
"metadata": {
- "timestamp": "2024-06-10T00:30:18Z",
+ "timestamp": "2024-06-17T00:30:29Z",
"tools": {
"components": [
{
@@ -658,7 +658,7 @@
"type": "library",
"bom-ref": "16-gsutil",
"name": "gsutil",
- "version": "5.29",
+ "version": "5.30",
"supplier": {
"name": "Google Inc .",
"contact": [
@@ -667,7 +667,7 @@
}
]
},
- "cpe": "cpe:2.3:a:google_inc.:gsutil:5.29:*:*:*:*:*:*:*",
+ "cpe": "cpe:2.3:a:google_inc.:gsutil:5.30:*:*:*:*:*:*:*",
"description": "A command line tool for interacting with cloud storage services.",
"licenses": [
{
@@ -679,12 +679,12 @@
],
"externalReferences": [
{
- "url": "https://pypi.org/project/gsutil/5.29",
+ "url": "https://pypi.org/project/gsutil/5.30",
"type": "distribution",
"comment": "Download location for component"
}
],
- "purl": "pkg:pypi/gsutil@5.29",
+ "purl": "pkg:pypi/gsutil@5.30",
"properties": [
{
"name": "language",
@@ -700,7 +700,7 @@
"type": "library",
"bom-ref": "17-argcomplete",
"name": "argcomplete",
- "version": "3.3.0",
+ "version": "3.4.0",
"supplier": {
"name": "Andrey Kislyuk",
"contact": [
@@ -709,14 +709,8 @@
}
]
},
- "cpe": "cpe:2.3:a:andrey_kislyuk:argcomplete:3.3.0:*:*:*:*:*:*:*",
+ "cpe": "cpe:2.3:a:andrey_kislyuk:argcomplete:3.4.0:*:*:*:*:*:*:*",
"description": "Bash tab completion for argparse",
- "hashes": [
- {
- "alg": "SHA-1",
- "content": "c7cc834df1fddcf94bd35b740fef7c7ab8e9c350"
- }
- ],
"licenses": [
{
"license": {
@@ -727,12 +721,12 @@
],
"externalReferences": [
{
- "url": "https://pypi.org/project/argcomplete/3.3.0",
+ "url": "https://pypi.org/project/argcomplete/3.4.0",
"type": "distribution",
"comment": "Download location for component"
}
],
- "purl": "pkg:pypi/argcomplete@3.3.0",
+ "purl": "pkg:pypi/argcomplete@3.4.0",
"properties": [
{
"name": "language",
@@ -2301,18 +2295,12 @@
"type": "library",
"bom-ref": "54-packageurl-python",
"name": "packageurl-python",
- "version": "0.15.0",
+ "version": "0.15.1",
"supplier": {
"name": "the purl authors"
},
- "cpe": "cpe:2.3:a:the_purl_authors:packageurl-python:0.15.0:*:*:*:*:*:*:*",
+ "cpe": "cpe:2.3:a:the_purl_authors:packageurl-python:0.15.1:*:*:*:*:*:*:*",
"description": "A purl aka. Package URL parser and builder",
- "hashes": [
- {
- "alg": "SHA-1",
- "content": "a46d42493bbb7ae1a227be7bbd6b180a149ad3b1"
- }
- ],
"licenses": [
{
"license": {
@@ -2323,12 +2311,12 @@
],
"externalReferences": [
{
- "url": "https://pypi.org/project/packageurl-python/0.15.0",
+ "url": "https://pypi.org/project/packageurl-python/0.15.1",
"type": "distribution",
"comment": "Download location for component"
}
],
- "purl": "pkg:pypi/packageurl-python@0.15.0",
+ "purl": "pkg:pypi/packageurl-python@0.15.1",
"properties": [
{
"name": "language",
diff --git a/sbom/cve-bin-tool-py3.8.spdx b/sbom/cve-bin-tool-py3.8.spdx
index 02d801e658..b216c8945a 100644
--- a/sbom/cve-bin-tool-py3.8.spdx
+++ b/sbom/cve-bin-tool-py3.8.spdx
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
DataLicense: CC0-1.0
SPDXID: SPDXRef-DOCUMENT
DocumentName: Python-cve-bin-tool
-DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-78a46fec-24e1-42cc-8eae-593d7cf2a545
+DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-9b2572c3-bc89-4031-9f9c-0823282d441e
LicenseListVersion: 3.22
Creator: Tool: sbom4python-0.10.4
-Created: 2024-06-10T00:28:35Z
+Created: 2024-06-17T00:28:55Z
CreatorComment: This document has been automatically generated.
#####
@@ -250,35 +250,34 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:tomas_aparicio:filetype:1.2.0:*:*:*:*:
PackageName: gsutil
SPDXID: SPDXRef-Package-16-gsutil
-PackageVersion: 5.29
+PackageVersion: 5.30
PrimaryPackagePurpose: LIBRARY
PackageSupplier: Person: Google Inc. (buganizer-system+187143@google.com)
-PackageDownloadLocation: https://pypi.org/project/gsutil/5.29
+PackageDownloadLocation: https://pypi.org/project/gsutil/5.30
FilesAnalyzed: false
PackageLicenseDeclared: NOASSERTION
PackageLicenseConcluded: Apache-2.0
PackageLicenseComments: gsutil declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.
PackageCopyrightText: NOASSERTION
PackageSummary: A command line tool for interacting with cloud storage services.
-ExternalRef: PACKAGE_MANAGER purl pkg:pypi/gsutil@5.29
-ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_inc.:gsutil:5.29:*:*:*:*:*:*:*
+ExternalRef: PACKAGE_MANAGER purl pkg:pypi/gsutil@5.30
+ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_inc.:gsutil:5.30:*:*:*:*:*:*:*
#####
PackageName: argcomplete
SPDXID: SPDXRef-Package-17-argcomplete
-PackageVersion: 3.3.0
+PackageVersion: 3.4.0
PrimaryPackagePurpose: LIBRARY
PackageSupplier: Person: Andrey Kislyuk (kislyuk@gmail.com)
-PackageDownloadLocation: https://pypi.org/project/argcomplete/3.3.0
+PackageDownloadLocation: https://pypi.org/project/argcomplete/3.4.0
FilesAnalyzed: false
-PackageChecksum: SHA1: c7cc834df1fddcf94bd35b740fef7c7ab8e9c350
PackageLicenseDeclared: NOASSERTION
PackageLicenseConcluded: Apache-2.0
PackageLicenseComments: argcomplete declares Apache Software License which is not currently a valid SPDX License identifier or expression.
PackageCopyrightText: NOASSERTION
PackageSummary: Bash tab completion for argparse
-ExternalRef: PACKAGE_MANAGER purl pkg:pypi/argcomplete@3.3.0
-ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_kislyuk:argcomplete:3.3.0:*:*:*:*:*:*:*
+ExternalRef: PACKAGE_MANAGER purl pkg:pypi/argcomplete@3.4.0
+ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_kislyuk:argcomplete:3.4.0:*:*:*:*:*:*:*
#####
PackageName: crcmod
@@ -856,18 +855,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:raphael_barrois:semantic-version:2.10.
PackageName: packageurl-python
SPDXID: SPDXRef-Package-54-packageurl-python
-PackageVersion: 0.15.0
+PackageVersion: 0.15.1
PrimaryPackagePurpose: LIBRARY
PackageSupplier: Person: the purl authors
-PackageDownloadLocation: https://pypi.org/project/packageurl-python/0.15.0
+PackageDownloadLocation: https://pypi.org/project/packageurl-python/0.15.1
FilesAnalyzed: false
-PackageChecksum: SHA1: a46d42493bbb7ae1a227be7bbd6b180a149ad3b1
PackageLicenseDeclared: MIT
PackageLicenseConcluded: MIT
PackageCopyrightText: NOASSERTION
PackageSummary: A purl aka. Package URL parser and builder
-ExternalRef: PACKAGE_MANAGER purl pkg:pypi/packageurl-python@0.15.0
-ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_purl_authors:packageurl-python:0.15.0:*:*:*:*:*:*:*
+ExternalRef: PACKAGE_MANAGER purl pkg:pypi/packageurl-python@0.15.1
+ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_purl_authors:packageurl-python:0.15.1:*:*:*:*:*:*:*
#####
PackageName: packaging