diff --git a/sbom/cve-bin-tool-py3.8.json b/sbom/cve-bin-tool-py3.8.json index 0b18a29331..0e78ff1b1d 100644 --- a/sbom/cve-bin-tool-py3.8.json +++ b/sbom/cve-bin-tool-py3.8.json @@ -2,10 +2,10 @@ "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json", "bomFormat": "CycloneDX", "specVersion": "1.6", - "serialNumber": "urn:uuid:05549142-5d45-4ceb-b2b7-b95ca4fb9e53", + "serialNumber": "urn:uuid:98b04938-ce5b-4df5-9d99-2eacbcb84cc3", "version": 1, "metadata": { - "timestamp": "2024-06-10T00:30:18Z", + "timestamp": "2024-06-17T00:30:29Z", "tools": { "components": [ { @@ -658,7 +658,7 @@ "type": "library", "bom-ref": "16-gsutil", "name": "gsutil", - "version": "5.29", + "version": "5.30", "supplier": { "name": "Google Inc .", "contact": [ @@ -667,7 +667,7 @@ } ] }, - "cpe": "cpe:2.3:a:google_inc.:gsutil:5.29:*:*:*:*:*:*:*", + "cpe": "cpe:2.3:a:google_inc.:gsutil:5.30:*:*:*:*:*:*:*", "description": "A command line tool for interacting with cloud storage services.", "licenses": [ { @@ -679,12 +679,12 @@ ], "externalReferences": [ { - "url": "https://pypi.org/project/gsutil/5.29", + "url": "https://pypi.org/project/gsutil/5.30", "type": "distribution", "comment": "Download location for component" } ], - "purl": "pkg:pypi/gsutil@5.29", + "purl": "pkg:pypi/gsutil@5.30", "properties": [ { "name": "language", @@ -700,7 +700,7 @@ "type": "library", "bom-ref": "17-argcomplete", "name": "argcomplete", - "version": "3.3.0", + "version": "3.4.0", "supplier": { "name": "Andrey Kislyuk", "contact": [ @@ -709,14 +709,8 @@ } ] }, - "cpe": "cpe:2.3:a:andrey_kislyuk:argcomplete:3.3.0:*:*:*:*:*:*:*", + "cpe": "cpe:2.3:a:andrey_kislyuk:argcomplete:3.4.0:*:*:*:*:*:*:*", "description": "Bash tab completion for argparse", - "hashes": [ - { - "alg": "SHA-1", - "content": "c7cc834df1fddcf94bd35b740fef7c7ab8e9c350" - } - ], "licenses": [ { "license": { @@ -727,12 +721,12 @@ ], "externalReferences": [ { - "url": "https://pypi.org/project/argcomplete/3.3.0", + "url": "https://pypi.org/project/argcomplete/3.4.0", "type": "distribution", "comment": "Download location for component" } ], - "purl": "pkg:pypi/argcomplete@3.3.0", + "purl": "pkg:pypi/argcomplete@3.4.0", "properties": [ { "name": "language", @@ -2301,18 +2295,12 @@ "type": "library", "bom-ref": "54-packageurl-python", "name": "packageurl-python", - "version": "0.15.0", + "version": "0.15.1", "supplier": { "name": "the purl authors" }, - "cpe": "cpe:2.3:a:the_purl_authors:packageurl-python:0.15.0:*:*:*:*:*:*:*", + "cpe": "cpe:2.3:a:the_purl_authors:packageurl-python:0.15.1:*:*:*:*:*:*:*", "description": "A purl aka. Package URL parser and builder", - "hashes": [ - { - "alg": "SHA-1", - "content": "a46d42493bbb7ae1a227be7bbd6b180a149ad3b1" - } - ], "licenses": [ { "license": { @@ -2323,12 +2311,12 @@ ], "externalReferences": [ { - "url": "https://pypi.org/project/packageurl-python/0.15.0", + "url": "https://pypi.org/project/packageurl-python/0.15.1", "type": "distribution", "comment": "Download location for component" } ], - "purl": "pkg:pypi/packageurl-python@0.15.0", + "purl": "pkg:pypi/packageurl-python@0.15.1", "properties": [ { "name": "language", diff --git a/sbom/cve-bin-tool-py3.8.spdx b/sbom/cve-bin-tool-py3.8.spdx index 02d801e658..b216c8945a 100644 --- a/sbom/cve-bin-tool-py3.8.spdx +++ b/sbom/cve-bin-tool-py3.8.spdx @@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3 DataLicense: CC0-1.0 SPDXID: SPDXRef-DOCUMENT DocumentName: Python-cve-bin-tool -DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-78a46fec-24e1-42cc-8eae-593d7cf2a545 +DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-9b2572c3-bc89-4031-9f9c-0823282d441e LicenseListVersion: 3.22 Creator: Tool: sbom4python-0.10.4 -Created: 2024-06-10T00:28:35Z +Created: 2024-06-17T00:28:55Z CreatorComment: This document has been automatically generated. ##### @@ -250,35 +250,34 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:tomas_aparicio:filetype:1.2.0:*:*:*:*: PackageName: gsutil SPDXID: SPDXRef-Package-16-gsutil -PackageVersion: 5.29 +PackageVersion: 5.30 PrimaryPackagePurpose: LIBRARY PackageSupplier: Person: Google Inc. (buganizer-system+187143@google.com) -PackageDownloadLocation: https://pypi.org/project/gsutil/5.29 +PackageDownloadLocation: https://pypi.org/project/gsutil/5.30 FilesAnalyzed: false PackageLicenseDeclared: NOASSERTION PackageLicenseConcluded: Apache-2.0 PackageLicenseComments: gsutil declares Apache 2.0 which is not currently a valid SPDX License identifier or expression. PackageCopyrightText: NOASSERTION PackageSummary: A command line tool for interacting with cloud storage services. -ExternalRef: PACKAGE_MANAGER purl pkg:pypi/gsutil@5.29 -ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_inc.:gsutil:5.29:*:*:*:*:*:*:* +ExternalRef: PACKAGE_MANAGER purl pkg:pypi/gsutil@5.30 +ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_inc.:gsutil:5.30:*:*:*:*:*:*:* ##### PackageName: argcomplete SPDXID: SPDXRef-Package-17-argcomplete -PackageVersion: 3.3.0 +PackageVersion: 3.4.0 PrimaryPackagePurpose: LIBRARY PackageSupplier: Person: Andrey Kislyuk (kislyuk@gmail.com) -PackageDownloadLocation: https://pypi.org/project/argcomplete/3.3.0 +PackageDownloadLocation: https://pypi.org/project/argcomplete/3.4.0 FilesAnalyzed: false -PackageChecksum: SHA1: c7cc834df1fddcf94bd35b740fef7c7ab8e9c350 PackageLicenseDeclared: NOASSERTION PackageLicenseConcluded: Apache-2.0 PackageLicenseComments: argcomplete declares Apache Software License which is not currently a valid SPDX License identifier or expression. PackageCopyrightText: NOASSERTION PackageSummary: Bash tab completion for argparse -ExternalRef: PACKAGE_MANAGER purl pkg:pypi/argcomplete@3.3.0 -ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_kislyuk:argcomplete:3.3.0:*:*:*:*:*:*:* +ExternalRef: PACKAGE_MANAGER purl pkg:pypi/argcomplete@3.4.0 +ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_kislyuk:argcomplete:3.4.0:*:*:*:*:*:*:* ##### PackageName: crcmod @@ -856,18 +855,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:raphael_barrois:semantic-version:2.10. PackageName: packageurl-python SPDXID: SPDXRef-Package-54-packageurl-python -PackageVersion: 0.15.0 +PackageVersion: 0.15.1 PrimaryPackagePurpose: LIBRARY PackageSupplier: Person: the purl authors -PackageDownloadLocation: https://pypi.org/project/packageurl-python/0.15.0 +PackageDownloadLocation: https://pypi.org/project/packageurl-python/0.15.1 FilesAnalyzed: false -PackageChecksum: SHA1: a46d42493bbb7ae1a227be7bbd6b180a149ad3b1 PackageLicenseDeclared: MIT PackageLicenseConcluded: MIT PackageCopyrightText: NOASSERTION PackageSummary: A purl aka. Package URL parser and builder -ExternalRef: PACKAGE_MANAGER purl pkg:pypi/packageurl-python@0.15.0 -ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_purl_authors:packageurl-python:0.15.0:*:*:*:*:*:*:* +ExternalRef: PACKAGE_MANAGER purl pkg:pypi/packageurl-python@0.15.1 +ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_purl_authors:packageurl-python:0.15.1:*:*:*:*:*:*:* ##### PackageName: packaging