Skip to content

Commit

Permalink
chore: update SBOM for Python 3.10
Browse files Browse the repository at this point in the history
  • Loading branch information
web-flow authored and github-actions[bot] committed May 13, 2024
1 parent 234f8ea commit 4609a4d
Show file tree
Hide file tree
Showing 2 changed files with 43 additions and 50 deletions.
54 changes: 24 additions & 30 deletions sbom/cve-bin-tool-py3.10.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,10 +2,10 @@
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
"bomFormat": "CycloneDX",
"specVersion": "1.6",
"serialNumber": "urn:uuid:d2fdc99c-7d87-42c4-89a0-9274b36f0f25",
"serialNumber": "urn:uuid:f7285934-6771-420a-9951-5901142b3594",
"version": 1,
"metadata": {
"timestamp": "2024-05-06T00:28:30Z",
"timestamp": "2024-05-13T00:28:49Z",
"tools": {
"components": [
{
Expand Down Expand Up @@ -483,6 +483,12 @@
},
"cpe": "cpe:2.3:a:stanislav_red_hat_product_security:cvss:3.1:*:*:*:*:*:*:*",
"description": "CVSS2/3/4 library with interactive calculator for Python 2 and Python 3",
"hashes": [
{
"alg": "SHA-1",
"content": "e4cf69bea6bcfa1cbc38dca13b9ec8bf3363a475"
}
],
"licenses": [
{
"license": {
Expand Down Expand Up @@ -652,7 +658,7 @@
"type": "library",
"bom-ref": "16-gsutil",
"name": "gsutil",
"version": "5.28",
"version": "5.29",
"supplier": {
"name": "Google Inc .",
"contact": [
Expand All @@ -661,7 +667,7 @@
}
]
},
"cpe": "cpe:2.3:a:google_inc.:gsutil:5.28:*:*:*:*:*:*:*",
"cpe": "cpe:2.3:a:google_inc.:gsutil:5.29:*:*:*:*:*:*:*",
"description": "A command line tool for interacting with cloud storage services.",
"licenses": [
{
Expand All @@ -673,12 +679,12 @@
],
"externalReferences": [
{
"url": "https://pypi.org/project/gsutil/5.28",
"url": "https://pypi.org/project/gsutil/5.29",
"type": "distribution",
"comment": "Download location for component"
}
],
"purl": "pkg:pypi/gsutil@5.28",
"purl": "pkg:pypi/gsutil@5.29",
"properties": [
{
"name": "language",
Expand Down Expand Up @@ -1514,7 +1520,7 @@
"type": "library",
"bom-ref": "35-cryptography",
"name": "cryptography",
"version": "42.0.6",
"version": "42.0.7",
"supplier": {
"name": "The Python Cryptographic Authority and individual contributors",
"contact": [
Expand All @@ -1523,7 +1529,7 @@
}
]
},
"cpe": "cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:42.0.6:*:*:*:*:*:*:*",
"cpe": "cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:42.0.7:*:*:*:*:*:*:*",
"description": "cryptography is a package which provides cryptographic recipes and primitives to Python developers.",
"licenses": [
{
Expand All @@ -1532,12 +1538,12 @@
],
"externalReferences": [
{
"url": "https://pypi.org/project/cryptography/42.0.6",
"url": "https://pypi.org/project/cryptography/42.0.7",
"type": "distribution",
"comment": "Download location for component"
}
],
"purl": "pkg:pypi/cryptography@42.0.6",
"purl": "pkg:pypi/cryptography@42.0.7",
"properties": [
{
"name": "language",
Expand Down Expand Up @@ -1820,12 +1826,6 @@
"name": "markupsafe",
"version": "2.1.5",
"description": "Safely add untrusted strings to HTML/XML markup.",
"hashes": [
{
"alg": "SHA-1",
"content": "fbba4acd0312826cec9cfe18371c7df07962cb65"
}
],
"licenses": [
{
"license": {
Expand Down Expand Up @@ -1966,11 +1966,11 @@
"type": "library",
"bom-ref": "46-rpds-py",
"name": "rpds-py",
"version": "0.18.0",
"version": "0.18.1",
"supplier": {
"name": "Julian Berman"
},
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.18.0:*:*:*:*:*:*:*",
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.18.1:*:*:*:*:*:*:*",
"description": "Python bindings to Rust's persistent data structures (rpds)",
"licenses": [
{
Expand All @@ -1982,12 +1982,12 @@
],
"externalReferences": [
{
"url": "https://pypi.org/project/rpds-py/0.18.0",
"url": "https://pypi.org/project/rpds-py/0.18.1",
"type": "distribution",
"comment": "Download location for component"
}
],
"purl": "pkg:pypi/rpds-py@0.18.0",
"purl": "pkg:pypi/rpds-py@0.18.1",
"properties": [
{
"name": "language",
Expand Down Expand Up @@ -2266,7 +2266,7 @@
"type": "library",
"bom-ref": "53-tenacity",
"name": "tenacity",
"version": "8.2.3",
"version": "8.3.0",
"supplier": {
"name": "Julien Danjou",
"contact": [
Expand All @@ -2275,14 +2275,8 @@
}
]
},
"cpe": "cpe:2.3:a:julien_danjou:tenacity:8.2.3:*:*:*:*:*:*:*",
"cpe": "cpe:2.3:a:julien_danjou:tenacity:8.3.0:*:*:*:*:*:*:*",
"description": "Retry code until it succeeds",
"hashes": [
{
"alg": "SHA-1",
"content": "41ed2420cda8ab7650a39900451099f4730266c3"
}
],
"licenses": [
{
"license": {
Expand All @@ -2293,12 +2287,12 @@
],
"externalReferences": [
{
"url": "https://pypi.org/project/tenacity/8.2.3",
"url": "https://pypi.org/project/tenacity/8.3.0",
"type": "distribution",
"comment": "Download location for component"
}
],
"purl": "pkg:pypi/tenacity@8.2.3",
"purl": "pkg:pypi/tenacity@8.3.0",
"properties": [
{
"name": "language",
Expand Down
39 changes: 19 additions & 20 deletions sbom/cve-bin-tool-py3.10.spdx
Original file line number Diff line number Diff line change
Expand Up @@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
DataLicense: CC0-1.0
SPDXID: SPDXRef-DOCUMENT
DocumentName: Python-cve-bin-tool
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-e55ebc57-b76a-458c-95c3-ac8d39a01d6f
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-7ebf2507-d2e7-4da3-966b-3116faa0d6c1
LicenseListVersion: 3.22
Creator: Tool: sbom4python-0.10.4
Created: 2024-05-06T00:26:49Z
Created: 2024-05-13T00:27:18Z
CreatorComment: <text>This document has been automatically generated.</text>
#####

Expand Down Expand Up @@ -189,6 +189,7 @@ PrimaryPackagePurpose: LIBRARY
PackageSupplier: Organization: Stanislav Red Hat Product Security (skontar@redhat.com)
PackageDownloadLocation: https://pypi.org/project/cvss/3.1
FilesAnalyzed: false
PackageChecksum: SHA1: e4cf69bea6bcfa1cbc38dca13b9ec8bf3363a475
PackageLicenseDeclared: NOASSERTION
PackageLicenseConcluded: LGPL-3.0-or-later
PackageLicenseComments: <text>cvss declares LGPLv3+ which is not currently a valid SPDX License identifier or expression.</text>
Expand Down Expand Up @@ -249,18 +250,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:tomas_aparicio:filetype:1.2.0:*:*:*:*:

PackageName: gsutil
SPDXID: SPDXRef-Package-16-gsutil
PackageVersion: 5.28
PackageVersion: 5.29
PrimaryPackagePurpose: LIBRARY
PackageSupplier: Person: Google Inc. (buganizer-system+187143@google.com)
PackageDownloadLocation: https://pypi.org/project/gsutil/5.28
PackageDownloadLocation: https://pypi.org/project/gsutil/5.29
FilesAnalyzed: false
PackageLicenseDeclared: NOASSERTION
PackageLicenseConcluded: Apache-2.0
PackageLicenseComments: <text>gsutil declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
PackageCopyrightText: NOASSERTION
PackageSummary: <text>A command line tool for interacting with cloud storage services.</text>
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/gsutil@5.28
ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_inc.:gsutil:5.28:*:*:*:*:*:*:*
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/gsutil@5.29
ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_inc.:gsutil:5.29:*:*:*:*:*:*:*
#####

PackageName: argcomplete
Expand Down Expand Up @@ -557,17 +558,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_pyopenssl_developers:pyopenssl:24.

PackageName: cryptography
SPDXID: SPDXRef-Package-35-cryptography
PackageVersion: 42.0.6
PackageVersion: 42.0.7
PrimaryPackagePurpose: LIBRARY
PackageSupplier: Organization: The Python Cryptographic Authority and individual contributors (cryptography-dev@python.org)
PackageDownloadLocation: https://pypi.org/project/cryptography/42.0.6
PackageDownloadLocation: https://pypi.org/project/cryptography/42.0.7
FilesAnalyzed: false
PackageLicenseDeclared: Apache-2.0 OR BSD-3-Clause
PackageLicenseConcluded: Apache-2.0 OR BSD-3-Clause
PackageCopyrightText: NOASSERTION
PackageSummary: <text>cryptography is a package which provides cryptographic recipes and primitives to Python developers.</text>
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/cryptography@42.0.6
ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:42.0.6:*:*:*:*:*:*:*
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/cryptography@42.0.7
ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:42.0.7:*:*:*:*:*:*:*
#####

PackageName: cffi
Expand Down Expand Up @@ -673,7 +674,6 @@ PrimaryPackagePurpose: LIBRARY
PackageSupplier: NOASSERTION
PackageDownloadLocation: https://pypi.org/project/MarkupSafe/2.1.5
FilesAnalyzed: false
PackageChecksum: SHA1: fbba4acd0312826cec9cfe18371c7df07962cb65
PackageLicenseDeclared: BSD-3-Clause
PackageLicenseConcluded: BSD-3-Clause
PackageCopyrightText: NOASSERTION
Expand Down Expand Up @@ -729,17 +729,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:referencing:0.35.1:*:*:*

PackageName: rpds-py
SPDXID: SPDXRef-Package-46-rpds-py
PackageVersion: 0.18.0
PackageVersion: 0.18.1
PrimaryPackagePurpose: LIBRARY
PackageSupplier: Person: Julian Berman
PackageDownloadLocation: https://pypi.org/project/rpds-py/0.18.0
PackageDownloadLocation: https://pypi.org/project/rpds-py/0.18.1
FilesAnalyzed: false
PackageLicenseDeclared: MIT
PackageLicenseConcluded: MIT
PackageCopyrightText: NOASSERTION
PackageSummary: <text>Python bindings to Rust's persistent data structures (rpds)</text>
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/rpds-py@0.18.0
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.18.0:*:*:*:*:*:*:*
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/rpds-py@0.18.1
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.18.1:*:*:*:*:*:*:*
#####

PackageName: lib4sbom
Expand Down Expand Up @@ -839,19 +839,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:5.22.0:*:*:*:*:*:*:*

PackageName: tenacity
SPDXID: SPDXRef-Package-53-tenacity
PackageVersion: 8.2.3
PackageVersion: 8.3.0
PrimaryPackagePurpose: LIBRARY
PackageSupplier: Person: Julien Danjou (julien@danjou.info)
PackageDownloadLocation: https://pypi.org/project/tenacity/8.2.3
PackageDownloadLocation: https://pypi.org/project/tenacity/8.3.0
FilesAnalyzed: false
PackageChecksum: SHA1: 41ed2420cda8ab7650a39900451099f4730266c3
PackageLicenseDeclared: NOASSERTION
PackageLicenseConcluded: Apache-2.0
PackageLicenseComments: <text>tenacity declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
PackageCopyrightText: NOASSERTION
PackageSummary: <text>Retry code until it succeeds</text>
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/tenacity@8.2.3
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julien_danjou:tenacity:8.2.3:*:*:*:*:*:*:*
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/tenacity@8.3.0
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julien_danjou:tenacity:8.3.0:*:*:*:*:*:*:*
#####

PackageName: python-gnupg
Expand Down

0 comments on commit 4609a4d

Please sign in to comment.