diff --git a/sbom/cve-bin-tool-py3.9.json b/sbom/cve-bin-tool-py3.9.json index c40fd18e65..3f1af196e3 100644 --- a/sbom/cve-bin-tool-py3.9.json +++ b/sbom/cve-bin-tool-py3.9.json @@ -2,10 +2,10 @@ "$schema": "http://cyclonedx.org/schema/bom-1.5.schema.json", "bomFormat": "CycloneDX", "specVersion": "1.5", - "serialNumber": "urn:uuid:233d04b0-bdbb-4457-bac7-f220a1ddaf27", + "serialNumber": "urn:uuid:c4ac0f22-4e79-4a23-bd46-bbb9c8a434c8", "version": 1, "metadata": { - "timestamp": "2023-11-06T00:25:57Z", + "timestamp": "2023-11-13T00:26:21Z", "tools": { "components": [ { @@ -544,7 +544,7 @@ "type": "library", "bom-ref": "17-argcomplete", "name": "argcomplete", - "version": "3.1.4", + "version": "3.1.6", "supplier": { "name": "Andrey Kislyuk", "contact": [ @@ -553,7 +553,7 @@ } ] }, - "cpe": "cpe:2.3:a:andrey_kislyuk:argcomplete:3.1.4:*:*:*:*:*:*:*", + "cpe": "cpe:2.3:a:andrey_kislyuk:argcomplete:3.1.6:*:*:*:*:*:*:*", "description": "Bash tab completion for argparse", "licenses": [ { @@ -565,12 +565,12 @@ ], "externalReferences": [ { - "url": "https://pypi.org/project/argcomplete/3.1.4", + "url": "https://pypi.org/project/argcomplete/3.1.6", "type": "distribution", "comment": "Download location for component" } ], - "purl": "pkg:pypi/argcomplete@3.1.4", + "purl": "pkg:pypi/argcomplete@3.1.6", "properties": [ { "name": "License Comments", @@ -2029,7 +2029,7 @@ "type": "library", "bom-ref": "63-rpmfile", "name": "rpmfile", - "version": "1.1.1", + "version": "2.0.0", "supplier": { "name": "Sean Ross", "contact": [ @@ -2038,7 +2038,7 @@ } ] }, - "cpe": "cpe:2.3:a:sean_ross:rpmfile:1.1.1:*:*:*:*:*:*:*", + "cpe": "cpe:2.3:a:sean_ross:rpmfile:2.0.0:*:*:*:*:*:*:*", "description": "Read rpm archive files", "licenses": [ { @@ -2050,12 +2050,12 @@ ], "externalReferences": [ { - "url": "https://pypi.org/project/rpmfile/1.1.1", + "url": "https://pypi.org/project/rpmfile/2.0.0", "type": "distribution", "comment": "Download location for component" } ], - "purl": "pkg:pypi/rpmfile@1.1.1" + "purl": "pkg:pypi/rpmfile@2.0.0" }, { "type": "library", diff --git a/sbom/cve-bin-tool-py3.9.spdx b/sbom/cve-bin-tool-py3.9.spdx index eee15a01d2..ac207c20d5 100644 --- a/sbom/cve-bin-tool-py3.9.spdx +++ b/sbom/cve-bin-tool-py3.9.spdx @@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3 DataLicense: CC0-1.0 SPDXID: SPDXRef-DOCUMENT DocumentName: Python-cve-bin-tool -DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-f6fb3e58-b97b-457f-b808-a1adf2ef6fc6 +DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-02eb3e5e-cebe-43fa-be6e-8add9ecd719f LicenseListVersion: 3.21 Creator: Tool: sbom4python-0.10.0 -Created: 2023-11-06T00:24:49Z +Created: 2023-11-13T00:25:10Z CreatorComment: This document has been automatically generated. ##### @@ -256,18 +256,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_inc.:gsutil:5.27:*:*:*:*:*:*:* PackageName: argcomplete SPDXID: SPDXRef-Package-17-argcomplete -PackageVersion: 3.1.4 +PackageVersion: 3.1.6 PrimaryPackagePurpose: LIBRARY PackageSupplier: Person: Andrey Kislyuk (kislyuk@gmail.com) -PackageDownloadLocation: https://pypi.org/project/argcomplete/3.1.4 +PackageDownloadLocation: https://pypi.org/project/argcomplete/3.1.6 FilesAnalyzed: false PackageLicenseDeclared: NOASSERTION PackageLicenseConcluded: Apache-2.0 PackageLicenseComments: argcomplete declares Apache Software License which is not currently a valid SPDX License identifier or expression. PackageCopyrightText: NOASSERTION PackageSummary: Bash tab completion for argparse -ExternalRef: PACKAGE-MANAGER purl pkg:pypi/argcomplete@3.1.4 -ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_kislyuk:argcomplete:3.1.4:*:*:*:*:*:*:* +ExternalRef: PACKAGE-MANAGER purl pkg:pypi/argcomplete@3.1.6 +ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_kislyuk:argcomplete:3.1.6:*:*:*:*:*:*:* ##### PackageName: crcmod @@ -962,17 +962,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:georg_brandl:pygments:2.16.1:*:*:*:*:* PackageName: rpmfile SPDXID: SPDXRef-Package-63-rpmfile -PackageVersion: 1.1.1 +PackageVersion: 2.0.0 PrimaryPackagePurpose: LIBRARY PackageSupplier: Person: Sean Ross (srossross@gmail.com) -PackageDownloadLocation: https://pypi.org/project/rpmfile/1.1.1 +PackageDownloadLocation: https://pypi.org/project/rpmfile/2.0.0 FilesAnalyzed: false PackageLicenseDeclared: MIT PackageLicenseConcluded: MIT PackageCopyrightText: NOASSERTION PackageSummary: Read rpm archive files -ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rpmfile@1.1.1 -ExternalRef: SECURITY cpe23Type cpe:2.3:a:sean_ross:rpmfile:1.1.1:*:*:*:*:*:*:* +ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rpmfile@2.0.0 +ExternalRef: SECURITY cpe23Type cpe:2.3:a:sean_ross:rpmfile:2.0.0:*:*:*:*:*:*:* ##### PackageName: toml