Skip to content

Commit

Permalink
chore: update SBOM for Python 3.9 (#3562)
Browse files Browse the repository at this point in the history
Co-authored-by: GitHub <noreply@github.com>
  • Loading branch information
github-actions[bot] and web-flow committed Dec 5, 2023
1 parent dc2bc84 commit ecef5b0
Show file tree
Hide file tree
Showing 2 changed files with 60 additions and 60 deletions.
60 changes: 30 additions & 30 deletions sbom/cve-bin-tool-py3.9.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,10 +2,10 @@
"$schema": "http://cyclonedx.org/schema/bom-1.5.schema.json",
"bomFormat": "CycloneDX",
"specVersion": "1.5",
"serialNumber": "urn:uuid:b4f44dfe-0171-4624-85dd-ff6ced2500c0",
"serialNumber": "urn:uuid:5faec005-00d7-49fc-be2c-b56094c5996d",
"version": 1,
"metadata": {
"timestamp": "2023-11-27T00:26:46Z",
"timestamp": "2023-12-04T00:26:52Z",
"tools": {
"components": [
{
Expand All @@ -26,7 +26,7 @@
"type": "application",
"bom-ref": "1-cve-bin-tool",
"name": "cve-bin-tool",
"version": "3.2.2.dev0",
"version": "3.3a0",
"supplier": {
"name": "Terri Oda",
"contact": [
Expand All @@ -35,7 +35,7 @@
}
]
},
"cpe": "cpe:2.3:a:terri_oda:cve-bin-tool:3.2.2.dev0:*:*:*:*:*:*:*",
"cpe": "cpe:2.3:a:terri_oda:cve-bin-tool:3.3a0:*:*:*:*:*:*:*",
"description": "CVE Binary Checker Tool",
"licenses": [
{
Expand All @@ -47,12 +47,12 @@
],
"externalReferences": [
{
"url": "https://pypi.org/project/cve-bin-tool/3.2.2.dev0",
"url": "https://pypi.org/project/cve-bin-tool/3.3a0",
"type": "distribution",
"comment": "Download location for component"
}
],
"purl": "pkg:pypi/cve-bin-tool@3.2.2.dev0",
"purl": "pkg:pypi/cve-bin-tool@3.3a0",
"properties": [
{
"name": "language",
Expand Down Expand Up @@ -1173,7 +1173,7 @@
"type": "library",
"bom-ref": "31-cryptography",
"name": "cryptography",
"version": "41.0.5",
"version": "41.0.7",
"supplier": {
"name": "The Python Cryptographic Authority and individual contributors",
"contact": [
Expand All @@ -1182,7 +1182,7 @@
}
]
},
"cpe": "cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:41.0.5:*:*:*:*:*:*:*",
"cpe": "cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:41.0.7:*:*:*:*:*:*:*",
"description": "cryptography is a package which provides cryptographic recipes and primitives to Python developers.",
"licenses": [
{
Expand All @@ -1191,12 +1191,12 @@
],
"externalReferences": [
{
"url": "https://pypi.org/project/cryptography/41.0.5",
"url": "https://pypi.org/project/cryptography/41.0.7",
"type": "distribution",
"comment": "Download location for component"
}
],
"purl": "pkg:pypi/cryptography@41.0.5",
"purl": "pkg:pypi/cryptography@41.0.7",
"properties": [
{
"name": "language",
Expand Down Expand Up @@ -1368,7 +1368,7 @@
"type": "library",
"bom-ref": "36-google-auth",
"name": "google-auth",
"version": "2.23.4",
"version": "2.24.0",
"supplier": {
"name": "Google Cloud Platform",
"contact": [
Expand All @@ -1377,7 +1377,7 @@
}
]
},
"cpe": "cpe:2.3:a:google_cloud_platform:google-auth:2.23.4:*:*:*:*:*:*:*",
"cpe": "cpe:2.3:a:google_cloud_platform:google-auth:2.24.0:*:*:*:*:*:*:*",
"description": "Google Authentication Library",
"licenses": [
{
Expand All @@ -1389,12 +1389,12 @@
],
"externalReferences": [
{
"url": "https://pypi.org/project/google-auth/2.23.4",
"url": "https://pypi.org/project/google-auth/2.24.0",
"type": "distribution",
"comment": "Download location for component"
}
],
"purl": "pkg:pypi/google-auth@2.23.4",
"purl": "pkg:pypi/google-auth@2.24.0",
"properties": [
{
"name": "language",
Expand Down Expand Up @@ -1490,7 +1490,7 @@
"type": "library",
"bom-ref": "39-importlib-metadata",
"name": "importlib-metadata",
"version": "6.8.0",
"version": "7.0.0",
"supplier": {
"name": "Jason R . Coombs",
"contact": [
Expand All @@ -1499,16 +1499,16 @@
}
]
},
"cpe": "cpe:2.3:a:jason_r._coombs:importlib-metadata:6.8.0:*:*:*:*:*:*:*",
"cpe": "cpe:2.3:a:jason_r._coombs:importlib-metadata:7.0.0:*:*:*:*:*:*:*",
"description": "Read metadata from Python packages",
"externalReferences": [
{
"url": "https://pypi.org/project/importlib-metadata/6.8.0",
"url": "https://pypi.org/project/importlib-metadata/7.0.0",
"type": "distribution",
"comment": "Download location for component"
}
],
"purl": "pkg:pypi/importlib-metadata@6.8.0",
"purl": "pkg:pypi/importlib-metadata@7.0.0",
"properties": [
{
"name": "language",
Expand Down Expand Up @@ -1654,11 +1654,11 @@
"type": "library",
"bom-ref": "44-jsonschema-specifications",
"name": "jsonschema-specifications",
"version": "2023.11.1",
"version": "2023.11.2",
"supplier": {
"name": "Julian Berman"
},
"cpe": "cpe:2.3:a:julian_berman:jsonschema-specifications:2023.11.1:*:*:*:*:*:*:*",
"cpe": "cpe:2.3:a:julian_berman:jsonschema-specifications:2023.11.2:*:*:*:*:*:*:*",
"description": "The JSON Schema meta-schemas and vocabularies, exposed as a Registry",
"licenses": [
{
Expand All @@ -1670,12 +1670,12 @@
],
"externalReferences": [
{
"url": "https://pypi.org/project/jsonschema-specifications/2023.11.1",
"url": "https://pypi.org/project/jsonschema-specifications/2023.11.2",
"type": "distribution",
"comment": "Download location for component"
}
],
"purl": "pkg:pypi/jsonschema-specifications@2023.11.1",
"purl": "pkg:pypi/jsonschema-specifications@2023.11.2",
"properties": [
{
"name": "language",
Expand All @@ -1687,11 +1687,11 @@
"type": "library",
"bom-ref": "45-referencing",
"name": "referencing",
"version": "0.31.0",
"version": "0.31.1",
"supplier": {
"name": "Julian Berman"
},
"cpe": "cpe:2.3:a:julian_berman:referencing:0.31.0:*:*:*:*:*:*:*",
"cpe": "cpe:2.3:a:julian_berman:referencing:0.31.1:*:*:*:*:*:*:*",
"description": "JSON Referencing + Python",
"licenses": [
{
Expand All @@ -1703,12 +1703,12 @@
],
"externalReferences": [
{
"url": "https://pypi.org/project/referencing/0.31.0",
"url": "https://pypi.org/project/referencing/0.31.1",
"type": "distribution",
"comment": "Download location for component"
}
],
"purl": "pkg:pypi/referencing@0.31.0",
"purl": "pkg:pypi/referencing@0.31.1",
"properties": [
{
"name": "language",
Expand All @@ -1720,11 +1720,11 @@
"type": "library",
"bom-ref": "46-rpds-py",
"name": "rpds-py",
"version": "0.13.1",
"version": "0.13.2",
"supplier": {
"name": "Julian Berman"
},
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.13.1:*:*:*:*:*:*:*",
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.13.2:*:*:*:*:*:*:*",
"description": "Python bindings to Rust's persistent data structures (rpds)",
"licenses": [
{
Expand All @@ -1736,12 +1736,12 @@
],
"externalReferences": [
{
"url": "https://pypi.org/project/rpds-py/0.13.1",
"url": "https://pypi.org/project/rpds-py/0.13.2",
"type": "distribution",
"comment": "Download location for component"
}
],
"purl": "pkg:pypi/rpds-py@0.13.1",
"purl": "pkg:pypi/rpds-py@0.13.2",
"properties": [
{
"name": "language",
Expand Down
60 changes: 30 additions & 30 deletions sbom/cve-bin-tool-py3.9.spdx
Original file line number Diff line number Diff line change
Expand Up @@ -2,26 +2,26 @@ SPDXVersion: SPDX-2.3
DataLicense: CC0-1.0
SPDXID: SPDXRef-DOCUMENT
DocumentName: Python-cve-bin-tool
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-6d2fcca5-9f0f-4ca5-a0b1-33750bae9ba0
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-959a5a9a-4960-46de-b5bd-1c59a2b55f26
LicenseListVersion: 3.22
Creator: Tool: sbom4python-0.10.1
Created: 2023-11-27T00:25:40Z
Created: 2023-12-04T00:25:47Z
CreatorComment: <text>This document has been automatically generated.</text>
#####

PackageName: cve-bin-tool
SPDXID: SPDXRef-Package-1-cve-bin-tool
PackageVersion: 3.2.2.dev0
PackageVersion: 3.3a0
PrimaryPackagePurpose: APPLICATION
PackageSupplier: Person: Terri Oda (terri.oda@intel.com)
PackageDownloadLocation: https://pypi.org/project/cve-bin-tool/3.2.2.dev0
PackageDownloadLocation: https://pypi.org/project/cve-bin-tool/3.3a0
FilesAnalyzed: false
PackageLicenseDeclared: GPL-3.0-or-later
PackageLicenseConcluded: GPL-3.0-or-later
PackageCopyrightText: NOASSERTION
PackageSummary: <text>CVE Binary Checker Tool</text>
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/cve-bin-tool@3.2.2.dev0
ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.2.2.dev0:*:*:*:*:*:*:*
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/cve-bin-tool@3.3a0
ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.3a0:*:*:*:*:*:*:*
#####

PackageName: aiohttp
Expand Down Expand Up @@ -474,17 +474,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_pyopenssl_developers:pyopenssl:23.

PackageName: cryptography
SPDXID: SPDXRef-Package-31-cryptography
PackageVersion: 41.0.5
PackageVersion: 41.0.7
PrimaryPackagePurpose: LIBRARY
PackageSupplier: Organization: The Python Cryptographic Authority and individual contributors (cryptography-dev@python.org)
PackageDownloadLocation: https://pypi.org/project/cryptography/41.0.5
PackageDownloadLocation: https://pypi.org/project/cryptography/41.0.7
FilesAnalyzed: false
PackageLicenseDeclared: Apache-2.0 OR BSD-3-Clause
PackageLicenseConcluded: Apache-2.0 OR BSD-3-Clause
PackageCopyrightText: NOASSERTION
PackageSummary: <text>cryptography is a package which provides cryptographic recipes and primitives to Python developers.</text>
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/cryptography@41.0.5
ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:41.0.5:*:*:*:*:*:*:*
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/cryptography@41.0.7
ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:41.0.7:*:*:*:*:*:*:*
#####

PackageName: cffi
Expand Down Expand Up @@ -551,18 +551,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:craig_citro:google-apitools:0.5.32:*:*

PackageName: google-auth
SPDXID: SPDXRef-Package-36-google-auth
PackageVersion: 2.23.4
PackageVersion: 2.24.0
PrimaryPackagePurpose: LIBRARY
PackageSupplier: Organization: Google Cloud Platform (googleapis-packages@google.com)
PackageDownloadLocation: https://pypi.org/project/google-auth/2.23.4
PackageDownloadLocation: https://pypi.org/project/google-auth/2.24.0
FilesAnalyzed: false
PackageLicenseDeclared: NOASSERTION
PackageLicenseConcluded: Apache-2.0
PackageLicenseComments: <text>google-auth declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
PackageCopyrightText: NOASSERTION
PackageSummary: <text>Google Authentication Library</text>
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/google-auth@2.23.4
ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_cloud_platform:google-auth:2.23.4:*:*:*:*:*:*:*
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/google-auth@2.24.0
ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_cloud_platform:google-auth:2.24.0:*:*:*:*:*:*:*
#####

PackageName: cachetools
Expand Down Expand Up @@ -598,17 +598,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:ori_livneh:monotonic:1.6:*:*:*:*:*:*:*

PackageName: importlib-metadata
SPDXID: SPDXRef-Package-39-importlib-metadata
PackageVersion: 6.8.0
PackageVersion: 7.0.0
PrimaryPackagePurpose: LIBRARY
PackageSupplier: Organization: Jason R. Coombs (jaraco@jaraco.com)
PackageDownloadLocation: https://pypi.org/project/importlib-metadata/6.8.0
PackageDownloadLocation: https://pypi.org/project/importlib-metadata/7.0.0
FilesAnalyzed: false
PackageLicenseDeclared: NOASSERTION
PackageLicenseConcluded: NOASSERTION
PackageCopyrightText: NOASSERTION
PackageSummary: <text>Read metadata from Python packages</text>
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/importlib-metadata@6.8.0
ExternalRef: SECURITY cpe23Type cpe:2.3:a:jason_r._coombs:importlib-metadata:6.8.0:*:*:*:*:*:*:*
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/importlib-metadata@7.0.0
ExternalRef: SECURITY cpe23Type cpe:2.3:a:jason_r._coombs:importlib-metadata:7.0.0:*:*:*:*:*:*:*
#####

PackageName: zipp
Expand Down Expand Up @@ -672,47 +672,47 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:jsonschema:4.20.0:*:*:*:

PackageName: jsonschema-specifications
SPDXID: SPDXRef-Package-44-jsonschema-specifications
PackageVersion: 2023.11.1
PackageVersion: 2023.11.2
PrimaryPackagePurpose: LIBRARY
PackageSupplier: Person: Julian Berman
PackageDownloadLocation: https://pypi.org/project/jsonschema-specifications/2023.11.1
PackageDownloadLocation: https://pypi.org/project/jsonschema-specifications/2023.11.2
FilesAnalyzed: false
PackageLicenseDeclared: MIT
PackageLicenseConcluded: MIT
PackageCopyrightText: NOASSERTION
PackageSummary: <text>The JSON Schema meta-schemas and vocabularies, exposed as a Registry</text>
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/jsonschema-specifications@2023.11.1
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:jsonschema-specifications:2023.11.1:*:*:*:*:*:*:*
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/jsonschema-specifications@2023.11.2
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:jsonschema-specifications:2023.11.2:*:*:*:*:*:*:*
#####

PackageName: referencing
SPDXID: SPDXRef-Package-45-referencing
PackageVersion: 0.31.0
PackageVersion: 0.31.1
PrimaryPackagePurpose: LIBRARY
PackageSupplier: Person: Julian Berman
PackageDownloadLocation: https://pypi.org/project/referencing/0.31.0
PackageDownloadLocation: https://pypi.org/project/referencing/0.31.1
FilesAnalyzed: false
PackageLicenseDeclared: MIT
PackageLicenseConcluded: MIT
PackageCopyrightText: NOASSERTION
PackageSummary: <text>JSON Referencing + Python</text>
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/referencing@0.31.0
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:referencing:0.31.0:*:*:*:*:*:*:*
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/referencing@0.31.1
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:referencing:0.31.1:*:*:*:*:*:*:*
#####

PackageName: rpds-py
SPDXID: SPDXRef-Package-46-rpds-py
PackageVersion: 0.13.1
PackageVersion: 0.13.2
PrimaryPackagePurpose: LIBRARY
PackageSupplier: Person: Julian Berman
PackageDownloadLocation: https://pypi.org/project/rpds-py/0.13.1
PackageDownloadLocation: https://pypi.org/project/rpds-py/0.13.2
FilesAnalyzed: false
PackageLicenseDeclared: MIT
PackageLicenseConcluded: MIT
PackageCopyrightText: NOASSERTION
PackageSummary: <text>Python bindings to Rust's persistent data structures (rpds)</text>
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rpds-py@0.13.1
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.13.1:*:*:*:*:*:*:*
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rpds-py@0.13.2
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.13.2:*:*:*:*:*:*:*
#####

PackageName: lib4sbom
Expand Down

0 comments on commit ecef5b0

Please sign in to comment.