Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: update SBOM for Python 3.10 #3560

Merged
merged 1 commit into from
Dec 5, 2023
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
52 changes: 26 additions & 26 deletions sbom/cve-bin-tool-py3.10.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,10 +2,10 @@
"$schema": "http://cyclonedx.org/schema/bom-1.5.schema.json",
"bomFormat": "CycloneDX",
"specVersion": "1.5",
"serialNumber": "urn:uuid:bb0b8982-7878-46ff-96c7-fc5dab4eec83",
"serialNumber": "urn:uuid:6baa9a42-0ae2-43de-ae54-80a7c7975217",
"version": 1,
"metadata": {
"timestamp": "2023-11-27T00:26:26Z",
"timestamp": "2023-12-04T00:26:42Z",
"tools": {
"components": [
{
Expand All @@ -26,7 +26,7 @@
"type": "application",
"bom-ref": "1-cve-bin-tool",
"name": "cve-bin-tool",
"version": "3.2.2.dev0",
"version": "3.3a0",
"supplier": {
"name": "Terri Oda",
"contact": [
Expand All @@ -35,7 +35,7 @@
}
]
},
"cpe": "cpe:2.3:a:terri_oda:cve-bin-tool:3.2.2.dev0:*:*:*:*:*:*:*",
"cpe": "cpe:2.3:a:terri_oda:cve-bin-tool:3.3a0:*:*:*:*:*:*:*",
"description": "CVE Binary Checker Tool",
"licenses": [
{
Expand All @@ -47,12 +47,12 @@
],
"externalReferences": [
{
"url": "https://pypi.org/project/cve-bin-tool/3.2.2.dev0",
"url": "https://pypi.org/project/cve-bin-tool/3.3a0",
"type": "distribution",
"comment": "Download location for component"
}
],
"purl": "pkg:pypi/cve-bin-tool@3.2.2.dev0",
"purl": "pkg:pypi/cve-bin-tool@3.3a0",
"properties": [
{
"name": "language",
Expand Down Expand Up @@ -1173,7 +1173,7 @@
"type": "library",
"bom-ref": "31-cryptography",
"name": "cryptography",
"version": "41.0.5",
"version": "41.0.7",
"supplier": {
"name": "The Python Cryptographic Authority and individual contributors",
"contact": [
Expand All @@ -1182,7 +1182,7 @@
}
]
},
"cpe": "cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:41.0.5:*:*:*:*:*:*:*",
"cpe": "cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:41.0.7:*:*:*:*:*:*:*",
"description": "cryptography is a package which provides cryptographic recipes and primitives to Python developers.",
"licenses": [
{
Expand All @@ -1191,12 +1191,12 @@
],
"externalReferences": [
{
"url": "https://pypi.org/project/cryptography/41.0.5",
"url": "https://pypi.org/project/cryptography/41.0.7",
"type": "distribution",
"comment": "Download location for component"
}
],
"purl": "pkg:pypi/cryptography@41.0.5",
"purl": "pkg:pypi/cryptography@41.0.7",
"properties": [
{
"name": "language",
Expand Down Expand Up @@ -1368,7 +1368,7 @@
"type": "library",
"bom-ref": "36-google-auth",
"name": "google-auth",
"version": "2.23.4",
"version": "2.24.0",
"supplier": {
"name": "Google Cloud Platform",
"contact": [
Expand All @@ -1377,7 +1377,7 @@
}
]
},
"cpe": "cpe:2.3:a:google_cloud_platform:google-auth:2.23.4:*:*:*:*:*:*:*",
"cpe": "cpe:2.3:a:google_cloud_platform:google-auth:2.24.0:*:*:*:*:*:*:*",
"description": "Google Authentication Library",
"licenses": [
{
Expand All @@ -1389,12 +1389,12 @@
],
"externalReferences": [
{
"url": "https://pypi.org/project/google-auth/2.23.4",
"url": "https://pypi.org/project/google-auth/2.24.0",
"type": "distribution",
"comment": "Download location for component"
}
],
"purl": "pkg:pypi/google-auth@2.23.4",
"purl": "pkg:pypi/google-auth@2.24.0",
"properties": [
{
"name": "language",
Expand Down Expand Up @@ -1594,11 +1594,11 @@
"type": "library",
"bom-ref": "42-jsonschema-specifications",
"name": "jsonschema-specifications",
"version": "2023.11.1",
"version": "2023.11.2",
"supplier": {
"name": "Julian Berman"
},
"cpe": "cpe:2.3:a:julian_berman:jsonschema-specifications:2023.11.1:*:*:*:*:*:*:*",
"cpe": "cpe:2.3:a:julian_berman:jsonschema-specifications:2023.11.2:*:*:*:*:*:*:*",
"description": "The JSON Schema meta-schemas and vocabularies, exposed as a Registry",
"licenses": [
{
Expand All @@ -1610,12 +1610,12 @@
],
"externalReferences": [
{
"url": "https://pypi.org/project/jsonschema-specifications/2023.11.1",
"url": "https://pypi.org/project/jsonschema-specifications/2023.11.2",
"type": "distribution",
"comment": "Download location for component"
}
],
"purl": "pkg:pypi/jsonschema-specifications@2023.11.1",
"purl": "pkg:pypi/jsonschema-specifications@2023.11.2",
"properties": [
{
"name": "language",
Expand All @@ -1627,11 +1627,11 @@
"type": "library",
"bom-ref": "43-referencing",
"name": "referencing",
"version": "0.31.0",
"version": "0.31.1",
"supplier": {
"name": "Julian Berman"
},
"cpe": "cpe:2.3:a:julian_berman:referencing:0.31.0:*:*:*:*:*:*:*",
"cpe": "cpe:2.3:a:julian_berman:referencing:0.31.1:*:*:*:*:*:*:*",
"description": "JSON Referencing + Python",
"licenses": [
{
Expand All @@ -1643,12 +1643,12 @@
],
"externalReferences": [
{
"url": "https://pypi.org/project/referencing/0.31.0",
"url": "https://pypi.org/project/referencing/0.31.1",
"type": "distribution",
"comment": "Download location for component"
}
],
"purl": "pkg:pypi/referencing@0.31.0",
"purl": "pkg:pypi/referencing@0.31.1",
"properties": [
{
"name": "language",
Expand All @@ -1660,11 +1660,11 @@
"type": "library",
"bom-ref": "44-rpds-py",
"name": "rpds-py",
"version": "0.13.1",
"version": "0.13.2",
"supplier": {
"name": "Julian Berman"
},
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.13.1:*:*:*:*:*:*:*",
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.13.2:*:*:*:*:*:*:*",
"description": "Python bindings to Rust's persistent data structures (rpds)",
"licenses": [
{
Expand All @@ -1676,12 +1676,12 @@
],
"externalReferences": [
{
"url": "https://pypi.org/project/rpds-py/0.13.1",
"url": "https://pypi.org/project/rpds-py/0.13.2",
"type": "distribution",
"comment": "Download location for component"
}
],
"purl": "pkg:pypi/rpds-py@0.13.1",
"purl": "pkg:pypi/rpds-py@0.13.2",
"properties": [
{
"name": "language",
Expand Down
52 changes: 26 additions & 26 deletions sbom/cve-bin-tool-py3.10.spdx
Original file line number Diff line number Diff line change
Expand Up @@ -2,26 +2,26 @@ SPDXVersion: SPDX-2.3
DataLicense: CC0-1.0
SPDXID: SPDXRef-DOCUMENT
DocumentName: Python-cve-bin-tool
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-ab06f588-e314-40f5-ae47-5ec7bb254f31
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-0628dc5c-a9ba-4bef-85a5-0bff8ab02543
LicenseListVersion: 3.22
Creator: Tool: sbom4python-0.10.1
Created: 2023-11-27T00:25:26Z
Created: 2023-12-04T00:25:42Z
CreatorComment: <text>This document has been automatically generated.</text>
#####

PackageName: cve-bin-tool
SPDXID: SPDXRef-Package-1-cve-bin-tool
PackageVersion: 3.2.2.dev0
PackageVersion: 3.3a0
PrimaryPackagePurpose: APPLICATION
PackageSupplier: Person: Terri Oda (terri.oda@intel.com)
PackageDownloadLocation: https://pypi.org/project/cve-bin-tool/3.2.2.dev0
PackageDownloadLocation: https://pypi.org/project/cve-bin-tool/3.3a0
FilesAnalyzed: false
PackageLicenseDeclared: GPL-3.0-or-later
PackageLicenseConcluded: GPL-3.0-or-later
PackageCopyrightText: NOASSERTION
PackageSummary: <text>CVE Binary Checker Tool</text>
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/cve-bin-tool@3.2.2.dev0
ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.2.2.dev0:*:*:*:*:*:*:*
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/cve-bin-tool@3.3a0
ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.3a0:*:*:*:*:*:*:*
#####

PackageName: aiohttp
Expand Down Expand Up @@ -474,17 +474,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_pyopenssl_developers:pyopenssl:23.

PackageName: cryptography
SPDXID: SPDXRef-Package-31-cryptography
PackageVersion: 41.0.5
PackageVersion: 41.0.7
PrimaryPackagePurpose: LIBRARY
PackageSupplier: Organization: The Python Cryptographic Authority and individual contributors (cryptography-dev@python.org)
PackageDownloadLocation: https://pypi.org/project/cryptography/41.0.5
PackageDownloadLocation: https://pypi.org/project/cryptography/41.0.7
FilesAnalyzed: false
PackageLicenseDeclared: Apache-2.0 OR BSD-3-Clause
PackageLicenseConcluded: Apache-2.0 OR BSD-3-Clause
PackageCopyrightText: NOASSERTION
PackageSummary: <text>cryptography is a package which provides cryptographic recipes and primitives to Python developers.</text>
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/cryptography@41.0.5
ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:41.0.5:*:*:*:*:*:*:*
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/cryptography@41.0.7
ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:41.0.7:*:*:*:*:*:*:*
#####

PackageName: cffi
Expand Down Expand Up @@ -551,18 +551,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:craig_citro:google-apitools:0.5.32:*:*

PackageName: google-auth
SPDXID: SPDXRef-Package-36-google-auth
PackageVersion: 2.23.4
PackageVersion: 2.24.0
PrimaryPackagePurpose: LIBRARY
PackageSupplier: Organization: Google Cloud Platform (googleapis-packages@google.com)
PackageDownloadLocation: https://pypi.org/project/google-auth/2.23.4
PackageDownloadLocation: https://pypi.org/project/google-auth/2.24.0
FilesAnalyzed: false
PackageLicenseDeclared: NOASSERTION
PackageLicenseConcluded: Apache-2.0
PackageLicenseComments: <text>google-auth declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
PackageCopyrightText: NOASSERTION
PackageSummary: <text>Google Authentication Library</text>
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/google-auth@2.23.4
ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_cloud_platform:google-auth:2.23.4:*:*:*:*:*:*:*
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/google-auth@2.24.0
ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_cloud_platform:google-auth:2.24.0:*:*:*:*:*:*:*
#####

PackageName: cachetools
Expand Down Expand Up @@ -642,47 +642,47 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:jsonschema:4.20.0:*:*:*:

PackageName: jsonschema-specifications
SPDXID: SPDXRef-Package-42-jsonschema-specifications
PackageVersion: 2023.11.1
PackageVersion: 2023.11.2
PrimaryPackagePurpose: LIBRARY
PackageSupplier: Person: Julian Berman
PackageDownloadLocation: https://pypi.org/project/jsonschema-specifications/2023.11.1
PackageDownloadLocation: https://pypi.org/project/jsonschema-specifications/2023.11.2
FilesAnalyzed: false
PackageLicenseDeclared: MIT
PackageLicenseConcluded: MIT
PackageCopyrightText: NOASSERTION
PackageSummary: <text>The JSON Schema meta-schemas and vocabularies, exposed as a Registry</text>
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/jsonschema-specifications@2023.11.1
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:jsonschema-specifications:2023.11.1:*:*:*:*:*:*:*
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/jsonschema-specifications@2023.11.2
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:jsonschema-specifications:2023.11.2:*:*:*:*:*:*:*
#####

PackageName: referencing
SPDXID: SPDXRef-Package-43-referencing
PackageVersion: 0.31.0
PackageVersion: 0.31.1
PrimaryPackagePurpose: LIBRARY
PackageSupplier: Person: Julian Berman
PackageDownloadLocation: https://pypi.org/project/referencing/0.31.0
PackageDownloadLocation: https://pypi.org/project/referencing/0.31.1
FilesAnalyzed: false
PackageLicenseDeclared: MIT
PackageLicenseConcluded: MIT
PackageCopyrightText: NOASSERTION
PackageSummary: <text>JSON Referencing + Python</text>
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/referencing@0.31.0
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:referencing:0.31.0:*:*:*:*:*:*:*
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/referencing@0.31.1
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:referencing:0.31.1:*:*:*:*:*:*:*
#####

PackageName: rpds-py
SPDXID: SPDXRef-Package-44-rpds-py
PackageVersion: 0.13.1
PackageVersion: 0.13.2
PrimaryPackagePurpose: LIBRARY
PackageSupplier: Person: Julian Berman
PackageDownloadLocation: https://pypi.org/project/rpds-py/0.13.1
PackageDownloadLocation: https://pypi.org/project/rpds-py/0.13.2
FilesAnalyzed: false
PackageLicenseDeclared: MIT
PackageLicenseConcluded: MIT
PackageCopyrightText: NOASSERTION
PackageSummary: <text>Python bindings to Rust's persistent data structures (rpds)</text>
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rpds-py@0.13.1
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.13.1:*:*:*:*:*:*:*
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rpds-py@0.13.2
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.13.2:*:*:*:*:*:*:*
#####

PackageName: lib4sbom
Expand Down