Skip to content

Commit

Permalink
chore: update SBOM for Python 3.11 (#4064)
Browse files Browse the repository at this point in the history
Co-authored-by: GitHub <noreply@github.com>
  • Loading branch information
github-actions[bot] and web-flow committed Apr 22, 2024
1 parent ff7949a commit 52a3f76
Show file tree
Hide file tree
Showing 2 changed files with 34 additions and 48 deletions.
46 changes: 17 additions & 29 deletions sbom/cve-bin-tool-py3.11.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,10 +2,10 @@
"$schema": "http://cyclonedx.org/schema/bom-1.5.schema.json",
"bomFormat": "CycloneDX",
"specVersion": "1.5",
"serialNumber": "urn:uuid:fa92daaf-b6b6-4b4d-8d0a-02f5be3d2743",
"serialNumber": "urn:uuid:a724c9fa-1450-4ee9-90df-ea70f46028f5",
"version": 1,
"metadata": {
"timestamp": "2024-04-15T02:43:05Z",
"timestamp": "2024-04-22T00:27:30Z",
"tools": {
"components": [
{
Expand All @@ -26,7 +26,7 @@
"type": "application",
"bom-ref": "1-cve-bin-tool",
"name": "cve-bin-tool",
"version": "3.3",
"version": "3.3.1.dev0",
"supplier": {
"name": "Terri Oda",
"contact": [
Expand All @@ -35,14 +35,8 @@
}
]
},
"cpe": "cpe:2.3:a:terri_oda:cve-bin-tool:3.3:*:*:*:*:*:*:*",
"cpe": "cpe:2.3:a:terri_oda:cve-bin-tool:3.3.1.dev0:*:*:*:*:*:*:*",
"description": "CVE Binary Checker Tool",
"hashes": [
{
"alg": "SHA-1",
"content": "83e30ee0f640bce7a20d4346c85873d359c05d1f"
}
],
"licenses": [
{
"license": {
Expand All @@ -53,12 +47,12 @@
],
"externalReferences": [
{
"url": "https://pypi.org/project/cve-bin-tool/3.3",
"url": "https://pypi.org/project/cve-bin-tool/3.3.1.dev0",
"type": "distribution",
"comment": "Download location for component"
}
],
"purl": "pkg:pypi/cve-bin-tool@3.3",
"purl": "pkg:pypi/cve-bin-tool@3.3.1.dev0",
"properties": [
{
"name": "language",
Expand All @@ -74,7 +68,7 @@
"type": "library",
"bom-ref": "2-aiohttp",
"name": "aiohttp",
"version": "3.9.4",
"version": "3.9.5",
"description": "Async http client/server framework (asyncio)",
"licenses": [
{
Expand All @@ -86,12 +80,12 @@
],
"externalReferences": [
{
"url": "https://pypi.org/project/aiohttp/3.9.4",
"url": "https://pypi.org/project/aiohttp/3.9.5",
"type": "distribution",
"comment": "Download location for component"
}
],
"purl": "pkg:pypi/aiohttp@3.9.4",
"purl": "pkg:pypi/aiohttp@3.9.5",
"properties": [
{
"name": "language",
Expand Down Expand Up @@ -2119,7 +2113,7 @@
"type": "library",
"bom-ref": "50-plotly",
"name": "plotly",
"version": "5.20.0",
"version": "5.21.0",
"supplier": {
"name": "Chris P",
"contact": [
Expand All @@ -2128,14 +2122,8 @@
}
]
},
"cpe": "cpe:2.3:a:chris_p:plotly:5.20.0:*:*:*:*:*:*:*",
"cpe": "cpe:2.3:a:chris_p:plotly:5.21.0:*:*:*:*:*:*:*",
"description": "An open-source, interactive data visualization library for Python",
"hashes": [
{
"alg": "SHA-1",
"content": "9335a34ca77399a597a72420f73e947217d3d410"
}
],
"licenses": [
{
"license": {
Expand All @@ -2146,12 +2134,12 @@
],
"externalReferences": [
{
"url": "https://pypi.org/project/plotly/5.20.0",
"url": "https://pypi.org/project/plotly/5.21.0",
"type": "distribution",
"comment": "Download location for component"
}
],
"purl": "pkg:pypi/plotly@5.20.0",
"purl": "pkg:pypi/plotly@5.21.0",
"properties": [
{
"name": "language",
Expand Down Expand Up @@ -2647,7 +2635,7 @@
"type": "library",
"bom-ref": "62-xmlschema",
"name": "xmlschema",
"version": "3.2.1",
"version": "3.3.0",
"supplier": {
"name": "Davide Brunato",
"contact": [
Expand All @@ -2656,7 +2644,7 @@
}
]
},
"cpe": "cpe:2.3:a:davide_brunato:xmlschema:3.2.1:*:*:*:*:*:*:*",
"cpe": "cpe:2.3:a:davide_brunato:xmlschema:3.3.0:*:*:*:*:*:*:*",
"description": "An XML Schema validator and decoder",
"licenses": [
{
Expand All @@ -2668,12 +2656,12 @@
],
"externalReferences": [
{
"url": "https://pypi.org/project/xmlschema/3.2.1",
"url": "https://pypi.org/project/xmlschema/3.3.0",
"type": "distribution",
"comment": "Download location for component"
}
],
"purl": "pkg:pypi/xmlschema@3.2.1",
"purl": "pkg:pypi/xmlschema@3.3.0",
"properties": [
{
"name": "language",
Expand Down
36 changes: 17 additions & 19 deletions sbom/cve-bin-tool-py3.11.spdx
Original file line number Diff line number Diff line change
Expand Up @@ -2,42 +2,41 @@ SPDXVersion: SPDX-2.3
DataLicense: CC0-1.0
SPDXID: SPDXRef-DOCUMENT
DocumentName: Python-cve-bin-tool
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-2bb412b6-9cd4-4fea-848c-dea1256fc8ee
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-82f58543-22bd-4a27-9870-1027bc4a581b
LicenseListVersion: 3.22
Creator: Tool: sbom4python-0.10.4
Created: 2024-04-15T02:41:53Z
Created: 2024-04-22T00:26:28Z
CreatorComment: <text>This document has been automatically generated.</text>
#####

PackageName: cve-bin-tool
SPDXID: SPDXRef-Package-1-cve-bin-tool
PackageVersion: 3.3
PackageVersion: 3.3.1.dev0
PrimaryPackagePurpose: APPLICATION
PackageSupplier: Person: Terri Oda (terri.oda@intel.com)
PackageDownloadLocation: https://pypi.org/project/cve-bin-tool/3.3
PackageDownloadLocation: https://pypi.org/project/cve-bin-tool/3.3.1.dev0
FilesAnalyzed: false
PackageChecksum: SHA1: 83e30ee0f640bce7a20d4346c85873d359c05d1f
PackageLicenseDeclared: GPL-3.0-or-later
PackageLicenseConcluded: GPL-3.0-or-later
PackageCopyrightText: NOASSERTION
PackageSummary: <text>CVE Binary Checker Tool</text>
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/cve-bin-tool@3.3
ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.3:*:*:*:*:*:*:*
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/cve-bin-tool@3.3.1.dev0
ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.3.1.dev0:*:*:*:*:*:*:*
#####

PackageName: aiohttp
SPDXID: SPDXRef-Package-2-aiohttp
PackageVersion: 3.9.4
PackageVersion: 3.9.5
PrimaryPackagePurpose: LIBRARY
PackageSupplier: NOASSERTION
PackageDownloadLocation: https://pypi.org/project/aiohttp/3.9.4
PackageDownloadLocation: https://pypi.org/project/aiohttp/3.9.5
FilesAnalyzed: false
PackageLicenseDeclared: NOASSERTION
PackageLicenseConcluded: Apache-2.0
PackageLicenseComments: <text>aiohttp declares Apache 2 which is not currently a valid SPDX License identifier or expression.</text>
PackageCopyrightText: NOASSERTION
PackageSummary: <text>Async http client/server framework (asyncio)</text>
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/aiohttp@3.9.4
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/aiohttp@3.9.5
#####

PackageName: aiosignal
Expand Down Expand Up @@ -788,18 +787,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:donald_stufft:packaging:24.0:*:*:*:*:*

PackageName: plotly
SPDXID: SPDXRef-Package-50-plotly
PackageVersion: 5.20.0
PackageVersion: 5.21.0
PrimaryPackagePurpose: LIBRARY
PackageSupplier: Person: Chris P (chris@plot.ly)
PackageDownloadLocation: https://pypi.org/project/plotly/5.20.0
PackageDownloadLocation: https://pypi.org/project/plotly/5.21.0
FilesAnalyzed: false
PackageChecksum: SHA1: 9335a34ca77399a597a72420f73e947217d3d410
PackageLicenseDeclared: MIT
PackageLicenseConcluded: MIT
PackageCopyrightText: NOASSERTION
PackageSummary: <text>An open-source, interactive data visualization library for Python</text>
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/plotly@5.20.0
ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:5.20.0:*:*:*:*:*:*:*
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/plotly@5.21.0
ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:5.21.0:*:*:*:*:*:*:*
#####

PackageName: tenacity
Expand Down Expand Up @@ -979,17 +977,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:sean_ross:rpmfile:2.0.0:*:*:*:*:*:*:*

PackageName: xmlschema
SPDXID: SPDXRef-Package-62-xmlschema
PackageVersion: 3.2.1
PackageVersion: 3.3.0
PrimaryPackagePurpose: LIBRARY
PackageSupplier: Person: Davide Brunato (brunato@sissa.it)
PackageDownloadLocation: https://pypi.org/project/xmlschema/3.2.1
PackageDownloadLocation: https://pypi.org/project/xmlschema/3.3.0
FilesAnalyzed: false
PackageLicenseDeclared: MIT
PackageLicenseConcluded: MIT
PackageCopyrightText: NOASSERTION
PackageSummary: <text>An XML Schema validator and decoder</text>
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/xmlschema@3.2.1
ExternalRef: SECURITY cpe23Type cpe:2.3:a:davide_brunato:xmlschema:3.2.1:*:*:*:*:*:*:*
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/xmlschema@3.3.0
ExternalRef: SECURITY cpe23Type cpe:2.3:a:davide_brunato:xmlschema:3.3.0:*:*:*:*:*:*:*
#####

PackageName: elementpath
Expand Down

0 comments on commit 52a3f76

Please sign in to comment.