Skip to content

Commit

Permalink
chore: update SBOM for Python 3.9
Browse files Browse the repository at this point in the history
  • Loading branch information
web-flow authored Oct 9, 2023
1 parent 2847879 commit 7babc06
Show file tree
Hide file tree
Showing 2 changed files with 66 additions and 58 deletions.
79 changes: 43 additions & 36 deletions sbom/cve-bin-tool-py3.9.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,10 +2,10 @@
"$schema": "http://cyclonedx.org/schema/bom-1.5.schema.json",
"bomFormat": "CycloneDX",
"specVersion": "1.5",
"serialNumber": "urn:uuid:02712a9c-0509-4001-b41d-e9a8f6cf981a",
"serialNumber": "urn:uuid:ae042e3e-8148-4e8c-a232-3357d7c42abe",
"version": 1,
"metadata": {
"timestamp": "2023-10-02T01:12:12Z",
"timestamp": "2023-10-09T00:26:53Z",
"tools": {
"components": [
{
Expand Down Expand Up @@ -58,7 +58,11 @@
"type": "library",
"bom-ref": "2-aiohttp",
"name": "aiohttp",
"version": "3.8.5",
"version": "3.8.6",
"supplier": {
"name": "NOASSERTION"
},
"cpe": "cpe:/a:NOASSERTION:aiohttp:3.8.6",
"description": "Async http client/server framework (asyncio)",
"licenses": [
{
Expand All @@ -70,12 +74,12 @@
],
"externalReferences": [
{
"url": "https://pypi.org/project/aiohttp/3.8.5",
"url": "https://pypi.org/project/aiohttp/3.8.6",
"type": "distribution",
"comment": "Download location for component"
}
],
"purl": "pkg:pypi/aiohttp@3.8.5",
"purl": "pkg:pypi/aiohttp@3.8.6",
"properties": [
{
"name": "License Comments",
Expand All @@ -88,6 +92,10 @@
"bom-ref": "3-aiosignal",
"name": "aiosignal",
"version": "1.3.1",
"supplier": {
"name": "NOASSERTION"
},
"cpe": "cpe:/a:NOASSERTION:aiosignal:1.3.1",
"licenses": [
{
"license": {
Expand Down Expand Up @@ -116,6 +124,10 @@
"bom-ref": "4-frozenlist",
"name": "frozenlist",
"version": "1.4.0",
"supplier": {
"name": "NOASSERTION"
},
"cpe": "cpe:/a:NOASSERTION:frozenlist:1.4.0",
"description": "A list-like structure which implements collections.abc.MutableSequence",
"licenses": [
{
Expand Down Expand Up @@ -496,7 +508,7 @@
"name": "gsutil",
"version": "5.26",
"supplier": {
"name": "Google Inc.",
"name": "Google Inc .",
"contact": [
{
"email": "buganizer-system+187143@google.com"
Expand Down Expand Up @@ -631,7 +643,7 @@
"name": "gcs-oauth2-boto-plugin",
"version": "3.0",
"supplier": {
"name": "Google Inc.",
"name": "Google Inc .",
"contact": [
{
"email": "gs-team@google.com"
Expand Down Expand Up @@ -739,7 +751,7 @@
"name": "pyu2f",
"version": "0.1.5",
"supplier": {
"name": "Google Inc.",
"name": "Google Inc .",
"contact": [
{
"email": "pyu2f-team@google.com"
Expand Down Expand Up @@ -865,7 +877,7 @@
"name": "oauth2client",
"version": "4.1.3",
"supplier": {
"name": "Google Inc.",
"name": "Google Inc .",
"contact": [
{
"email": "jonwayne+oauth2client@google.com"
Expand Down Expand Up @@ -973,7 +985,7 @@
"name": "rsa",
"version": "4.7.2",
"supplier": {
"name": "Sybren A. Stuvel",
"name": "Sybren A . Stuvel",
"contact": [
{
"email": "sybren@stuvel.eu"
Expand Down Expand Up @@ -1060,9 +1072,7 @@
"description": "cryptography is a package which provides cryptographic recipes and primitives to Python developers.",
"licenses": [
{
"license": {
"expression": "Apache-2.0 OR BSD-3-Clause"
}
"expression": "Apache-2.0 OR BSD-3-Clause"
}
],
"externalReferences": [
Expand Down Expand Up @@ -1328,7 +1338,7 @@
"name": "importlib-metadata",
"version": "6.8.0",
"supplier": {
"name": "Jason R. Coombs",
"name": "Jason R . Coombs",
"contact": [
{
"email": "jaraco@jaraco.com"
Expand All @@ -1352,7 +1362,7 @@
"name": "zipp",
"version": "3.17.0",
"supplier": {
"name": "Jason R. Coombs",
"name": "Jason R . Coombs",
"contact": [
{
"email": "jaraco@jaraco.com"
Expand Down Expand Up @@ -1407,6 +1417,10 @@
"bom-ref": "43-markupsafe",
"name": "markupsafe",
"version": "2.1.3",
"supplier": {
"name": "NOASSERTION"
},
"cpe": "cpe:/a:NOASSERTION:markupsafe:2.1.3",
"description": "Safely add untrusted strings to HTML/XML markup.",
"licenses": [
{
Expand Down Expand Up @@ -1510,11 +1524,11 @@
"type": "library",
"bom-ref": "47-rpds-py",
"name": "rpds-py",
"version": "0.10.3",
"version": "0.10.4",
"supplier": {
"name": "Julian Berman"
},
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.10.3:*:*:*:*:*:*:*",
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.10.4:*:*:*:*:*:*:*",
"description": "Python bindings to Rust's persistent data structures (rpds)",
"licenses": [
{
Expand All @@ -1526,18 +1540,18 @@
],
"externalReferences": [
{
"url": "https://pypi.org/project/rpds-py/0.10.3",
"url": "https://pypi.org/project/rpds-py/0.10.4",
"type": "distribution",
"comment": "Download location for component"
}
],
"purl": "pkg:pypi/rpds-py@0.10.3"
"purl": "pkg:pypi/rpds-py@0.10.4"
},
{
"type": "library",
"bom-ref": "48-lib4sbom",
"name": "lib4sbom",
"version": "0.4.3",
"version": "0.5.1",
"supplier": {
"name": "Anthony Harrison",
"contact": [
Expand All @@ -1546,7 +1560,7 @@
}
]
},
"cpe": "cpe:2.3:a:anthony_harrison:lib4sbom:0.4.3:*:*:*:*:*:*:*",
"cpe": "cpe:2.3:a:anthony_harrison:lib4sbom:0.5.1:*:*:*:*:*:*:*",
"description": "Software Bill of Material (SBOM) generator and consumer library",
"licenses": [
{
Expand All @@ -1558,12 +1572,12 @@
],
"externalReferences": [
{
"url": "https://pypi.org/project/lib4sbom/0.4.3",
"url": "https://pypi.org/project/lib4sbom/0.5.1",
"type": "distribution",
"comment": "Download location for component"
}
],
"purl": "pkg:pypi/lib4sbom@0.4.3"
"purl": "pkg:pypi/lib4sbom@0.5.1"
},
{
"type": "library",
Expand Down Expand Up @@ -1652,9 +1666,7 @@
"description": "Core utilities for Python packages",
"licenses": [
{
"license": {
"expression": "BSD-2-Clause OR Apache-2.0"
}
"expression": "BSD-2-Clause OR Apache-2.0"
}
],
"externalReferences": [
Expand Down Expand Up @@ -1854,7 +1866,7 @@
"type": "library",
"bom-ref": "57-urllib3",
"name": "urllib3",
"version": "2.0.5",
"version": "2.0.6",
"supplier": {
"name": "Andrey Petrov",
"contact": [
Expand All @@ -1863,16 +1875,16 @@
}
]
},
"cpe": "cpe:2.3:a:andrey_petrov:urllib3:2.0.5:*:*:*:*:*:*:*",
"cpe": "cpe:2.3:a:andrey_petrov:urllib3:2.0.6:*:*:*:*:*:*:*",
"description": "HTTP library with thread-safe connection pooling, file post, and more.",
"externalReferences": [
{
"url": "https://pypi.org/project/urllib3/2.0.5",
"url": "https://pypi.org/project/urllib3/2.0.6",
"type": "distribution",
"comment": "Download location for component"
}
],
"purl": "pkg:pypi/urllib3@2.0.5"
"purl": "pkg:pypi/urllib3@2.0.6"
},
{
"type": "library",
Expand Down Expand Up @@ -2154,12 +2166,6 @@
}
],
"dependencies": [
{
"ref": "CDXRef-DOCUMENT",
"dependsOn": [
"1-cve-bin-tool"
]
},
{
"ref": "1-cve-bin-tool",
"dependsOn": [
Expand Down Expand Up @@ -2359,6 +2365,7 @@
{
"ref": "48-lib4sbom",
"dependsOn": [
"14-defusedxml",
"49-pyyaml",
"50-semantic-version"
]
Expand Down
Loading

0 comments on commit 7babc06

Please sign in to comment.