diff --git a/sbom/cve-bin-tool-py3.10.json b/sbom/cve-bin-tool-py3.10.json index e60b284e6f..4afacd9183 100644 --- a/sbom/cve-bin-tool-py3.10.json +++ b/sbom/cve-bin-tool-py3.10.json @@ -2,10 +2,10 @@ "$schema": "http://cyclonedx.org/schema/bom-1.4.schema.json", "bomFormat": "CycloneDX", "specVersion": "1.4", - "serialNumber": "urn:uuid9b76c916-732e-4270-b318-b3184bd48654", + "serialNumber": "urn:uuidab9fd8ae-703a-417b-a04d-bfab3c8b0427", "version": 1, "metadata": { - "timestamp": "2023-04-24T00:26:29Z", + "timestamp": "2023-05-01T01:40:46Z", "tools": [ { "name": "sbom4python", @@ -309,7 +309,7 @@ "type": "library", "bom-ref": "9-yarl", "name": "yarl", - "version": "1.9.1", + "version": "1.9.2", "supplier": { "name": "Andrew Svetlov", "contact": [ @@ -318,7 +318,7 @@ } ] }, - "cpe": "cpe:2.3:a:andrew_svetlov:yarl:1.9.1:*:*:*:*:*:*:*", + "cpe": "cpe:2.3:a:andrew_svetlov:yarl:1.9.2:*:*:*:*:*:*:*", "description": "Yet another URL library", "licenses": [ { @@ -335,12 +335,12 @@ "comment": "Home page for project" }, { - "url": "https://pypi.org/project/yarl/1.9.1", + "url": "https://pypi.org/project/yarl/1.9.2", "type": "distribution", "comment": "Download location for component" } ], - "purl": "pkg:pypi/yarl@1.9.1" + "purl": "pkg:pypi/yarl@1.9.2" }, { "type": "library", @@ -1877,7 +1877,7 @@ "type": "library", "bom-ref": "50-requests", "name": "requests", - "version": "2.28.2", + "version": "2.29.0", "supplier": { "name": "Kenneth Reitz", "contact": [ @@ -1886,7 +1886,7 @@ } ] }, - "cpe": "cpe:2.3:a:kenneth_reitz:requests:2.28.2:*:*:*:*:*:*:*", + "cpe": "cpe:2.3:a:kenneth_reitz:requests:2.29.0:*:*:*:*:*:*:*", "description": "Python HTTP for Humans.", "licenses": [ { @@ -1903,12 +1903,12 @@ "comment": "Home page for project" }, { - "url": "https://pypi.org/project/requests/2.28.2", + "url": "https://pypi.org/project/requests/2.29.0", "type": "distribution", "comment": "Download location for component" } ], - "purl": "pkg:pypi/requests@2.28.2", + "purl": "pkg:pypi/requests@2.29.0", "properties": [ { "name": "License Comments", @@ -1994,7 +1994,7 @@ "type": "library", "bom-ref": "53-rich", "name": "rich", - "version": "13.3.4", + "version": "13.3.5", "supplier": { "name": "Will McGugan", "contact": [ @@ -2003,7 +2003,7 @@ } ] }, - "cpe": "cpe:2.3:a:will_mcgugan:rich:13.3.4:*:*:*:*:*:*:*", + "cpe": "cpe:2.3:a:will_mcgugan:rich:13.3.5:*:*:*:*:*:*:*", "description": "Render rich text, tables, progress bars, syntax highlighting, markdown and more to the terminal", "licenses": [ { @@ -2020,12 +2020,12 @@ "comment": "Home page for project" }, { - "url": "https://pypi.org/project/rich/13.3.4", + "url": "https://pypi.org/project/rich/13.3.5", "type": "distribution", "comment": "Download location for component" } ], - "purl": "pkg:pypi/rich@13.3.4" + "purl": "pkg:pypi/rich@13.3.5" }, { "type": "library", diff --git a/sbom/cve-bin-tool-py3.10.spdx b/sbom/cve-bin-tool-py3.10.spdx index 16e35b3029..ad43a4ee27 100644 --- a/sbom/cve-bin-tool-py3.10.spdx +++ b/sbom/cve-bin-tool-py3.10.spdx @@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3 DataLicense: CC0-1.0 SPDXID: SPDXRef-DOCUMENT DocumentName: Python-cve-bin-tool -DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-39a8443b-80ea-4d11-b1fe-547b534a2d42 +DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-56ab17cc-2314-4b26-ba2e-1a4492bcbcb8 LicenseListVersion: 3.20 Creator: Tool: sbom4python-0.9.1 -Created: 2023-04-24T00:25:19Z +Created: 2023-05-01T01:39:01Z CreatorComment: This document has been automatically generated. ##### @@ -140,18 +140,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrew_svetlov:multidict:6.0.4:*:*:*:* PackageName: yarl SPDXID: SPDXRef-Package-9-yarl -PackageVersion: 1.9.1 +PackageVersion: 1.9.2 PrimaryPackagePurpose: LIBRARY PackageSupplier: Person: Andrew Svetlov (andrew.svetlov@gmail.com) -PackageDownloadLocation: https://pypi.org/project/yarl/1.9.1 +PackageDownloadLocation: https://pypi.org/project/yarl/1.9.2 FilesAnalyzed: false PackageHomePage: https://github.com/aio-libs/yarl/ PackageLicenseDeclared: Apache-2.0 PackageLicenseConcluded: Apache-2.0 PackageCopyrightText: NOASSERTION PackageSummary: Yet another URL library -ExternalRef: PACKAGE-MANAGER purl pkg:pypi/yarl@1.9.1 -ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrew_svetlov:yarl:1.9.1:*:*:*:*:*:*:* +ExternalRef: PACKAGE-MANAGER purl pkg:pypi/yarl@1.9.2 +ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrew_svetlov:yarl:1.9.2:*:*:*:*:*:*:* ##### PackageName: idna @@ -811,10 +811,10 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julien_danjou:tenacity:8.2.2:*:*:*:*:* PackageName: requests SPDXID: SPDXRef-Package-50-requests -PackageVersion: 2.28.2 +PackageVersion: 2.29.0 PrimaryPackagePurpose: LIBRARY PackageSupplier: Person: Kenneth Reitz (me@kennethreitz.org) -PackageDownloadLocation: https://pypi.org/project/requests/2.28.2 +PackageDownloadLocation: https://pypi.org/project/requests/2.29.0 FilesAnalyzed: false PackageHomePage: https://requests.readthedocs.io PackageLicenseDeclared: NOASSERTION @@ -822,8 +822,8 @@ PackageLicenseConcluded: Apache-2.0 PackageLicenseComments: requests declares Apache 2.0 which is not currently a valid SPDX License identifier or expression. PackageCopyrightText: NOASSERTION PackageSummary: Python HTTP for Humans. -ExternalRef: PACKAGE-MANAGER purl pkg:pypi/requests@2.28.2 -ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:requests:2.28.2:*:*:*:*:*:*:* +ExternalRef: PACKAGE-MANAGER purl pkg:pypi/requests@2.29.0 +ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:requests:2.29.0:*:*:*:*:*:*:* ##### PackageName: certifi @@ -860,18 +860,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_petrov:urllib3:1.26.15:*:*:*:*: PackageName: rich SPDXID: SPDXRef-Package-53-rich -PackageVersion: 13.3.4 +PackageVersion: 13.3.5 PrimaryPackagePurpose: LIBRARY PackageSupplier: Person: Will McGugan (willmcgugan@gmail.com) -PackageDownloadLocation: https://pypi.org/project/rich/13.3.4 +PackageDownloadLocation: https://pypi.org/project/rich/13.3.5 FilesAnalyzed: false PackageHomePage: https://github.com/Textualize/rich PackageLicenseDeclared: MIT PackageLicenseConcluded: MIT PackageCopyrightText: NOASSERTION PackageSummary: Render rich text, tables, progress bars, syntax highlighting, markdown and more to the terminal -ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rich@13.3.4 -ExternalRef: SECURITY cpe23Type cpe:2.3:a:will_mcgugan:rich:13.3.4:*:*:*:*:*:*:* +ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rich@13.3.5 +ExternalRef: SECURITY cpe23Type cpe:2.3:a:will_mcgugan:rich:13.3.5:*:*:*:*:*:*:* ##### PackageName: markdown-it-py