Skip to content

Commit

Permalink
chore: update SBOM for Python 3.12 (#4407)
Browse files Browse the repository at this point in the history
Co-authored-by: GitHub <[email protected]>
  • Loading branch information
github-actions[bot] and web-flow authored Sep 3, 2024
1 parent 7953bc8 commit 3008800
Show file tree
Hide file tree
Showing 2 changed files with 90 additions and 90 deletions.
100 changes: 50 additions & 50 deletions sbom/cve-bin-tool-py3.12.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,10 +2,10 @@
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
"bomFormat": "CycloneDX",
"specVersion": "1.6",
"serialNumber": "urn:uuid:1a468904-d4b4-4448-9ff4-2a4c6cda96ce",
"serialNumber": "urn:uuid:b1f117ed-2d0e-4be8-99ca-e91c6c6428cc",
"version": 1,
"metadata": {
"timestamp": "2024-08-26T00:35:14Z",
"timestamp": "2024-09-02T00:35:23Z",
"lifecycles": [
{
"phase": "build"
Expand All @@ -31,7 +31,7 @@
"type": "application",
"bom-ref": "1-cve-bin-tool",
"name": "cve-bin-tool",
"version": "3.4rc0",
"version": "3.4rc1",
"supplier": {
"name": "Terri Oda",
"contact": [
Expand All @@ -40,7 +40,7 @@
}
]
},
"cpe": "cpe:2.3:a:terri_oda:cve-bin-tool:3.4rc0:*:*:*:*:*:*:*",
"cpe": "cpe:2.3:a:terri_oda:cve-bin-tool:3.4rc1:*:*:*:*:*:*:*",
"description": "CVE Binary Checker Tool",
"licenses": [
{
Expand All @@ -53,12 +53,12 @@
],
"externalReferences": [
{
"url": "https://pypi.org/project/cve-bin-tool/3.4rc0",
"url": "https://pypi.org/project/cve-bin-tool/3.4rc1",
"type": "distribution",
"comment": "Download location for component"
}
],
"purl": "pkg:pypi/cve-bin-tool@3.4rc0",
"purl": "pkg:pypi/cve-bin-tool@3.4rc1",
"properties": [
{
"name": "language",
Expand Down Expand Up @@ -119,6 +119,12 @@
},
"cpe": "cpe:2.3:a:j._nick_koston:aiohappyeyeballs:2.4.0:*:*:*:*:*:*:*",
"description": "Happy Eyeballs for asyncio",
"hashes": [
{
"alg": "SHA-1",
"content": "c31b127a69bdcd7895d1a521985d918061955348"
}
],
"licenses": [
{
"license": {
Expand Down Expand Up @@ -307,7 +313,7 @@
"type": "library",
"bom-ref": "8-yarl",
"name": "yarl",
"version": "1.9.4",
"version": "1.9.7",
"supplier": {
"name": "Andrew Svetlov",
"contact": [
Expand All @@ -316,14 +322,8 @@
}
]
},
"cpe": "cpe:2.3:a:andrew_svetlov:yarl:1.9.4:*:*:*:*:*:*:*",
"cpe": "cpe:2.3:a:andrew_svetlov:yarl:1.9.7:*:*:*:*:*:*:*",
"description": "Yet another URL library",
"hashes": [
{
"alg": "SHA-1",
"content": "6362ff155ba02964a5e773927412f7cf4ca23cd1"
}
],
"licenses": [
{
"license": {
Expand All @@ -335,12 +335,12 @@
],
"externalReferences": [
{
"url": "https://pypi.org/project/yarl/1.9.4",
"url": "https://pypi.org/project/yarl/1.9.7",
"type": "distribution",
"comment": "Download location for component"
}
],
"purl": "pkg:pypi/[email protected].4",
"purl": "pkg:pypi/[email protected].7",
"properties": [
{
"name": "language",
Expand All @@ -367,6 +367,12 @@
},
"cpe": "cpe:2.3:a:kim_davies:idna:3.8:*:*:*:*:*:*:*",
"description": "Internationalized Domain Names in Applications (IDNA)",
"hashes": [
{
"alg": "SHA-1",
"content": "784c6f45c162db9709588124f2f1def5b70615ff"
}
],
"externalReferences": [
{
"url": "https://pypi.org/project/idna/3.8",
Expand Down Expand Up @@ -2023,7 +2029,7 @@
"type": "library",
"bom-ref": "47-lib4sbom",
"name": "lib4sbom",
"version": "0.7.3",
"version": "0.7.4",
"supplier": {
"name": "Anthony Harrison",
"contact": [
Expand All @@ -2032,7 +2038,7 @@
}
]
},
"cpe": "cpe:2.3:a:anthony_harrison:lib4sbom:0.7.3:*:*:*:*:*:*:*",
"cpe": "cpe:2.3:a:anthony_harrison:lib4sbom:0.7.4:*:*:*:*:*:*:*",
"description": "Software Bill of Material (SBOM) generator and consumer library",
"licenses": [
{
Expand All @@ -2045,12 +2051,12 @@
],
"externalReferences": [
{
"url": "https://pypi.org/project/lib4sbom/0.7.3",
"url": "https://pypi.org/project/lib4sbom/0.7.4",
"type": "distribution",
"comment": "Download location for component"
}
],
"purl": "pkg:pypi/[email protected].3",
"purl": "pkg:pypi/[email protected].4",
"properties": [
{
"name": "language",
Expand Down Expand Up @@ -2158,7 +2164,7 @@
"type": "library",
"bom-ref": "50-lib4vex",
"name": "lib4vex",
"version": "0.1.0",
"version": "0.2.0",
"supplier": {
"name": "Anthony Harrison",
"contact": [
Expand All @@ -2167,14 +2173,8 @@
}
]
},
"cpe": "cpe:2.3:a:anthony_harrison:lib4vex:0.1.0:*:*:*:*:*:*:*",
"cpe": "cpe:2.3:a:anthony_harrison:lib4vex:0.2.0:*:*:*:*:*:*:*",
"description": "VEX generator and consumer library",
"hashes": [
{
"alg": "SHA-1",
"content": "84229c7770dd95cf887d6874e0203da4c8aa809b"
}
],
"licenses": [
{
"license": {
Expand All @@ -2186,12 +2186,12 @@
],
"externalReferences": [
{
"url": "https://pypi.org/project/lib4vex/0.1.0",
"url": "https://pypi.org/project/lib4vex/0.2.0",
"type": "distribution",
"comment": "Download location for component"
}
],
"purl": "pkg:pypi/lib4vex@0.1.0",
"purl": "pkg:pypi/lib4vex@0.2.0",
"properties": [
{
"name": "language",
Expand Down Expand Up @@ -2300,7 +2300,7 @@
"type": "library",
"bom-ref": "53-rich",
"name": "rich",
"version": "13.7.1",
"version": "13.8.0",
"supplier": {
"name": "Will McGugan",
"contact": [
Expand All @@ -2309,7 +2309,7 @@
}
]
},
"cpe": "cpe:2.3:a:will_mcgugan:rich:13.7.1:*:*:*:*:*:*:*",
"cpe": "cpe:2.3:a:will_mcgugan:rich:13.8.0:*:*:*:*:*:*:*",
"description": "Render rich text, tables, progress bars, syntax highlighting, markdown and more to the terminal",
"licenses": [
{
Expand All @@ -2322,12 +2322,12 @@
],
"externalReferences": [
{
"url": "https://pypi.org/project/rich/13.7.1",
"url": "https://pypi.org/project/rich/13.8.0",
"type": "distribution",
"comment": "Download location for component"
}
],
"purl": "pkg:pypi/rich@13.7.1",
"purl": "pkg:pypi/rich@13.8.0",
"properties": [
{
"name": "language",
Expand Down Expand Up @@ -2506,7 +2506,7 @@
"type": "library",
"bom-ref": "58-plotly",
"name": "plotly",
"version": "5.23.0",
"version": "5.24.0",
"supplier": {
"name": "Chris P",
"contact": [
Expand All @@ -2515,7 +2515,7 @@
}
]
},
"cpe": "cpe:2.3:a:chris_p:plotly:5.23.0:*:*:*:*:*:*:*",
"cpe": "cpe:2.3:a:chris_p:plotly:5.24.0:*:*:*:*:*:*:*",
"description": "An open-source, interactive data visualization library for Python",
"licenses": [
{
Expand All @@ -2528,12 +2528,12 @@
],
"externalReferences": [
{
"url": "https://pypi.org/project/plotly/5.23.0",
"url": "https://pypi.org/project/plotly/5.24.0",
"type": "distribution",
"comment": "Download location for component"
}
],
"purl": "pkg:pypi/plotly@5.23.0",
"purl": "pkg:pypi/plotly@5.24.0",
"properties": [
{
"name": "language",
Expand Down Expand Up @@ -2696,7 +2696,7 @@
"type": "library",
"bom-ref": "62-certifi",
"name": "certifi",
"version": "2024.7.4",
"version": "2024.8.30",
"supplier": {
"name": "Kenneth Reitz",
"contact": [
Expand All @@ -2705,7 +2705,7 @@
}
]
},
"cpe": "cpe:2.3:a:kenneth_reitz:certifi:2024.7.4:*:*:*:*:*:*:*",
"cpe": "cpe:2.3:a:kenneth_reitz:certifi:2024.8.30:*:*:*:*:*:*:*",
"description": "Python package for providing Mozilla's CA Bundle.",
"licenses": [
{
Expand All @@ -2718,12 +2718,12 @@
],
"externalReferences": [
{
"url": "https://pypi.org/project/certifi/2024.7.4",
"url": "https://pypi.org/project/certifi/2024.8.30",
"type": "distribution",
"comment": "Download location for component"
}
],
"purl": "pkg:pypi/certifi@2024.7.4",
"purl": "pkg:pypi/certifi@2024.8.30",
"properties": [
{
"name": "language",
Expand Down Expand Up @@ -2871,7 +2871,7 @@
"type": "library",
"bom-ref": "66-setuptools",
"name": "setuptools",
"version": "73.0.1",
"version": "74.0.0",
"supplier": {
"name": "Python Packaging Authority",
"contact": [
Expand All @@ -2880,16 +2880,16 @@
}
]
},
"cpe": "cpe:2.3:a:python_packaging_authority:setuptools:73.0.1:*:*:*:*:*:*:*",
"cpe": "cpe:2.3:a:python_packaging_authority:setuptools:74.0.0:*:*:*:*:*:*:*",
"description": "Easily download, build, install, upgrade, and uninstall Python packages",
"externalReferences": [
{
"url": "https://pypi.org/project/setuptools/73.0.1",
"url": "https://pypi.org/project/setuptools/74.0.0",
"type": "distribution",
"comment": "Download location for component"
}
],
"purl": "pkg:pypi/setuptools@73.0.1",
"purl": "pkg:pypi/setuptools@74.0.0",
"properties": [
{
"name": "language",
Expand Down Expand Up @@ -3003,7 +3003,7 @@
"type": "library",
"bom-ref": "69-zipp",
"name": "zipp",
"version": "3.20.0",
"version": "3.20.1",
"supplier": {
"name": "Jason R .",
"contact": [
Expand All @@ -3012,16 +3012,16 @@
}
]
},
"cpe": "cpe:2.3:a:jason_r.:zipp:3.20.0:*:*:*:*:*:*:*",
"cpe": "cpe:2.3:a:jason_r.:zipp:3.20.1:*:*:*:*:*:*:*",
"description": "Backport of pathlib-compatible object wrapper for zip files",
"externalReferences": [
{
"url": "https://pypi.org/project/zipp/3.20.0",
"url": "https://pypi.org/project/zipp/3.20.1",
"type": "distribution",
"comment": "Download location for component"
}
],
"purl": "pkg:pypi/[email protected].0",
"purl": "pkg:pypi/[email protected].1",
"properties": [
{
"name": "language",
Expand Down
Loading

0 comments on commit 3008800

Please sign in to comment.