Skip to content

Commit 1aaa457

Browse files
chore: update SBOM for Python 3.12 (#4233)
Co-authored-by: GitHub <[email protected]>
1 parent da8b738 commit 1aaa457

File tree

2 files changed

+19
-12
lines changed

2 files changed

+19
-12
lines changed

sbom/cve-bin-tool-py3.12.json

Lines changed: 12 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:a587ecc0-5f69-4c77-bf48-18630025c783",
5+
"serialNumber": "urn:uuid:e27b5902-ba3a-444c-8a9d-845375e9619f",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2024-06-24T00:29:36Z",
8+
"timestamp": "2024-07-01T00:32:44Z",
99
"tools": {
1010
"components": [
1111
{
@@ -2484,7 +2484,7 @@
24842484
"type": "library",
24852485
"bom-ref": "58-tenacity",
24862486
"name": "tenacity",
2487-
"version": "8.4.1",
2487+
"version": "8.4.2",
24882488
"supplier": {
24892489
"name": "Julien Danjou",
24902490
"contact": [
@@ -2493,7 +2493,7 @@
24932493
}
24942494
]
24952495
},
2496-
"cpe": "cpe:2.3:a:julien_danjou:tenacity:8.4.1:*:*:*:*:*:*:*",
2496+
"cpe": "cpe:2.3:a:julien_danjou:tenacity:8.4.2:*:*:*:*:*:*:*",
24972497
"description": "Retry code until it succeeds",
24982498
"licenses": [
24992499
{
@@ -2505,12 +2505,12 @@
25052505
],
25062506
"externalReferences": [
25072507
{
2508-
"url": "https://pypi.org/project/tenacity/8.4.1",
2508+
"url": "https://pypi.org/project/tenacity/8.4.2",
25092509
"type": "distribution",
25102510
"comment": "Download location for component"
25112511
}
25122512
],
2513-
"purl": "pkg:pypi/[email protected].1",
2513+
"purl": "pkg:pypi/[email protected].2",
25142514
"properties": [
25152515
{
25162516
"name": "language",
@@ -2847,6 +2847,12 @@
28472847
},
28482848
"cpe": "cpe:2.3:a:davide_brunato:elementpath:4.4.0:*:*:*:*:*:*:*",
28492849
"description": "XPath 1.0/2.0/3.0/3.1 parsers and selectors for ElementTree and lxml",
2850+
"hashes": [
2851+
{
2852+
"alg": "SHA-1",
2853+
"content": "004fca18366974c34193176bd3a356f711330ca0"
2854+
}
2855+
],
28502856
"licenses": [
28512857
{
28522858
"license": {

sbom/cve-bin-tool-py3.12.spdx

Lines changed: 7 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-08ab13b5-ad50-440f-8363-f8493ae5004f
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-75779e7c-ca25-46c2-85fa-80dc4ed349c7
66
LicenseListVersion: 3.22
77
Creator: Tool: sbom4python-0.10.4
8-
Created: 2024-06-24T00:28:39Z
8+
Created: 2024-07-01T00:31:47Z
99
CreatorComment: <text>This document has been automatically generated.</text>
1010
#####
1111

@@ -917,18 +917,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:5.22.0:*:*:*:*:*:*:*
917917

918918
PackageName: tenacity
919919
SPDXID: SPDXRef-Package-58-tenacity
920-
PackageVersion: 8.4.1
920+
PackageVersion: 8.4.2
921921
PrimaryPackagePurpose: LIBRARY
922922
PackageSupplier: Person: Julien Danjou ([email protected])
923-
PackageDownloadLocation: https://pypi.org/project/tenacity/8.4.1
923+
PackageDownloadLocation: https://pypi.org/project/tenacity/8.4.2
924924
FilesAnalyzed: false
925925
PackageLicenseDeclared: NOASSERTION
926926
PackageLicenseConcluded: Apache-2.0
927927
PackageLicenseComments: <text>tenacity declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
928928
PackageCopyrightText: NOASSERTION
929929
PackageSummary: <text>Retry code until it succeeds</text>
930-
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].1
931-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julien_danjou:tenacity:8.4.1:*:*:*:*:*:*:*
930+
ExternalRef: PACKAGE_MANAGER purl pkg:pypi/[email protected].2
931+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julien_danjou:tenacity:8.4.2:*:*:*:*:*:*:*
932932
#####
933933

934934
PackageName: python-gnupg
@@ -1048,6 +1048,7 @@ PrimaryPackagePurpose: LIBRARY
10481048
PackageSupplier: Person: Davide Brunato ([email protected])
10491049
PackageDownloadLocation: https://pypi.org/project/elementpath/4.4.0
10501050
FilesAnalyzed: false
1051+
PackageChecksum: SHA1: 004fca18366974c34193176bd3a356f711330ca0
10511052
PackageLicenseDeclared: MIT
10521053
PackageLicenseConcluded: MIT
10531054
PackageCopyrightText: NOASSERTION

0 commit comments

Comments
 (0)