Skip to content

Commit 096a746

Browse files
web-flowgithub-actions[bot]
authored andcommitted
chore: update SBOM for Python 3.9
1 parent eabf69d commit 096a746

File tree

2 files changed

+33
-12
lines changed

2 files changed

+33
-12
lines changed

sbom/cve-bin-tool-py3.9.json

Lines changed: 24 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.5.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.5",
5-
"serialNumber": "urn:uuid:570b5dab-b52f-4d7a-ad5e-b1f57e27bde8",
5+
"serialNumber": "urn:uuid:0d5bb44b-9fae-490b-8e5b-632e576a6f30",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2024-02-05T00:27:53Z",
8+
"timestamp": "2024-02-12T00:27:19Z",
99
"tools": {
1010
"components": [
1111
{
@@ -1791,6 +1791,12 @@
17911791
},
17921792
"cpe": "cpe:2.3:a:jason_r._coombs:importlib-metadata:7.0.1:*:*:*:*:*:*:*",
17931793
"description": "Read metadata from Python packages",
1794+
"hashes": [
1795+
{
1796+
"alg": "SHA-1",
1797+
"content": "f2e84e3fb5a240b054e8669e5162914bb4a4e68b"
1798+
}
1799+
],
17941800
"externalReferences": [
17951801
{
17961802
"url": "https://pypi.org/project/importlib-metadata/7.0.1",
@@ -1856,6 +1862,12 @@
18561862
"name": "jinja2",
18571863
"version": "3.1.3",
18581864
"description": "A very fast and expressive template engine.",
1865+
"hashes": [
1866+
{
1867+
"alg": "SHA-1",
1868+
"content": "d9de4bb215fd1cc8092a410fb834c7c4060b1fc1"
1869+
}
1870+
],
18591871
"licenses": [
18601872
{
18611873
"license": {
@@ -2935,7 +2947,7 @@
29352947
"type": "library",
29362948
"bom-ref": "66-elementpath",
29372949
"name": "elementpath",
2938-
"version": "4.2.0",
2950+
"version": "4.2.1",
29392951
"supplier": {
29402952
"name": "Davide Brunato",
29412953
"contact": [
@@ -2944,8 +2956,14 @@
29442956
}
29452957
]
29462958
},
2947-
"cpe": "cpe:2.3:a:davide_brunato:elementpath:4.2.0:*:*:*:*:*:*:*",
2959+
"cpe": "cpe:2.3:a:davide_brunato:elementpath:4.2.1:*:*:*:*:*:*:*",
29482960
"description": "XPath 1.0/2.0/3.0/3.1 parsers and selectors for ElementTree and lxml",
2961+
"hashes": [
2962+
{
2963+
"alg": "SHA-1",
2964+
"content": "6795c9d5691f56d5f2548f45dc188706bf038675"
2965+
}
2966+
],
29492967
"licenses": [
29502968
{
29512969
"license": {
@@ -2956,12 +2974,12 @@
29562974
],
29572975
"externalReferences": [
29582976
{
2959-
"url": "https://pypi.org/project/elementpath/4.2.0",
2977+
"url": "https://pypi.org/project/elementpath/4.2.1",
29602978
"type": "distribution",
29612979
"comment": "Download location for component"
29622980
}
29632981
],
2964-
"purl": "pkg:pypi/elementpath@4.2.0",
2982+
"purl": "pkg:pypi/elementpath@4.2.1",
29652983
"properties": [
29662984
{
29672985
"name": "language",

sbom/cve-bin-tool-py3.9.spdx

Lines changed: 9 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-5c4390c3-0924-402b-a03d-c04ed11babe7
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-2c351609-c615-4661-9111-b4af6df5821a
66
LicenseListVersion: 3.22
77
Creator: Tool: sbom4python-0.10.3
8-
Created: 2024-02-05T00:26:07Z
8+
Created: 2024-02-12T00:25:34Z
99
CreatorComment: <text>This document has been automatically generated.</text>
1010
#####
1111

@@ -627,6 +627,7 @@ PrimaryPackagePurpose: LIBRARY
627627
PackageSupplier: Organization: Jason R. Coombs (jaraco@jaraco.com)
628628
PackageDownloadLocation: https://pypi.org/project/importlib-metadata/7.0.1
629629
FilesAnalyzed: false
630+
PackageChecksum: SHA1: f2e84e3fb5a240b054e8669e5162914bb4a4e68b
630631
PackageLicenseDeclared: NOASSERTION
631632
PackageLicenseConcluded: NOASSERTION
632633
PackageCopyrightText: NOASSERTION
@@ -658,6 +659,7 @@ PrimaryPackagePurpose: LIBRARY
658659
PackageSupplier: NOASSERTION
659660
PackageDownloadLocation: https://pypi.org/project/Jinja2/3.1.3
660661
FilesAnalyzed: false
662+
PackageChecksum: SHA1: d9de4bb215fd1cc8092a410fb834c7c4060b1fc1
661663
PackageLicenseDeclared: BSD-3-Clause
662664
PackageLicenseConcluded: BSD-3-Clause
663665
PackageCopyrightText: NOASSERTION
@@ -1045,17 +1047,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:davide_brunato:xmlschema:3.0.1:*:*:*:*
10451047

10461048
PackageName: elementpath
10471049
SPDXID: SPDXRef-Package-66-elementpath
1048-
PackageVersion: 4.2.0
1050+
PackageVersion: 4.2.1
10491051
PrimaryPackagePurpose: LIBRARY
10501052
PackageSupplier: Person: Davide Brunato (brunato@sissa.it)
1051-
PackageDownloadLocation: https://pypi.org/project/elementpath/4.2.0
1053+
PackageDownloadLocation: https://pypi.org/project/elementpath/4.2.1
10521054
FilesAnalyzed: false
1055+
PackageChecksum: SHA1: 6795c9d5691f56d5f2548f45dc188706bf038675
10531056
PackageLicenseDeclared: MIT
10541057
PackageLicenseConcluded: MIT
10551058
PackageCopyrightText: NOASSERTION
10561059
PackageSummary: <text>XPath 1.0/2.0/3.0/3.1 parsers and selectors for ElementTree and lxml</text>
1057-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/elementpath@4.2.0
1058-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:davide_brunato:elementpath:4.2.0:*:*:*:*:*:*:*
1060+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/elementpath@4.2.1
1061+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:davide_brunato:elementpath:4.2.1:*:*:*:*:*:*:*
10591062
#####
10601063

10611064
PackageName: zstandard

0 commit comments

Comments
 (0)