diff --git a/sbom/cve-bin-tool-py3.9.json b/sbom/cve-bin-tool-py3.9.json index 1c9712b1fa..775099565d 100644 --- a/sbom/cve-bin-tool-py3.9.json +++ b/sbom/cve-bin-tool-py3.9.json @@ -2,10 +2,10 @@ "$schema": "http://cyclonedx.org/schema/bom-1.5.schema.json", "bomFormat": "CycloneDX", "specVersion": "1.5", - "serialNumber": "urn:uuid:b4f44dfe-0171-4624-85dd-ff6ced2500c0", + "serialNumber": "urn:uuid:5faec005-00d7-49fc-be2c-b56094c5996d", "version": 1, "metadata": { - "timestamp": "2023-11-27T00:26:46Z", + "timestamp": "2023-12-04T00:26:52Z", "tools": { "components": [ { @@ -26,7 +26,7 @@ "type": "application", "bom-ref": "1-cve-bin-tool", "name": "cve-bin-tool", - "version": "3.2.2.dev0", + "version": "3.3a0", "supplier": { "name": "Terri Oda", "contact": [ @@ -35,7 +35,7 @@ } ] }, - "cpe": "cpe:2.3:a:terri_oda:cve-bin-tool:3.2.2.dev0:*:*:*:*:*:*:*", + "cpe": "cpe:2.3:a:terri_oda:cve-bin-tool:3.3a0:*:*:*:*:*:*:*", "description": "CVE Binary Checker Tool", "licenses": [ { @@ -47,12 +47,12 @@ ], "externalReferences": [ { - "url": "https://pypi.org/project/cve-bin-tool/3.2.2.dev0", + "url": "https://pypi.org/project/cve-bin-tool/3.3a0", "type": "distribution", "comment": "Download location for component" } ], - "purl": "pkg:pypi/cve-bin-tool@3.2.2.dev0", + "purl": "pkg:pypi/cve-bin-tool@3.3a0", "properties": [ { "name": "language", @@ -1173,7 +1173,7 @@ "type": "library", "bom-ref": "31-cryptography", "name": "cryptography", - "version": "41.0.5", + "version": "41.0.7", "supplier": { "name": "The Python Cryptographic Authority and individual contributors", "contact": [ @@ -1182,7 +1182,7 @@ } ] }, - "cpe": "cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:41.0.5:*:*:*:*:*:*:*", + "cpe": "cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:41.0.7:*:*:*:*:*:*:*", "description": "cryptography is a package which provides cryptographic recipes and primitives to Python developers.", "licenses": [ { @@ -1191,12 +1191,12 @@ ], "externalReferences": [ { - "url": "https://pypi.org/project/cryptography/41.0.5", + "url": "https://pypi.org/project/cryptography/41.0.7", "type": "distribution", "comment": "Download location for component" } ], - "purl": "pkg:pypi/cryptography@41.0.5", + "purl": "pkg:pypi/cryptography@41.0.7", "properties": [ { "name": "language", @@ -1368,7 +1368,7 @@ "type": "library", "bom-ref": "36-google-auth", "name": "google-auth", - "version": "2.23.4", + "version": "2.24.0", "supplier": { "name": "Google Cloud Platform", "contact": [ @@ -1377,7 +1377,7 @@ } ] }, - "cpe": "cpe:2.3:a:google_cloud_platform:google-auth:2.23.4:*:*:*:*:*:*:*", + "cpe": "cpe:2.3:a:google_cloud_platform:google-auth:2.24.0:*:*:*:*:*:*:*", "description": "Google Authentication Library", "licenses": [ { @@ -1389,12 +1389,12 @@ ], "externalReferences": [ { - "url": "https://pypi.org/project/google-auth/2.23.4", + "url": "https://pypi.org/project/google-auth/2.24.0", "type": "distribution", "comment": "Download location for component" } ], - "purl": "pkg:pypi/google-auth@2.23.4", + "purl": "pkg:pypi/google-auth@2.24.0", "properties": [ { "name": "language", @@ -1490,7 +1490,7 @@ "type": "library", "bom-ref": "39-importlib-metadata", "name": "importlib-metadata", - "version": "6.8.0", + "version": "7.0.0", "supplier": { "name": "Jason R . Coombs", "contact": [ @@ -1499,16 +1499,16 @@ } ] }, - "cpe": "cpe:2.3:a:jason_r._coombs:importlib-metadata:6.8.0:*:*:*:*:*:*:*", + "cpe": "cpe:2.3:a:jason_r._coombs:importlib-metadata:7.0.0:*:*:*:*:*:*:*", "description": "Read metadata from Python packages", "externalReferences": [ { - "url": "https://pypi.org/project/importlib-metadata/6.8.0", + "url": "https://pypi.org/project/importlib-metadata/7.0.0", "type": "distribution", "comment": "Download location for component" } ], - "purl": "pkg:pypi/importlib-metadata@6.8.0", + "purl": "pkg:pypi/importlib-metadata@7.0.0", "properties": [ { "name": "language", @@ -1654,11 +1654,11 @@ "type": "library", "bom-ref": "44-jsonschema-specifications", "name": "jsonschema-specifications", - "version": "2023.11.1", + "version": "2023.11.2", "supplier": { "name": "Julian Berman" }, - "cpe": "cpe:2.3:a:julian_berman:jsonschema-specifications:2023.11.1:*:*:*:*:*:*:*", + "cpe": "cpe:2.3:a:julian_berman:jsonschema-specifications:2023.11.2:*:*:*:*:*:*:*", "description": "The JSON Schema meta-schemas and vocabularies, exposed as a Registry", "licenses": [ { @@ -1670,12 +1670,12 @@ ], "externalReferences": [ { - "url": "https://pypi.org/project/jsonschema-specifications/2023.11.1", + "url": "https://pypi.org/project/jsonschema-specifications/2023.11.2", "type": "distribution", "comment": "Download location for component" } ], - "purl": "pkg:pypi/jsonschema-specifications@2023.11.1", + "purl": "pkg:pypi/jsonschema-specifications@2023.11.2", "properties": [ { "name": "language", @@ -1687,11 +1687,11 @@ "type": "library", "bom-ref": "45-referencing", "name": "referencing", - "version": "0.31.0", + "version": "0.31.1", "supplier": { "name": "Julian Berman" }, - "cpe": "cpe:2.3:a:julian_berman:referencing:0.31.0:*:*:*:*:*:*:*", + "cpe": "cpe:2.3:a:julian_berman:referencing:0.31.1:*:*:*:*:*:*:*", "description": "JSON Referencing + Python", "licenses": [ { @@ -1703,12 +1703,12 @@ ], "externalReferences": [ { - "url": "https://pypi.org/project/referencing/0.31.0", + "url": "https://pypi.org/project/referencing/0.31.1", "type": "distribution", "comment": "Download location for component" } ], - "purl": "pkg:pypi/referencing@0.31.0", + "purl": "pkg:pypi/referencing@0.31.1", "properties": [ { "name": "language", @@ -1720,11 +1720,11 @@ "type": "library", "bom-ref": "46-rpds-py", "name": "rpds-py", - "version": "0.13.1", + "version": "0.13.2", "supplier": { "name": "Julian Berman" }, - "cpe": "cpe:2.3:a:julian_berman:rpds-py:0.13.1:*:*:*:*:*:*:*", + "cpe": "cpe:2.3:a:julian_berman:rpds-py:0.13.2:*:*:*:*:*:*:*", "description": "Python bindings to Rust's persistent data structures (rpds)", "licenses": [ { @@ -1736,12 +1736,12 @@ ], "externalReferences": [ { - "url": "https://pypi.org/project/rpds-py/0.13.1", + "url": "https://pypi.org/project/rpds-py/0.13.2", "type": "distribution", "comment": "Download location for component" } ], - "purl": "pkg:pypi/rpds-py@0.13.1", + "purl": "pkg:pypi/rpds-py@0.13.2", "properties": [ { "name": "language", diff --git a/sbom/cve-bin-tool-py3.9.spdx b/sbom/cve-bin-tool-py3.9.spdx index f9717226ce..5b35f20db4 100644 --- a/sbom/cve-bin-tool-py3.9.spdx +++ b/sbom/cve-bin-tool-py3.9.spdx @@ -2,26 +2,26 @@ SPDXVersion: SPDX-2.3 DataLicense: CC0-1.0 SPDXID: SPDXRef-DOCUMENT DocumentName: Python-cve-bin-tool -DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-6d2fcca5-9f0f-4ca5-a0b1-33750bae9ba0 +DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-959a5a9a-4960-46de-b5bd-1c59a2b55f26 LicenseListVersion: 3.22 Creator: Tool: sbom4python-0.10.1 -Created: 2023-11-27T00:25:40Z +Created: 2023-12-04T00:25:47Z CreatorComment: This document has been automatically generated. ##### PackageName: cve-bin-tool SPDXID: SPDXRef-Package-1-cve-bin-tool -PackageVersion: 3.2.2.dev0 +PackageVersion: 3.3a0 PrimaryPackagePurpose: APPLICATION PackageSupplier: Person: Terri Oda (terri.oda@intel.com) -PackageDownloadLocation: https://pypi.org/project/cve-bin-tool/3.2.2.dev0 +PackageDownloadLocation: https://pypi.org/project/cve-bin-tool/3.3a0 FilesAnalyzed: false PackageLicenseDeclared: GPL-3.0-or-later PackageLicenseConcluded: GPL-3.0-or-later PackageCopyrightText: NOASSERTION PackageSummary: CVE Binary Checker Tool -ExternalRef: PACKAGE-MANAGER purl pkg:pypi/cve-bin-tool@3.2.2.dev0 -ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.2.2.dev0:*:*:*:*:*:*:* +ExternalRef: PACKAGE-MANAGER purl pkg:pypi/cve-bin-tool@3.3a0 +ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.3a0:*:*:*:*:*:*:* ##### PackageName: aiohttp @@ -474,17 +474,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_pyopenssl_developers:pyopenssl:23. PackageName: cryptography SPDXID: SPDXRef-Package-31-cryptography -PackageVersion: 41.0.5 +PackageVersion: 41.0.7 PrimaryPackagePurpose: LIBRARY PackageSupplier: Organization: The Python Cryptographic Authority and individual contributors (cryptography-dev@python.org) -PackageDownloadLocation: https://pypi.org/project/cryptography/41.0.5 +PackageDownloadLocation: https://pypi.org/project/cryptography/41.0.7 FilesAnalyzed: false PackageLicenseDeclared: Apache-2.0 OR BSD-3-Clause PackageLicenseConcluded: Apache-2.0 OR BSD-3-Clause PackageCopyrightText: NOASSERTION PackageSummary: cryptography is a package which provides cryptographic recipes and primitives to Python developers. -ExternalRef: PACKAGE-MANAGER purl pkg:pypi/cryptography@41.0.5 -ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:41.0.5:*:*:*:*:*:*:* +ExternalRef: PACKAGE-MANAGER purl pkg:pypi/cryptography@41.0.7 +ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:41.0.7:*:*:*:*:*:*:* ##### PackageName: cffi @@ -551,18 +551,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:craig_citro:google-apitools:0.5.32:*:* PackageName: google-auth SPDXID: SPDXRef-Package-36-google-auth -PackageVersion: 2.23.4 +PackageVersion: 2.24.0 PrimaryPackagePurpose: LIBRARY PackageSupplier: Organization: Google Cloud Platform (googleapis-packages@google.com) -PackageDownloadLocation: https://pypi.org/project/google-auth/2.23.4 +PackageDownloadLocation: https://pypi.org/project/google-auth/2.24.0 FilesAnalyzed: false PackageLicenseDeclared: NOASSERTION PackageLicenseConcluded: Apache-2.0 PackageLicenseComments: google-auth declares Apache 2.0 which is not currently a valid SPDX License identifier or expression. PackageCopyrightText: NOASSERTION PackageSummary: Google Authentication Library -ExternalRef: PACKAGE-MANAGER purl pkg:pypi/google-auth@2.23.4 -ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_cloud_platform:google-auth:2.23.4:*:*:*:*:*:*:* +ExternalRef: PACKAGE-MANAGER purl pkg:pypi/google-auth@2.24.0 +ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_cloud_platform:google-auth:2.24.0:*:*:*:*:*:*:* ##### PackageName: cachetools @@ -598,17 +598,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:ori_livneh:monotonic:1.6:*:*:*:*:*:*:* PackageName: importlib-metadata SPDXID: SPDXRef-Package-39-importlib-metadata -PackageVersion: 6.8.0 +PackageVersion: 7.0.0 PrimaryPackagePurpose: LIBRARY PackageSupplier: Organization: Jason R. Coombs (jaraco@jaraco.com) -PackageDownloadLocation: https://pypi.org/project/importlib-metadata/6.8.0 +PackageDownloadLocation: https://pypi.org/project/importlib-metadata/7.0.0 FilesAnalyzed: false PackageLicenseDeclared: NOASSERTION PackageLicenseConcluded: NOASSERTION PackageCopyrightText: NOASSERTION PackageSummary: Read metadata from Python packages -ExternalRef: PACKAGE-MANAGER purl pkg:pypi/importlib-metadata@6.8.0 -ExternalRef: SECURITY cpe23Type cpe:2.3:a:jason_r._coombs:importlib-metadata:6.8.0:*:*:*:*:*:*:* +ExternalRef: PACKAGE-MANAGER purl pkg:pypi/importlib-metadata@7.0.0 +ExternalRef: SECURITY cpe23Type cpe:2.3:a:jason_r._coombs:importlib-metadata:7.0.0:*:*:*:*:*:*:* ##### PackageName: zipp @@ -672,47 +672,47 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:jsonschema:4.20.0:*:*:*: PackageName: jsonschema-specifications SPDXID: SPDXRef-Package-44-jsonschema-specifications -PackageVersion: 2023.11.1 +PackageVersion: 2023.11.2 PrimaryPackagePurpose: LIBRARY PackageSupplier: Person: Julian Berman -PackageDownloadLocation: https://pypi.org/project/jsonschema-specifications/2023.11.1 +PackageDownloadLocation: https://pypi.org/project/jsonschema-specifications/2023.11.2 FilesAnalyzed: false PackageLicenseDeclared: MIT PackageLicenseConcluded: MIT PackageCopyrightText: NOASSERTION PackageSummary: The JSON Schema meta-schemas and vocabularies, exposed as a Registry -ExternalRef: PACKAGE-MANAGER purl pkg:pypi/jsonschema-specifications@2023.11.1 -ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:jsonschema-specifications:2023.11.1:*:*:*:*:*:*:* +ExternalRef: PACKAGE-MANAGER purl pkg:pypi/jsonschema-specifications@2023.11.2 +ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:jsonschema-specifications:2023.11.2:*:*:*:*:*:*:* ##### PackageName: referencing SPDXID: SPDXRef-Package-45-referencing -PackageVersion: 0.31.0 +PackageVersion: 0.31.1 PrimaryPackagePurpose: LIBRARY PackageSupplier: Person: Julian Berman -PackageDownloadLocation: https://pypi.org/project/referencing/0.31.0 +PackageDownloadLocation: https://pypi.org/project/referencing/0.31.1 FilesAnalyzed: false PackageLicenseDeclared: MIT PackageLicenseConcluded: MIT PackageCopyrightText: NOASSERTION PackageSummary: JSON Referencing + Python -ExternalRef: PACKAGE-MANAGER purl pkg:pypi/referencing@0.31.0 -ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:referencing:0.31.0:*:*:*:*:*:*:* +ExternalRef: PACKAGE-MANAGER purl pkg:pypi/referencing@0.31.1 +ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:referencing:0.31.1:*:*:*:*:*:*:* ##### PackageName: rpds-py SPDXID: SPDXRef-Package-46-rpds-py -PackageVersion: 0.13.1 +PackageVersion: 0.13.2 PrimaryPackagePurpose: LIBRARY PackageSupplier: Person: Julian Berman -PackageDownloadLocation: https://pypi.org/project/rpds-py/0.13.1 +PackageDownloadLocation: https://pypi.org/project/rpds-py/0.13.2 FilesAnalyzed: false PackageLicenseDeclared: MIT PackageLicenseConcluded: MIT PackageCopyrightText: NOASSERTION PackageSummary: Python bindings to Rust's persistent data structures (rpds) -ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rpds-py@0.13.1 -ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.13.1:*:*:*:*:*:*:* +ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rpds-py@0.13.2 +ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.13.2:*:*:*:*:*:*:* ##### PackageName: lib4sbom