diff --git a/sbom/cve-bin-tool-py3.11.json b/sbom/cve-bin-tool-py3.11.json index c01ebca2f6..7a438ba112 100644 --- a/sbom/cve-bin-tool-py3.11.json +++ b/sbom/cve-bin-tool-py3.11.json @@ -2,10 +2,10 @@ "$schema": "http://cyclonedx.org/schema/bom-1.4.schema.json", "bomFormat": "CycloneDX", "specVersion": "1.4", - "serialNumber": "urn:uuid806fabec-b518-41f4-b67b-7274576fee0b", + "serialNumber": "urn:uuid56ffe157-1aa8-4626-b95d-f0203759282e", "version": 1, "metadata": { - "timestamp": "2023-05-22T00:27:03Z", + "timestamp": "2023-05-29T00:26:45Z", "tools": [ { "name": "sbom4python", @@ -1377,7 +1377,7 @@ "type": "library", "bom-ref": "37-google-auth", "name": "google-auth", - "version": "2.18.1", + "version": "2.19.0", "supplier": { "name": "Google Cloud Platform", "contact": [ @@ -1386,7 +1386,7 @@ } ] }, - "cpe": "cpe:2.3:a:google_cloud_platform:google-auth:2.18.1:*:*:*:*:*:*:*", + "cpe": "cpe:2.3:a:google_cloud_platform:google-auth:2.19.0:*:*:*:*:*:*:*", "description": "Google Authentication Library", "licenses": [ { @@ -1403,12 +1403,12 @@ "comment": "Home page for project" }, { - "url": "https://pypi.org/project/google-auth/2.18.1", + "url": "https://pypi.org/project/google-auth/2.19.0", "type": "distribution", "comment": "Download location for component" } ], - "purl": "pkg:pypi/google-auth@2.18.1", + "purl": "pkg:pypi/google-auth@2.19.0", "properties": [ { "name": "License Comments", @@ -1420,7 +1420,7 @@ "type": "library", "bom-ref": "38-cachetools", "name": "cachetools", - "version": "5.3.0", + "version": "5.3.1", "supplier": { "name": "Thomas Kemmer", "contact": [ @@ -1429,7 +1429,7 @@ } ] }, - "cpe": "cpe:2.3:a:thomas_kemmer:cachetools:5.3.0:*:*:*:*:*:*:*", + "cpe": "cpe:2.3:a:thomas_kemmer:cachetools:5.3.1:*:*:*:*:*:*:*", "description": "Extensible memoizing collections and decorators", "licenses": [ { @@ -1446,18 +1446,18 @@ "comment": "Home page for project" }, { - "url": "https://pypi.org/project/cachetools/5.3.0", + "url": "https://pypi.org/project/cachetools/5.3.1", "type": "distribution", "comment": "Download location for component" } ], - "purl": "pkg:pypi/cachetools@5.3.0" + "purl": "pkg:pypi/cachetools@5.3.1" }, { "type": "library", "bom-ref": "39-urllib3", "name": "urllib3", - "version": "1.26.15", + "version": "1.26.16", "supplier": { "name": "Andrey Petrov", "contact": [ @@ -1466,7 +1466,7 @@ } ] }, - "cpe": "cpe:2.3:a:andrey_petrov:urllib3:1.26.15:*:*:*:*:*:*:*", + "cpe": "cpe:2.3:a:andrey_petrov:urllib3:1.26.16:*:*:*:*:*:*:*", "description": "HTTP library with thread-safe connection pooling, file post, and more.", "licenses": [ { @@ -1483,12 +1483,12 @@ "comment": "Home page for project" }, { - "url": "https://pypi.org/project/urllib3/1.26.15", + "url": "https://pypi.org/project/urllib3/1.26.16", "type": "distribution", "comment": "Download location for component" } ], - "purl": "pkg:pypi/urllib3@1.26.15" + "purl": "pkg:pypi/urllib3@1.26.16" }, { "type": "library", @@ -1914,7 +1914,7 @@ "type": "library", "bom-ref": "51-requests", "name": "requests", - "version": "2.30.0", + "version": "2.31.0", "supplier": { "name": "Kenneth Reitz", "contact": [ @@ -1923,7 +1923,7 @@ } ] }, - "cpe": "cpe:2.3:a:kenneth_reitz:requests:2.30.0:*:*:*:*:*:*:*", + "cpe": "cpe:2.3:a:kenneth_reitz:requests:2.31.0:*:*:*:*:*:*:*", "description": "Python HTTP for Humans.", "licenses": [ { @@ -1940,12 +1940,12 @@ "comment": "Home page for project" }, { - "url": "https://pypi.org/project/requests/2.30.0", + "url": "https://pypi.org/project/requests/2.31.0", "type": "distribution", "comment": "Download location for component" } ], - "purl": "pkg:pypi/requests@2.30.0", + "purl": "pkg:pypi/requests@2.31.0", "properties": [ { "name": "License Comments", diff --git a/sbom/cve-bin-tool-py3.11.spdx b/sbom/cve-bin-tool-py3.11.spdx index 14c78a136d..1f82e5ba50 100644 --- a/sbom/cve-bin-tool-py3.11.spdx +++ b/sbom/cve-bin-tool-py3.11.spdx @@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3 DataLicense: CC0-1.0 SPDXID: SPDXRef-DOCUMENT DocumentName: Python-cve-bin-tool -DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-9a5f711c-9dfa-43c2-996c-89f569e12c7e +DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-7eed8c47-89f1-488a-8a83-07756294d0c8 LicenseListVersion: 3.20 Creator: Tool: sbom4python-0.9.1 -Created: 2023-05-22T00:25:52Z +Created: 2023-05-29T00:25:37Z CreatorComment: This document has been automatically generated. ##### @@ -599,10 +599,10 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:craig_citro:google-apitools:0.5.32:*:* PackageName: google-auth SPDXID: SPDXRef-Package-37-google-auth -PackageVersion: 2.18.1 +PackageVersion: 2.19.0 PrimaryPackagePurpose: LIBRARY PackageSupplier: Organization: Google Cloud Platform (googleapis-packages@google.com) -PackageDownloadLocation: https://pypi.org/project/google-auth/2.18.1 +PackageDownloadLocation: https://pypi.org/project/google-auth/2.19.0 FilesAnalyzed: false PackageHomePage: https://github.com/googleapis/google-auth-library-python PackageLicenseDeclared: NOASSERTION @@ -610,40 +610,40 @@ PackageLicenseConcluded: Apache-2.0 PackageLicenseComments: google-auth declares Apache 2.0 which is not currently a valid SPDX License identifier or expression. PackageCopyrightText: NOASSERTION PackageSummary: Google Authentication Library -ExternalRef: PACKAGE-MANAGER purl pkg:pypi/google-auth@2.18.1 -ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_cloud_platform:google-auth:2.18.1:*:*:*:*:*:*:* +ExternalRef: PACKAGE-MANAGER purl pkg:pypi/google-auth@2.19.0 +ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_cloud_platform:google-auth:2.19.0:*:*:*:*:*:*:* ##### PackageName: cachetools SPDXID: SPDXRef-Package-38-cachetools -PackageVersion: 5.3.0 +PackageVersion: 5.3.1 PrimaryPackagePurpose: LIBRARY PackageSupplier: Person: Thomas Kemmer (tkemmer@computer.org) -PackageDownloadLocation: https://pypi.org/project/cachetools/5.3.0 +PackageDownloadLocation: https://pypi.org/project/cachetools/5.3.1 FilesAnalyzed: false PackageHomePage: https://github.com/tkem/cachetools/ PackageLicenseDeclared: MIT PackageLicenseConcluded: MIT PackageCopyrightText: NOASSERTION PackageSummary: Extensible memoizing collections and decorators -ExternalRef: PACKAGE-MANAGER purl pkg:pypi/cachetools@5.3.0 -ExternalRef: SECURITY cpe23Type cpe:2.3:a:thomas_kemmer:cachetools:5.3.0:*:*:*:*:*:*:* +ExternalRef: PACKAGE-MANAGER purl pkg:pypi/cachetools@5.3.1 +ExternalRef: SECURITY cpe23Type cpe:2.3:a:thomas_kemmer:cachetools:5.3.1:*:*:*:*:*:*:* ##### PackageName: urllib3 SPDXID: SPDXRef-Package-39-urllib3 -PackageVersion: 1.26.15 +PackageVersion: 1.26.16 PrimaryPackagePurpose: LIBRARY PackageSupplier: Person: Andrey Petrov (andrey.petrov@shazow.net) -PackageDownloadLocation: https://pypi.org/project/urllib3/1.26.15 +PackageDownloadLocation: https://pypi.org/project/urllib3/1.26.16 FilesAnalyzed: false PackageHomePage: https://urllib3.readthedocs.io/ PackageLicenseDeclared: MIT PackageLicenseConcluded: MIT PackageCopyrightText: NOASSERTION PackageSummary: HTTP library with thread-safe connection pooling, file post, and more. -ExternalRef: PACKAGE-MANAGER purl pkg:pypi/urllib3@1.26.15 -ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_petrov:urllib3:1.26.15:*:*:*:*:*:*:* +ExternalRef: PACKAGE-MANAGER purl pkg:pypi/urllib3@1.26.16 +ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_petrov:urllib3:1.26.16:*:*:*:*:*:*:* ##### PackageName: monotonic @@ -827,10 +827,10 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julien_danjou:tenacity:8.2.2:*:*:*:*:* PackageName: requests SPDXID: SPDXRef-Package-51-requests -PackageVersion: 2.30.0 +PackageVersion: 2.31.0 PrimaryPackagePurpose: LIBRARY PackageSupplier: Person: Kenneth Reitz (me@kennethreitz.org) -PackageDownloadLocation: https://pypi.org/project/requests/2.30.0 +PackageDownloadLocation: https://pypi.org/project/requests/2.31.0 FilesAnalyzed: false PackageHomePage: https://requests.readthedocs.io PackageLicenseDeclared: NOASSERTION @@ -838,8 +838,8 @@ PackageLicenseConcluded: Apache-2.0 PackageLicenseComments: requests declares Apache 2.0 which is not currently a valid SPDX License identifier or expression. PackageCopyrightText: NOASSERTION PackageSummary: Python HTTP for Humans. -ExternalRef: PACKAGE-MANAGER purl pkg:pypi/requests@2.30.0 -ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:requests:2.30.0:*:*:*:*:*:*:* +ExternalRef: PACKAGE-MANAGER purl pkg:pypi/requests@2.31.0 +ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:requests:2.31.0:*:*:*:*:*:*:* ##### PackageName: certifi