From 8e7c5b3c1de5f2468013fd1af505d427d3f7847e Mon Sep 17 00:00:00 2001 From: GitHub Actions Date: Fri, 29 Dec 2023 22:10:17 +0000 Subject: [PATCH] chore: update SBOM for Python 3.12 --- sbom/dffml-py3.12.json | 16 +++++++++++++--- sbom/dffml-py3.12.spdx | 7 ++++--- 2 files changed, 17 insertions(+), 6 deletions(-) diff --git a/sbom/dffml-py3.12.json b/sbom/dffml-py3.12.json index 5ed43b501d..4de10223f4 100644 --- a/sbom/dffml-py3.12.json +++ b/sbom/dffml-py3.12.json @@ -2,15 +2,15 @@ "$schema": "http://cyclonedx.org/schema/bom-1.5.schema.json", "bomFormat": "CycloneDX", "specVersion": "1.5", - "serialNumber": "urn:uuid:b374cb1b-4c8d-4eb2-a1bf-f85529ffc06a", + "serialNumber": "urn:uuid:c09ca2f6-fca7-4d6f-bfdc-e764a5fb9ebb", "version": 1, "metadata": { - "timestamp": "2023-12-13T16:35:03Z", + "timestamp": "2023-12-29T22:09:58Z", "tools": { "components": [ { "name": "sbom4python", - "version": "0.10.1", + "version": "0.10.2", "type": "application" } ] @@ -37,6 +37,12 @@ }, "cpe": "cpe:2.3:a:john_andersen:dffml:0.4.0:*:*:*:*:*:*:*", "description": "Data Flow Facilitator for Machine Learning", + "hashes": [ + { + "alg": "SHA-1", + "content": "9720e3acb7fb865c74a3be65aaa8d741111477bf" + } + ], "licenses": [ { "license": { @@ -57,6 +63,10 @@ { "name": "language", "value": "Python" + }, + { + "name": "python_version", + "value": "3.12.1" } ] } diff --git a/sbom/dffml-py3.12.spdx b/sbom/dffml-py3.12.spdx index 9a14ba098b..e48e1b0310 100644 --- a/sbom/dffml-py3.12.spdx +++ b/sbom/dffml-py3.12.spdx @@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3 DataLicense: CC0-1.0 SPDXID: SPDXRef-DOCUMENT DocumentName: Python-dffml -DocumentNamespace: http://spdx.org/spdxdocs/Python-dffml-d412cbaf-e2c4-45c6-b5e6-4f2d1c3b0d1f +DocumentNamespace: http://spdx.org/spdxdocs/Python-dffml-d5ccf3fd-2bb8-44c2-aa44-e1e56c5e5272 LicenseListVersion: 3.22 -Creator: Tool: sbom4python-0.10.1 -Created: 2023-12-13T16:35:02Z +Creator: Tool: sbom4python-0.10.2 +Created: 2023-12-29T22:09:56Z CreatorComment: This document has been automatically generated. ##### @@ -16,6 +16,7 @@ PrimaryPackagePurpose: APPLICATION PackageSupplier: Person: John Andersen (john.s.andersen@intel.com) PackageDownloadLocation: https://pypi.org/project/dffml/0.4.0 FilesAnalyzed: false +PackageChecksum: SHA1: 9720e3acb7fb865c74a3be65aaa8d741111477bf PackageLicenseDeclared: MIT PackageLicenseConcluded: MIT PackageCopyrightText: NOASSERTION