{
"SPDXID": "SPDXRef-DOCUMENT",
"creationInfo": {
"created": "2024-08-06T21:02:33Z",
"creators": [
"Person: Python Release Managers",
"Tool: ReleaseTools-ad2d64fb8d7738e9d2a4802dbe8d4cb5f180a21c"
],
"licenseListVersion": "3.22"
},
"dataLicense": "CC0-1.0",
"documentNamespace": "
https://www.python.org/ftp/python/3.12.5/python-3.12.5-embed-amd64.zip.spdx.json",
"files": [],
"name": "CPython SBOM",
"packages": [
{
"SPDXID": "SPDXRef-PACKAGE-bzip2",
"checksums": [
{
"algorithm": "SHA256",
"checksumValue": "ab8d1b0cc087c20d4c32c0e4fcf7d0c733a95da12cedc6d63b3f0a9af07427e2"
}
],
"downloadLocation": "
https://github.com/python/cpython-source-deps/archive/refs/tags/bzip2-1.0.8.tar.gz",
"externalRefs": [
{
"referenceCategory": "SECURITY",
"referenceLocator": "cpe:2.3:a:bzip:bzip2:1.0.8:*:*:*:*:*:*:*",
"referenceType": "cpe23Type"
}
],
"licenseConcluded": "NOASSERTION",
"name": "bzip2",
"primaryPackagePurpose": "LIBRARY",
"supplier": "Organization: Python Software Foundation",
"versionInfo": "1.0.8"
},
{
"SPDXID": "SPDXRef-PACKAGE-cpython",
"checksums": [
{
"algorithm": "SHA256",
"checksumValue": "54d4a758fbc87bd425a32b2f390077e6e8c2c0155d9907739240322ee84e44ab"
}
],
"downloadLocation": "
https://www.python.org/ftp/python/3.12.5/python-3.12.5-embed-amd64.zip",
"externalRefs": [
{
"referenceCategory": "SECURITY",
"referenceLocator": "cpe:2.3:a:python:python:3.12.5:*:*:*:*:*:*:*",
"referenceType": "cpe23Type"
}
],
"licenseConcluded": "PSF-2.0",
"name": "CPython",
"originator": "Organization: Python Software Foundation",
"packageFileName": "python-3.12.5-embed-amd64.zip",
"primaryPackagePurpose": "LIBRARY",
"supplier": "Organization: Python Software Foundation",
"versionInfo": "3.12.5"
},
{
"SPDXID": "SPDXRef-PACKAGE-expat",
"checksums": [
{
"algorithm": "SHA256",
"checksumValue": "d4cf38d26e21a56654ffe4acd9cd5481164619626802328506a2869afab29ab3"
}
],
"downloadLocation": "
https://github.com/libexpat/libexpat/releases/download/R_2_6_2/expat-2.6.2.tar.gz",
"externalRefs": [
{
"referenceCategory": "SECURITY",
"referenceLocator": "cpe:2.3:a:libexpat_project:libexpat:2.6.2:*:*:*:*:*:*:*",
"referenceType": "cpe23Type"
}
],
"licenseConcluded": "NOASSERTION",
"name": "expat",
"originator": "Organization: Expat development team",
"primaryPackagePurpose": "LIBRARY",
"supplier": "Organization: Python Software Foundation",
"versionInfo": "2.6.2"
},
{
"SPDXID": "SPDXRef-PACKAGE-hacl-star",
"checksums": [
{
"algorithm": "SHA256",
"checksumValue": "e31e4ca10da91c585793c0eaf1b98aee3cb43e3a58d3d8d478593e5a6bd82927"
}
],
"downloadLocation": "
https://github.com/hacl-star/hacl-star/archive/bb3d0dc8d9d15a5cd51094d5b69e70aa09005ff0.zip",
"externalRefs": [
{
"referenceCategory": "SECURITY",
"referenceLocator": "cpe:2.3:a:hacl-star:hacl-star:bb3d0dc8d9d15a5cd51094d5b69e70aa09005ff0:*:*:*:*:*:*:*",
"referenceType": "cpe23Type"
}
],
"licenseConcluded": "NOASSERTION",
"name": "hacl-star",
"originator": "Organization: HACL* Developers",
"primaryPackagePurpose": "LIBRARY",
"supplier": "Organization: Python Software Foundation",
"versionInfo": "bb3d0dc8d9d15a5cd51094d5b69e70aa09005ff0"
},
{
"SPDXID": "SPDXRef-PACKAGE-libb2",
"checksums": [
{
"algorithm": "SHA256",
"checksumValue": "53626fddce753c454a3fea581cbbc7fe9bbcf0bc70416d48fdbbf5d87ef6c72e"
}
],
"downloadLocation": "
https://github.com/BLAKE2/libb2/releases/download/v0.98.1/libb2-0.98.1.tar.gz",
"externalRefs": [
{
"referenceCategory": "SECURITY",
"referenceLocator": "cpe:2.3:a:blake2:libb2:0.98.1:*:*:*:*:*:*:*",
"referenceType": "cpe23Type"
}
],
"licenseConcluded": "NOASSERTION",
"name": "libb2",
"originator": "Organization: BLAKE2 - fast secure hashing",
"primaryPackagePurpose": "LIBRARY",
"supplier": "Organization: Python Software Foundation",
"versionInfo": "0.98.1"
},
{
"SPDXID": "SPDXRef-PACKAGE-libffi",
"checksums": [
{
"algorithm": "SHA256",
"checksumValue": "9d802681adfea27d84cae0487a785fb9caa925bdad44c401b364c59ab2b8edda"
}
],
"downloadLocation": "
https://github.com/python/cpython-source-deps/archive/refs/tags/libffi-3.4.4.tar.gz",
"externalRefs": [
{
"referenceCategory": "SECURITY",
"referenceLocator": "cpe:2.3:a:libffi_project:libffi:3.4.4:*:*:*:*:*:*:*",
"referenceType": "cpe23Type"
}
],
"licenseConcluded": "NOASSERTION",
"name": "libffi",
"primaryPackagePurpose": "LIBRARY",
"supplier": "Organization: Python Software Foundation",
"versionInfo": "3.4.4"
},
{
"SPDXID": "SPDXRef-PACKAGE-macholib",
"checksums": [
{
"algorithm": "SHA256",
"checksumValue": "c76f268f5054024e962f2515a0e522baf85313064f6740d80375afc850787a38"
}
],
"downloadLocation": "
https://files.pythonhosted.org/packages/ec/57/f0a712efc3ed982cf4038a3cee172057303b9be914c32c93b2fbec27f785/macholib-1.0.tar.gz",
"externalRefs": [
{
"referenceCategory": "PACKAGE_MANAGER",
"referenceLocator": "pkg:pypi/
[email protected]",
"referenceType": "purl"
}
],
"licenseConcluded": "NOASSERTION",
"name": "macholib",
"originator": "Person: Ronald Oussoren (
[email protected])",
"primaryPackagePurpose": "LIBRARY",
"supplier": "Organization: Python Software Foundation",
"versionInfo": "1.0"
},
{
"SPDXID": "SPDXRef-PACKAGE-mpdecimal",
"checksums": [
{
"algorithm": "SHA256",
"checksumValue": "9f9cd4c041f99b5c49ffb7b59d9f12d95b683d88585608aa56a6307667b2b21f"
}
],
"downloadLocation": "
https://www.bytereef.org/software/mpdecimal/releases/mpdecimal-2.5.1.tar.gz",
"externalRefs": [
{
"referenceCategory": "SECURITY",
"referenceLocator": "cpe:2.3:a:bytereef:mpdecimal:2.5.1:*:*:*:*:*:*:*",
"referenceType": "cpe23Type"
}
],
"licenseConcluded": "NOASSERTION",
"name": "mpdecimal",
"originator": "Organization: bytereef.org",
"primaryPackagePurpose": "LIBRARY",
"supplier": "Organization: Python Software Foundation",
"versionInfo": "2.5.1"
},
{
"SPDXID": "SPDXRef-PACKAGE-openssl",
"checksums": [
{
"algorithm": "SHA256",
"checksumValue": "e6a77c273ebb284fedd8ea19b081fce74a9455936ffd47215f7c24713e2614b2"
}
],
"downloadLocation": "
https://github.com/python/cpython-source-deps/archive/refs/tags/openssl-3.0.13.tar.gz",
"externalRefs": [
{
"referenceCategory": "SECURITY",
"referenceLocator": "cpe:2.3:a:openssl:openssl:3.0.13:*:*:*:*:*:*:*",
"referenceType": "cpe23Type"
}
],
"licenseConcluded": "NOASSERTION",
"name": "openssl",
"primaryPackagePurpose": "LIBRARY",
"supplier": "Organization: Python Software Foundation",
"versionInfo": "3.0.13"
},
{
"SPDXID": "SPDXRef-PACKAGE-sqlite",
"checksums": [
{
"algorithm": "SHA256",
"checksumValue": "730e4a3efd6a63828bee499940fb13acc2a32c182502ce8a1d970387895d0504"
}
],
"downloadLocation": "
https://github.com/python/cpython-source-deps/archive/refs/tags/sqlite-3.45.3.0.tar.gz",
"externalRefs": [
{
"referenceCategory": "SECURITY",
"referenceLocator": "cpe:2.3:a:sqlite:sqlite:3.45.3.0:*:*:*:*:*:*:*",
"referenceType": "cpe23Type"
}
],
"licenseConcluded": "NOASSERTION",
"name": "sqlite",
"primaryPackagePurpose": "LIBRARY",
"supplier": "Organization: Python Software Foundation",
"versionInfo": "3.45.3.0"
},
{
"SPDXID": "SPDXRef-PACKAGE-tcl-core",
"checksums": [
{
"algorithm": "SHA256",
"checksumValue": "6e33a88f116822167734cd72b693b5d30ced130a3cae6dc2ff696042f993bb42"
}
],
"downloadLocation": "
https://github.com/python/cpython-source-deps/archive/refs/tags/tcl-core-8.6.13.0.tar.gz",
"externalRefs": [
{
"referenceCategory": "SECURITY",
"referenceLocator": "cpe:2.3:a:tcl_tk:tcl_tk:8.6.13.0:*:*:*:*:*:*:*",
"referenceType": "cpe23Type"
}
],
"licenseConcluded": "NOASSERTION",
"name": "tcl-core",
"primaryPackagePurpose": "LIBRARY",
"supplier": "Organization: Python Software Foundation",
"versionInfo": "8.6.13.0"
},
{
"SPDXID": "SPDXRef-PACKAGE-tix",
"checksums": [
{
"algorithm": "SHA256",
"checksumValue": "f7b21d115867a41ae5fd7c635a4c234d3ca25126c3661eb36028c6e25601f85e"
}
],
"downloadLocation": "
https://github.com/python/cpython-source-deps/archive/refs/tags/tix-8.4.3.6.tar.gz",
"externalRefs": [
{
"referenceCategory": "SECURITY",
"referenceLocator": "cpe:2.3:a:tcl_tk:tcl_tk:8.4.3.6:*:*:*:*:*:*:*",
"referenceType": "cpe23Type"
}
],
"licenseConcluded": "NOASSERTION",
"name": "tix",
"primaryPackagePurpose": "LIBRARY",
"supplier": "Organization: Python Software Foundation",
"versionInfo": "8.4.3.6"
},
{
"SPDXID": "SPDXRef-PACKAGE-tk",
"checksums": [
{
"algorithm": "SHA256",
"checksumValue": "896c1f488bdd0159091bd5cce124b756dfdffa4a5350b7fd4d7d8e48421089a4"
}
],
"downloadLocation": "
https://github.com/python/cpython-source-deps/archive/refs/tags/tk-8.6.13.0.tar.gz",
"externalRefs": [
{
"referenceCategory": "SECURITY",
"referenceLocator": "cpe:2.3:a:tcl_tk:tcl_tk:8.6.13.0:*:*:*:*:*:*:*",
"referenceType": "cpe23Type"
}
],
"licenseConcluded": "NOASSERTION",
"name": "tk",
"primaryPackagePurpose": "LIBRARY",
"supplier": "Organization: Python Software Foundation",
"versionInfo": "8.6.13.0"
},
{
"SPDXID": "SPDXRef-PACKAGE-xz",
"checksums": [
{
"algorithm": "SHA256",
"checksumValue": "a15c168e39e87d750c3dc766edc7f19bdda57dacf01e509678467eace91ad282"
}
],
"downloadLocation": "
https://github.com/python/cpython-source-deps/archive/refs/tags/xz-5.2.5.tar.gz",
"externalRefs": [
{
"referenceCategory": "SECURITY",
"referenceLocator": "cpe:2.3:a:tukaani:xz:5.2.5:*:*:*:*:*:*:*",
"referenceType": "cpe23Type"
}
],
"licenseConcluded": "NOASSERTION",
"name": "xz",
"primaryPackagePurpose": "LIBRARY",
"supplier": "Organization: Python Software Foundation",
"versionInfo": "5.2.5"
},
{
"SPDXID": "SPDXRef-PACKAGE-zlib",
"checksums": [
{
"algorithm": "SHA256",
"checksumValue": "e3f3fb32564952006eb18b091ca8464740e5eca29d328cfb0b2da22768e0b638"
}
],
"downloadLocation": "
https://github.com/python/cpython-source-deps/archive/refs/tags/zlib-1.3.1.tar.gz",
"externalRefs": [
{
"referenceCategory": "SECURITY",
"referenceLocator": "cpe:2.3:a:zlib:zlib:1.3.1:*:*:*:*:*:*:*",
"referenceType": "cpe23Type"
}
],
"licenseConcluded": "NOASSERTION",
"name": "zlib",
"primaryPackagePurpose": "LIBRARY",
"supplier": "Organization: Python Software Foundation",
"versionInfo": "1.3.1"
}
],
"relationships": [
{
"relatedSpdxElement": "SPDXRef-PACKAGE-bzip2",
"relationshipType": "DEPENDS_ON",
"spdxElementId": "SPDXRef-PACKAGE-cpython"
},
{
"relatedSpdxElement": "SPDXRef-PACKAGE-cpython",
"relationshipType": "DESCRIBES",
"spdxElementId": "SPDXRef-DOCUMENT"
},
{
"relatedSpdxElement": "SPDXRef-PACKAGE-expat",
"relationshipType": "DEPENDS_ON",
"spdxElementId": "SPDXRef-PACKAGE-cpython"
},
{
"relatedSpdxElement": "SPDXRef-PACKAGE-hacl-star",
"relationshipType": "DEPENDS_ON",
"spdxElementId": "SPDXRef-PACKAGE-cpython"
},
{
"relatedSpdxElement": "SPDXRef-PACKAGE-libb2",
"relationshipType": "DEPENDS_ON",
"spdxElementId": "SPDXRef-PACKAGE-cpython"
},
{
"relatedSpdxElement": "SPDXRef-PACKAGE-libffi",
"relationshipType": "DEPENDS_ON",
"spdxElementId": "SPDXRef-PACKAGE-cpython"
},
{
"relatedSpdxElement": "SPDXRef-PACKAGE-macholib",
"relationshipType": "DEPENDS_ON",
"spdxElementId": "SPDXRef-PACKAGE-cpython"
},
{
"relatedSpdxElement": "SPDXRef-PACKAGE-mpdecimal",
"relationshipType": "DEPENDS_ON",
"spdxElementId": "SPDXRef-PACKAGE-cpython"
},
{
"relatedSpdxElement": "SPDXRef-PACKAGE-openssl",
"relationshipType": "DEPENDS_ON",
"spdxElementId": "SPDXRef-PACKAGE-cpython"
},
{
"relatedSpdxElement": "SPDXRef-PACKAGE-sqlite",
"relationshipType": "DEPENDS_ON",
"spdxElementId": "SPDXRef-PACKAGE-cpython"
},
{
"relatedSpdxElement": "SPDXRef-PACKAGE-tcl-core",
"relationshipType": "DEPENDS_ON",
"spdxElementId": "SPDXRef-PACKAGE-cpython"
},
{
"relatedSpdxElement": "SPDXRef-PACKAGE-tix",
"relationshipType": "DEPENDS_ON",
"spdxElementId": "SPDXRef-PACKAGE-cpython"
},
{
"relatedSpdxElement": "SPDXRef-PACKAGE-tk",
"relationshipType": "DEPENDS_ON",
"spdxElementId": "SPDXRef-PACKAGE-cpython"
},
{
"relatedSpdxElement": "SPDXRef-PACKAGE-xz",
"relationshipType": "DEPENDS_ON",
"spdxElementId": "SPDXRef-PACKAGE-cpython"
},
{
"relatedSpdxElement": "SPDXRef-PACKAGE-zlib",
"relationshipType": "DEPENDS_ON",
"spdxElementId": "SPDXRef-PACKAGE-cpython"
}
],
"spdxVersion": "SPDX-2.3"
}