Perseus SBOM (Software Bill of Materials)

June 20, 2026 · View on GitHub

For Federal Procurement Compliance

Package: perseus-ctx v1.0.8 License: MIT Repository: https://github.com/Perseus-Computing-LLC/perseus Language: Python 3.10+ Format: SPDX Lite / NTIA Minimum Elements


SBOM Metadata

FieldValue
SupplierPerseus Computing LLC
Supplier Contactperseus@perseus.observer
SBOM AuthorPerseus Computing LLC
Timestamp2026-06-20T14:08:00-05:00
SBOM FormatNTIA Minimum Elements + SPDX Lite

Dependency Inventory

Runtime Dependencies

PackageVersionLicenseType
pyyaml>=6.0.1MITDirect

Optional Dependencies

PackageVersionLicenseTypeRequired For
mcp* (latest)MITOptionalMCP server mode

Dev Dependencies (not in production)

PackageVersionLicenseType
pytest>=8.0.0MITDev
coverage*Apache-2.0Dev
hypothesis*MPL-2.0Dev

Python Runtime

ComponentMinimum Version
Python3.10

Supply Chain Summary

MetricValue
Total direct dependencies (runtime)1
Total transitive dependencies0 (pyyaml has no Python deps)
Total optional dependencies1 (mcp)
Dependencies with known CVEs0
Copyleft licenses (GPL/AGPL)0
Non-MIT/BSD licenses0
Foreign-owned dependencies0

Build & Distribution

FieldValue
Build systemsetuptools >=68
Wheel published toPyPI
Build reproducibilityrequirements.txt lockable
Code signingNot implemented

Security Assessment

  • All dependencies are MIT-licensed — no copyleft risk
  • pyyaml is widely audited, maintained, and CVE-tracked
  • YAML parsing uses yaml.safe_load() — no arbitrary code execution risk
  • No code signing on PyPI releases (TODO)
  • No SLSA provenance attestations (TODO for FedRAMP)

NTIA Minimum Elements Checklist

  • Supplier name: Perseus Computing LLC
  • Component name: perseus-ctx
  • Version string: 1.0.8
  • Unique identifier: pypi:perseus-ctx@1.0.8
  • Dependency relationship: listed above
  • SBOM author: Perseus Computing LLC
  • Timestamp: included