Skip to content

Commit 17921d2

Browse files
chore: update SBOM for Python 3.12 (#5268)
Co-authored-by: GitHub <[email protected]>
1 parent 9a84155 commit 17921d2

File tree

2 files changed

+66
-75
lines changed

2 files changed

+66
-75
lines changed

sbom/cve-bin-tool-py3.12.json

Lines changed: 32 additions & 41 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:ceaa1b8c-bf44-4cb8-97ea-c548156df63a",
5+
"serialNumber": "urn:uuid:7cbb7314-5643-4a0a-af4a-a3de69de0d0e",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-08-04T00:53:00Z",
8+
"timestamp": "2025-08-11T00:44:59Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -1004,7 +1004,7 @@
10041004
"type": "library",
10051005
"bom-ref": "14-cvss",
10061006
"name": "cvss",
1007-
"version": "3.4",
1007+
"version": "3.6",
10081008
"supplier": {
10091009
"name": "Stanislav Red Hat Product Security",
10101010
"contact": [
@@ -1013,12 +1013,12 @@
10131013
}
10141014
]
10151015
},
1016-
"cpe": "cpe:2.3:a:stanislav_red_hat_product_security:cvss:3.4:*:*:*:*:*:*:*",
1016+
"cpe": "cpe:2.3:a:stanislav_red_hat_product_security:cvss:3.6:*:*:*:*:*:*:*",
10171017
"description": "CVSS2/3/4 library with interactive calculator for Python 2 and Python 3",
10181018
"hashes": [
10191019
{
10201020
"alg": "SHA-256",
1021-
"content": "d9950613758e60820f7fac37ca5f35158712f8f2ea4f6629858a60c4984fe4ef"
1021+
"content": "e342c6ad9c7eb69d2aebbbc2768a03cabd57eb947c806e145de5b936219833ea"
10221022
}
10231023
],
10241024
"licenses": [
@@ -1037,7 +1037,7 @@
10371037
"comment": "Home page for project"
10381038
},
10391039
{
1040-
"url": "https://pypi.org/project/cvss/3.4/#files",
1040+
"url": "https://pypi.org/project/cvss/3.6/#files",
10411041
"type": "distribution",
10421042
"comment": "Download location for component"
10431043
},
@@ -1058,11 +1058,11 @@
10581058
"type": "build-system"
10591059
}
10601060
],
1061-
"purl": "pkg:pypi/cvss@3.4",
1061+
"purl": "pkg:pypi/cvss@3.6",
10621062
"properties": [
10631063
{
10641064
"name": "release_date",
1065-
"value": "2025-02-11T17:28:21Z"
1065+
"value": "2025-08-04T10:50:12Z"
10661066
},
10671067
{
10681068
"name": "language",
@@ -3192,7 +3192,7 @@
31923192
"type": "library",
31933193
"bom-ref": "48-rpds-py",
31943194
"name": "rpds-py",
3195-
"version": "0.26.0",
3195+
"version": "0.27.0",
31963196
"supplier": {
31973197
"name": "Julian Berman",
31983198
"contact": [
@@ -3201,21 +3201,12 @@
32013201
}
32023202
]
32033203
},
3204-
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.26.0:*:*:*:*:*:*:*",
3204+
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.27.0:*:*:*:*:*:*:*",
32053205
"description": "Python bindings to Rust's persistent data structures (rpds)",
32063206
"hashes": [
32073207
{
32083208
"alg": "SHA-256",
3209-
"content": "4c70c70f9169692b36307a95f3d8c0a9fcd79f7b4a383aad5eaa0e9718b79b37"
3210-
}
3211-
],
3212-
"licenses": [
3213-
{
3214-
"license": {
3215-
"id": "MIT",
3216-
"url": "https://opensource.org/license/mit/",
3217-
"acknowledgement": "concluded"
3218-
}
3209+
"content": "130c1ffa5039a333f5926b09e346ab335f0d4ec393b030a18549a7c7e7c2cea4"
32193210
}
32203211
],
32213212
"externalReferences": [
@@ -3225,7 +3216,7 @@
32253216
"comment": "Home page for project"
32263217
},
32273218
{
3228-
"url": "https://pypi.org/project/rpds-py/0.26.0/#files",
3219+
"url": "https://pypi.org/project/rpds-py/0.27.0/#files",
32293220
"type": "distribution",
32303221
"comment": "Download location for component"
32313222
},
@@ -3254,11 +3245,11 @@
32543245
"type": "other"
32553246
}
32563247
],
3257-
"purl": "pkg:pypi/rpds-py@0.26.0",
3248+
"purl": "pkg:pypi/rpds-py@0.27.0",
32583249
"properties": [
32593250
{
32603251
"name": "release_date",
3261-
"value": "2025-07-01T15:53:40Z"
3252+
"value": "2025-08-07T08:23:06Z"
32623253
},
32633254
{
32643255
"name": "language",
@@ -3686,16 +3677,16 @@
36863677
"type": "library",
36873678
"bom-ref": "56-packageurl-python",
36883679
"name": "packageurl-python",
3689-
"version": "0.17.3",
3680+
"version": "0.17.5",
36903681
"supplier": {
36913682
"name": "the purl authors"
36923683
},
3693-
"cpe": "cpe:2.3:a:the_purl_authors:packageurl-python:0.17.3:*:*:*:*:*:*:*",
3684+
"cpe": "cpe:2.3:a:the_purl_authors:packageurl-python:0.17.5:*:*:*:*:*:*:*",
36943685
"description": "A purl aka. Package URL parser and builder",
36953686
"hashes": [
36963687
{
36973688
"alg": "SHA-256",
3698-
"content": "f51b5aab570159f07258c8e998e9972ff3bf060da16b7334a42bd9f9737777d9"
3689+
"content": "f0e55452ab37b5c192c443de1458e3f3b4d8ac27f747df6e8c48adeab081d321"
36993690
}
37003691
],
37013692
"licenses": [
@@ -3714,16 +3705,16 @@
37143705
"comment": "Home page for project"
37153706
},
37163707
{
3717-
"url": "https://pypi.org/project/packageurl-python/0.17.3/#files",
3708+
"url": "https://pypi.org/project/packageurl-python/0.17.5/#files",
37183709
"type": "distribution",
37193710
"comment": "Download location for component"
37203711
}
37213712
],
3722-
"purl": "pkg:pypi/[email protected].3",
3713+
"purl": "pkg:pypi/[email protected].5",
37233714
"properties": [
37243715
{
37253716
"name": "release_date",
3726-
"value": "2025-08-01T03:24:33Z"
3717+
"value": "2025-08-06T14:08:19Z"
37273718
},
37283719
{
37293720
"name": "language",
@@ -4204,7 +4195,7 @@
42044195
"type": "library",
42054196
"bom-ref": "64-python-gnupg",
42064197
"name": "python-gnupg",
4207-
"version": "0.5.4",
4198+
"version": "0.5.5",
42084199
"supplier": {
42094200
"name": "Vinay Sajip",
42104201
"contact": [
@@ -4213,12 +4204,12 @@
42134204
}
42144205
]
42154206
},
4216-
"cpe": "cpe:2.3:a:vinay_sajip:python-gnupg:0.5.4:*:*:*:*:*:*:*",
4207+
"cpe": "cpe:2.3:a:vinay_sajip:python-gnupg:0.5.5:*:*:*:*:*:*:*",
42174208
"description": "A wrapper for the Gnu Privacy Guard (GPG or GnuPG)",
42184209
"hashes": [
42194210
{
42204211
"alg": "SHA-256",
4221-
"content": "40ce25cde9df29af91fe931ce9df3ce544e14a37f62b13ca878c897217b2de6c"
4212+
"content": "51fa7b8831ff0914bc73d74c59b99c613de7247b91294323c39733bb85ac3fc1"
42224213
}
42234214
],
42244215
"licenses": [
@@ -4237,7 +4228,7 @@
42374228
"comment": "Home page for project"
42384229
},
42394230
{
4240-
"url": "https://pypi.org/project/python-gnupg/0.5.4/#files",
4231+
"url": "https://pypi.org/project/python-gnupg/0.5.5/#files",
42414232
"type": "distribution",
42424233
"comment": "Download location for component"
42434234
},
@@ -4254,11 +4245,11 @@
42544245
"type": "issue-tracker"
42554246
}
42564247
],
4257-
"purl": "pkg:pypi/[email protected].4",
4248+
"purl": "pkg:pypi/[email protected].5",
42584249
"properties": [
42594250
{
42604251
"name": "release_date",
4261-
"value": "2025-01-07T11:58:32Z"
4252+
"value": "2025-08-04T19:26:54Z"
42624253
},
42634254
{
42644255
"name": "language",
@@ -4344,7 +4335,7 @@
43444335
"type": "library",
43454336
"bom-ref": "66-charset-normalizer",
43464337
"name": "charset-normalizer",
4347-
"version": "3.4.2",
4338+
"version": "3.4.3",
43484339
"supplier": {
43494340
"name": "Ahmed R .",
43504341
"contact": [
@@ -4353,12 +4344,12 @@
43534344
}
43544345
]
43554346
},
4356-
"cpe": "cpe:2.3:a:ahmed_r.:charset-normalizer:3.4.2:*:*:*:*:*:*:*",
4347+
"cpe": "cpe:2.3:a:ahmed_r.:charset-normalizer:3.4.3:*:*:*:*:*:*:*",
43574348
"description": "The Real First Universal Charset Detector. Open, modern and actively maintained alternative to Chardet.",
43584349
"hashes": [
43594350
{
43604351
"alg": "SHA-256",
4361-
"content": "7c48ed483eb946e6c04ccbe02c6b4d1d48e51944b6db70f697e089c193404941"
4352+
"content": "fb7f67a1bfa6e40b438170ebdc8158b78dc465a5a67b6dde178a46987b244a72"
43624353
}
43634354
],
43644355
"licenses": [
@@ -4372,7 +4363,7 @@
43724363
],
43734364
"externalReferences": [
43744365
{
4375-
"url": "https://pypi.org/project/charset-normalizer/3.4.2/#files",
4366+
"url": "https://pypi.org/project/charset-normalizer/3.4.3/#files",
43764367
"type": "distribution",
43774368
"comment": "Download location for component"
43784369
},
@@ -4393,11 +4384,11 @@
43934384
"type": "issue-tracker"
43944385
}
43954386
],
4396-
"purl": "pkg:pypi/[email protected].2",
4387+
"purl": "pkg:pypi/[email protected].3",
43974388
"properties": [
43984389
{
43994390
"name": "release_date",
4400-
"value": "2025-05-02T08:31:46Z"
4391+
"value": "2025-08-09T07:55:36Z"
44014392
},
44024393
{
44034394
"name": "language",

0 commit comments

Comments
 (0)