Skip to content

Commit 17ee0c2

Browse files
chore: update SBOM for Python 3.10 (#5269)
Co-authored-by: GitHub <[email protected]>
1 parent 61d2db3 commit 17ee0c2

File tree

2 files changed

+66
-75
lines changed

2 files changed

+66
-75
lines changed

sbom/cve-bin-tool-py3.10.json

Lines changed: 32 additions & 41 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:8e5a9ac8-16d3-4348-933c-350d7f690edb",
5+
"serialNumber": "urn:uuid:e5fa14c3-4381-4ce6-92e5-41b46dcbed90",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-08-04T00:53:06Z",
8+
"timestamp": "2025-08-11T00:45:01Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -1086,7 +1086,7 @@
10861086
"type": "library",
10871087
"bom-ref": "15-cvss",
10881088
"name": "cvss",
1089-
"version": "3.4",
1089+
"version": "3.6",
10901090
"supplier": {
10911091
"name": "Stanislav Red Hat Product Security",
10921092
"contact": [
@@ -1095,12 +1095,12 @@
10951095
}
10961096
]
10971097
},
1098-
"cpe": "cpe:2.3:a:stanislav_red_hat_product_security:cvss:3.4:*:*:*:*:*:*:*",
1098+
"cpe": "cpe:2.3:a:stanislav_red_hat_product_security:cvss:3.6:*:*:*:*:*:*:*",
10991099
"description": "CVSS2/3/4 library with interactive calculator for Python 2 and Python 3",
11001100
"hashes": [
11011101
{
11021102
"alg": "SHA-256",
1103-
"content": "d9950613758e60820f7fac37ca5f35158712f8f2ea4f6629858a60c4984fe4ef"
1103+
"content": "e342c6ad9c7eb69d2aebbbc2768a03cabd57eb947c806e145de5b936219833ea"
11041104
}
11051105
],
11061106
"licenses": [
@@ -1119,7 +1119,7 @@
11191119
"comment": "Home page for project"
11201120
},
11211121
{
1122-
"url": "https://pypi.org/project/cvss/3.4/#files",
1122+
"url": "https://pypi.org/project/cvss/3.6/#files",
11231123
"type": "distribution",
11241124
"comment": "Download location for component"
11251125
},
@@ -1140,11 +1140,11 @@
11401140
"type": "build-system"
11411141
}
11421142
],
1143-
"purl": "pkg:pypi/cvss@3.4",
1143+
"purl": "pkg:pypi/cvss@3.6",
11441144
"properties": [
11451145
{
11461146
"name": "release_date",
1147-
"value": "2025-02-11T17:28:21Z"
1147+
"value": "2025-08-04T10:50:12Z"
11481148
},
11491149
{
11501150
"name": "language",
@@ -3274,7 +3274,7 @@
32743274
"type": "library",
32753275
"bom-ref": "49-rpds-py",
32763276
"name": "rpds-py",
3277-
"version": "0.26.0",
3277+
"version": "0.27.0",
32783278
"supplier": {
32793279
"name": "Julian Berman",
32803280
"contact": [
@@ -3283,21 +3283,12 @@
32833283
}
32843284
]
32853285
},
3286-
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.26.0:*:*:*:*:*:*:*",
3286+
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.27.0:*:*:*:*:*:*:*",
32873287
"description": "Python bindings to Rust's persistent data structures (rpds)",
32883288
"hashes": [
32893289
{
32903290
"alg": "SHA-256",
3291-
"content": "4c70c70f9169692b36307a95f3d8c0a9fcd79f7b4a383aad5eaa0e9718b79b37"
3292-
}
3293-
],
3294-
"licenses": [
3295-
{
3296-
"license": {
3297-
"id": "MIT",
3298-
"url": "https://opensource.org/license/mit/",
3299-
"acknowledgement": "concluded"
3300-
}
3291+
"content": "130c1ffa5039a333f5926b09e346ab335f0d4ec393b030a18549a7c7e7c2cea4"
33013292
}
33023293
],
33033294
"externalReferences": [
@@ -3307,7 +3298,7 @@
33073298
"comment": "Home page for project"
33083299
},
33093300
{
3310-
"url": "https://pypi.org/project/rpds-py/0.26.0/#files",
3301+
"url": "https://pypi.org/project/rpds-py/0.27.0/#files",
33113302
"type": "distribution",
33123303
"comment": "Download location for component"
33133304
},
@@ -3336,11 +3327,11 @@
33363327
"type": "other"
33373328
}
33383329
],
3339-
"purl": "pkg:pypi/rpds-py@0.26.0",
3330+
"purl": "pkg:pypi/rpds-py@0.27.0",
33403331
"properties": [
33413332
{
33423333
"name": "release_date",
3343-
"value": "2025-07-01T15:53:40Z"
3334+
"value": "2025-08-07T08:23:06Z"
33443335
},
33453336
{
33463337
"name": "language",
@@ -3768,16 +3759,16 @@
37683759
"type": "library",
37693760
"bom-ref": "57-packageurl-python",
37703761
"name": "packageurl-python",
3771-
"version": "0.17.3",
3762+
"version": "0.17.5",
37723763
"supplier": {
37733764
"name": "the purl authors"
37743765
},
3775-
"cpe": "cpe:2.3:a:the_purl_authors:packageurl-python:0.17.3:*:*:*:*:*:*:*",
3766+
"cpe": "cpe:2.3:a:the_purl_authors:packageurl-python:0.17.5:*:*:*:*:*:*:*",
37763767
"description": "A purl aka. Package URL parser and builder",
37773768
"hashes": [
37783769
{
37793770
"alg": "SHA-256",
3780-
"content": "f51b5aab570159f07258c8e998e9972ff3bf060da16b7334a42bd9f9737777d9"
3771+
"content": "f0e55452ab37b5c192c443de1458e3f3b4d8ac27f747df6e8c48adeab081d321"
37813772
}
37823773
],
37833774
"licenses": [
@@ -3796,16 +3787,16 @@
37963787
"comment": "Home page for project"
37973788
},
37983789
{
3799-
"url": "https://pypi.org/project/packageurl-python/0.17.3/#files",
3790+
"url": "https://pypi.org/project/packageurl-python/0.17.5/#files",
38003791
"type": "distribution",
38013792
"comment": "Download location for component"
38023793
}
38033794
],
3804-
"purl": "pkg:pypi/[email protected].3",
3795+
"purl": "pkg:pypi/[email protected].5",
38053796
"properties": [
38063797
{
38073798
"name": "release_date",
3808-
"value": "2025-08-01T03:24:33Z"
3799+
"value": "2025-08-06T14:08:19Z"
38093800
},
38103801
{
38113802
"name": "language",
@@ -4286,7 +4277,7 @@
42864277
"type": "library",
42874278
"bom-ref": "65-python-gnupg",
42884279
"name": "python-gnupg",
4289-
"version": "0.5.4",
4280+
"version": "0.5.5",
42904281
"supplier": {
42914282
"name": "Vinay Sajip",
42924283
"contact": [
@@ -4295,12 +4286,12 @@
42954286
}
42964287
]
42974288
},
4298-
"cpe": "cpe:2.3:a:vinay_sajip:python-gnupg:0.5.4:*:*:*:*:*:*:*",
4289+
"cpe": "cpe:2.3:a:vinay_sajip:python-gnupg:0.5.5:*:*:*:*:*:*:*",
42994290
"description": "A wrapper for the Gnu Privacy Guard (GPG or GnuPG)",
43004291
"hashes": [
43014292
{
43024293
"alg": "SHA-256",
4303-
"content": "40ce25cde9df29af91fe931ce9df3ce544e14a37f62b13ca878c897217b2de6c"
4294+
"content": "51fa7b8831ff0914bc73d74c59b99c613de7247b91294323c39733bb85ac3fc1"
43044295
}
43054296
],
43064297
"licenses": [
@@ -4319,7 +4310,7 @@
43194310
"comment": "Home page for project"
43204311
},
43214312
{
4322-
"url": "https://pypi.org/project/python-gnupg/0.5.4/#files",
4313+
"url": "https://pypi.org/project/python-gnupg/0.5.5/#files",
43234314
"type": "distribution",
43244315
"comment": "Download location for component"
43254316
},
@@ -4336,11 +4327,11 @@
43364327
"type": "issue-tracker"
43374328
}
43384329
],
4339-
"purl": "pkg:pypi/[email protected].4",
4330+
"purl": "pkg:pypi/[email protected].5",
43404331
"properties": [
43414332
{
43424333
"name": "release_date",
4343-
"value": "2025-01-07T11:58:32Z"
4334+
"value": "2025-08-04T19:26:54Z"
43444335
},
43454336
{
43464337
"name": "language",
@@ -4426,7 +4417,7 @@
44264417
"type": "library",
44274418
"bom-ref": "67-charset-normalizer",
44284419
"name": "charset-normalizer",
4429-
"version": "3.4.2",
4420+
"version": "3.4.3",
44304421
"supplier": {
44314422
"name": "Ahmed R .",
44324423
"contact": [
@@ -4435,12 +4426,12 @@
44354426
}
44364427
]
44374428
},
4438-
"cpe": "cpe:2.3:a:ahmed_r.:charset-normalizer:3.4.2:*:*:*:*:*:*:*",
4429+
"cpe": "cpe:2.3:a:ahmed_r.:charset-normalizer:3.4.3:*:*:*:*:*:*:*",
44394430
"description": "The Real First Universal Charset Detector. Open, modern and actively maintained alternative to Chardet.",
44404431
"hashes": [
44414432
{
44424433
"alg": "SHA-256",
4443-
"content": "7c48ed483eb946e6c04ccbe02c6b4d1d48e51944b6db70f697e089c193404941"
4434+
"content": "fb7f67a1bfa6e40b438170ebdc8158b78dc465a5a67b6dde178a46987b244a72"
44444435
}
44454436
],
44464437
"licenses": [
@@ -4454,7 +4445,7 @@
44544445
],
44554446
"externalReferences": [
44564447
{
4457-
"url": "https://pypi.org/project/charset-normalizer/3.4.2/#files",
4448+
"url": "https://pypi.org/project/charset-normalizer/3.4.3/#files",
44584449
"type": "distribution",
44594450
"comment": "Download location for component"
44604451
},
@@ -4475,11 +4466,11 @@
44754466
"type": "issue-tracker"
44764467
}
44774468
],
4478-
"purl": "pkg:pypi/[email protected].2",
4469+
"purl": "pkg:pypi/[email protected].3",
44794470
"properties": [
44804471
{
44814472
"name": "release_date",
4482-
"value": "2025-05-02T08:31:46Z"
4473+
"value": "2025-08-09T07:55:36Z"
44834474
},
44844475
{
44854476
"name": "language",

0 commit comments

Comments
 (0)