Skip to content

Commit 271264d

Browse files
chore: update SBOM for Python 3.11 (#5260)
Co-authored-by: GitHub <[email protected]>
1 parent d9f84c6 commit 271264d

File tree

2 files changed

+65
-58
lines changed

2 files changed

+65
-58
lines changed

sbom/cve-bin-tool-py3.11.json

Lines changed: 32 additions & 29 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:782cd393-2c1e-4248-80ef-5068a1a15015",
5+
"serialNumber": "urn:uuid:5ab92791-f41f-4b08-b4c4-db025c92b5b9",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-07-28T00:57:29Z",
8+
"timestamp": "2025-08-04T00:53:01Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -79,21 +79,18 @@
7979
"type": "library",
8080
"bom-ref": "2-aiohttp",
8181
"name": "aiohttp",
82-
"version": "3.12.14",
82+
"version": "3.12.15",
8383
"description": "Async http client/server framework (asyncio)",
8484
"hashes": [
8585
{
8686
"alg": "SHA-256",
87-
"content": "906d5075b5ba0dd1c66fcaaf60eb09926a9fef3ca92d912d2a0bbdbecf8b1248"
87+
"content": "b6fc902bff74d9b1879ad55f5404153e2b33a82e72a95c89cec5eb6cc9e92fbc"
8888
}
8989
],
9090
"licenses": [
9191
{
92-
"license": {
93-
"id": "Apache-2.0",
94-
"url": "https://www.apache.org/licenses/LICENSE-2.0",
95-
"acknowledgement": "concluded"
96-
}
92+
"expression": "Apache-2.0 AND MIT",
93+
"acknowledgement": "concluded"
9794
}
9895
],
9996
"externalReferences": [
@@ -103,7 +100,7 @@
103100
"comment": "Home page for project"
104101
},
105102
{
106-
"url": "https://pypi.org/project/aiohttp/3.12.14/#files",
103+
"url": "https://pypi.org/project/aiohttp/3.12.15/#files",
107104
"type": "distribution",
108105
"comment": "Download location for component"
109106
},
@@ -140,11 +137,11 @@
140137
"type": "vcs"
141138
}
142139
],
143-
"purl": "pkg:pypi/[email protected].14",
140+
"purl": "pkg:pypi/[email protected].15",
144141
"properties": [
145142
{
146143
"name": "release_date",
147-
"value": "2025-07-10T13:02:38Z"
144+
"value": "2025-07-29T05:49:43Z"
148145
},
149146
{
150147
"name": "language",
@@ -3689,16 +3686,16 @@
36893686
"type": "library",
36903687
"bom-ref": "56-packageurl-python",
36913688
"name": "packageurl-python",
3692-
"version": "0.17.1",
3689+
"version": "0.17.3",
36933690
"supplier": {
36943691
"name": "the purl authors"
36953692
},
3696-
"cpe": "cpe:2.3:a:the_purl_authors:packageurl-python:0.17.1:*:*:*:*:*:*:*",
3693+
"cpe": "cpe:2.3:a:the_purl_authors:packageurl-python:0.17.3:*:*:*:*:*:*:*",
36973694
"description": "A purl aka. Package URL parser and builder",
36983695
"hashes": [
36993696
{
37003697
"alg": "SHA-256",
3701-
"content": "59b0862ae0b216994f847e05b4c6e870e0d16e1ddd706feefb19d79810f22cbd"
3698+
"content": "f51b5aab570159f07258c8e998e9972ff3bf060da16b7334a42bd9f9737777d9"
37023699
}
37033700
],
37043701
"licenses": [
@@ -3717,16 +3714,16 @@
37173714
"comment": "Home page for project"
37183715
},
37193716
{
3720-
"url": "https://pypi.org/project/packageurl-python/0.17.1/#files",
3717+
"url": "https://pypi.org/project/packageurl-python/0.17.3/#files",
37213718
"type": "distribution",
37223719
"comment": "Download location for component"
37233720
}
37243721
],
3725-
"purl": "pkg:pypi/[email protected].1",
3722+
"purl": "pkg:pypi/[email protected].3",
37263723
"properties": [
37273724
{
37283725
"name": "release_date",
3729-
"value": "2025-06-06T13:13:58Z"
3726+
"value": "2025-08-01T03:24:33Z"
37303727
},
37313728
{
37323729
"name": "language",
@@ -4133,7 +4130,7 @@
41334130
"type": "library",
41344131
"bom-ref": "63-narwhals",
41354132
"name": "narwhals",
4136-
"version": "1.48.1",
4133+
"version": "2.0.1",
41374134
"supplier": {
41384135
"name": "Marco Gorelli",
41394136
"contact": [
@@ -4142,8 +4139,14 @@
41424139
}
41434140
]
41444141
},
4145-
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:1.48.1:*:*:*:*:*:*:*",
4142+
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:2.0.1:*:*:*:*:*:*:*",
41464143
"description": "Extremely lightweight compatibility layer between dataframe libraries",
4144+
"hashes": [
4145+
{
4146+
"alg": "SHA-256",
4147+
"content": "837457e36a2ba1710c881fb69e1f79ce44fb81728c92ac378f70892a53af8ddb"
4148+
}
4149+
],
41474150
"licenses": [
41484151
{
41494152
"license": {
@@ -4160,7 +4163,7 @@
41604163
"comment": "Home page for project"
41614164
},
41624165
{
4163-
"url": "https://pypi.org/project/narwhals/1.48.1/#files",
4166+
"url": "https://pypi.org/project/narwhals/2.0.1/#files",
41644167
"type": "distribution",
41654168
"comment": "Download location for component"
41664169
},
@@ -4177,11 +4180,11 @@
41774180
"type": "issue-tracker"
41784181
}
41794182
],
4180-
"purl": "pkg:pypi/narwhals@1.48.1",
4183+
"purl": "pkg:pypi/narwhals@2.0.1",
41814184
"properties": [
41824185
{
41834186
"name": "release_date",
4184-
"value": "2025-06-26T16:20:40Z"
4187+
"value": "2025-07-29T08:39:03Z"
41854188
},
41864189
{
41874190
"name": "language",
@@ -4470,7 +4473,7 @@
44704473
"type": "library",
44714474
"bom-ref": "68-certifi",
44724475
"name": "certifi",
4473-
"version": "2025.7.14",
4476+
"version": "2025.8.3",
44744477
"supplier": {
44754478
"name": "Kenneth Reitz",
44764479
"contact": [
@@ -4479,12 +4482,12 @@
44794482
}
44804483
]
44814484
},
4482-
"cpe": "cpe:2.3:a:kenneth_reitz:certifi:2025.7.14:*:*:*:*:*:*:*",
4485+
"cpe": "cpe:2.3:a:kenneth_reitz:certifi:2025.8.3:*:*:*:*:*:*:*",
44834486
"description": "Python package for providing Mozilla's CA Bundle.",
44844487
"hashes": [
44854488
{
44864489
"alg": "SHA-256",
4487-
"content": "6b31f564a415d79ee77df69d757bb49a5bb53bd9f756cbbe24394ffd6fc1f4b2"
4490+
"content": "f6c12493cfb1b06ba2ff328595af9350c65d6644968e5d3a2ffd78699af217a5"
44884491
}
44894492
],
44904493
"licenses": [
@@ -4503,7 +4506,7 @@
45034506
"comment": "Home page for project"
45044507
},
45054508
{
4506-
"url": "https://pypi.org/project/certifi/2025.7.14/#files",
4509+
"url": "https://pypi.org/project/certifi/2025.8.3/#files",
45074510
"type": "distribution",
45084511
"comment": "Download location for component"
45094512
},
@@ -4512,11 +4515,11 @@
45124515
"type": "vcs"
45134516
}
45144517
],
4515-
"purl": "pkg:pypi/certifi@2025.7.14",
4518+
"purl": "pkg:pypi/certifi@2025.8.3",
45164519
"properties": [
45174520
{
45184521
"name": "release_date",
4519-
"value": "2025-07-14T03:29:26Z"
4522+
"value": "2025-08-03T03:07:45Z"
45204523
},
45214524
{
45224525
"name": "language",

sbom/cve-bin-tool-py3.11.spdx

Lines changed: 33 additions & 29 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-994eb14e-2b88-4df0-9829-a6f6ef097526
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-7c378e2d-f181-4971-b509-6b6e5d0f3d1a
66
LicenseListVersion: 3.26
77
Creator: Tool: sbom4python-0.12.4
8-
Created: 2025-07-28T00:56:35Z
8+
Created: 2025-08-04T00:52:52Z
99
CreatorComment: <text>SBOM Type: Build - This document has been automatically generated.</text>
1010
#####
1111

@@ -27,18 +27,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.4.1:*:*:*:*:*
2727

2828
PackageName: aiohttp
2929
SPDXID: SPDXRef-2-aiohttp
30-
PackageVersion: 3.12.14
30+
PackageVersion: 3.12.15
3131
PrimaryPackagePurpose: LIBRARY
3232
PackageSupplier: NOASSERTION
33-
PackageDownloadLocation: https://pypi.org/project/aiohttp/3.12.14/#files
33+
PackageDownloadLocation: https://pypi.org/project/aiohttp/3.12.15/#files
3434
FilesAnalyzed: false
3535
PackageHomePage: https://github.com/aio-libs/aiohttp
36-
PackageChecksum: SHA256: 906d5075b5ba0dd1c66fcaaf60eb09926a9fef3ca92d912d2a0bbdbecf8b1248
37-
PackageLicenseDeclared: Apache-2.0
38-
PackageLicenseConcluded: Apache-2.0
36+
PackageChecksum: SHA256: b6fc902bff74d9b1879ad55f5404153e2b33a82e72a95c89cec5eb6cc9e92fbc
37+
PackageLicenseDeclared: Apache-2.0 AND MIT
38+
PackageLicenseConcluded: Apache-2.0 AND MIT
3939
PackageCopyrightText: NOASSERTION
4040
PackageSummary: <text>Async http client/server framework (asyncio)</text>
41-
ReleaseDate: 2025-07-10T13:02:38Z
41+
ReleaseDate: 2025-07-29T05:49:43Z
4242
ExternalRef: OTHER other https://matrix.to/#/#aio-libs:matrix.org
4343
ExternalRef: OTHER other https://matrix.to/#/#aio-libs-space:matrix.org
4444
ExternalRef: OTHER build-system https://github.com/aio-libs/aiohttp/actions?query=workflow%3ACI
@@ -47,7 +47,7 @@ ExternalRef: OTHER log https://docs.aiohttp.org/en/stable/changes.html
4747
ExternalRef: OTHER other https://docs.aiohttp.org
4848
ExternalRef: OTHER issue-tracker https://github.com/aio-libs/aiohttp/issues
4949
ExternalRef: OTHER vcs https://github.com/aio-libs/aiohttp
50-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].14
50+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].15
5151
#####
5252

5353
PackageName: aiohappyeyeballs
@@ -843,12 +843,13 @@ PackageSupplier: Person: Craig Citro ([email protected])
843843
PackageDownloadLocation: https://pypi.org/project/google-apitools/0.5.32/#files
844844
FilesAnalyzed: false
845845
PackageHomePage: http://github.com/google/apitools
846+
PackageChecksum: SHA256: b78f74116558e0476e19501b5b4b2ac7c93261a69c5449c861ea95cbc853c688
846847
PackageLicenseDeclared: NOASSERTION
847848
PackageLicenseConcluded: Apache-2.0
848849
PackageLicenseComments: <text>google-apitools declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
849850
PackageCopyrightText: NOASSERTION
850851
PackageSummary: <text>client libraries for humans</text>
851-
ReleaseDate: 2023-12-12T17:40:13Z
852+
ReleaseDate: 2021-05-05T22:12:58Z
852853
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected]
853854
ExternalRef: SECURITY cpe23Type cpe:2.3:a:craig_citro:google-apitools:0.5.32:*:*:*:*:*:*:*
854855
#####
@@ -1161,31 +1162,32 @@ PackageSupplier: Person: Anthony Harrison ([email protected])
11611162
PackageDownloadLocation: https://pypi.org/project/csaf-tool/0.3.2/#files
11621163
FilesAnalyzed: false
11631164
PackageHomePage: https://github.com/anthonyharrison/csaf
1165+
PackageChecksum: SHA256: 7e5559cb522eb76e3acad39a7bf9ba1b81e5a6224099d511a4c9c2dcf36caa16
11641166
PackageLicenseDeclared: MIT
11651167
PackageLicenseConcluded: MIT
11661168
PackageCopyrightText: NOASSERTION
11671169
PackageSummary: <text>CSAF generator and analyser</text>
1168-
ReleaseDate: 2024-08-29T20:36:52Z
1170+
ReleaseDate: 2024-06-12T20:10:06Z
11691171
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected]
11701172
ExternalRef: SECURITY cpe23Type cpe:2.3:a:anthony_harrison:csaf-tool:0.3.2:*:*:*:*:*:*:*
11711173
#####
11721174

11731175
PackageName: packageurl-python
11741176
SPDXID: SPDXRef-56-packageurl-python
1175-
PackageVersion: 0.17.1
1177+
PackageVersion: 0.17.3
11761178
PrimaryPackagePurpose: LIBRARY
11771179
PackageSupplier: Person: the purl authors
1178-
PackageDownloadLocation: https://pypi.org/project/packageurl-python/0.17.1/#files
1180+
PackageDownloadLocation: https://pypi.org/project/packageurl-python/0.17.3/#files
11791181
FilesAnalyzed: false
11801182
PackageHomePage: https://github.com/package-url/packageurl-python
1181-
PackageChecksum: SHA256: 59b0862ae0b216994f847e05b4c6e870e0d16e1ddd706feefb19d79810f22cbd
1183+
PackageChecksum: SHA256: f51b5aab570159f07258c8e998e9972ff3bf060da16b7334a42bd9f9737777d9
11821184
PackageLicenseDeclared: MIT
11831185
PackageLicenseConcluded: MIT
11841186
PackageCopyrightText: NOASSERTION
11851187
PackageSummary: <text>A purl aka. Package URL parser and builder</text>
1186-
ReleaseDate: 2025-06-06T13:13:58Z
1187-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].1
1188-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_purl_authors:packageurl-python:0.17.1:*:*:*:*:*:*:*
1188+
ReleaseDate: 2025-08-01T03:24:33Z
1189+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].3
1190+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_purl_authors:packageurl-python:0.17.3:*:*:*:*:*:*:*
11891191
#####
11901192

11911193
PackageName: rich
@@ -1333,23 +1335,24 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:6.2.0:*:*:*:*:*:*:*
13331335

13341336
PackageName: narwhals
13351337
SPDXID: SPDXRef-63-narwhals
1336-
PackageVersion: 1.48.1
1338+
PackageVersion: 2.0.1
13371339
PrimaryPackagePurpose: LIBRARY
13381340
PackageSupplier: Person: Marco Gorelli ([email protected])
1339-
PackageDownloadLocation: https://pypi.org/project/narwhals/1.48.1/#files
1341+
PackageDownloadLocation: https://pypi.org/project/narwhals/2.0.1/#files
13401342
FilesAnalyzed: false
13411343
PackageHomePage: https://github.com/narwhals-dev/narwhals
1344+
PackageChecksum: SHA256: 837457e36a2ba1710c881fb69e1f79ce44fb81728c92ac378f70892a53af8ddb
13421345
PackageLicenseDeclared: NOASSERTION
13431346
PackageLicenseConcluded: MIT
13441347
PackageLicenseComments: <text>narwhals declares MIT License which is not currently a valid SPDX License identifier or expression.</text>
13451348
PackageCopyrightText: NOASSERTION
13461349
PackageSummary: <text>Extremely lightweight compatibility layer between dataframe libraries</text>
1347-
ReleaseDate: 2025-06-26T16:20:40Z
1350+
ReleaseDate: 2025-07-29T08:39:03Z
13481351
ExternalRef: OTHER documentation https://narwhals-dev.github.io/narwhals/
13491352
ExternalRef: OTHER vcs https://github.com/narwhals-dev/narwhals
13501353
ExternalRef: OTHER issue-tracker https://github.com/narwhals-dev/narwhals/issues
1351-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@1.48.1
1352-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:1.48.1:*:*:*:*:*:*:*
1354+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@2.0.1
1355+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:2.0.1:*:*:*:*:*:*:*
13531356
#####
13541357

13551358
PackageName: python-gnupg
@@ -1360,12 +1363,13 @@ PackageSupplier: Person: Vinay Sajip ([email protected])
13601363
PackageDownloadLocation: https://pypi.org/project/python-gnupg/0.5.4/#files
13611364
FilesAnalyzed: false
13621365
PackageHomePage: https://github.com/vsajip/python-gnupg
1366+
PackageChecksum: SHA256: 40ce25cde9df29af91fe931ce9df3ce544e14a37f62b13ca878c897217b2de6c
13631367
PackageLicenseDeclared: NOASSERTION
13641368
PackageLicenseConcluded: BSD-3-Clause
13651369
PackageLicenseComments: <text>python-gnupg declares BSD which is not currently a valid SPDX License identifier or expression.</text>
13661370
PackageCopyrightText: NOASSERTION
13671371
PackageSummary: <text>A wrapper for the Gnu Privacy Guard (GPG or GnuPG)</text>
1368-
ReleaseDate: 2025-06-26T16:20:40Z
1372+
ReleaseDate: 2025-01-07T11:58:32Z
13691373
ExternalRef: OTHER documentation https://gnupg.readthedocs.io/
13701374
ExternalRef: OTHER vcs https://github.com/vsajip/python-gnupg
13711375
ExternalRef: OTHER issue-tracker https://github.com/vsajip/python-gnupg/issues
@@ -1437,21 +1441,21 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_petrov:urllib3:2.5.0:*:*:*:*:*:
14371441

14381442
PackageName: certifi
14391443
SPDXID: SPDXRef-68-certifi
1440-
PackageVersion: 2025.7.14
1444+
PackageVersion: 2025.8.3
14411445
PrimaryPackagePurpose: LIBRARY
14421446
PackageSupplier: Person: Kenneth Reitz ([email protected])
1443-
PackageDownloadLocation: https://pypi.org/project/certifi/2025.7.14/#files
1447+
PackageDownloadLocation: https://pypi.org/project/certifi/2025.8.3/#files
14441448
FilesAnalyzed: false
14451449
PackageHomePage: https://github.com/certifi/python-certifi
1446-
PackageChecksum: SHA256: 6b31f564a415d79ee77df69d757bb49a5bb53bd9f756cbbe24394ffd6fc1f4b2
1450+
PackageChecksum: SHA256: f6c12493cfb1b06ba2ff328595af9350c65d6644968e5d3a2ffd78699af217a5
14471451
PackageLicenseDeclared: MPL-2.0
14481452
PackageLicenseConcluded: MPL-2.0
14491453
PackageCopyrightText: NOASSERTION
14501454
PackageSummary: <text>Python package for providing Mozilla's CA Bundle.</text>
1451-
ReleaseDate: 2025-07-14T03:29:26Z
1455+
ReleaseDate: 2025-08-03T03:07:45Z
14521456
ExternalRef: OTHER vcs https://github.com/certifi/python-certifi
1453-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/certifi@2025.7.14
1454-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:certifi:2025.7.14:*:*:*:*:*:*:*
1457+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/certifi@2025.8.3
1458+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:certifi:2025.8.3:*:*:*:*:*:*:*
14551459
#####
14561460

14571461
PackageName: rpmfile

0 commit comments

Comments
 (0)