Skip to content

Commit 381000f

Browse files
web-flowgithub-actions[bot]
authored andcommitted
chore: update SBOM for Python 3.13
1 parent 259bf9b commit 381000f

File tree

2 files changed

+86
-93
lines changed

2 files changed

+86
-93
lines changed

sbom/cve-bin-tool-py3.13.json

Lines changed: 43 additions & 49 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:fb20c3d5-da0d-4c39-a74c-4949c29c5bb4",
5+
"serialNumber": "urn:uuid:57d30b09-0d84-490b-8bb7-e03a1bb5affe",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-09-29T00:37:57Z",
8+
"timestamp": "2025-10-06T00:40:08Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -619,7 +619,7 @@
619619
"type": "library",
620620
"bom-ref": "9-propcache",
621621
"name": "propcache",
622-
"version": "0.3.2",
622+
"version": "0.4.0",
623623
"supplier": {
624624
"name": "Andrew Svetlov",
625625
"contact": [
@@ -628,12 +628,12 @@
628628
}
629629
]
630630
},
631-
"cpe": "cpe:2.3:a:andrew_svetlov:propcache:0.3.2:*:*:*:*:*:*:*",
631+
"cpe": "cpe:2.3:a:andrew_svetlov:propcache:0.4.0:*:*:*:*:*:*:*",
632632
"description": "Accelerated property cache",
633633
"hashes": [
634634
{
635635
"alg": "SHA-256",
636-
"content": "22d9962a358aedbb7a2e36187ff273adeaab9743373a272976d2e348d08c7770"
636+
"content": "779aaae64089e2f4992e993faea801925395d26bb5de4a47df7ef7f942c14f80"
637637
}
638638
],
639639
"licenses": [
@@ -652,7 +652,7 @@
652652
"comment": "Home page for project"
653653
},
654654
{
655-
"url": "https://pypi.org/project/propcache/0.3.2/#files",
655+
"url": "https://pypi.org/project/propcache/0.4.0/#files",
656656
"type": "distribution",
657657
"comment": "Download location for component"
658658
},
@@ -693,11 +693,11 @@
693693
"type": "vcs"
694694
}
695695
],
696-
"purl": "pkg:pypi/propcache@0.3.2",
696+
"purl": "pkg:pypi/propcache@0.4.0",
697697
"properties": [
698698
{
699699
"name": "release_date",
700-
"value": "2025-06-09T22:53:40Z"
700+
"value": "2025-10-04T21:54:49Z"
701701
},
702702
{
703703
"name": "language",
@@ -713,7 +713,7 @@
713713
"type": "library",
714714
"bom-ref": "10-yarl",
715715
"name": "yarl",
716-
"version": "1.20.1",
716+
"version": "1.21.0",
717717
"supplier": {
718718
"name": "Andrew Svetlov",
719719
"contact": [
@@ -722,14 +722,8 @@
722722
}
723723
]
724724
},
725-
"cpe": "cpe:2.3:a:andrew_svetlov:yarl:1.20.1:*:*:*:*:*:*:*",
725+
"cpe": "cpe:2.3:a:andrew_svetlov:yarl:1.21.0:*:*:*:*:*:*:*",
726726
"description": "Yet another URL library",
727-
"hashes": [
728-
{
729-
"alg": "SHA-256",
730-
"content": "6032e6da6abd41e4acda34d75a816012717000fa6839f37124a47fcefc49bec4"
731-
}
732-
],
733727
"licenses": [
734728
{
735729
"license": {
@@ -746,7 +740,7 @@
746740
"comment": "Home page for project"
747741
},
748742
{
749-
"url": "https://pypi.org/project/yarl/1.20.1/#files",
743+
"url": "https://pypi.org/project/yarl/1.21.0/#files",
750744
"type": "distribution",
751745
"comment": "Download location for component"
752746
},
@@ -787,11 +781,11 @@
787781
"type": "vcs"
788782
}
789783
],
790-
"purl": "pkg:pypi/yarl@1.20.1",
784+
"purl": "pkg:pypi/yarl@1.21.0",
791785
"properties": [
792786
{
793787
"name": "release_date",
794-
"value": "2025-06-10T00:42:31Z"
788+
"value": "2025-10-04T21:54:49Z"
795789
},
796790
{
797791
"name": "language",
@@ -876,7 +870,7 @@
876870
"type": "library",
877871
"bom-ref": "12-beautifulsoup4",
878872
"name": "beautifulsoup4",
879-
"version": "4.14.0",
873+
"version": "4.14.2",
880874
"supplier": {
881875
"name": "Leonard Richardson",
882876
"contact": [
@@ -885,12 +879,12 @@
885879
}
886880
]
887881
},
888-
"cpe": "cpe:2.3:a:leonard_richardson:beautifulsoup4:4.14.0:*:*:*:*:*:*:*",
882+
"cpe": "cpe:2.3:a:leonard_richardson:beautifulsoup4:4.14.2:*:*:*:*:*:*:*",
889883
"description": "Screen-scraping library",
890884
"hashes": [
891885
{
892886
"alg": "SHA-256",
893-
"content": "aee96fbccdf2d2a8d1288b2afa51fc76bb60823b7881a50fb1ed5f711d1a7d73"
887+
"content": "5ef6fa3a8cbece8488d66985560f97ed091e22bbc4e9c2338508a9d5de6d4515"
894888
}
895889
],
896890
"licenses": [
@@ -909,7 +903,7 @@
909903
"comment": "Home page for project"
910904
},
911905
{
912-
"url": "https://pypi.org/project/beautifulsoup4/4.14.0/#files",
906+
"url": "https://pypi.org/project/beautifulsoup4/4.14.2/#files",
913907
"type": "distribution",
914908
"comment": "Download location for component"
915909
},
@@ -918,11 +912,11 @@
918912
"type": "other"
919913
}
920914
],
921-
"purl": "pkg:pypi/[email protected].0",
915+
"purl": "pkg:pypi/[email protected].2",
922916
"properties": [
923917
{
924918
"name": "release_date",
925-
"value": "2025-09-27T17:22:16Z"
919+
"value": "2025-09-29T10:05:43Z"
926920
},
927921
{
928922
"name": "language",
@@ -3578,7 +3572,7 @@
35783572
"type": "library",
35793573
"bom-ref": "55-lib4vex",
35803574
"name": "lib4vex",
3581-
"version": "0.2.0",
3575+
"version": "0.2.1",
35823576
"supplier": {
35833577
"name": "Anthony Harrison",
35843578
"contact": [
@@ -3587,12 +3581,12 @@
35873581
}
35883582
]
35893583
},
3590-
"cpe": "cpe:2.3:a:anthony_harrison:lib4vex:0.2.0:*:*:*:*:*:*:*",
3584+
"cpe": "cpe:2.3:a:anthony_harrison:lib4vex:0.2.1:*:*:*:*:*:*:*",
35913585
"description": "VEX generator and consumer library",
35923586
"hashes": [
35933587
{
35943588
"alg": "SHA-256",
3595-
"content": "bbe730148c1a7629473067ba9702b673af11e225fcd76e6431b881f0731f52ce"
3589+
"content": "7277b368807507b2808332954480c968f73a5f51edf0218f13260cbe7110a341"
35963590
}
35973591
],
35983592
"licenses": [
@@ -3611,16 +3605,16 @@
36113605
"comment": "Home page for project"
36123606
},
36133607
{
3614-
"url": "https://pypi.org/project/lib4vex/0.2.0/#files",
3608+
"url": "https://pypi.org/project/lib4vex/0.2.1/#files",
36153609
"type": "distribution",
36163610
"comment": "Download location for component"
36173611
}
36183612
],
3619-
"purl": "pkg:pypi/[email protected].0",
3613+
"purl": "pkg:pypi/[email protected].1",
36203614
"properties": [
36213615
{
36223616
"name": "release_date",
3623-
"value": "2024-08-29T20:36:52Z"
3617+
"value": "2025-10-02T10:35:09Z"
36243618
},
36253619
{
36263620
"name": "language",
@@ -4073,7 +4067,7 @@
40734067
"type": "library",
40744068
"bom-ref": "63-plotly",
40754069
"name": "plotly",
4076-
"version": "6.3.0",
4070+
"version": "6.3.1",
40774071
"supplier": {
40784072
"name": "Chris P",
40794073
"contact": [
@@ -4082,12 +4076,12 @@
40824076
}
40834077
]
40844078
},
4085-
"cpe": "cpe:2.3:a:chris_p:plotly:6.3.0:*:*:*:*:*:*:*",
4079+
"cpe": "cpe:2.3:a:chris_p:plotly:6.3.1:*:*:*:*:*:*:*",
40864080
"description": "An open-source interactive data visualization library for Python",
40874081
"hashes": [
40884082
{
40894083
"alg": "SHA-256",
4090-
"content": "7ad806edce9d3cdd882eaebaf97c0c9e252043ed1ed3d382c3e3520ec07806d4"
4084+
"content": "8b4420d1dcf2b040f5983eed433f95732ed24930e496d36eb70d211923532e64"
40914085
}
40924086
],
40934087
"externalReferences": [
@@ -4097,7 +4091,7 @@
40974091
"comment": "Home page for project"
40984092
},
40994093
{
4100-
"url": "https://pypi.org/project/plotly/6.3.0/#files",
4094+
"url": "https://pypi.org/project/plotly/6.3.1/#files",
41014095
"type": "distribution",
41024096
"comment": "Download location for component"
41034097
},
@@ -4114,11 +4108,11 @@
41144108
"type": "log"
41154109
}
41164110
],
4117-
"purl": "pkg:pypi/[email protected].0",
4111+
"purl": "pkg:pypi/[email protected].1",
41184112
"properties": [
41194113
{
41204114
"name": "release_date",
4121-
"value": "2025-08-12T20:22:09Z"
4115+
"value": "2025-10-02T16:10:22Z"
41224116
},
41234117
{
41244118
"name": "language",
@@ -4138,7 +4132,7 @@
41384132
"type": "library",
41394133
"bom-ref": "64-narwhals",
41404134
"name": "narwhals",
4141-
"version": "2.5.0",
4135+
"version": "2.6.0",
41424136
"supplier": {
41434137
"name": "Marco Gorelli",
41444138
"contact": [
@@ -4147,12 +4141,12 @@
41474141
}
41484142
]
41494143
},
4150-
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:2.5.0:*:*:*:*:*:*:*",
4144+
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:2.6.0:*:*:*:*:*:*:*",
41514145
"description": "Extremely lightweight compatibility layer between dataframe libraries",
41524146
"hashes": [
41534147
{
41544148
"alg": "SHA-256",
4155-
"content": "7e213f9ca7db3f8bf6f7eff35eaee6a1cf80902997e1b78d49b7755775d8f423"
4149+
"content": "3215ea42afb452c6c8527e79cefbe542b674aa08d7e2e99d46b2c9708870e0d4"
41564150
}
41574151
],
41584152
"licenses": [
@@ -4171,7 +4165,7 @@
41714165
"comment": "Home page for project"
41724166
},
41734167
{
4174-
"url": "https://pypi.org/project/narwhals/2.5.0/#files",
4168+
"url": "https://pypi.org/project/narwhals/2.6.0/#files",
41754169
"type": "distribution",
41764170
"comment": "Download location for component"
41774171
},
@@ -4188,11 +4182,11 @@
41884182
"type": "issue-tracker"
41894183
}
41904184
],
4191-
"purl": "pkg:pypi/narwhals@2.5.0",
4185+
"purl": "pkg:pypi/narwhals@2.6.0",
41924186
"properties": [
41934187
{
41944188
"name": "release_date",
4195-
"value": "2025-09-12T10:04:22Z"
4189+
"value": "2025-09-29T09:08:54Z"
41964190
},
41974191
{
41984192
"name": "language",
@@ -4481,7 +4475,7 @@
44814475
"type": "library",
44824476
"bom-ref": "69-certifi",
44834477
"name": "certifi",
4484-
"version": "2025.8.3",
4478+
"version": "2025.10.5",
44854479
"supplier": {
44864480
"name": "Kenneth Reitz",
44874481
"contact": [
@@ -4490,12 +4484,12 @@
44904484
}
44914485
]
44924486
},
4493-
"cpe": "cpe:2.3:a:kenneth_reitz:certifi:2025.8.3:*:*:*:*:*:*:*",
4487+
"cpe": "cpe:2.3:a:kenneth_reitz:certifi:2025.10.5:*:*:*:*:*:*:*",
44944488
"description": "Python package for providing Mozilla's CA Bundle.",
44954489
"hashes": [
44964490
{
44974491
"alg": "SHA-256",
4498-
"content": "f6c12493cfb1b06ba2ff328595af9350c65d6644968e5d3a2ffd78699af217a5"
4492+
"content": "0f212c2744a9bb6de0c56639a6f68afe01ecd92d91f14ae897c4fe7bbeeef0de"
44994493
}
45004494
],
45014495
"licenses": [
@@ -4514,7 +4508,7 @@
45144508
"comment": "Home page for project"
45154509
},
45164510
{
4517-
"url": "https://pypi.org/project/certifi/2025.8.3/#files",
4511+
"url": "https://pypi.org/project/certifi/2025.10.5/#files",
45184512
"type": "distribution",
45194513
"comment": "Download location for component"
45204514
},
@@ -4523,11 +4517,11 @@
45234517
"type": "vcs"
45244518
}
45254519
],
4526-
"purl": "pkg:pypi/certifi@2025.8.3",
4520+
"purl": "pkg:pypi/certifi@2025.10.5",
45274521
"properties": [
45284522
{
45294523
"name": "release_date",
4530-
"value": "2025-08-03T03:07:45Z"
4524+
"value": "2025-10-05T04:12:14Z"
45314525
},
45324526
{
45334527
"name": "language",

0 commit comments

Comments
 (0)