Skip to content

Commit 492491e

Browse files
chore: update SBOM for Python 3.11 (#5249)
Co-authored-by: GitHub <[email protected]>
1 parent 9bcc082 commit 492491e

File tree

2 files changed

+30
-34
lines changed

2 files changed

+30
-34
lines changed

sbom/cve-bin-tool-py3.11.json

Lines changed: 13 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:8d1c95e9-8db8-44d3-b046-3d5fac38da36",
5+
"serialNumber": "urn:uuid:782cd393-2c1e-4248-80ef-5068a1a15015",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-07-21T00:54:52Z",
8+
"timestamp": "2025-07-28T00:57:29Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -3742,7 +3742,7 @@
37423742
"type": "library",
37433743
"bom-ref": "57-rich",
37443744
"name": "rich",
3745-
"version": "14.0.0",
3745+
"version": "14.1.0",
37463746
"supplier": {
37473747
"name": "Will McGugan",
37483748
"contact": [
@@ -3751,12 +3751,12 @@
37513751
}
37523752
]
37533753
},
3754-
"cpe": "cpe:2.3:a:will_mcgugan:rich:14.0.0:*:*:*:*:*:*:*",
3754+
"cpe": "cpe:2.3:a:will_mcgugan:rich:14.1.0:*:*:*:*:*:*:*",
37553755
"description": "Render rich text, tables, progress bars, syntax highlighting, markdown and more to the terminal",
37563756
"hashes": [
37573757
{
37583758
"alg": "SHA-256",
3759-
"content": "1c9491e1951aac09caffd42f448ee3d04e58923ffe14993f6e83068dc395d7e0"
3759+
"content": "536f5f1785986d6dbdea3c75205c473f970777b4a0d6c6dd1b696aa05a3fa04f"
37603760
}
37613761
],
37623762
"licenses": [
@@ -3775,7 +3775,7 @@
37753775
"comment": "Home page for project"
37763776
},
37773777
{
3778-
"url": "https://pypi.org/project/rich/14.0.0/#files",
3778+
"url": "https://pypi.org/project/rich/14.1.0/#files",
37793779
"type": "distribution",
37803780
"comment": "Download location for component"
37813781
},
@@ -3784,11 +3784,11 @@
37843784
"type": "documentation"
37853785
}
37863786
],
3787-
"purl": "pkg:pypi/rich@14.0.0",
3787+
"purl": "pkg:pypi/rich@14.1.0",
37883788
"properties": [
37893789
{
37903790
"name": "release_date",
3791-
"value": "2025-03-30T14:15:12Z"
3791+
"value": "2025-07-25T07:32:56Z"
37923792
},
37933793
{
37943794
"name": "language",
@@ -4133,7 +4133,7 @@
41334133
"type": "library",
41344134
"bom-ref": "63-narwhals",
41354135
"name": "narwhals",
4136-
"version": "1.47.1",
4136+
"version": "1.48.1",
41374137
"supplier": {
41384138
"name": "Marco Gorelli",
41394139
"contact": [
@@ -4142,7 +4142,7 @@
41424142
}
41434143
]
41444144
},
4145-
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:1.47.1:*:*:*:*:*:*:*",
4145+
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:1.48.1:*:*:*:*:*:*:*",
41464146
"description": "Extremely lightweight compatibility layer between dataframe libraries",
41474147
"licenses": [
41484148
{
@@ -4160,7 +4160,7 @@
41604160
"comment": "Home page for project"
41614161
},
41624162
{
4163-
"url": "https://pypi.org/project/narwhals/1.47.1/#files",
4163+
"url": "https://pypi.org/project/narwhals/1.48.1/#files",
41644164
"type": "distribution",
41654165
"comment": "Download location for component"
41664166
},
@@ -4177,7 +4177,7 @@
41774177
"type": "issue-tracker"
41784178
}
41794179
],
4180-
"purl": "pkg:pypi/narwhals@1.47.1",
4180+
"purl": "pkg:pypi/narwhals@1.48.1",
41814181
"properties": [
41824182
{
41834183
"name": "release_date",
@@ -5008,8 +5008,7 @@
50085008
"ref": "57-rich",
50095009
"dependsOn": [
50105010
"58-markdown-it-py",
5011-
"60-pygments",
5012-
"6-typing-extensions"
5011+
"60-pygments"
50135012
]
50145013
},
50155014
{

sbom/cve-bin-tool-py3.11.spdx

Lines changed: 17 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-d75d7ed0-27fe-47a9-b38e-4b006911997d
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-994eb14e-2b88-4df0-9829-a6f6ef097526
66
LicenseListVersion: 3.26
77
Creator: Tool: sbom4python-0.12.4
8-
Created: 2025-07-21T00:54:46Z
8+
Created: 2025-07-28T00:56:35Z
99
CreatorComment: <text>SBOM Type: Build - This document has been automatically generated.</text>
1010
#####
1111

@@ -414,12 +414,13 @@ PackageSupplier: Person: Andrey Kislyuk ([email protected])
414414
PackageDownloadLocation: https://pypi.org/project/argcomplete/3.6.2/#files
415415
FilesAnalyzed: false
416416
PackageHomePage: https://github.com/kislyuk/argcomplete
417+
PackageChecksum: SHA256: 65b3133a29ad53fb42c48cf5114752c7ab66c1c38544fdf6460f450c09b42591
417418
PackageLicenseDeclared: NOASSERTION
418419
PackageLicenseConcluded: Apache-2.0
419420
PackageLicenseComments: <text>argcomplete declares Apache Software License which is not currently a valid SPDX License identifier or expression.</text>
420421
PackageCopyrightText: NOASSERTION
421422
PackageSummary: <text>Bash tab completion for argparse</text>
422-
ReleaseDate: 2025-06-25T08:28:10Z
423+
ReleaseDate: 2025-04-03T04:57:01Z
423424
ExternalRef: OTHER documentation https://kislyuk.github.io/argcomplete
424425
ExternalRef: OTHER vcs https://github.com/kislyuk/argcomplete
425426
ExternalRef: OTHER issue-tracker https://github.com/kislyuk/argcomplete/issues
@@ -842,13 +843,12 @@ PackageSupplier: Person: Craig Citro ([email protected])
842843
PackageDownloadLocation: https://pypi.org/project/google-apitools/0.5.32/#files
843844
FilesAnalyzed: false
844845
PackageHomePage: http://github.com/google/apitools
845-
PackageChecksum: SHA256: b78f74116558e0476e19501b5b4b2ac7c93261a69c5449c861ea95cbc853c688
846846
PackageLicenseDeclared: NOASSERTION
847847
PackageLicenseConcluded: Apache-2.0
848848
PackageLicenseComments: <text>google-apitools declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
849849
PackageCopyrightText: NOASSERTION
850850
PackageSummary: <text>client libraries for humans</text>
851-
ReleaseDate: 2021-05-05T22:12:58Z
851+
ReleaseDate: 2023-12-12T17:40:13Z
852852
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected]
853853
ExternalRef: SECURITY cpe23Type cpe:2.3:a:craig_citro:google-apitools:0.5.32:*:*:*:*:*:*:*
854854
#####
@@ -1161,12 +1161,11 @@ PackageSupplier: Person: Anthony Harrison ([email protected])
11611161
PackageDownloadLocation: https://pypi.org/project/csaf-tool/0.3.2/#files
11621162
FilesAnalyzed: false
11631163
PackageHomePage: https://github.com/anthonyharrison/csaf
1164-
PackageChecksum: SHA256: 7e5559cb522eb76e3acad39a7bf9ba1b81e5a6224099d511a4c9c2dcf36caa16
11651164
PackageLicenseDeclared: MIT
11661165
PackageLicenseConcluded: MIT
11671166
PackageCopyrightText: NOASSERTION
11681167
PackageSummary: <text>CSAF generator and analyser</text>
1169-
ReleaseDate: 2024-06-12T20:10:06Z
1168+
ReleaseDate: 2024-08-29T20:36:52Z
11701169
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected]
11711170
ExternalRef: SECURITY cpe23Type cpe:2.3:a:anthony_harrison:csaf-tool:0.3.2:*:*:*:*:*:*:*
11721171
#####
@@ -1191,21 +1190,21 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_purl_authors:packageurl-python:0.1
11911190

11921191
PackageName: rich
11931192
SPDXID: SPDXRef-57-rich
1194-
PackageVersion: 14.0.0
1193+
PackageVersion: 14.1.0
11951194
PrimaryPackagePurpose: LIBRARY
11961195
PackageSupplier: Person: Will McGugan ([email protected])
1197-
PackageDownloadLocation: https://pypi.org/project/rich/14.0.0/#files
1196+
PackageDownloadLocation: https://pypi.org/project/rich/14.1.0/#files
11981197
FilesAnalyzed: false
11991198
PackageHomePage: https://github.com/Textualize/rich
1200-
PackageChecksum: SHA256: 1c9491e1951aac09caffd42f448ee3d04e58923ffe14993f6e83068dc395d7e0
1199+
PackageChecksum: SHA256: 536f5f1785986d6dbdea3c75205c473f970777b4a0d6c6dd1b696aa05a3fa04f
12011200
PackageLicenseDeclared: MIT
12021201
PackageLicenseConcluded: MIT
12031202
PackageCopyrightText: NOASSERTION
12041203
PackageSummary: <text>Render rich text, tables, progress bars, syntax highlighting, markdown and more to the terminal</text>
1205-
ReleaseDate: 2025-03-30T14:15:12Z
1204+
ReleaseDate: 2025-07-25T07:32:56Z
12061205
ExternalRef: OTHER documentation https://rich.readthedocs.io/en/latest/
1207-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rich@14.0.0
1208-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:will_mcgugan:rich:14.0.0:*:*:*:*:*:*:*
1206+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rich@14.1.0
1207+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:will_mcgugan:rich:14.1.0:*:*:*:*:*:*:*
12091208
#####
12101209

12111210
PackageName: markdown-it-py
@@ -1334,10 +1333,10 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:6.2.0:*:*:*:*:*:*:*
13341333

13351334
PackageName: narwhals
13361335
SPDXID: SPDXRef-63-narwhals
1337-
PackageVersion: 1.47.1
1336+
PackageVersion: 1.48.1
13381337
PrimaryPackagePurpose: LIBRARY
13391338
PackageSupplier: Person: Marco Gorelli ([email protected])
1340-
PackageDownloadLocation: https://pypi.org/project/narwhals/1.47.1/#files
1339+
PackageDownloadLocation: https://pypi.org/project/narwhals/1.48.1/#files
13411340
FilesAnalyzed: false
13421341
PackageHomePage: https://github.com/narwhals-dev/narwhals
13431342
PackageLicenseDeclared: NOASSERTION
@@ -1349,8 +1348,8 @@ ReleaseDate: 2025-06-26T16:20:40Z
13491348
ExternalRef: OTHER documentation https://narwhals-dev.github.io/narwhals/
13501349
ExternalRef: OTHER vcs https://github.com/narwhals-dev/narwhals
13511350
ExternalRef: OTHER issue-tracker https://github.com/narwhals-dev/narwhals/issues
1352-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@1.47.1
1353-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:1.47.1:*:*:*:*:*:*:*
1351+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@1.48.1
1352+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:1.48.1:*:*:*:*:*:*:*
13541353
#####
13551354

13561355
PackageName: python-gnupg
@@ -1361,13 +1360,12 @@ PackageSupplier: Person: Vinay Sajip ([email protected])
13611360
PackageDownloadLocation: https://pypi.org/project/python-gnupg/0.5.4/#files
13621361
FilesAnalyzed: false
13631362
PackageHomePage: https://github.com/vsajip/python-gnupg
1364-
PackageChecksum: SHA256: 40ce25cde9df29af91fe931ce9df3ce544e14a37f62b13ca878c897217b2de6c
13651363
PackageLicenseDeclared: NOASSERTION
13661364
PackageLicenseConcluded: BSD-3-Clause
13671365
PackageLicenseComments: <text>python-gnupg declares BSD which is not currently a valid SPDX License identifier or expression.</text>
13681366
PackageCopyrightText: NOASSERTION
13691367
PackageSummary: <text>A wrapper for the Gnu Privacy Guard (GPG or GnuPG)</text>
1370-
ReleaseDate: 2025-01-07T11:58:32Z
1368+
ReleaseDate: 2025-06-26T16:20:40Z
13711369
ExternalRef: OTHER documentation https://gnupg.readthedocs.io/
13721370
ExternalRef: OTHER vcs https://github.com/vsajip/python-gnupg
13731371
ExternalRef: OTHER issue-tracker https://github.com/vsajip/python-gnupg/issues
@@ -1635,7 +1633,6 @@ Relationship: SPDXRef-54-lib4vex DEPENDS_ON SPDXRef-56-packageurl-python
16351633
Relationship: SPDXRef-55-csaf-tool DEPENDS_ON SPDXRef-56-packageurl-python
16361634
Relationship: SPDXRef-55-csaf-tool DEPENDS_ON SPDXRef-57-rich
16371635
Relationship: SPDXRef-57-rich DEPENDS_ON SPDXRef-58-markdown-it-py
1638-
Relationship: SPDXRef-57-rich DEPENDS_ON SPDXRef-6-typing-extensions
16391636
Relationship: SPDXRef-57-rich DEPENDS_ON SPDXRef-60-pygments
16401637
Relationship: SPDXRef-58-markdown-it-py DEPENDS_ON SPDXRef-59-mdurl
16411638
Relationship: SPDXRef-62-plotly DEPENDS_ON SPDXRef-61-packaging

0 commit comments

Comments
 (0)