Skip to content

Commit 61d2db3

Browse files
chore: update SBOM for Python 3.9 (#5270)
Co-authored-by: GitHub <[email protected]>
1 parent c5bc81b commit 61d2db3

File tree

2 files changed

+66
-75
lines changed

2 files changed

+66
-75
lines changed

sbom/cve-bin-tool-py3.9.json

Lines changed: 32 additions & 41 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:29ffed1c-efa7-44d7-afdf-1a001af181ee",
5+
"serialNumber": "urn:uuid:5bf150ae-9e66-44e4-a266-d4e87fd3a83e",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-08-04T00:53:09Z",
8+
"timestamp": "2025-08-11T00:45:01Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -1086,7 +1086,7 @@
10861086
"type": "library",
10871087
"bom-ref": "15-cvss",
10881088
"name": "cvss",
1089-
"version": "3.4",
1089+
"version": "3.6",
10901090
"supplier": {
10911091
"name": "Stanislav Red Hat Product Security",
10921092
"contact": [
@@ -1095,12 +1095,12 @@
10951095
}
10961096
]
10971097
},
1098-
"cpe": "cpe:2.3:a:stanislav_red_hat_product_security:cvss:3.4:*:*:*:*:*:*:*",
1098+
"cpe": "cpe:2.3:a:stanislav_red_hat_product_security:cvss:3.6:*:*:*:*:*:*:*",
10991099
"description": "CVSS2/3/4 library with interactive calculator for Python 2 and Python 3",
11001100
"hashes": [
11011101
{
11021102
"alg": "SHA-256",
1103-
"content": "d9950613758e60820f7fac37ca5f35158712f8f2ea4f6629858a60c4984fe4ef"
1103+
"content": "e342c6ad9c7eb69d2aebbbc2768a03cabd57eb947c806e145de5b936219833ea"
11041104
}
11051105
],
11061106
"licenses": [
@@ -1119,7 +1119,7 @@
11191119
"comment": "Home page for project"
11201120
},
11211121
{
1122-
"url": "https://pypi.org/project/cvss/3.4/#files",
1122+
"url": "https://pypi.org/project/cvss/3.6/#files",
11231123
"type": "distribution",
11241124
"comment": "Download location for component"
11251125
},
@@ -1140,11 +1140,11 @@
11401140
"type": "build-system"
11411141
}
11421142
],
1143-
"purl": "pkg:pypi/cvss@3.4",
1143+
"purl": "pkg:pypi/cvss@3.6",
11441144
"properties": [
11451145
{
11461146
"name": "release_date",
1147-
"value": "2025-02-11T17:28:21Z"
1147+
"value": "2025-08-04T10:50:12Z"
11481148
},
11491149
{
11501150
"name": "language",
@@ -3383,7 +3383,7 @@
33833383
"type": "library",
33843384
"bom-ref": "51-rpds-py",
33853385
"name": "rpds-py",
3386-
"version": "0.26.0",
3386+
"version": "0.27.0",
33873387
"supplier": {
33883388
"name": "Julian Berman",
33893389
"contact": [
@@ -3392,21 +3392,12 @@
33923392
}
33933393
]
33943394
},
3395-
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.26.0:*:*:*:*:*:*:*",
3395+
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.27.0:*:*:*:*:*:*:*",
33963396
"description": "Python bindings to Rust's persistent data structures (rpds)",
33973397
"hashes": [
33983398
{
33993399
"alg": "SHA-256",
3400-
"content": "4c70c70f9169692b36307a95f3d8c0a9fcd79f7b4a383aad5eaa0e9718b79b37"
3401-
}
3402-
],
3403-
"licenses": [
3404-
{
3405-
"license": {
3406-
"id": "MIT",
3407-
"url": "https://opensource.org/license/mit/",
3408-
"acknowledgement": "concluded"
3409-
}
3400+
"content": "130c1ffa5039a333f5926b09e346ab335f0d4ec393b030a18549a7c7e7c2cea4"
34103401
}
34113402
],
34123403
"externalReferences": [
@@ -3416,7 +3407,7 @@
34163407
"comment": "Home page for project"
34173408
},
34183409
{
3419-
"url": "https://pypi.org/project/rpds-py/0.26.0/#files",
3410+
"url": "https://pypi.org/project/rpds-py/0.27.0/#files",
34203411
"type": "distribution",
34213412
"comment": "Download location for component"
34223413
},
@@ -3445,11 +3436,11 @@
34453436
"type": "other"
34463437
}
34473438
],
3448-
"purl": "pkg:pypi/rpds-py@0.26.0",
3439+
"purl": "pkg:pypi/rpds-py@0.27.0",
34493440
"properties": [
34503441
{
34513442
"name": "release_date",
3452-
"value": "2025-07-01T15:53:40Z"
3443+
"value": "2025-08-07T08:23:06Z"
34533444
},
34543445
{
34553446
"name": "language",
@@ -3877,16 +3868,16 @@
38773868
"type": "library",
38783869
"bom-ref": "59-packageurl-python",
38793870
"name": "packageurl-python",
3880-
"version": "0.17.3",
3871+
"version": "0.17.5",
38813872
"supplier": {
38823873
"name": "the purl authors"
38833874
},
3884-
"cpe": "cpe:2.3:a:the_purl_authors:packageurl-python:0.17.3:*:*:*:*:*:*:*",
3875+
"cpe": "cpe:2.3:a:the_purl_authors:packageurl-python:0.17.5:*:*:*:*:*:*:*",
38853876
"description": "A purl aka. Package URL parser and builder",
38863877
"hashes": [
38873878
{
38883879
"alg": "SHA-256",
3889-
"content": "f51b5aab570159f07258c8e998e9972ff3bf060da16b7334a42bd9f9737777d9"
3880+
"content": "f0e55452ab37b5c192c443de1458e3f3b4d8ac27f747df6e8c48adeab081d321"
38903881
}
38913882
],
38923883
"licenses": [
@@ -3905,16 +3896,16 @@
39053896
"comment": "Home page for project"
39063897
},
39073898
{
3908-
"url": "https://pypi.org/project/packageurl-python/0.17.3/#files",
3899+
"url": "https://pypi.org/project/packageurl-python/0.17.5/#files",
39093900
"type": "distribution",
39103901
"comment": "Download location for component"
39113902
}
39123903
],
3913-
"purl": "pkg:pypi/[email protected].3",
3904+
"purl": "pkg:pypi/[email protected].5",
39143905
"properties": [
39153906
{
39163907
"name": "release_date",
3917-
"value": "2025-08-01T03:24:33Z"
3908+
"value": "2025-08-06T14:08:19Z"
39183909
},
39193910
{
39203911
"name": "language",
@@ -4395,7 +4386,7 @@
43954386
"type": "library",
43964387
"bom-ref": "67-python-gnupg",
43974388
"name": "python-gnupg",
4398-
"version": "0.5.4",
4389+
"version": "0.5.5",
43994390
"supplier": {
44004391
"name": "Vinay Sajip",
44014392
"contact": [
@@ -4404,12 +4395,12 @@
44044395
}
44054396
]
44064397
},
4407-
"cpe": "cpe:2.3:a:vinay_sajip:python-gnupg:0.5.4:*:*:*:*:*:*:*",
4398+
"cpe": "cpe:2.3:a:vinay_sajip:python-gnupg:0.5.5:*:*:*:*:*:*:*",
44084399
"description": "A wrapper for the Gnu Privacy Guard (GPG or GnuPG)",
44094400
"hashes": [
44104401
{
44114402
"alg": "SHA-256",
4412-
"content": "40ce25cde9df29af91fe931ce9df3ce544e14a37f62b13ca878c897217b2de6c"
4403+
"content": "51fa7b8831ff0914bc73d74c59b99c613de7247b91294323c39733bb85ac3fc1"
44134404
}
44144405
],
44154406
"licenses": [
@@ -4428,7 +4419,7 @@
44284419
"comment": "Home page for project"
44294420
},
44304421
{
4431-
"url": "https://pypi.org/project/python-gnupg/0.5.4/#files",
4422+
"url": "https://pypi.org/project/python-gnupg/0.5.5/#files",
44324423
"type": "distribution",
44334424
"comment": "Download location for component"
44344425
},
@@ -4445,11 +4436,11 @@
44454436
"type": "issue-tracker"
44464437
}
44474438
],
4448-
"purl": "pkg:pypi/[email protected].4",
4439+
"purl": "pkg:pypi/[email protected].5",
44494440
"properties": [
44504441
{
44514442
"name": "release_date",
4452-
"value": "2025-01-07T11:58:32Z"
4443+
"value": "2025-08-04T19:26:54Z"
44534444
},
44544445
{
44554446
"name": "language",
@@ -4535,7 +4526,7 @@
45354526
"type": "library",
45364527
"bom-ref": "69-charset-normalizer",
45374528
"name": "charset-normalizer",
4538-
"version": "3.4.2",
4529+
"version": "3.4.3",
45394530
"supplier": {
45404531
"name": "Ahmed R .",
45414532
"contact": [
@@ -4544,12 +4535,12 @@
45444535
}
45454536
]
45464537
},
4547-
"cpe": "cpe:2.3:a:ahmed_r.:charset-normalizer:3.4.2:*:*:*:*:*:*:*",
4538+
"cpe": "cpe:2.3:a:ahmed_r.:charset-normalizer:3.4.3:*:*:*:*:*:*:*",
45484539
"description": "The Real First Universal Charset Detector. Open, modern and actively maintained alternative to Chardet.",
45494540
"hashes": [
45504541
{
45514542
"alg": "SHA-256",
4552-
"content": "7c48ed483eb946e6c04ccbe02c6b4d1d48e51944b6db70f697e089c193404941"
4543+
"content": "fb7f67a1bfa6e40b438170ebdc8158b78dc465a5a67b6dde178a46987b244a72"
45534544
}
45544545
],
45554546
"licenses": [
@@ -4563,7 +4554,7 @@
45634554
],
45644555
"externalReferences": [
45654556
{
4566-
"url": "https://pypi.org/project/charset-normalizer/3.4.2/#files",
4557+
"url": "https://pypi.org/project/charset-normalizer/3.4.3/#files",
45674558
"type": "distribution",
45684559
"comment": "Download location for component"
45694560
},
@@ -4584,11 +4575,11 @@
45844575
"type": "issue-tracker"
45854576
}
45864577
],
4587-
"purl": "pkg:pypi/[email protected].2",
4578+
"purl": "pkg:pypi/[email protected].3",
45884579
"properties": [
45894580
{
45904581
"name": "release_date",
4591-
"value": "2025-05-02T08:31:46Z"
4582+
"value": "2025-08-09T07:55:36Z"
45924583
},
45934584
{
45944585
"name": "language",

0 commit comments

Comments
 (0)