Skip to content

Commit b95b3a8

Browse files
chore: update SBOM for Python 3.13 (#5247)
Co-authored-by: GitHub <[email protected]>
1 parent e854793 commit b95b3a8

File tree

2 files changed

+26
-29
lines changed

2 files changed

+26
-29
lines changed

sbom/cve-bin-tool-py3.13.json

Lines changed: 13 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:fb74c625-c429-4f5b-b30c-43cc78902dea",
5+
"serialNumber": "urn:uuid:36ba5917-da55-4614-9e16-f2896e66508b",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-07-21T00:55:19Z",
8+
"timestamp": "2025-07-28T00:57:13Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -3742,7 +3742,7 @@
37423742
"type": "library",
37433743
"bom-ref": "57-rich",
37443744
"name": "rich",
3745-
"version": "14.0.0",
3745+
"version": "14.1.0",
37463746
"supplier": {
37473747
"name": "Will McGugan",
37483748
"contact": [
@@ -3751,12 +3751,12 @@
37513751
}
37523752
]
37533753
},
3754-
"cpe": "cpe:2.3:a:will_mcgugan:rich:14.0.0:*:*:*:*:*:*:*",
3754+
"cpe": "cpe:2.3:a:will_mcgugan:rich:14.1.0:*:*:*:*:*:*:*",
37553755
"description": "Render rich text, tables, progress bars, syntax highlighting, markdown and more to the terminal",
37563756
"hashes": [
37573757
{
37583758
"alg": "SHA-256",
3759-
"content": "1c9491e1951aac09caffd42f448ee3d04e58923ffe14993f6e83068dc395d7e0"
3759+
"content": "536f5f1785986d6dbdea3c75205c473f970777b4a0d6c6dd1b696aa05a3fa04f"
37603760
}
37613761
],
37623762
"licenses": [
@@ -3775,7 +3775,7 @@
37753775
"comment": "Home page for project"
37763776
},
37773777
{
3778-
"url": "https://pypi.org/project/rich/14.0.0/#files",
3778+
"url": "https://pypi.org/project/rich/14.1.0/#files",
37793779
"type": "distribution",
37803780
"comment": "Download location for component"
37813781
},
@@ -3784,11 +3784,11 @@
37843784
"type": "documentation"
37853785
}
37863786
],
3787-
"purl": "pkg:pypi/rich@14.0.0",
3787+
"purl": "pkg:pypi/rich@14.1.0",
37883788
"properties": [
37893789
{
37903790
"name": "release_date",
3791-
"value": "2025-03-30T14:15:12Z"
3791+
"value": "2025-07-25T07:32:56Z"
37923792
},
37933793
{
37943794
"name": "language",
@@ -4133,7 +4133,7 @@
41334133
"type": "library",
41344134
"bom-ref": "63-narwhals",
41354135
"name": "narwhals",
4136-
"version": "1.47.1",
4136+
"version": "1.48.1",
41374137
"supplier": {
41384138
"name": "Marco Gorelli",
41394139
"contact": [
@@ -4142,7 +4142,7 @@
41424142
}
41434143
]
41444144
},
4145-
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:1.47.1:*:*:*:*:*:*:*",
4145+
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:1.48.1:*:*:*:*:*:*:*",
41464146
"description": "Extremely lightweight compatibility layer between dataframe libraries",
41474147
"licenses": [
41484148
{
@@ -4160,7 +4160,7 @@
41604160
"comment": "Home page for project"
41614161
},
41624162
{
4163-
"url": "https://pypi.org/project/narwhals/1.47.1/#files",
4163+
"url": "https://pypi.org/project/narwhals/1.48.1/#files",
41644164
"type": "distribution",
41654165
"comment": "Download location for component"
41664166
},
@@ -4177,7 +4177,7 @@
41774177
"type": "issue-tracker"
41784178
}
41794179
],
4180-
"purl": "pkg:pypi/narwhals@1.47.1",
4180+
"purl": "pkg:pypi/narwhals@1.48.1",
41814181
"properties": [
41824182
{
41834183
"name": "release_date",
@@ -5008,8 +5008,7 @@
50085008
"ref": "57-rich",
50095009
"dependsOn": [
50105010
"58-markdown-it-py",
5011-
"60-pygments",
5012-
"6-typing-extensions"
5011+
"60-pygments"
50135012
]
50145013
},
50155014
{

sbom/cve-bin-tool-py3.13.spdx

Lines changed: 13 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-058c5540-1d06-4078-a6ba-7ff62dbe14bf
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-26da68f2-4b83-478c-a3a4-9cf7dc97e92e
66
LicenseListVersion: 3.26
77
Creator: Tool: sbom4python-0.12.4
8-
Created: 2025-07-21T00:54:46Z
8+
Created: 2025-07-28T00:56:36Z
99
CreatorComment: <text>SBOM Type: Build - This document has been automatically generated.</text>
1010
#####
1111

@@ -843,13 +843,12 @@ PackageSupplier: Person: Craig Citro ([email protected])
843843
PackageDownloadLocation: https://pypi.org/project/google-apitools/0.5.32/#files
844844
FilesAnalyzed: false
845845
PackageHomePage: http://github.com/google/apitools
846-
PackageChecksum: SHA256: b78f74116558e0476e19501b5b4b2ac7c93261a69c5449c861ea95cbc853c688
847846
PackageLicenseDeclared: NOASSERTION
848847
PackageLicenseConcluded: Apache-2.0
849848
PackageLicenseComments: <text>google-apitools declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
850849
PackageCopyrightText: NOASSERTION
851850
PackageSummary: <text>client libraries for humans</text>
852-
ReleaseDate: 2021-05-05T22:12:58Z
851+
ReleaseDate: 2023-12-12T17:40:13Z
853852
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected]
854853
ExternalRef: SECURITY cpe23Type cpe:2.3:a:craig_citro:google-apitools:0.5.32:*:*:*:*:*:*:*
855854
#####
@@ -1192,21 +1191,21 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_purl_authors:packageurl-python:0.1
11921191

11931192
PackageName: rich
11941193
SPDXID: SPDXRef-57-rich
1195-
PackageVersion: 14.0.0
1194+
PackageVersion: 14.1.0
11961195
PrimaryPackagePurpose: LIBRARY
11971196
PackageSupplier: Person: Will McGugan ([email protected])
1198-
PackageDownloadLocation: https://pypi.org/project/rich/14.0.0/#files
1197+
PackageDownloadLocation: https://pypi.org/project/rich/14.1.0/#files
11991198
FilesAnalyzed: false
12001199
PackageHomePage: https://github.com/Textualize/rich
1201-
PackageChecksum: SHA256: 1c9491e1951aac09caffd42f448ee3d04e58923ffe14993f6e83068dc395d7e0
1200+
PackageChecksum: SHA256: 536f5f1785986d6dbdea3c75205c473f970777b4a0d6c6dd1b696aa05a3fa04f
12021201
PackageLicenseDeclared: MIT
12031202
PackageLicenseConcluded: MIT
12041203
PackageCopyrightText: NOASSERTION
12051204
PackageSummary: <text>Render rich text, tables, progress bars, syntax highlighting, markdown and more to the terminal</text>
1206-
ReleaseDate: 2025-03-30T14:15:12Z
1205+
ReleaseDate: 2025-07-25T07:32:56Z
12071206
ExternalRef: OTHER documentation https://rich.readthedocs.io/en/latest/
1208-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rich@14.0.0
1209-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:will_mcgugan:rich:14.0.0:*:*:*:*:*:*:*
1207+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rich@14.1.0
1208+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:will_mcgugan:rich:14.1.0:*:*:*:*:*:*:*
12101209
#####
12111210

12121211
PackageName: markdown-it-py
@@ -1335,10 +1334,10 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:6.2.0:*:*:*:*:*:*:*
13351334

13361335
PackageName: narwhals
13371336
SPDXID: SPDXRef-63-narwhals
1338-
PackageVersion: 1.47.1
1337+
PackageVersion: 1.48.1
13391338
PrimaryPackagePurpose: LIBRARY
13401339
PackageSupplier: Person: Marco Gorelli ([email protected])
1341-
PackageDownloadLocation: https://pypi.org/project/narwhals/1.47.1/#files
1340+
PackageDownloadLocation: https://pypi.org/project/narwhals/1.48.1/#files
13421341
FilesAnalyzed: false
13431342
PackageHomePage: https://github.com/narwhals-dev/narwhals
13441343
PackageLicenseDeclared: NOASSERTION
@@ -1350,8 +1349,8 @@ ReleaseDate: 2025-06-26T16:20:40Z
13501349
ExternalRef: OTHER documentation https://narwhals-dev.github.io/narwhals/
13511350
ExternalRef: OTHER vcs https://github.com/narwhals-dev/narwhals
13521351
ExternalRef: OTHER issue-tracker https://github.com/narwhals-dev/narwhals/issues
1353-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@1.47.1
1354-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:1.47.1:*:*:*:*:*:*:*
1352+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@1.48.1
1353+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:1.48.1:*:*:*:*:*:*:*
13551354
#####
13561355

13571356
PackageName: python-gnupg
@@ -1636,7 +1635,6 @@ Relationship: SPDXRef-54-lib4vex DEPENDS_ON SPDXRef-56-packageurl-python
16361635
Relationship: SPDXRef-55-csaf-tool DEPENDS_ON SPDXRef-56-packageurl-python
16371636
Relationship: SPDXRef-55-csaf-tool DEPENDS_ON SPDXRef-57-rich
16381637
Relationship: SPDXRef-57-rich DEPENDS_ON SPDXRef-58-markdown-it-py
1639-
Relationship: SPDXRef-57-rich DEPENDS_ON SPDXRef-6-typing-extensions
16401638
Relationship: SPDXRef-57-rich DEPENDS_ON SPDXRef-60-pygments
16411639
Relationship: SPDXRef-58-markdown-it-py DEPENDS_ON SPDXRef-59-mdurl
16421640
Relationship: SPDXRef-62-plotly DEPENDS_ON SPDXRef-61-packaging

0 commit comments

Comments
 (0)