Skip to content

Commit c02a7e1

Browse files
chore: update SBOM for Python 3.12 (#5259)
Co-authored-by: GitHub <[email protected]>
1 parent 271264d commit c02a7e1

File tree

2 files changed

+59
-55
lines changed

2 files changed

+59
-55
lines changed

sbom/cve-bin-tool-py3.12.json

Lines changed: 32 additions & 29 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:e2c997fc-ffcb-409c-afb4-eb78e9d03a40",
5+
"serialNumber": "urn:uuid:ceaa1b8c-bf44-4cb8-97ea-c548156df63a",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-07-28T00:57:11Z",
8+
"timestamp": "2025-08-04T00:53:00Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -79,21 +79,18 @@
7979
"type": "library",
8080
"bom-ref": "2-aiohttp",
8181
"name": "aiohttp",
82-
"version": "3.12.14",
82+
"version": "3.12.15",
8383
"description": "Async http client/server framework (asyncio)",
8484
"hashes": [
8585
{
8686
"alg": "SHA-256",
87-
"content": "906d5075b5ba0dd1c66fcaaf60eb09926a9fef3ca92d912d2a0bbdbecf8b1248"
87+
"content": "b6fc902bff74d9b1879ad55f5404153e2b33a82e72a95c89cec5eb6cc9e92fbc"
8888
}
8989
],
9090
"licenses": [
9191
{
92-
"license": {
93-
"id": "Apache-2.0",
94-
"url": "https://www.apache.org/licenses/LICENSE-2.0",
95-
"acknowledgement": "concluded"
96-
}
92+
"expression": "Apache-2.0 AND MIT",
93+
"acknowledgement": "concluded"
9794
}
9895
],
9996
"externalReferences": [
@@ -103,7 +100,7 @@
103100
"comment": "Home page for project"
104101
},
105102
{
106-
"url": "https://pypi.org/project/aiohttp/3.12.14/#files",
103+
"url": "https://pypi.org/project/aiohttp/3.12.15/#files",
107104
"type": "distribution",
108105
"comment": "Download location for component"
109106
},
@@ -140,11 +137,11 @@
140137
"type": "vcs"
141138
}
142139
],
143-
"purl": "pkg:pypi/[email protected].14",
140+
"purl": "pkg:pypi/[email protected].15",
144141
"properties": [
145142
{
146143
"name": "release_date",
147-
"value": "2025-07-10T13:02:38Z"
144+
"value": "2025-07-29T05:49:43Z"
148145
},
149146
{
150147
"name": "language",
@@ -3689,16 +3686,16 @@
36893686
"type": "library",
36903687
"bom-ref": "56-packageurl-python",
36913688
"name": "packageurl-python",
3692-
"version": "0.17.1",
3689+
"version": "0.17.3",
36933690
"supplier": {
36943691
"name": "the purl authors"
36953692
},
3696-
"cpe": "cpe:2.3:a:the_purl_authors:packageurl-python:0.17.1:*:*:*:*:*:*:*",
3693+
"cpe": "cpe:2.3:a:the_purl_authors:packageurl-python:0.17.3:*:*:*:*:*:*:*",
36973694
"description": "A purl aka. Package URL parser and builder",
36983695
"hashes": [
36993696
{
37003697
"alg": "SHA-256",
3701-
"content": "59b0862ae0b216994f847e05b4c6e870e0d16e1ddd706feefb19d79810f22cbd"
3698+
"content": "f51b5aab570159f07258c8e998e9972ff3bf060da16b7334a42bd9f9737777d9"
37023699
}
37033700
],
37043701
"licenses": [
@@ -3717,16 +3714,16 @@
37173714
"comment": "Home page for project"
37183715
},
37193716
{
3720-
"url": "https://pypi.org/project/packageurl-python/0.17.1/#files",
3717+
"url": "https://pypi.org/project/packageurl-python/0.17.3/#files",
37213718
"type": "distribution",
37223719
"comment": "Download location for component"
37233720
}
37243721
],
3725-
"purl": "pkg:pypi/[email protected].1",
3722+
"purl": "pkg:pypi/[email protected].3",
37263723
"properties": [
37273724
{
37283725
"name": "release_date",
3729-
"value": "2025-06-06T13:13:58Z"
3726+
"value": "2025-08-01T03:24:33Z"
37303727
},
37313728
{
37323729
"name": "language",
@@ -4133,7 +4130,7 @@
41334130
"type": "library",
41344131
"bom-ref": "63-narwhals",
41354132
"name": "narwhals",
4136-
"version": "1.48.1",
4133+
"version": "2.0.1",
41374134
"supplier": {
41384135
"name": "Marco Gorelli",
41394136
"contact": [
@@ -4142,8 +4139,14 @@
41424139
}
41434140
]
41444141
},
4145-
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:1.48.1:*:*:*:*:*:*:*",
4142+
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:2.0.1:*:*:*:*:*:*:*",
41464143
"description": "Extremely lightweight compatibility layer between dataframe libraries",
4144+
"hashes": [
4145+
{
4146+
"alg": "SHA-256",
4147+
"content": "837457e36a2ba1710c881fb69e1f79ce44fb81728c92ac378f70892a53af8ddb"
4148+
}
4149+
],
41474150
"licenses": [
41484151
{
41494152
"license": {
@@ -4160,7 +4163,7 @@
41604163
"comment": "Home page for project"
41614164
},
41624165
{
4163-
"url": "https://pypi.org/project/narwhals/1.48.1/#files",
4166+
"url": "https://pypi.org/project/narwhals/2.0.1/#files",
41644167
"type": "distribution",
41654168
"comment": "Download location for component"
41664169
},
@@ -4177,11 +4180,11 @@
41774180
"type": "issue-tracker"
41784181
}
41794182
],
4180-
"purl": "pkg:pypi/narwhals@1.48.1",
4183+
"purl": "pkg:pypi/narwhals@2.0.1",
41814184
"properties": [
41824185
{
41834186
"name": "release_date",
4184-
"value": "2025-06-26T16:20:40Z"
4187+
"value": "2025-07-29T08:39:03Z"
41854188
},
41864189
{
41874190
"name": "language",
@@ -4470,7 +4473,7 @@
44704473
"type": "library",
44714474
"bom-ref": "68-certifi",
44724475
"name": "certifi",
4473-
"version": "2025.7.14",
4476+
"version": "2025.8.3",
44744477
"supplier": {
44754478
"name": "Kenneth Reitz",
44764479
"contact": [
@@ -4479,12 +4482,12 @@
44794482
}
44804483
]
44814484
},
4482-
"cpe": "cpe:2.3:a:kenneth_reitz:certifi:2025.7.14:*:*:*:*:*:*:*",
4485+
"cpe": "cpe:2.3:a:kenneth_reitz:certifi:2025.8.3:*:*:*:*:*:*:*",
44834486
"description": "Python package for providing Mozilla's CA Bundle.",
44844487
"hashes": [
44854488
{
44864489
"alg": "SHA-256",
4487-
"content": "6b31f564a415d79ee77df69d757bb49a5bb53bd9f756cbbe24394ffd6fc1f4b2"
4490+
"content": "f6c12493cfb1b06ba2ff328595af9350c65d6644968e5d3a2ffd78699af217a5"
44884491
}
44894492
],
44904493
"licenses": [
@@ -4503,7 +4506,7 @@
45034506
"comment": "Home page for project"
45044507
},
45054508
{
4506-
"url": "https://pypi.org/project/certifi/2025.7.14/#files",
4509+
"url": "https://pypi.org/project/certifi/2025.8.3/#files",
45074510
"type": "distribution",
45084511
"comment": "Download location for component"
45094512
},
@@ -4512,11 +4515,11 @@
45124515
"type": "vcs"
45134516
}
45144517
],
4515-
"purl": "pkg:pypi/certifi@2025.7.14",
4518+
"purl": "pkg:pypi/certifi@2025.8.3",
45164519
"properties": [
45174520
{
45184521
"name": "release_date",
4519-
"value": "2025-07-14T03:29:26Z"
4522+
"value": "2025-08-03T03:07:45Z"
45204523
},
45214524
{
45224525
"name": "language",

sbom/cve-bin-tool-py3.12.spdx

Lines changed: 27 additions & 26 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-931eb3be-4fa7-445e-8125-67b7d5b83228
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-8b2aaee3-bbf4-40f9-90bf-fcd6dd65d02e
66
LicenseListVersion: 3.26
77
Creator: Tool: sbom4python-0.12.4
8-
Created: 2025-07-28T00:56:37Z
8+
Created: 2025-08-04T00:52:52Z
99
CreatorComment: <text>SBOM Type: Build - This document has been automatically generated.</text>
1010
#####
1111

@@ -27,18 +27,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.4.1:*:*:*:*:*
2727

2828
PackageName: aiohttp
2929
SPDXID: SPDXRef-2-aiohttp
30-
PackageVersion: 3.12.14
30+
PackageVersion: 3.12.15
3131
PrimaryPackagePurpose: LIBRARY
3232
PackageSupplier: NOASSERTION
33-
PackageDownloadLocation: https://pypi.org/project/aiohttp/3.12.14/#files
33+
PackageDownloadLocation: https://pypi.org/project/aiohttp/3.12.15/#files
3434
FilesAnalyzed: false
3535
PackageHomePage: https://github.com/aio-libs/aiohttp
36-
PackageChecksum: SHA256: 906d5075b5ba0dd1c66fcaaf60eb09926a9fef3ca92d912d2a0bbdbecf8b1248
37-
PackageLicenseDeclared: Apache-2.0
38-
PackageLicenseConcluded: Apache-2.0
36+
PackageChecksum: SHA256: b6fc902bff74d9b1879ad55f5404153e2b33a82e72a95c89cec5eb6cc9e92fbc
37+
PackageLicenseDeclared: Apache-2.0 AND MIT
38+
PackageLicenseConcluded: Apache-2.0 AND MIT
3939
PackageCopyrightText: NOASSERTION
4040
PackageSummary: <text>Async http client/server framework (asyncio)</text>
41-
ReleaseDate: 2025-07-10T13:02:38Z
41+
ReleaseDate: 2025-07-29T05:49:43Z
4242
ExternalRef: OTHER other https://matrix.to/#/#aio-libs:matrix.org
4343
ExternalRef: OTHER other https://matrix.to/#/#aio-libs-space:matrix.org
4444
ExternalRef: OTHER build-system https://github.com/aio-libs/aiohttp/actions?query=workflow%3ACI
@@ -47,7 +47,7 @@ ExternalRef: OTHER log https://docs.aiohttp.org/en/stable/changes.html
4747
ExternalRef: OTHER other https://docs.aiohttp.org
4848
ExternalRef: OTHER issue-tracker https://github.com/aio-libs/aiohttp/issues
4949
ExternalRef: OTHER vcs https://github.com/aio-libs/aiohttp
50-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].14
50+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].15
5151
#####
5252

5353
PackageName: aiohappyeyeballs
@@ -1174,20 +1174,20 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:anthony_harrison:csaf-tool:0.3.2:*:*:*
11741174

11751175
PackageName: packageurl-python
11761176
SPDXID: SPDXRef-56-packageurl-python
1177-
PackageVersion: 0.17.1
1177+
PackageVersion: 0.17.3
11781178
PrimaryPackagePurpose: LIBRARY
11791179
PackageSupplier: Person: the purl authors
1180-
PackageDownloadLocation: https://pypi.org/project/packageurl-python/0.17.1/#files
1180+
PackageDownloadLocation: https://pypi.org/project/packageurl-python/0.17.3/#files
11811181
FilesAnalyzed: false
11821182
PackageHomePage: https://github.com/package-url/packageurl-python
1183-
PackageChecksum: SHA256: 59b0862ae0b216994f847e05b4c6e870e0d16e1ddd706feefb19d79810f22cbd
1183+
PackageChecksum: SHA256: f51b5aab570159f07258c8e998e9972ff3bf060da16b7334a42bd9f9737777d9
11841184
PackageLicenseDeclared: MIT
11851185
PackageLicenseConcluded: MIT
11861186
PackageCopyrightText: NOASSERTION
11871187
PackageSummary: <text>A purl aka. Package URL parser and builder</text>
1188-
ReleaseDate: 2025-06-06T13:13:58Z
1189-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].1
1190-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_purl_authors:packageurl-python:0.17.1:*:*:*:*:*:*:*
1188+
ReleaseDate: 2025-08-01T03:24:33Z
1189+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].3
1190+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_purl_authors:packageurl-python:0.17.3:*:*:*:*:*:*:*
11911191
#####
11921192

11931193
PackageName: rich
@@ -1335,23 +1335,24 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:6.2.0:*:*:*:*:*:*:*
13351335

13361336
PackageName: narwhals
13371337
SPDXID: SPDXRef-63-narwhals
1338-
PackageVersion: 1.48.1
1338+
PackageVersion: 2.0.1
13391339
PrimaryPackagePurpose: LIBRARY
13401340
PackageSupplier: Person: Marco Gorelli ([email protected])
1341-
PackageDownloadLocation: https://pypi.org/project/narwhals/1.48.1/#files
1341+
PackageDownloadLocation: https://pypi.org/project/narwhals/2.0.1/#files
13421342
FilesAnalyzed: false
13431343
PackageHomePage: https://github.com/narwhals-dev/narwhals
1344+
PackageChecksum: SHA256: 837457e36a2ba1710c881fb69e1f79ce44fb81728c92ac378f70892a53af8ddb
13441345
PackageLicenseDeclared: NOASSERTION
13451346
PackageLicenseConcluded: MIT
13461347
PackageLicenseComments: <text>narwhals declares MIT License which is not currently a valid SPDX License identifier or expression.</text>
13471348
PackageCopyrightText: NOASSERTION
13481349
PackageSummary: <text>Extremely lightweight compatibility layer between dataframe libraries</text>
1349-
ReleaseDate: 2025-06-26T16:20:40Z
1350+
ReleaseDate: 2025-07-29T08:39:03Z
13501351
ExternalRef: OTHER documentation https://narwhals-dev.github.io/narwhals/
13511352
ExternalRef: OTHER vcs https://github.com/narwhals-dev/narwhals
13521353
ExternalRef: OTHER issue-tracker https://github.com/narwhals-dev/narwhals/issues
1353-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@1.48.1
1354-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:1.48.1:*:*:*:*:*:*:*
1354+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@2.0.1
1355+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:2.0.1:*:*:*:*:*:*:*
13551356
#####
13561357

13571358
PackageName: python-gnupg
@@ -1440,21 +1441,21 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_petrov:urllib3:2.5.0:*:*:*:*:*:
14401441

14411442
PackageName: certifi
14421443
SPDXID: SPDXRef-68-certifi
1443-
PackageVersion: 2025.7.14
1444+
PackageVersion: 2025.8.3
14441445
PrimaryPackagePurpose: LIBRARY
14451446
PackageSupplier: Person: Kenneth Reitz ([email protected])
1446-
PackageDownloadLocation: https://pypi.org/project/certifi/2025.7.14/#files
1447+
PackageDownloadLocation: https://pypi.org/project/certifi/2025.8.3/#files
14471448
FilesAnalyzed: false
14481449
PackageHomePage: https://github.com/certifi/python-certifi
1449-
PackageChecksum: SHA256: 6b31f564a415d79ee77df69d757bb49a5bb53bd9f756cbbe24394ffd6fc1f4b2
1450+
PackageChecksum: SHA256: f6c12493cfb1b06ba2ff328595af9350c65d6644968e5d3a2ffd78699af217a5
14501451
PackageLicenseDeclared: MPL-2.0
14511452
PackageLicenseConcluded: MPL-2.0
14521453
PackageCopyrightText: NOASSERTION
14531454
PackageSummary: <text>Python package for providing Mozilla's CA Bundle.</text>
1454-
ReleaseDate: 2025-07-14T03:29:26Z
1455+
ReleaseDate: 2025-08-03T03:07:45Z
14551456
ExternalRef: OTHER vcs https://github.com/certifi/python-certifi
1456-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/certifi@2025.7.14
1457-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:certifi:2025.7.14:*:*:*:*:*:*:*
1457+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/certifi@2025.8.3
1458+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:certifi:2025.8.3:*:*:*:*:*:*:*
14581459
#####
14591460

14601461
PackageName: rpmfile

0 commit comments

Comments
 (0)