Skip to content

Commit c4ba8ab

Browse files
web-flowgithub-actions[bot]
authored andcommitted
chore: update SBOM for Python 3.13
1 parent c2cbfb9 commit c4ba8ab

File tree

2 files changed

+59
-85
lines changed

2 files changed

+59
-85
lines changed

sbom/cve-bin-tool-py3.13.json

Lines changed: 32 additions & 30 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:8e073784-8a9b-46fe-8a88-6ddf94534847",
5+
"serialNumber": "urn:uuid:fb20c3d5-da0d-4c39-a74c-4949c29c5bb4",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-09-22T00:45:57Z",
8+
"timestamp": "2025-09-29T00:37:57Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -876,7 +876,7 @@
876876
"type": "library",
877877
"bom-ref": "12-beautifulsoup4",
878878
"name": "beautifulsoup4",
879-
"version": "4.13.5",
879+
"version": "4.14.0",
880880
"supplier": {
881881
"name": "Leonard Richardson",
882882
"contact": [
@@ -885,12 +885,12 @@
885885
}
886886
]
887887
},
888-
"cpe": "cpe:2.3:a:leonard_richardson:beautifulsoup4:4.13.5:*:*:*:*:*:*:*",
888+
"cpe": "cpe:2.3:a:leonard_richardson:beautifulsoup4:4.14.0:*:*:*:*:*:*:*",
889889
"description": "Screen-scraping library",
890890
"hashes": [
891891
{
892892
"alg": "SHA-256",
893-
"content": "642085eaa22233aceadff9c69651bc51e8bf3f874fb6d7104ece2beb24b47c4a"
893+
"content": "aee96fbccdf2d2a8d1288b2afa51fc76bb60823b7881a50fb1ed5f711d1a7d73"
894894
}
895895
],
896896
"licenses": [
@@ -909,7 +909,7 @@
909909
"comment": "Home page for project"
910910
},
911911
{
912-
"url": "https://pypi.org/project/beautifulsoup4/4.13.5/#files",
912+
"url": "https://pypi.org/project/beautifulsoup4/4.14.0/#files",
913913
"type": "distribution",
914914
"comment": "Download location for component"
915915
},
@@ -918,11 +918,11 @@
918918
"type": "other"
919919
}
920920
],
921-
"purl": "pkg:pypi/beautifulsoup4@4.13.5",
921+
"purl": "pkg:pypi/beautifulsoup4@4.14.0",
922922
"properties": [
923923
{
924924
"name": "release_date",
925-
"value": "2025-08-24T14:06:14Z"
925+
"value": "2025-09-27T17:22:16Z"
926926
},
927927
{
928928
"name": "language",
@@ -2013,6 +2013,12 @@
20132013
},
20142014
"cpe": "cpe:2.3:a:paul_mcguire:pyparsing:3.2.5:*:*:*:*:*:*:*",
20152015
"description": "pyparsing - Classes and methods to define and execute parsing grammars",
2016+
"hashes": [
2017+
{
2018+
"alg": "SHA-256",
2019+
"content": "e38a4f02064cf41fe6593d328d0512495ad1f3d8a91c4f73fc401b3079a59a5e"
2020+
}
2021+
],
20162022
"externalReferences": [
20172023
{
20182024
"url": "https://github.com/pyparsing/pyparsing/",
@@ -2029,7 +2035,7 @@
20292035
"properties": [
20302036
{
20312037
"name": "release_date",
2032-
"value": "2022-02-03T00:00:29Z"
2038+
"value": "2025-09-21T04:11:04Z"
20332039
},
20342040
{
20352041
"name": "language",
@@ -2679,7 +2685,7 @@
26792685
"type": "library",
26802686
"bom-ref": "41-google-apitools",
26812687
"name": "google-apitools",
2682-
"version": "0.5.32",
2688+
"version": "0.5.35",
26832689
"supplier": {
26842690
"name": "Craig Citro",
26852691
"contact": [
@@ -2688,12 +2694,12 @@
26882694
}
26892695
]
26902696
},
2691-
"cpe": "cpe:2.3:a:craig_citro:google-apitools:0.5.32:*:*:*:*:*:*:*",
2697+
"cpe": "cpe:2.3:a:craig_citro:google-apitools:0.5.35:*:*:*:*:*:*:*",
26922698
"description": "client libraries for humans",
26932699
"hashes": [
26942700
{
26952701
"alg": "SHA-256",
2696-
"content": "b78f74116558e0476e19501b5b4b2ac7c93261a69c5449c861ea95cbc853c688"
2702+
"content": "0f6f67fbe6f228f4777ae7e9d00e01476f7b8a48dca3a4353a1c32369437bbd0"
26972703
}
26982704
],
26992705
"licenses": [
@@ -2712,16 +2718,16 @@
27122718
"comment": "Home page for project"
27132719
},
27142720
{
2715-
"url": "https://pypi.org/project/google-apitools/0.5.32/#files",
2721+
"url": "https://pypi.org/project/google-apitools/0.5.35/#files",
27162722
"type": "distribution",
27172723
"comment": "Download location for component"
27182724
}
27192725
],
2720-
"purl": "pkg:pypi/[email protected].32",
2726+
"purl": "pkg:pypi/[email protected].35",
27212727
"properties": [
27222728
{
27232729
"name": "release_date",
2724-
"value": "2021-05-05T22:12:58Z"
2730+
"value": "2025-09-24T20:22:49Z"
27252731
},
27262732
{
27272733
"name": "language",
@@ -2871,17 +2877,17 @@
28712877
"type": "library",
28722878
"bom-ref": "44-markupsafe",
28732879
"name": "markupsafe",
2874-
"version": "3.0.2",
2880+
"version": "3.0.3",
28752881
"description": "Safely add untrusted strings to HTML/XML markup.",
28762882
"hashes": [
28772883
{
28782884
"alg": "SHA-256",
2879-
"content": "7e94c425039cde14257288fd61dcfb01963e658efbc0ff54f5306b06054700f8"
2885+
"content": "2f981d352f04553a7171b8e44369f2af4055f888dfb147d55e42d29e29e74559"
28802886
}
28812887
],
28822888
"externalReferences": [
28832889
{
2884-
"url": "https://pypi.org/project/markupsafe/3.0.2/#files",
2890+
"url": "https://pypi.org/project/markupsafe/3.0.3/#files",
28852891
"type": "distribution",
28862892
"comment": "Download location for component"
28872893
},
@@ -2894,7 +2900,7 @@
28942900
"type": "documentation"
28952901
},
28962902
{
2897-
"url": "https://markupsafe.palletsprojects.com/changes/",
2903+
"url": "https://markupsafe.palletsprojects.com/page/changes/",
28982904
"type": "log"
28992905
},
29002906
{
@@ -2906,11 +2912,11 @@
29062912
"type": "chat"
29072913
}
29082914
],
2909-
"purl": "pkg:pypi/[email protected].2",
2915+
"purl": "pkg:pypi/[email protected].3",
29102916
"properties": [
29112917
{
29122918
"name": "release_date",
2913-
"value": "2024-10-18T15:20:51Z"
2919+
"value": "2025-09-27T18:36:05Z"
29142920
},
29152921
{
29162922
"name": "language",
@@ -2919,10 +2925,6 @@
29192925
{
29202926
"name": "python_version",
29212927
"value": "3.13.7"
2922-
},
2923-
{
2924-
"name": "License Comments",
2925-
"value": "markupsafe declares Copyright 2010 Pallets\n\nRedistribution and use in source and binary forms, with or without\nmodification, are permitted provided that the following conditions are\nmet:\n\n1. Redistributions of source code must retain the above copyright\n notice, this list of conditions and the following disclaimer.\n\n2. Redistributions in binary form must reproduce the above copyright\n notice, this list of conditions and the following disclaimer in the\n documentation and/or other materials provided with the distribution.\n\n3. Neither the name of the copyright holder nor the names of its\n contributors may be used to endorse or promote products derived from\n this software without specific prior written permission.\n\nTHIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS\n\"AS IS\" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT\nLIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A\nPARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT\nHOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,\nSPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED\nTO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR\nPROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF\nLIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING\nNEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS\nSOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.\n which is not currently a valid SPDX License identifier or expression."
29262928
}
29272929
]
29282930
},
@@ -3276,7 +3278,7 @@
32763278
"type": "library",
32773279
"bom-ref": "50-pyyaml",
32783280
"name": "pyyaml",
3279-
"version": "6.0.2",
3281+
"version": "6.0.3",
32803282
"supplier": {
32813283
"name": "Kirill Simonov",
32823284
"contact": [
@@ -3285,12 +3287,12 @@
32853287
}
32863288
]
32873289
},
3288-
"cpe": "cpe:2.3:a:kirill_simonov:pyyaml:6.0.2:*:*:*:*:*:*:*",
3290+
"cpe": "cpe:2.3:a:kirill_simonov:pyyaml:6.0.3:*:*:*:*:*:*:*",
32893291
"description": "YAML parser and emitter for Python",
32903292
"hashes": [
32913293
{
32923294
"alg": "SHA-256",
3293-
"content": "0a9a2848a5b7feac301353437eb7d5957887edbf81d56e903999a75a3d743086"
3295+
"content": "214ed4befebe12df36bcc8bc2b64b396ca31be9304b8f59e25c11cf94a4c033b"
32943296
}
32953297
],
32963298
"licenses": [
@@ -3334,11 +3336,11 @@
33343336
"type": "vcs"
33353337
}
33363338
],
3337-
"purl": "pkg:pypi/[email protected].2",
3339+
"purl": "pkg:pypi/[email protected].3",
33383340
"properties": [
33393341
{
33403342
"name": "release_date",
3341-
"value": "2024-08-06T20:31:40Z"
3343+
"value": "2025-09-25T21:31:46Z"
33423344
},
33433345
{
33443346
"name": "language",

sbom/cve-bin-tool-py3.13.spdx

Lines changed: 27 additions & 55 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-df626266-91c9-4f36-a228-57b53bea7e86
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-afe29016-65a3-45f3-9fee-8779a2dff759
66
LicenseListVersion: 3.26
77
Creator: Tool: sbom4python-0.12.4
8-
Created: 2025-09-22T00:45:34Z
8+
Created: 2025-09-29T00:37:37Z
99
CreatorComment: <text>SBOM Type: Build - This document has been automatically generated.</text>
1010
#####
1111

@@ -271,22 +271,22 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:kim_davies:idna:3.10:*:*:*:*:*:*:*
271271

272272
PackageName: beautifulsoup4
273273
SPDXID: SPDXRef-12-beautifulsoup4
274-
PackageVersion: 4.13.5
274+
PackageVersion: 4.14.0
275275
PrimaryPackagePurpose: LIBRARY
276276
PackageSupplier: Person: Leonard Richardson ([email protected])
277-
PackageDownloadLocation: https://pypi.org/project/beautifulsoup4/4.13.5/#files
277+
PackageDownloadLocation: https://pypi.org/project/beautifulsoup4/4.14.0/#files
278278
FilesAnalyzed: false
279279
PackageHomePage: https://www.crummy.com/software/BeautifulSoup/bs4/
280-
PackageChecksum: SHA256: 642085eaa22233aceadff9c69651bc51e8bf3f874fb6d7104ece2beb24b47c4a
280+
PackageChecksum: SHA256: aee96fbccdf2d2a8d1288b2afa51fc76bb60823b7881a50fb1ed5f711d1a7d73
281281
PackageLicenseDeclared: NOASSERTION
282282
PackageLicenseConcluded: MIT
283283
PackageLicenseComments: <text>beautifulsoup4 declares MIT License which is not currently a valid SPDX License identifier or expression.</text>
284284
PackageCopyrightText: NOASSERTION
285285
PackageSummary: <text>Screen-scraping library</text>
286-
ReleaseDate: 2025-08-24T14:06:14Z
286+
ReleaseDate: 2025-09-27T17:22:16Z
287287
ExternalRef: OTHER other https://www.crummy.com/software/BeautifulSoup/bs4/download/
288-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/beautifulsoup4@4.13.5
289-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:leonard_richardson:beautifulsoup4:4.13.5:*:*:*:*:*:*:*
288+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/beautifulsoup4@4.14.0
289+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:leonard_richardson:beautifulsoup4:4.14.0:*:*:*:*:*:*:*
290290
#####
291291

292292
PackageName: soupsieve
@@ -625,11 +625,12 @@ PackageSupplier: Person: Paul McGuire ([email protected])
625625
PackageDownloadLocation: https://pypi.org/project/pyparsing/3.2.5/#files
626626
FilesAnalyzed: false
627627
PackageHomePage: https://github.com/pyparsing/pyparsing/
628+
PackageChecksum: SHA256: e38a4f02064cf41fe6593d328d0512495ad1f3d8a91c4f73fc401b3079a59a5e
628629
PackageLicenseDeclared: NOASSERTION
629630
PackageLicenseConcluded: NOASSERTION
630631
PackageCopyrightText: NOASSERTION
631632
PackageSummary: <text>pyparsing - Classes and methods to define and execute parsing grammars</text>
632-
ReleaseDate: 2022-02-03T00:00:29Z
633+
ReleaseDate: 2025-09-21T04:11:04Z
633634
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected]
634635
ExternalRef: SECURITY cpe23Type cpe:2.3:a:paul_mcguire:pyparsing:3.2.5:*:*:*:*:*:*:*
635636
#####
@@ -834,21 +835,21 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_cloud_platform:google-auth-http
834835

835836
PackageName: google-apitools
836837
SPDXID: SPDXRef-41-google-apitools
837-
PackageVersion: 0.5.32
838+
PackageVersion: 0.5.35
838839
PrimaryPackagePurpose: LIBRARY
839840
PackageSupplier: Person: Craig Citro ([email protected])
840-
PackageDownloadLocation: https://pypi.org/project/google-apitools/0.5.32/#files
841+
PackageDownloadLocation: https://pypi.org/project/google-apitools/0.5.35/#files
841842
FilesAnalyzed: false
842843
PackageHomePage: http://github.com/google/apitools
843-
PackageChecksum: SHA256: b78f74116558e0476e19501b5b4b2ac7c93261a69c5449c861ea95cbc853c688
844+
PackageChecksum: SHA256: 0f6f67fbe6f228f4777ae7e9d00e01476f7b8a48dca3a4353a1c32369437bbd0
844845
PackageLicenseDeclared: NOASSERTION
845846
PackageLicenseConcluded: Apache-2.0
846847
PackageLicenseComments: <text>google-apitools declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
847848
PackageCopyrightText: NOASSERTION
848849
PackageSummary: <text>client libraries for humans</text>
849-
ReleaseDate: 2021-05-05T22:12:58Z
850-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].32
851-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:craig_citro:google-apitools:0.5.32:*:*:*:*:*:*:*
850+
ReleaseDate: 2025-09-24T20:22:49Z
851+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].35
852+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:craig_citro:google-apitools:0.5.35:*:*:*:*:*:*:*
852853
#####
853854

854855
PackageName: monotonic
@@ -894,52 +895,23 @@ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected]
894895

895896
PackageName: markupsafe
896897
SPDXID: SPDXRef-44-markupsafe
897-
PackageVersion: 3.0.2
898+
PackageVersion: 3.0.3
898899
PrimaryPackagePurpose: LIBRARY
899900
PackageSupplier: NOASSERTION
900-
PackageDownloadLocation: https://pypi.org/project/markupsafe/3.0.2/#files
901+
PackageDownloadLocation: https://pypi.org/project/markupsafe/3.0.3/#files
901902
FilesAnalyzed: false
902-
PackageChecksum: SHA256: 7e94c425039cde14257288fd61dcfb01963e658efbc0ff54f5306b06054700f8
903+
PackageChecksum: SHA256: 2f981d352f04553a7171b8e44369f2af4055f888dfb147d55e42d29e29e74559
903904
PackageLicenseDeclared: NOASSERTION
904905
PackageLicenseConcluded: NOASSERTION
905-
PackageLicenseComments: <text>markupsafe declares Copyright 2010 Pallets
906-
907-
Redistribution and use in source and binary forms, with or without
908-
modification, are permitted provided that the following conditions are
909-
met:
910-
911-
1. Redistributions of source code must retain the above copyright
912-
notice, this list of conditions and the following disclaimer.
913-
914-
2. Redistributions in binary form must reproduce the above copyright
915-
notice, this list of conditions and the following disclaimer in the
916-
documentation and/or other materials provided with the distribution.
917-
918-
3. Neither the name of the copyright holder nor the names of its
919-
contributors may be used to endorse or promote products derived from
920-
this software without specific prior written permission.
921-
922-
THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
923-
"AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
924-
LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A
925-
PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
926-
HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
927-
SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED
928-
TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR
929-
PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF
930-
LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING
931-
NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
932-
SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
933-
which is not currently a valid SPDX License identifier or expression.</text>
934906
PackageCopyrightText: NOASSERTION
935907
PackageSummary: <text>Safely add untrusted strings to HTML/XML markup.</text>
936-
ReleaseDate: 2024-10-18T15:20:51Z
908+
ReleaseDate: 2025-09-27T18:36:05Z
937909
ExternalRef: OTHER other https://palletsprojects.com/donate
938910
ExternalRef: OTHER documentation https://markupsafe.palletsprojects.com/
939-
ExternalRef: OTHER log https://markupsafe.palletsprojects.com/changes/
911+
ExternalRef: OTHER log https://markupsafe.palletsprojects.com/page/changes/
940912
ExternalRef: OTHER vcs https://github.com/pallets/markupsafe/
941913
ExternalRef: OTHER chat https://discord.gg/pallets
942-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].2
914+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].3
943915
#####
944916

945917
PackageName: jsonschema
@@ -1057,25 +1029,25 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:anthony_harrison:lib4sbom:0.8.8:*:*:*:
10571029

10581030
PackageName: pyyaml
10591031
SPDXID: SPDXRef-50-pyyaml
1060-
PackageVersion: 6.0.2
1032+
PackageVersion: 6.0.3
10611033
PrimaryPackagePurpose: LIBRARY
10621034
PackageSupplier: Person: Kirill Simonov ([email protected])
10631035
PackageDownloadLocation: https://pypi.org/project/PyYAML/
10641036
FilesAnalyzed: false
10651037
PackageHomePage: https://pyyaml.org/
1066-
PackageChecksum: SHA256: 0a9a2848a5b7feac301353437eb7d5957887edbf81d56e903999a75a3d743086
1038+
PackageChecksum: SHA256: 214ed4befebe12df36bcc8bc2b64b396ca31be9304b8f59e25c11cf94a4c033b
10671039
PackageLicenseDeclared: MIT
10681040
PackageLicenseConcluded: MIT
10691041
PackageCopyrightText: NOASSERTION
10701042
PackageSummary: <text>YAML parser and emitter for Python</text>
1071-
ReleaseDate: 2024-08-06T20:31:40Z
1043+
ReleaseDate: 2025-09-25T21:31:46Z
10721044
ExternalRef: OTHER issue-tracker https://github.com/yaml/pyyaml/issues
10731045
ExternalRef: OTHER build-system https://github.com/yaml/pyyaml/actions
10741046
ExternalRef: OTHER documentation https://pyyaml.org/wiki/PyYAMLDocumentation
10751047
ExternalRef: OTHER mailing-list http://lists.sourceforge.net/lists/listinfo/yaml-core
10761048
ExternalRef: OTHER vcs https://github.com/yaml/pyyaml
1077-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].2
1078-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:kirill_simonov:pyyaml:6.0.2:*:*:*:*:*:*:*
1049+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].3
1050+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:kirill_simonov:pyyaml:6.0.3:*:*:*:*:*:*:*
10791051
#####
10801052

10811053
PackageName: semantic-version

0 commit comments

Comments
 (0)