Skip to content

Commit ce1e91a

Browse files
chore: update SBOM for Python 3.9 (#5262)
Co-authored-by: GitHub <[email protected]>
1 parent d2495d4 commit ce1e91a

File tree

2 files changed

+63
-57
lines changed

2 files changed

+63
-57
lines changed

sbom/cve-bin-tool-py3.9.json

Lines changed: 32 additions & 29 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:ffb3a190-8265-4621-bc3e-dd215e726b80",
5+
"serialNumber": "urn:uuid:29ffed1c-efa7-44d7-afdf-1a001af181ee",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-07-28T00:57:10Z",
8+
"timestamp": "2025-08-04T00:53:09Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -79,21 +79,18 @@
7979
"type": "library",
8080
"bom-ref": "2-aiohttp",
8181
"name": "aiohttp",
82-
"version": "3.12.14",
82+
"version": "3.12.15",
8383
"description": "Async http client/server framework (asyncio)",
8484
"hashes": [
8585
{
8686
"alg": "SHA-256",
87-
"content": "906d5075b5ba0dd1c66fcaaf60eb09926a9fef3ca92d912d2a0bbdbecf8b1248"
87+
"content": "b6fc902bff74d9b1879ad55f5404153e2b33a82e72a95c89cec5eb6cc9e92fbc"
8888
}
8989
],
9090
"licenses": [
9191
{
92-
"license": {
93-
"id": "Apache-2.0",
94-
"url": "https://www.apache.org/licenses/LICENSE-2.0",
95-
"acknowledgement": "concluded"
96-
}
92+
"expression": "Apache-2.0 AND MIT",
93+
"acknowledgement": "concluded"
9794
}
9895
],
9996
"externalReferences": [
@@ -103,7 +100,7 @@
103100
"comment": "Home page for project"
104101
},
105102
{
106-
"url": "https://pypi.org/project/aiohttp/3.12.14/#files",
103+
"url": "https://pypi.org/project/aiohttp/3.12.15/#files",
107104
"type": "distribution",
108105
"comment": "Download location for component"
109106
},
@@ -140,11 +137,11 @@
140137
"type": "vcs"
141138
}
142139
],
143-
"purl": "pkg:pypi/[email protected].14",
140+
"purl": "pkg:pypi/[email protected].15",
144141
"properties": [
145142
{
146143
"name": "release_date",
147-
"value": "2025-07-10T13:02:38Z"
144+
"value": "2025-07-29T05:49:43Z"
148145
},
149146
{
150147
"name": "language",
@@ -3880,16 +3877,16 @@
38803877
"type": "library",
38813878
"bom-ref": "59-packageurl-python",
38823879
"name": "packageurl-python",
3883-
"version": "0.17.1",
3880+
"version": "0.17.3",
38843881
"supplier": {
38853882
"name": "the purl authors"
38863883
},
3887-
"cpe": "cpe:2.3:a:the_purl_authors:packageurl-python:0.17.1:*:*:*:*:*:*:*",
3884+
"cpe": "cpe:2.3:a:the_purl_authors:packageurl-python:0.17.3:*:*:*:*:*:*:*",
38883885
"description": "A purl aka. Package URL parser and builder",
38893886
"hashes": [
38903887
{
38913888
"alg": "SHA-256",
3892-
"content": "59b0862ae0b216994f847e05b4c6e870e0d16e1ddd706feefb19d79810f22cbd"
3889+
"content": "f51b5aab570159f07258c8e998e9972ff3bf060da16b7334a42bd9f9737777d9"
38933890
}
38943891
],
38953892
"licenses": [
@@ -3908,16 +3905,16 @@
39083905
"comment": "Home page for project"
39093906
},
39103907
{
3911-
"url": "https://pypi.org/project/packageurl-python/0.17.1/#files",
3908+
"url": "https://pypi.org/project/packageurl-python/0.17.3/#files",
39123909
"type": "distribution",
39133910
"comment": "Download location for component"
39143911
}
39153912
],
3916-
"purl": "pkg:pypi/[email protected].1",
3913+
"purl": "pkg:pypi/[email protected].3",
39173914
"properties": [
39183915
{
39193916
"name": "release_date",
3920-
"value": "2025-06-06T13:13:58Z"
3917+
"value": "2025-08-01T03:24:33Z"
39213918
},
39223919
{
39233920
"name": "language",
@@ -4324,7 +4321,7 @@
43244321
"type": "library",
43254322
"bom-ref": "66-narwhals",
43264323
"name": "narwhals",
4327-
"version": "1.48.1",
4324+
"version": "2.0.1",
43284325
"supplier": {
43294326
"name": "Marco Gorelli",
43304327
"contact": [
@@ -4333,8 +4330,14 @@
43334330
}
43344331
]
43354332
},
4336-
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:1.48.1:*:*:*:*:*:*:*",
4333+
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:2.0.1:*:*:*:*:*:*:*",
43374334
"description": "Extremely lightweight compatibility layer between dataframe libraries",
4335+
"hashes": [
4336+
{
4337+
"alg": "SHA-256",
4338+
"content": "837457e36a2ba1710c881fb69e1f79ce44fb81728c92ac378f70892a53af8ddb"
4339+
}
4340+
],
43384341
"licenses": [
43394342
{
43404343
"license": {
@@ -4351,7 +4354,7 @@
43514354
"comment": "Home page for project"
43524355
},
43534356
{
4354-
"url": "https://pypi.org/project/narwhals/1.48.1/#files",
4357+
"url": "https://pypi.org/project/narwhals/2.0.1/#files",
43554358
"type": "distribution",
43564359
"comment": "Download location for component"
43574360
},
@@ -4368,11 +4371,11 @@
43684371
"type": "issue-tracker"
43694372
}
43704373
],
4371-
"purl": "pkg:pypi/narwhals@1.48.1",
4374+
"purl": "pkg:pypi/narwhals@2.0.1",
43724375
"properties": [
43734376
{
43744377
"name": "release_date",
4375-
"value": "2025-06-26T16:20:40Z"
4378+
"value": "2025-07-29T08:39:03Z"
43764379
},
43774380
{
43784381
"name": "language",
@@ -4661,7 +4664,7 @@
46614664
"type": "library",
46624665
"bom-ref": "71-certifi",
46634666
"name": "certifi",
4664-
"version": "2025.7.14",
4667+
"version": "2025.8.3",
46654668
"supplier": {
46664669
"name": "Kenneth Reitz",
46674670
"contact": [
@@ -4670,12 +4673,12 @@
46704673
}
46714674
]
46724675
},
4673-
"cpe": "cpe:2.3:a:kenneth_reitz:certifi:2025.7.14:*:*:*:*:*:*:*",
4676+
"cpe": "cpe:2.3:a:kenneth_reitz:certifi:2025.8.3:*:*:*:*:*:*:*",
46744677
"description": "Python package for providing Mozilla's CA Bundle.",
46754678
"hashes": [
46764679
{
46774680
"alg": "SHA-256",
4678-
"content": "6b31f564a415d79ee77df69d757bb49a5bb53bd9f756cbbe24394ffd6fc1f4b2"
4681+
"content": "f6c12493cfb1b06ba2ff328595af9350c65d6644968e5d3a2ffd78699af217a5"
46794682
}
46804683
],
46814684
"licenses": [
@@ -4694,7 +4697,7 @@
46944697
"comment": "Home page for project"
46954698
},
46964699
{
4697-
"url": "https://pypi.org/project/certifi/2025.7.14/#files",
4700+
"url": "https://pypi.org/project/certifi/2025.8.3/#files",
46984701
"type": "distribution",
46994702
"comment": "Download location for component"
47004703
},
@@ -4703,11 +4706,11 @@
47034706
"type": "vcs"
47044707
}
47054708
],
4706-
"purl": "pkg:pypi/certifi@2025.7.14",
4709+
"purl": "pkg:pypi/certifi@2025.8.3",
47074710
"properties": [
47084711
{
47094712
"name": "release_date",
4710-
"value": "2025-07-14T03:29:26Z"
4713+
"value": "2025-08-03T03:07:45Z"
47114714
},
47124715
{
47134716
"name": "language",

sbom/cve-bin-tool-py3.9.spdx

Lines changed: 31 additions & 28 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-fa29f6d4-6cf8-4604-84f1-ac36679edc65
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-f8e059a2-ec6b-4f40-9972-58bca9d6d151
66
LicenseListVersion: 3.26
77
Creator: Tool: sbom4python-0.12.4
8-
Created: 2025-07-28T00:56:36Z
8+
Created: 2025-08-04T00:52:58Z
99
CreatorComment: <text>SBOM Type: Build - This document has been automatically generated.</text>
1010
#####
1111

@@ -27,18 +27,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.4.1:*:*:*:*:*
2727

2828
PackageName: aiohttp
2929
SPDXID: SPDXRef-2-aiohttp
30-
PackageVersion: 3.12.14
30+
PackageVersion: 3.12.15
3131
PrimaryPackagePurpose: LIBRARY
3232
PackageSupplier: NOASSERTION
33-
PackageDownloadLocation: https://pypi.org/project/aiohttp/3.12.14/#files
33+
PackageDownloadLocation: https://pypi.org/project/aiohttp/3.12.15/#files
3434
FilesAnalyzed: false
3535
PackageHomePage: https://github.com/aio-libs/aiohttp
36-
PackageChecksum: SHA256: 906d5075b5ba0dd1c66fcaaf60eb09926a9fef3ca92d912d2a0bbdbecf8b1248
37-
PackageLicenseDeclared: Apache-2.0
38-
PackageLicenseConcluded: Apache-2.0
36+
PackageChecksum: SHA256: b6fc902bff74d9b1879ad55f5404153e2b33a82e72a95c89cec5eb6cc9e92fbc
37+
PackageLicenseDeclared: Apache-2.0 AND MIT
38+
PackageLicenseConcluded: Apache-2.0 AND MIT
3939
PackageCopyrightText: NOASSERTION
4040
PackageSummary: <text>Async http client/server framework (asyncio)</text>
41-
ReleaseDate: 2025-07-10T13:02:38Z
41+
ReleaseDate: 2025-07-29T05:49:43Z
4242
ExternalRef: OTHER other https://matrix.to/#/#aio-libs:matrix.org
4343
ExternalRef: OTHER other https://matrix.to/#/#aio-libs-space:matrix.org
4444
ExternalRef: OTHER build-system https://github.com/aio-libs/aiohttp/actions?query=workflow%3ACI
@@ -47,7 +47,7 @@ ExternalRef: OTHER log https://docs.aiohttp.org/en/stable/changes.html
4747
ExternalRef: OTHER other https://docs.aiohttp.org
4848
ExternalRef: OTHER issue-tracker https://github.com/aio-libs/aiohttp/issues
4949
ExternalRef: OTHER vcs https://github.com/aio-libs/aiohttp
50-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].14
50+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].15
5151
#####
5252

5353
PackageName: aiohappyeyeballs
@@ -867,12 +867,13 @@ PackageSupplier: Person: Craig Citro ([email protected])
867867
PackageDownloadLocation: https://pypi.org/project/google-apitools/0.5.32/#files
868868
FilesAnalyzed: false
869869
PackageHomePage: http://github.com/google/apitools
870+
PackageChecksum: SHA256: b78f74116558e0476e19501b5b4b2ac7c93261a69c5449c861ea95cbc853c688
870871
PackageLicenseDeclared: NOASSERTION
871872
PackageLicenseConcluded: Apache-2.0
872873
PackageLicenseComments: <text>google-apitools declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
873874
PackageCopyrightText: NOASSERTION
874875
PackageSummary: <text>client libraries for humans</text>
875-
ReleaseDate: 2023-12-12T17:40:13Z
876+
ReleaseDate: 2021-05-05T22:12:58Z
876877
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected]
877878
ExternalRef: SECURITY cpe23Type cpe:2.3:a:craig_citro:google-apitools:0.5.32:*:*:*:*:*:*:*
878879
#####
@@ -1222,31 +1223,32 @@ PackageSupplier: Person: Anthony Harrison ([email protected])
12221223
PackageDownloadLocation: https://pypi.org/project/csaf-tool/0.3.2/#files
12231224
FilesAnalyzed: false
12241225
PackageHomePage: https://github.com/anthonyharrison/csaf
1226+
PackageChecksum: SHA256: 7e5559cb522eb76e3acad39a7bf9ba1b81e5a6224099d511a4c9c2dcf36caa16
12251227
PackageLicenseDeclared: MIT
12261228
PackageLicenseConcluded: MIT
12271229
PackageCopyrightText: NOASSERTION
12281230
PackageSummary: <text>CSAF generator and analyser</text>
1229-
ReleaseDate: 2024-08-29T20:36:52Z
1231+
ReleaseDate: 2024-06-12T20:10:06Z
12301232
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected]
12311233
ExternalRef: SECURITY cpe23Type cpe:2.3:a:anthony_harrison:csaf-tool:0.3.2:*:*:*:*:*:*:*
12321234
#####
12331235

12341236
PackageName: packageurl-python
12351237
SPDXID: SPDXRef-59-packageurl-python
1236-
PackageVersion: 0.17.1
1238+
PackageVersion: 0.17.3
12371239
PrimaryPackagePurpose: LIBRARY
12381240
PackageSupplier: Person: the purl authors
1239-
PackageDownloadLocation: https://pypi.org/project/packageurl-python/0.17.1/#files
1241+
PackageDownloadLocation: https://pypi.org/project/packageurl-python/0.17.3/#files
12401242
FilesAnalyzed: false
12411243
PackageHomePage: https://github.com/package-url/packageurl-python
1242-
PackageChecksum: SHA256: 59b0862ae0b216994f847e05b4c6e870e0d16e1ddd706feefb19d79810f22cbd
1244+
PackageChecksum: SHA256: f51b5aab570159f07258c8e998e9972ff3bf060da16b7334a42bd9f9737777d9
12431245
PackageLicenseDeclared: MIT
12441246
PackageLicenseConcluded: MIT
12451247
PackageCopyrightText: NOASSERTION
12461248
PackageSummary: <text>A purl aka. Package URL parser and builder</text>
1247-
ReleaseDate: 2025-06-06T13:13:58Z
1248-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].1
1249-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_purl_authors:packageurl-python:0.17.1:*:*:*:*:*:*:*
1249+
ReleaseDate: 2025-08-01T03:24:33Z
1250+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].3
1251+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_purl_authors:packageurl-python:0.17.3:*:*:*:*:*:*:*
12501252
#####
12511253

12521254
PackageName: rich
@@ -1394,23 +1396,24 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:6.2.0:*:*:*:*:*:*:*
13941396

13951397
PackageName: narwhals
13961398
SPDXID: SPDXRef-66-narwhals
1397-
PackageVersion: 1.48.1
1399+
PackageVersion: 2.0.1
13981400
PrimaryPackagePurpose: LIBRARY
13991401
PackageSupplier: Person: Marco Gorelli ([email protected])
1400-
PackageDownloadLocation: https://pypi.org/project/narwhals/1.48.1/#files
1402+
PackageDownloadLocation: https://pypi.org/project/narwhals/2.0.1/#files
14011403
FilesAnalyzed: false
14021404
PackageHomePage: https://github.com/narwhals-dev/narwhals
1405+
PackageChecksum: SHA256: 837457e36a2ba1710c881fb69e1f79ce44fb81728c92ac378f70892a53af8ddb
14031406
PackageLicenseDeclared: NOASSERTION
14041407
PackageLicenseConcluded: MIT
14051408
PackageLicenseComments: <text>narwhals declares MIT License which is not currently a valid SPDX License identifier or expression.</text>
14061409
PackageCopyrightText: NOASSERTION
14071410
PackageSummary: <text>Extremely lightweight compatibility layer between dataframe libraries</text>
1408-
ReleaseDate: 2025-06-26T16:20:40Z
1411+
ReleaseDate: 2025-07-29T08:39:03Z
14091412
ExternalRef: OTHER documentation https://narwhals-dev.github.io/narwhals/
14101413
ExternalRef: OTHER vcs https://github.com/narwhals-dev/narwhals
14111414
ExternalRef: OTHER issue-tracker https://github.com/narwhals-dev/narwhals/issues
1412-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@1.48.1
1413-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:1.48.1:*:*:*:*:*:*:*
1415+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@2.0.1
1416+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:2.0.1:*:*:*:*:*:*:*
14141417
#####
14151418

14161419
PackageName: python-gnupg
@@ -1499,21 +1502,21 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_petrov:urllib3:2.5.0:*:*:*:*:*:
14991502

15001503
PackageName: certifi
15011504
SPDXID: SPDXRef-71-certifi
1502-
PackageVersion: 2025.7.14
1505+
PackageVersion: 2025.8.3
15031506
PrimaryPackagePurpose: LIBRARY
15041507
PackageSupplier: Person: Kenneth Reitz ([email protected])
1505-
PackageDownloadLocation: https://pypi.org/project/certifi/2025.7.14/#files
1508+
PackageDownloadLocation: https://pypi.org/project/certifi/2025.8.3/#files
15061509
FilesAnalyzed: false
15071510
PackageHomePage: https://github.com/certifi/python-certifi
1508-
PackageChecksum: SHA256: 6b31f564a415d79ee77df69d757bb49a5bb53bd9f756cbbe24394ffd6fc1f4b2
1511+
PackageChecksum: SHA256: f6c12493cfb1b06ba2ff328595af9350c65d6644968e5d3a2ffd78699af217a5
15091512
PackageLicenseDeclared: MPL-2.0
15101513
PackageLicenseConcluded: MPL-2.0
15111514
PackageCopyrightText: NOASSERTION
15121515
PackageSummary: <text>Python package for providing Mozilla's CA Bundle.</text>
1513-
ReleaseDate: 2025-07-14T03:29:26Z
1516+
ReleaseDate: 2025-08-03T03:07:45Z
15141517
ExternalRef: OTHER vcs https://github.com/certifi/python-certifi
1515-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/certifi@2025.7.14
1516-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:certifi:2025.7.14:*:*:*:*:*:*:*
1518+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/certifi@2025.8.3
1519+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:certifi:2025.8.3:*:*:*:*:*:*:*
15171520
#####
15181521

15191522
PackageName: rpmfile

0 commit comments

Comments
 (0)