Skip to content

Commit d9f84c6

Browse files
chore: update SBOM for Python 3.10 (#5261)
Co-authored-by: GitHub <[email protected]>
1 parent ce1e91a commit d9f84c6

File tree

2 files changed

+61
-56
lines changed

2 files changed

+61
-56
lines changed

sbom/cve-bin-tool-py3.10.json

Lines changed: 32 additions & 29 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:cf6cc3f0-8d12-499b-97c9-44266344ceeb",
5+
"serialNumber": "urn:uuid:8e5a9ac8-16d3-4348-933c-350d7f690edb",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-07-28T00:57:27Z",
8+
"timestamp": "2025-08-04T00:53:06Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -79,21 +79,18 @@
7979
"type": "library",
8080
"bom-ref": "2-aiohttp",
8181
"name": "aiohttp",
82-
"version": "3.12.14",
82+
"version": "3.12.15",
8383
"description": "Async http client/server framework (asyncio)",
8484
"hashes": [
8585
{
8686
"alg": "SHA-256",
87-
"content": "906d5075b5ba0dd1c66fcaaf60eb09926a9fef3ca92d912d2a0bbdbecf8b1248"
87+
"content": "b6fc902bff74d9b1879ad55f5404153e2b33a82e72a95c89cec5eb6cc9e92fbc"
8888
}
8989
],
9090
"licenses": [
9191
{
92-
"license": {
93-
"id": "Apache-2.0",
94-
"url": "https://www.apache.org/licenses/LICENSE-2.0",
95-
"acknowledgement": "concluded"
96-
}
92+
"expression": "Apache-2.0 AND MIT",
93+
"acknowledgement": "concluded"
9794
}
9895
],
9996
"externalReferences": [
@@ -103,7 +100,7 @@
103100
"comment": "Home page for project"
104101
},
105102
{
106-
"url": "https://pypi.org/project/aiohttp/3.12.14/#files",
103+
"url": "https://pypi.org/project/aiohttp/3.12.15/#files",
107104
"type": "distribution",
108105
"comment": "Download location for component"
109106
},
@@ -140,11 +137,11 @@
140137
"type": "vcs"
141138
}
142139
],
143-
"purl": "pkg:pypi/[email protected].14",
140+
"purl": "pkg:pypi/[email protected].15",
144141
"properties": [
145142
{
146143
"name": "release_date",
147-
"value": "2025-07-10T13:02:38Z"
144+
"value": "2025-07-29T05:49:43Z"
148145
},
149146
{
150147
"name": "language",
@@ -3771,16 +3768,16 @@
37713768
"type": "library",
37723769
"bom-ref": "57-packageurl-python",
37733770
"name": "packageurl-python",
3774-
"version": "0.17.1",
3771+
"version": "0.17.3",
37753772
"supplier": {
37763773
"name": "the purl authors"
37773774
},
3778-
"cpe": "cpe:2.3:a:the_purl_authors:packageurl-python:0.17.1:*:*:*:*:*:*:*",
3775+
"cpe": "cpe:2.3:a:the_purl_authors:packageurl-python:0.17.3:*:*:*:*:*:*:*",
37793776
"description": "A purl aka. Package URL parser and builder",
37803777
"hashes": [
37813778
{
37823779
"alg": "SHA-256",
3783-
"content": "59b0862ae0b216994f847e05b4c6e870e0d16e1ddd706feefb19d79810f22cbd"
3780+
"content": "f51b5aab570159f07258c8e998e9972ff3bf060da16b7334a42bd9f9737777d9"
37843781
}
37853782
],
37863783
"licenses": [
@@ -3799,16 +3796,16 @@
37993796
"comment": "Home page for project"
38003797
},
38013798
{
3802-
"url": "https://pypi.org/project/packageurl-python/0.17.1/#files",
3799+
"url": "https://pypi.org/project/packageurl-python/0.17.3/#files",
38033800
"type": "distribution",
38043801
"comment": "Download location for component"
38053802
}
38063803
],
3807-
"purl": "pkg:pypi/[email protected].1",
3804+
"purl": "pkg:pypi/[email protected].3",
38083805
"properties": [
38093806
{
38103807
"name": "release_date",
3811-
"value": "2025-06-06T13:13:58Z"
3808+
"value": "2025-08-01T03:24:33Z"
38123809
},
38133810
{
38143811
"name": "language",
@@ -4215,7 +4212,7 @@
42154212
"type": "library",
42164213
"bom-ref": "64-narwhals",
42174214
"name": "narwhals",
4218-
"version": "1.48.1",
4215+
"version": "2.0.1",
42194216
"supplier": {
42204217
"name": "Marco Gorelli",
42214218
"contact": [
@@ -4224,8 +4221,14 @@
42244221
}
42254222
]
42264223
},
4227-
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:1.48.1:*:*:*:*:*:*:*",
4224+
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:2.0.1:*:*:*:*:*:*:*",
42284225
"description": "Extremely lightweight compatibility layer between dataframe libraries",
4226+
"hashes": [
4227+
{
4228+
"alg": "SHA-256",
4229+
"content": "837457e36a2ba1710c881fb69e1f79ce44fb81728c92ac378f70892a53af8ddb"
4230+
}
4231+
],
42294232
"licenses": [
42304233
{
42314234
"license": {
@@ -4242,7 +4245,7 @@
42424245
"comment": "Home page for project"
42434246
},
42444247
{
4245-
"url": "https://pypi.org/project/narwhals/1.48.1/#files",
4248+
"url": "https://pypi.org/project/narwhals/2.0.1/#files",
42464249
"type": "distribution",
42474250
"comment": "Download location for component"
42484251
},
@@ -4259,11 +4262,11 @@
42594262
"type": "issue-tracker"
42604263
}
42614264
],
4262-
"purl": "pkg:pypi/narwhals@1.48.1",
4265+
"purl": "pkg:pypi/narwhals@2.0.1",
42634266
"properties": [
42644267
{
42654268
"name": "release_date",
4266-
"value": "2025-06-26T16:20:40Z"
4269+
"value": "2025-07-29T08:39:03Z"
42674270
},
42684271
{
42694272
"name": "language",
@@ -4552,7 +4555,7 @@
45524555
"type": "library",
45534556
"bom-ref": "69-certifi",
45544557
"name": "certifi",
4555-
"version": "2025.7.14",
4558+
"version": "2025.8.3",
45564559
"supplier": {
45574560
"name": "Kenneth Reitz",
45584561
"contact": [
@@ -4561,12 +4564,12 @@
45614564
}
45624565
]
45634566
},
4564-
"cpe": "cpe:2.3:a:kenneth_reitz:certifi:2025.7.14:*:*:*:*:*:*:*",
4567+
"cpe": "cpe:2.3:a:kenneth_reitz:certifi:2025.8.3:*:*:*:*:*:*:*",
45654568
"description": "Python package for providing Mozilla's CA Bundle.",
45664569
"hashes": [
45674570
{
45684571
"alg": "SHA-256",
4569-
"content": "6b31f564a415d79ee77df69d757bb49a5bb53bd9f756cbbe24394ffd6fc1f4b2"
4572+
"content": "f6c12493cfb1b06ba2ff328595af9350c65d6644968e5d3a2ffd78699af217a5"
45704573
}
45714574
],
45724575
"licenses": [
@@ -4585,7 +4588,7 @@
45854588
"comment": "Home page for project"
45864589
},
45874590
{
4588-
"url": "https://pypi.org/project/certifi/2025.7.14/#files",
4591+
"url": "https://pypi.org/project/certifi/2025.8.3/#files",
45894592
"type": "distribution",
45904593
"comment": "Download location for component"
45914594
},
@@ -4594,11 +4597,11 @@
45944597
"type": "vcs"
45954598
}
45964599
],
4597-
"purl": "pkg:pypi/certifi@2025.7.14",
4600+
"purl": "pkg:pypi/certifi@2025.8.3",
45984601
"properties": [
45994602
{
46004603
"name": "release_date",
4601-
"value": "2025-07-14T03:29:26Z"
4604+
"value": "2025-08-03T03:07:45Z"
46024605
},
46034606
{
46044607
"name": "language",

sbom/cve-bin-tool-py3.10.spdx

Lines changed: 29 additions & 27 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-c36ae76e-814c-4678-86bf-d2ca7200a00e
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-c55e7d4f-a926-4b95-9891-671a0ab28523
66
LicenseListVersion: 3.26
77
Creator: Tool: sbom4python-0.12.4
8-
Created: 2025-07-28T00:56:36Z
8+
Created: 2025-08-04T00:52:59Z
99
CreatorComment: <text>SBOM Type: Build - This document has been automatically generated.</text>
1010
#####
1111

@@ -27,18 +27,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.4.1:*:*:*:*:*
2727

2828
PackageName: aiohttp
2929
SPDXID: SPDXRef-2-aiohttp
30-
PackageVersion: 3.12.14
30+
PackageVersion: 3.12.15
3131
PrimaryPackagePurpose: LIBRARY
3232
PackageSupplier: NOASSERTION
33-
PackageDownloadLocation: https://pypi.org/project/aiohttp/3.12.14/#files
33+
PackageDownloadLocation: https://pypi.org/project/aiohttp/3.12.15/#files
3434
FilesAnalyzed: false
3535
PackageHomePage: https://github.com/aio-libs/aiohttp
36-
PackageChecksum: SHA256: 906d5075b5ba0dd1c66fcaaf60eb09926a9fef3ca92d912d2a0bbdbecf8b1248
37-
PackageLicenseDeclared: Apache-2.0
38-
PackageLicenseConcluded: Apache-2.0
36+
PackageChecksum: SHA256: b6fc902bff74d9b1879ad55f5404153e2b33a82e72a95c89cec5eb6cc9e92fbc
37+
PackageLicenseDeclared: Apache-2.0 AND MIT
38+
PackageLicenseConcluded: Apache-2.0 AND MIT
3939
PackageCopyrightText: NOASSERTION
4040
PackageSummary: <text>Async http client/server framework (asyncio)</text>
41-
ReleaseDate: 2025-07-10T13:02:38Z
41+
ReleaseDate: 2025-07-29T05:49:43Z
4242
ExternalRef: OTHER other https://matrix.to/#/#aio-libs:matrix.org
4343
ExternalRef: OTHER other https://matrix.to/#/#aio-libs-space:matrix.org
4444
ExternalRef: OTHER build-system https://github.com/aio-libs/aiohttp/actions?query=workflow%3ACI
@@ -47,7 +47,7 @@ ExternalRef: OTHER log https://docs.aiohttp.org/en/stable/changes.html
4747
ExternalRef: OTHER other https://docs.aiohttp.org
4848
ExternalRef: OTHER issue-tracker https://github.com/aio-libs/aiohttp/issues
4949
ExternalRef: OTHER vcs https://github.com/aio-libs/aiohttp
50-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].14
50+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].15
5151
#####
5252

5353
PackageName: aiohappyeyeballs
@@ -867,12 +867,13 @@ PackageSupplier: Person: Craig Citro ([email protected])
867867
PackageDownloadLocation: https://pypi.org/project/google-apitools/0.5.32/#files
868868
FilesAnalyzed: false
869869
PackageHomePage: http://github.com/google/apitools
870+
PackageChecksum: SHA256: b78f74116558e0476e19501b5b4b2ac7c93261a69c5449c861ea95cbc853c688
870871
PackageLicenseDeclared: NOASSERTION
871872
PackageLicenseConcluded: Apache-2.0
872873
PackageLicenseComments: <text>google-apitools declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
873874
PackageCopyrightText: NOASSERTION
874875
PackageSummary: <text>client libraries for humans</text>
875-
ReleaseDate: 2023-12-12T17:40:13Z
876+
ReleaseDate: 2021-05-05T22:12:58Z
876877
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected]
877878
ExternalRef: SECURITY cpe23Type cpe:2.3:a:craig_citro:google-apitools:0.5.32:*:*:*:*:*:*:*
878879
#####
@@ -1197,20 +1198,20 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:anthony_harrison:csaf-tool:0.3.2:*:*:*
11971198

11981199
PackageName: packageurl-python
11991200
SPDXID: SPDXRef-57-packageurl-python
1200-
PackageVersion: 0.17.1
1201+
PackageVersion: 0.17.3
12011202
PrimaryPackagePurpose: LIBRARY
12021203
PackageSupplier: Person: the purl authors
1203-
PackageDownloadLocation: https://pypi.org/project/packageurl-python/0.17.1/#files
1204+
PackageDownloadLocation: https://pypi.org/project/packageurl-python/0.17.3/#files
12041205
FilesAnalyzed: false
12051206
PackageHomePage: https://github.com/package-url/packageurl-python
1206-
PackageChecksum: SHA256: 59b0862ae0b216994f847e05b4c6e870e0d16e1ddd706feefb19d79810f22cbd
1207+
PackageChecksum: SHA256: f51b5aab570159f07258c8e998e9972ff3bf060da16b7334a42bd9f9737777d9
12071208
PackageLicenseDeclared: MIT
12081209
PackageLicenseConcluded: MIT
12091210
PackageCopyrightText: NOASSERTION
12101211
PackageSummary: <text>A purl aka. Package URL parser and builder</text>
1211-
ReleaseDate: 2025-06-06T13:13:58Z
1212-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].1
1213-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_purl_authors:packageurl-python:0.17.1:*:*:*:*:*:*:*
1212+
ReleaseDate: 2025-08-01T03:24:33Z
1213+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].3
1214+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_purl_authors:packageurl-python:0.17.3:*:*:*:*:*:*:*
12141215
#####
12151216

12161217
PackageName: rich
@@ -1358,23 +1359,24 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:6.2.0:*:*:*:*:*:*:*
13581359

13591360
PackageName: narwhals
13601361
SPDXID: SPDXRef-64-narwhals
1361-
PackageVersion: 1.48.1
1362+
PackageVersion: 2.0.1
13621363
PrimaryPackagePurpose: LIBRARY
13631364
PackageSupplier: Person: Marco Gorelli ([email protected])
1364-
PackageDownloadLocation: https://pypi.org/project/narwhals/1.48.1/#files
1365+
PackageDownloadLocation: https://pypi.org/project/narwhals/2.0.1/#files
13651366
FilesAnalyzed: false
13661367
PackageHomePage: https://github.com/narwhals-dev/narwhals
1368+
PackageChecksum: SHA256: 837457e36a2ba1710c881fb69e1f79ce44fb81728c92ac378f70892a53af8ddb
13671369
PackageLicenseDeclared: NOASSERTION
13681370
PackageLicenseConcluded: MIT
13691371
PackageLicenseComments: <text>narwhals declares MIT License which is not currently a valid SPDX License identifier or expression.</text>
13701372
PackageCopyrightText: NOASSERTION
13711373
PackageSummary: <text>Extremely lightweight compatibility layer between dataframe libraries</text>
1372-
ReleaseDate: 2025-06-26T16:20:40Z
1374+
ReleaseDate: 2025-07-29T08:39:03Z
13731375
ExternalRef: OTHER documentation https://narwhals-dev.github.io/narwhals/
13741376
ExternalRef: OTHER vcs https://github.com/narwhals-dev/narwhals
13751377
ExternalRef: OTHER issue-tracker https://github.com/narwhals-dev/narwhals/issues
1376-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@1.48.1
1377-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:1.48.1:*:*:*:*:*:*:*
1378+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@2.0.1
1379+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:2.0.1:*:*:*:*:*:*:*
13781380
#####
13791381

13801382
PackageName: python-gnupg
@@ -1463,21 +1465,21 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_petrov:urllib3:2.5.0:*:*:*:*:*:
14631465

14641466
PackageName: certifi
14651467
SPDXID: SPDXRef-69-certifi
1466-
PackageVersion: 2025.7.14
1468+
PackageVersion: 2025.8.3
14671469
PrimaryPackagePurpose: LIBRARY
14681470
PackageSupplier: Person: Kenneth Reitz ([email protected])
1469-
PackageDownloadLocation: https://pypi.org/project/certifi/2025.7.14/#files
1471+
PackageDownloadLocation: https://pypi.org/project/certifi/2025.8.3/#files
14701472
FilesAnalyzed: false
14711473
PackageHomePage: https://github.com/certifi/python-certifi
1472-
PackageChecksum: SHA256: 6b31f564a415d79ee77df69d757bb49a5bb53bd9f756cbbe24394ffd6fc1f4b2
1474+
PackageChecksum: SHA256: f6c12493cfb1b06ba2ff328595af9350c65d6644968e5d3a2ffd78699af217a5
14731475
PackageLicenseDeclared: MPL-2.0
14741476
PackageLicenseConcluded: MPL-2.0
14751477
PackageCopyrightText: NOASSERTION
14761478
PackageSummary: <text>Python package for providing Mozilla's CA Bundle.</text>
1477-
ReleaseDate: 2025-07-14T03:29:26Z
1479+
ReleaseDate: 2025-08-03T03:07:45Z
14781480
ExternalRef: OTHER vcs https://github.com/certifi/python-certifi
1479-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/certifi@2025.7.14
1480-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:certifi:2025.7.14:*:*:*:*:*:*:*
1481+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/certifi@2025.8.3
1482+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:certifi:2025.8.3:*:*:*:*:*:*:*
14811483
#####
14821484

14831485
PackageName: rpmfile

0 commit comments

Comments
 (0)