Skip to content

Commit dd8a095

Browse files
chore: update SBOM for Python 3.13 (#5258)
Co-authored-by: GitHub <[email protected]>
1 parent c02a7e1 commit dd8a095

File tree

2 files changed

+61
-56
lines changed

2 files changed

+61
-56
lines changed

sbom/cve-bin-tool-py3.13.json

Lines changed: 32 additions & 29 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:36ba5917-da55-4614-9e16-f2896e66508b",
5+
"serialNumber": "urn:uuid:1456c7a7-7d48-4e40-8380-eb2a6c917420",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-07-28T00:57:13Z",
8+
"timestamp": "2025-08-04T00:53:00Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -79,21 +79,18 @@
7979
"type": "library",
8080
"bom-ref": "2-aiohttp",
8181
"name": "aiohttp",
82-
"version": "3.12.14",
82+
"version": "3.12.15",
8383
"description": "Async http client/server framework (asyncio)",
8484
"hashes": [
8585
{
8686
"alg": "SHA-256",
87-
"content": "906d5075b5ba0dd1c66fcaaf60eb09926a9fef3ca92d912d2a0bbdbecf8b1248"
87+
"content": "b6fc902bff74d9b1879ad55f5404153e2b33a82e72a95c89cec5eb6cc9e92fbc"
8888
}
8989
],
9090
"licenses": [
9191
{
92-
"license": {
93-
"id": "Apache-2.0",
94-
"url": "https://www.apache.org/licenses/LICENSE-2.0",
95-
"acknowledgement": "concluded"
96-
}
92+
"expression": "Apache-2.0 AND MIT",
93+
"acknowledgement": "concluded"
9794
}
9895
],
9996
"externalReferences": [
@@ -103,7 +100,7 @@
103100
"comment": "Home page for project"
104101
},
105102
{
106-
"url": "https://pypi.org/project/aiohttp/3.12.14/#files",
103+
"url": "https://pypi.org/project/aiohttp/3.12.15/#files",
107104
"type": "distribution",
108105
"comment": "Download location for component"
109106
},
@@ -140,11 +137,11 @@
140137
"type": "vcs"
141138
}
142139
],
143-
"purl": "pkg:pypi/[email protected].14",
140+
"purl": "pkg:pypi/[email protected].15",
144141
"properties": [
145142
{
146143
"name": "release_date",
147-
"value": "2025-07-10T13:02:38Z"
144+
"value": "2025-07-29T05:49:43Z"
148145
},
149146
{
150147
"name": "language",
@@ -3689,16 +3686,16 @@
36893686
"type": "library",
36903687
"bom-ref": "56-packageurl-python",
36913688
"name": "packageurl-python",
3692-
"version": "0.17.1",
3689+
"version": "0.17.3",
36933690
"supplier": {
36943691
"name": "the purl authors"
36953692
},
3696-
"cpe": "cpe:2.3:a:the_purl_authors:packageurl-python:0.17.1:*:*:*:*:*:*:*",
3693+
"cpe": "cpe:2.3:a:the_purl_authors:packageurl-python:0.17.3:*:*:*:*:*:*:*",
36973694
"description": "A purl aka. Package URL parser and builder",
36983695
"hashes": [
36993696
{
37003697
"alg": "SHA-256",
3701-
"content": "59b0862ae0b216994f847e05b4c6e870e0d16e1ddd706feefb19d79810f22cbd"
3698+
"content": "f51b5aab570159f07258c8e998e9972ff3bf060da16b7334a42bd9f9737777d9"
37023699
}
37033700
],
37043701
"licenses": [
@@ -3717,16 +3714,16 @@
37173714
"comment": "Home page for project"
37183715
},
37193716
{
3720-
"url": "https://pypi.org/project/packageurl-python/0.17.1/#files",
3717+
"url": "https://pypi.org/project/packageurl-python/0.17.3/#files",
37213718
"type": "distribution",
37223719
"comment": "Download location for component"
37233720
}
37243721
],
3725-
"purl": "pkg:pypi/[email protected].1",
3722+
"purl": "pkg:pypi/[email protected].3",
37263723
"properties": [
37273724
{
37283725
"name": "release_date",
3729-
"value": "2025-06-06T13:13:58Z"
3726+
"value": "2025-08-01T03:24:33Z"
37303727
},
37313728
{
37323729
"name": "language",
@@ -4133,7 +4130,7 @@
41334130
"type": "library",
41344131
"bom-ref": "63-narwhals",
41354132
"name": "narwhals",
4136-
"version": "1.48.1",
4133+
"version": "2.0.1",
41374134
"supplier": {
41384135
"name": "Marco Gorelli",
41394136
"contact": [
@@ -4142,8 +4139,14 @@
41424139
}
41434140
]
41444141
},
4145-
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:1.48.1:*:*:*:*:*:*:*",
4142+
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:2.0.1:*:*:*:*:*:*:*",
41464143
"description": "Extremely lightweight compatibility layer between dataframe libraries",
4144+
"hashes": [
4145+
{
4146+
"alg": "SHA-256",
4147+
"content": "837457e36a2ba1710c881fb69e1f79ce44fb81728c92ac378f70892a53af8ddb"
4148+
}
4149+
],
41474150
"licenses": [
41484151
{
41494152
"license": {
@@ -4160,7 +4163,7 @@
41604163
"comment": "Home page for project"
41614164
},
41624165
{
4163-
"url": "https://pypi.org/project/narwhals/1.48.1/#files",
4166+
"url": "https://pypi.org/project/narwhals/2.0.1/#files",
41644167
"type": "distribution",
41654168
"comment": "Download location for component"
41664169
},
@@ -4177,11 +4180,11 @@
41774180
"type": "issue-tracker"
41784181
}
41794182
],
4180-
"purl": "pkg:pypi/narwhals@1.48.1",
4183+
"purl": "pkg:pypi/narwhals@2.0.1",
41814184
"properties": [
41824185
{
41834186
"name": "release_date",
4184-
"value": "2025-06-26T16:20:40Z"
4187+
"value": "2025-07-29T08:39:03Z"
41854188
},
41864189
{
41874190
"name": "language",
@@ -4470,7 +4473,7 @@
44704473
"type": "library",
44714474
"bom-ref": "68-certifi",
44724475
"name": "certifi",
4473-
"version": "2025.7.14",
4476+
"version": "2025.8.3",
44744477
"supplier": {
44754478
"name": "Kenneth Reitz",
44764479
"contact": [
@@ -4479,12 +4482,12 @@
44794482
}
44804483
]
44814484
},
4482-
"cpe": "cpe:2.3:a:kenneth_reitz:certifi:2025.7.14:*:*:*:*:*:*:*",
4485+
"cpe": "cpe:2.3:a:kenneth_reitz:certifi:2025.8.3:*:*:*:*:*:*:*",
44834486
"description": "Python package for providing Mozilla's CA Bundle.",
44844487
"hashes": [
44854488
{
44864489
"alg": "SHA-256",
4487-
"content": "6b31f564a415d79ee77df69d757bb49a5bb53bd9f756cbbe24394ffd6fc1f4b2"
4490+
"content": "f6c12493cfb1b06ba2ff328595af9350c65d6644968e5d3a2ffd78699af217a5"
44884491
}
44894492
],
44904493
"licenses": [
@@ -4503,7 +4506,7 @@
45034506
"comment": "Home page for project"
45044507
},
45054508
{
4506-
"url": "https://pypi.org/project/certifi/2025.7.14/#files",
4509+
"url": "https://pypi.org/project/certifi/2025.8.3/#files",
45074510
"type": "distribution",
45084511
"comment": "Download location for component"
45094512
},
@@ -4512,11 +4515,11 @@
45124515
"type": "vcs"
45134516
}
45144517
],
4515-
"purl": "pkg:pypi/certifi@2025.7.14",
4518+
"purl": "pkg:pypi/certifi@2025.8.3",
45164519
"properties": [
45174520
{
45184521
"name": "release_date",
4519-
"value": "2025-07-14T03:29:26Z"
4522+
"value": "2025-08-03T03:07:45Z"
45204523
},
45214524
{
45224525
"name": "language",

sbom/cve-bin-tool-py3.13.spdx

Lines changed: 29 additions & 27 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-26da68f2-4b83-478c-a3a4-9cf7dc97e92e
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-f2900e1d-553c-4e25-a2db-a7c18cd9b2e2
66
LicenseListVersion: 3.26
77
Creator: Tool: sbom4python-0.12.4
8-
Created: 2025-07-28T00:56:36Z
8+
Created: 2025-08-04T00:52:52Z
99
CreatorComment: <text>SBOM Type: Build - This document has been automatically generated.</text>
1010
#####
1111

@@ -27,18 +27,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.4.1:*:*:*:*:*
2727

2828
PackageName: aiohttp
2929
SPDXID: SPDXRef-2-aiohttp
30-
PackageVersion: 3.12.14
30+
PackageVersion: 3.12.15
3131
PrimaryPackagePurpose: LIBRARY
3232
PackageSupplier: NOASSERTION
33-
PackageDownloadLocation: https://pypi.org/project/aiohttp/3.12.14/#files
33+
PackageDownloadLocation: https://pypi.org/project/aiohttp/3.12.15/#files
3434
FilesAnalyzed: false
3535
PackageHomePage: https://github.com/aio-libs/aiohttp
36-
PackageChecksum: SHA256: 906d5075b5ba0dd1c66fcaaf60eb09926a9fef3ca92d912d2a0bbdbecf8b1248
37-
PackageLicenseDeclared: Apache-2.0
38-
PackageLicenseConcluded: Apache-2.0
36+
PackageChecksum: SHA256: b6fc902bff74d9b1879ad55f5404153e2b33a82e72a95c89cec5eb6cc9e92fbc
37+
PackageLicenseDeclared: Apache-2.0 AND MIT
38+
PackageLicenseConcluded: Apache-2.0 AND MIT
3939
PackageCopyrightText: NOASSERTION
4040
PackageSummary: <text>Async http client/server framework (asyncio)</text>
41-
ReleaseDate: 2025-07-10T13:02:38Z
41+
ReleaseDate: 2025-07-29T05:49:43Z
4242
ExternalRef: OTHER other https://matrix.to/#/#aio-libs:matrix.org
4343
ExternalRef: OTHER other https://matrix.to/#/#aio-libs-space:matrix.org
4444
ExternalRef: OTHER build-system https://github.com/aio-libs/aiohttp/actions?query=workflow%3ACI
@@ -47,7 +47,7 @@ ExternalRef: OTHER log https://docs.aiohttp.org/en/stable/changes.html
4747
ExternalRef: OTHER other https://docs.aiohttp.org
4848
ExternalRef: OTHER issue-tracker https://github.com/aio-libs/aiohttp/issues
4949
ExternalRef: OTHER vcs https://github.com/aio-libs/aiohttp
50-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].14
50+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].15
5151
#####
5252

5353
PackageName: aiohappyeyeballs
@@ -843,12 +843,13 @@ PackageSupplier: Person: Craig Citro ([email protected])
843843
PackageDownloadLocation: https://pypi.org/project/google-apitools/0.5.32/#files
844844
FilesAnalyzed: false
845845
PackageHomePage: http://github.com/google/apitools
846+
PackageChecksum: SHA256: b78f74116558e0476e19501b5b4b2ac7c93261a69c5449c861ea95cbc853c688
846847
PackageLicenseDeclared: NOASSERTION
847848
PackageLicenseConcluded: Apache-2.0
848849
PackageLicenseComments: <text>google-apitools declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
849850
PackageCopyrightText: NOASSERTION
850851
PackageSummary: <text>client libraries for humans</text>
851-
ReleaseDate: 2023-12-12T17:40:13Z
852+
ReleaseDate: 2021-05-05T22:12:58Z
852853
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected]
853854
ExternalRef: SECURITY cpe23Type cpe:2.3:a:craig_citro:google-apitools:0.5.32:*:*:*:*:*:*:*
854855
#####
@@ -1173,20 +1174,20 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:anthony_harrison:csaf-tool:0.3.2:*:*:*
11731174

11741175
PackageName: packageurl-python
11751176
SPDXID: SPDXRef-56-packageurl-python
1176-
PackageVersion: 0.17.1
1177+
PackageVersion: 0.17.3
11771178
PrimaryPackagePurpose: LIBRARY
11781179
PackageSupplier: Person: the purl authors
1179-
PackageDownloadLocation: https://pypi.org/project/packageurl-python/0.17.1/#files
1180+
PackageDownloadLocation: https://pypi.org/project/packageurl-python/0.17.3/#files
11801181
FilesAnalyzed: false
11811182
PackageHomePage: https://github.com/package-url/packageurl-python
1182-
PackageChecksum: SHA256: 59b0862ae0b216994f847e05b4c6e870e0d16e1ddd706feefb19d79810f22cbd
1183+
PackageChecksum: SHA256: f51b5aab570159f07258c8e998e9972ff3bf060da16b7334a42bd9f9737777d9
11831184
PackageLicenseDeclared: MIT
11841185
PackageLicenseConcluded: MIT
11851186
PackageCopyrightText: NOASSERTION
11861187
PackageSummary: <text>A purl aka. Package URL parser and builder</text>
1187-
ReleaseDate: 2025-06-06T13:13:58Z
1188-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].1
1189-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_purl_authors:packageurl-python:0.17.1:*:*:*:*:*:*:*
1188+
ReleaseDate: 2025-08-01T03:24:33Z
1189+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].3
1190+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_purl_authors:packageurl-python:0.17.3:*:*:*:*:*:*:*
11901191
#####
11911192

11921193
PackageName: rich
@@ -1334,23 +1335,24 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:6.2.0:*:*:*:*:*:*:*
13341335

13351336
PackageName: narwhals
13361337
SPDXID: SPDXRef-63-narwhals
1337-
PackageVersion: 1.48.1
1338+
PackageVersion: 2.0.1
13381339
PrimaryPackagePurpose: LIBRARY
13391340
PackageSupplier: Person: Marco Gorelli ([email protected])
1340-
PackageDownloadLocation: https://pypi.org/project/narwhals/1.48.1/#files
1341+
PackageDownloadLocation: https://pypi.org/project/narwhals/2.0.1/#files
13411342
FilesAnalyzed: false
13421343
PackageHomePage: https://github.com/narwhals-dev/narwhals
1344+
PackageChecksum: SHA256: 837457e36a2ba1710c881fb69e1f79ce44fb81728c92ac378f70892a53af8ddb
13431345
PackageLicenseDeclared: NOASSERTION
13441346
PackageLicenseConcluded: MIT
13451347
PackageLicenseComments: <text>narwhals declares MIT License which is not currently a valid SPDX License identifier or expression.</text>
13461348
PackageCopyrightText: NOASSERTION
13471349
PackageSummary: <text>Extremely lightweight compatibility layer between dataframe libraries</text>
1348-
ReleaseDate: 2025-06-26T16:20:40Z
1350+
ReleaseDate: 2025-07-29T08:39:03Z
13491351
ExternalRef: OTHER documentation https://narwhals-dev.github.io/narwhals/
13501352
ExternalRef: OTHER vcs https://github.com/narwhals-dev/narwhals
13511353
ExternalRef: OTHER issue-tracker https://github.com/narwhals-dev/narwhals/issues
1352-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@1.48.1
1353-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:1.48.1:*:*:*:*:*:*:*
1354+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@2.0.1
1355+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:2.0.1:*:*:*:*:*:*:*
13541356
#####
13551357

13561358
PackageName: python-gnupg
@@ -1439,21 +1441,21 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_petrov:urllib3:2.5.0:*:*:*:*:*:
14391441

14401442
PackageName: certifi
14411443
SPDXID: SPDXRef-68-certifi
1442-
PackageVersion: 2025.7.14
1444+
PackageVersion: 2025.8.3
14431445
PrimaryPackagePurpose: LIBRARY
14441446
PackageSupplier: Person: Kenneth Reitz ([email protected])
1445-
PackageDownloadLocation: https://pypi.org/project/certifi/2025.7.14/#files
1447+
PackageDownloadLocation: https://pypi.org/project/certifi/2025.8.3/#files
14461448
FilesAnalyzed: false
14471449
PackageHomePage: https://github.com/certifi/python-certifi
1448-
PackageChecksum: SHA256: 6b31f564a415d79ee77df69d757bb49a5bb53bd9f756cbbe24394ffd6fc1f4b2
1450+
PackageChecksum: SHA256: f6c12493cfb1b06ba2ff328595af9350c65d6644968e5d3a2ffd78699af217a5
14491451
PackageLicenseDeclared: MPL-2.0
14501452
PackageLicenseConcluded: MPL-2.0
14511453
PackageCopyrightText: NOASSERTION
14521454
PackageSummary: <text>Python package for providing Mozilla's CA Bundle.</text>
1453-
ReleaseDate: 2025-07-14T03:29:26Z
1455+
ReleaseDate: 2025-08-03T03:07:45Z
14541456
ExternalRef: OTHER vcs https://github.com/certifi/python-certifi
1455-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/certifi@2025.7.14
1456-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:certifi:2025.7.14:*:*:*:*:*:*:*
1457+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/certifi@2025.8.3
1458+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:certifi:2025.8.3:*:*:*:*:*:*:*
14571459
#####
14581460

14591461
PackageName: rpmfile

0 commit comments

Comments
 (0)