Skip to content

Commit 0edd89e

Browse files
chore: update SBOM for Python 3.12 (#5148)
Co-authored-by: GitHub <noreply@github.com>
1 parent 76dd60d commit 0edd89e

File tree

2 files changed

+101
-94
lines changed

2 files changed

+101
-94
lines changed

sbom/cve-bin-tool-py3.12.json

Lines changed: 53 additions & 47 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:265c3965-1ebd-48a3-aa33-dbd9c129df65",
5+
"serialNumber": "urn:uuid:4f14492e-e8e7-4d53-bdf3-83433fde8690",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-06-09T00:44:40Z",
8+
"timestamp": "2025-06-16T00:45:59Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -31,7 +31,7 @@
3131
"type": "application",
3232
"bom-ref": "1-cve-bin-tool",
3333
"name": "cve-bin-tool",
34-
"version": "3.4",
34+
"version": "3.4.1rc0",
3535
"supplier": {
3636
"name": "Terri Oda",
3737
"contact": [
@@ -40,12 +40,12 @@
4040
}
4141
]
4242
},
43-
"cpe": "cpe:2.3:a:terri_oda:cve-bin-tool:3.4:*:*:*:*:*:*:*",
43+
"cpe": "cpe:2.3:a:terri_oda:cve-bin-tool:3.4.1rc0:*:*:*:*:*:*:*",
4444
"description": "CVE Binary Checker Tool",
4545
"hashes": [
4646
{
4747
"alg": "SHA-256",
48-
"content": "48c897ea59b84ee3142b3353f0bc5689232a5f464e4106ac9b7f1e5f691f888d"
48+
"content": "93d666f2742df44dc5ca76e61b72884cb1f95378cc253d505b18b1f0a13a501b"
4949
}
5050
],
5151
"licenses": [
@@ -64,16 +64,16 @@
6464
"comment": "Home page for project"
6565
},
6666
{
67-
"url": "https://pypi.org/project/cve-bin-tool/3.4/#files",
67+
"url": "https://pypi.org/project/cve-bin-tool/3.4.1rc0/#files",
6868
"type": "distribution",
6969
"comment": "Download location for component"
7070
}
7171
],
72-
"purl": "pkg:pypi/cve-bin-tool@3.4",
72+
"purl": "pkg:pypi/cve-bin-tool@3.4.1rc0",
7373
"properties": [
7474
{
7575
"name": "release_date",
76-
"value": "2024-09-17T18:57:44Z"
76+
"value": "2025-06-13T18:33:45Z"
7777
},
7878
{
7979
"name": "language",
@@ -89,12 +89,12 @@
8989
"type": "library",
9090
"bom-ref": "2-aiohttp",
9191
"name": "aiohttp",
92-
"version": "3.12.11",
92+
"version": "3.12.13",
9393
"description": "Async http client/server framework (asyncio)",
9494
"hashes": [
9595
{
9696
"alg": "SHA-256",
97-
"content": "ff576cb82b995ff213e58255bc776a06ebd5ebb94a587aab2fb5df8ee4e3f967"
97+
"content": "5421af8f22a98f640261ee48aae3a37f0c41371e99412d55eaf2f8a46d5dad29"
9898
}
9999
],
100100
"licenses": [
@@ -113,7 +113,7 @@
113113
"comment": "Home page for project"
114114
},
115115
{
116-
"url": "https://pypi.org/project/aiohttp/3.12.11/#files",
116+
"url": "https://pypi.org/project/aiohttp/3.12.13/#files",
117117
"type": "distribution",
118118
"comment": "Download location for component"
119119
},
@@ -150,11 +150,11 @@
150150
"type": "vcs"
151151
}
152152
],
153-
"purl": "pkg:pypi/aiohttp@3.12.11",
153+
"purl": "pkg:pypi/aiohttp@3.12.13",
154154
"properties": [
155155
{
156156
"name": "release_date",
157-
"value": "2025-06-07T15:50:24Z"
157+
"value": "2025-06-14T15:12:58Z"
158158
},
159159
{
160160
"name": "language",
@@ -316,12 +316,12 @@
316316
"type": "library",
317317
"bom-ref": "5-frozenlist",
318318
"name": "frozenlist",
319-
"version": "1.6.2",
319+
"version": "1.7.0",
320320
"description": "A list-like structure which implements collections.abc.MutableSequence",
321321
"hashes": [
322322
{
323323
"alg": "SHA-256",
324-
"content": "92836b9903e52f787f4f4bfc6cf3b03cf19de4cbc09f5969e58806f876d8647f"
324+
"content": "cc4df77d638aa2ed703b878dd093725b72a824c3c546c076e8fdf276f78ee84a"
325325
}
326326
],
327327
"licenses": [
@@ -340,7 +340,7 @@
340340
"comment": "Home page for project"
341341
},
342342
{
343-
"url": "https://pypi.org/project/frozenlist/1.6.2/#files",
343+
"url": "https://pypi.org/project/frozenlist/1.7.0/#files",
344344
"type": "distribution",
345345
"comment": "Download location for component"
346346
},
@@ -381,11 +381,11 @@
381381
"type": "vcs"
382382
}
383383
],
384-
"purl": "pkg:pypi/frozenlist@1.6.2",
384+
"purl": "pkg:pypi/frozenlist@1.7.0",
385385
"properties": [
386386
{
387387
"name": "release_date",
388-
"value": "2025-06-03T21:45:13Z"
388+
"value": "2025-06-09T22:59:46Z"
389389
},
390390
{
391391
"name": "language",
@@ -632,7 +632,7 @@
632632
"type": "library",
633633
"bom-ref": "9-propcache",
634634
"name": "propcache",
635-
"version": "0.3.1",
635+
"version": "0.3.2",
636636
"supplier": {
637637
"name": "Andrew Svetlov",
638638
"contact": [
@@ -641,12 +641,12 @@
641641
}
642642
]
643643
},
644-
"cpe": "cpe:2.3:a:andrew_svetlov:propcache:0.3.1:*:*:*:*:*:*:*",
644+
"cpe": "cpe:2.3:a:andrew_svetlov:propcache:0.3.2:*:*:*:*:*:*:*",
645645
"description": "Accelerated property cache",
646646
"hashes": [
647647
{
648648
"alg": "SHA-256",
649-
"content": "f27785888d2fdd918bc36de8b8739f2d6c791399552333721b58193f68ea3e98"
649+
"content": "22d9962a358aedbb7a2e36187ff273adeaab9743373a272976d2e348d08c7770"
650650
}
651651
],
652652
"licenses": [
@@ -665,7 +665,7 @@
665665
"comment": "Home page for project"
666666
},
667667
{
668-
"url": "https://pypi.org/project/propcache/0.3.1/#files",
668+
"url": "https://pypi.org/project/propcache/0.3.2/#files",
669669
"type": "distribution",
670670
"comment": "Download location for component"
671671
},
@@ -706,11 +706,11 @@
706706
"type": "vcs"
707707
}
708708
],
709-
"purl": "pkg:pypi/propcache@0.3.1",
709+
"purl": "pkg:pypi/propcache@0.3.2",
710710
"properties": [
711711
{
712712
"name": "release_date",
713-
"value": "2025-03-26T03:03:35Z"
713+
"value": "2025-06-09T22:53:40Z"
714714
},
715715
{
716716
"name": "language",
@@ -726,7 +726,7 @@
726726
"type": "library",
727727
"bom-ref": "10-yarl",
728728
"name": "yarl",
729-
"version": "1.20.0",
729+
"version": "1.20.1",
730730
"supplier": {
731731
"name": "Andrew Svetlov",
732732
"contact": [
@@ -735,12 +735,12 @@
735735
}
736736
]
737737
},
738-
"cpe": "cpe:2.3:a:andrew_svetlov:yarl:1.20.0:*:*:*:*:*:*:*",
738+
"cpe": "cpe:2.3:a:andrew_svetlov:yarl:1.20.1:*:*:*:*:*:*:*",
739739
"description": "Yet another URL library",
740740
"hashes": [
741741
{
742742
"alg": "SHA-256",
743-
"content": "f1f6670b9ae3daedb325fa55fbe31c22c8228f6e0b513772c2e1c623caa6ab22"
743+
"content": "6032e6da6abd41e4acda34d75a816012717000fa6839f37124a47fcefc49bec4"
744744
}
745745
],
746746
"licenses": [
@@ -759,7 +759,7 @@
759759
"comment": "Home page for project"
760760
},
761761
{
762-
"url": "https://pypi.org/project/yarl/1.20.0/#files",
762+
"url": "https://pypi.org/project/yarl/1.20.1/#files",
763763
"type": "distribution",
764764
"comment": "Download location for component"
765765
},
@@ -800,11 +800,11 @@
800800
"type": "vcs"
801801
}
802802
],
803-
"purl": "pkg:pypi/yarl@1.20.0",
803+
"purl": "pkg:pypi/yarl@1.20.1",
804804
"properties": [
805805
{
806806
"name": "release_date",
807-
"value": "2025-04-17T00:41:27Z"
807+
"value": "2025-06-10T00:42:31Z"
808808
},
809809
{
810810
"name": "language",
@@ -2934,6 +2934,12 @@
29342934
},
29352935
"cpe": "cpe:2.3:a:jason_r.:zipp:3.23.0:*:*:*:*:*:*:*",
29362936
"description": "Backport of pathlib-compatible object wrapper for zip files",
2937+
"hashes": [
2938+
{
2939+
"alg": "SHA-256",
2940+
"content": "071652d6115ed432f5ce1d34c336c0adfd6a884660d1e9712a256d3d3bd4b14e"
2941+
}
2942+
],
29372943
"externalReferences": [
29382944
{
29392945
"url": "https://pypi.org/project/zipp/3.23.0/#files",
@@ -2949,7 +2955,7 @@
29492955
"properties": [
29502956
{
29512957
"name": "release_date",
2952-
"value": "2024-06-25T18:38:02Z"
2958+
"value": "2025-06-08T17:06:38Z"
29532959
},
29542960
{
29552961
"name": "language",
@@ -4146,7 +4152,7 @@
41464152
"type": "library",
41474153
"bom-ref": "63-narwhals",
41484154
"name": "narwhals",
4149-
"version": "1.41.1",
4155+
"version": "1.42.1",
41504156
"supplier": {
41514157
"name": "Marco Gorelli",
41524158
"contact": [
@@ -4155,7 +4161,7 @@
41554161
}
41564162
]
41574163
},
4158-
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:1.41.1:*:*:*:*:*:*:*",
4164+
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:1.42.1:*:*:*:*:*:*:*",
41594165
"description": "Extremely lightweight compatibility layer between dataframe libraries",
41604166
"licenses": [
41614167
{
@@ -4173,7 +4179,7 @@
41734179
"comment": "Home page for project"
41744180
},
41754181
{
4176-
"url": "https://pypi.org/project/narwhals/1.41.1/#files",
4182+
"url": "https://pypi.org/project/narwhals/1.42.1/#files",
41774183
"type": "distribution",
41784184
"comment": "Download location for component"
41794185
},
@@ -4190,7 +4196,7 @@
41904196
"type": "issue-tracker"
41914197
}
41924198
],
4193-
"purl": "pkg:pypi/narwhals@1.41.1",
4199+
"purl": "pkg:pypi/narwhals@1.42.1",
41944200
"properties": [
41954201
{
41964202
"name": "release_date",
@@ -4288,7 +4294,7 @@
42884294
"type": "library",
42894295
"bom-ref": "65-requests",
42904296
"name": "requests",
4291-
"version": "2.32.3",
4297+
"version": "2.32.4",
42924298
"supplier": {
42934299
"name": "Kenneth Reitz",
42944300
"contact": [
@@ -4297,12 +4303,12 @@
42974303
}
42984304
]
42994305
},
4300-
"cpe": "cpe:2.3:a:kenneth_reitz:requests:2.32.3:*:*:*:*:*:*:*",
4306+
"cpe": "cpe:2.3:a:kenneth_reitz:requests:2.32.4:*:*:*:*:*:*:*",
43014307
"description": "Python HTTP for Humans.",
43024308
"hashes": [
43034309
{
43044310
"alg": "SHA-256",
4305-
"content": "70761cfe03c773ceb22aa2f671b4757976145175cdfca038c02654d061d6dcc6"
4311+
"content": "27babd3cda2a6d50b30443204ee89830707d396671944c998b5975b031ac2b2c"
43064312
}
43074313
],
43084314
"licenses": [
@@ -4321,7 +4327,7 @@
43214327
"comment": "Home page for project"
43224328
},
43234329
{
4324-
"url": "https://pypi.org/project/requests/2.32.3/#files",
4330+
"url": "https://pypi.org/project/requests/2.32.4/#files",
43254331
"type": "distribution",
43264332
"comment": "Download location for component"
43274333
},
@@ -4334,11 +4340,11 @@
43344340
"type": "vcs"
43354341
}
43364342
],
4337-
"purl": "pkg:pypi/requests@2.32.3",
4343+
"purl": "pkg:pypi/requests@2.32.4",
43384344
"properties": [
43394345
{
43404346
"name": "release_date",
4341-
"value": "2024-05-29T15:37:47Z"
4347+
"value": "2025-06-09T16:43:05Z"
43424348
},
43434349
{
43444350
"name": "language",
@@ -4483,7 +4489,7 @@
44834489
"type": "library",
44844490
"bom-ref": "68-certifi",
44854491
"name": "certifi",
4486-
"version": "2025.4.26",
4492+
"version": "2025.6.15",
44874493
"supplier": {
44884494
"name": "Kenneth Reitz",
44894495
"contact": [
@@ -4492,12 +4498,12 @@
44924498
}
44934499
]
44944500
},
4495-
"cpe": "cpe:2.3:a:kenneth_reitz:certifi:2025.4.26:*:*:*:*:*:*:*",
4501+
"cpe": "cpe:2.3:a:kenneth_reitz:certifi:2025.6.15:*:*:*:*:*:*:*",
44964502
"description": "Python package for providing Mozilla's CA Bundle.",
44974503
"hashes": [
44984504
{
44994505
"alg": "SHA-256",
4500-
"content": "30350364dfe371162649852c63336a15c70c6510c2ad5015b21c2345311805f3"
4506+
"content": "2e0c7ce7cb5d8f8634ca55d2ba7e6ec2689a2fd6537d8dec1296a477a4910057"
45014507
}
45024508
],
45034509
"licenses": [
@@ -4516,7 +4522,7 @@
45164522
"comment": "Home page for project"
45174523
},
45184524
{
4519-
"url": "https://pypi.org/project/certifi/2025.4.26/#files",
4525+
"url": "https://pypi.org/project/certifi/2025.6.15/#files",
45204526
"type": "distribution",
45214527
"comment": "Download location for component"
45224528
},
@@ -4525,11 +4531,11 @@
45254531
"type": "vcs"
45264532
}
45274533
],
4528-
"purl": "pkg:pypi/certifi@2025.4.26",
4534+
"purl": "pkg:pypi/certifi@2025.6.15",
45294535
"properties": [
45304536
{
45314537
"name": "release_date",
4532-
"value": "2025-04-26T02:12:27Z"
4538+
"value": "2025-06-15T02:45:49Z"
45334539
},
45344540
{
45354541
"name": "language",

0 commit comments

Comments
 (0)