Skip to content

Commit 808806b

Browse files
chore: update SBOM for Python 3.10 (#5213)
Co-authored-by: GitHub <noreply@github.com>
1 parent b475889 commit 808806b

File tree

2 files changed

+52
-38
lines changed

2 files changed

+52
-38
lines changed

sbom/cve-bin-tool-py3.10.json

Lines changed: 31 additions & 19 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:535a0d76-946a-4472-bdb4-3122955abe46",
5+
"serialNumber": "urn:uuid:1c937d38-1f58-49d4-af2a-9990a58206b3",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-07-07T00:43:31Z",
8+
"timestamp": "2025-07-14T00:45:49Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -79,12 +79,12 @@
7979
"type": "library",
8080
"bom-ref": "2-aiohttp",
8181
"name": "aiohttp",
82-
"version": "3.12.13",
82+
"version": "3.12.14",
8383
"description": "Async http client/server framework (asyncio)",
8484
"hashes": [
8585
{
8686
"alg": "SHA-256",
87-
"content": "5421af8f22a98f640261ee48aae3a37f0c41371e99412d55eaf2f8a46d5dad29"
87+
"content": "906d5075b5ba0dd1c66fcaaf60eb09926a9fef3ca92d912d2a0bbdbecf8b1248"
8888
}
8989
],
9090
"licenses": [
@@ -103,7 +103,7 @@
103103
"comment": "Home page for project"
104104
},
105105
{
106-
"url": "https://pypi.org/project/aiohttp/3.12.13/#files",
106+
"url": "https://pypi.org/project/aiohttp/3.12.14/#files",
107107
"type": "distribution",
108108
"comment": "Download location for component"
109109
},
@@ -140,11 +140,11 @@
140140
"type": "vcs"
141141
}
142142
],
143-
"purl": "pkg:pypi/aiohttp@3.12.13",
143+
"purl": "pkg:pypi/aiohttp@3.12.14",
144144
"properties": [
145145
{
146146
"name": "release_date",
147-
"value": "2025-06-14T15:12:58Z"
147+
"value": "2025-07-10T13:02:38Z"
148148
},
149149
{
150150
"name": "language",
@@ -231,6 +231,12 @@
231231
"name": "aiosignal",
232232
"version": "1.4.0",
233233
"description": "aiosignal: a list of registered asynchronous callbacks",
234+
"hashes": [
235+
{
236+
"alg": "SHA-256",
237+
"content": "053243f8b92b990551949e63930a839ff0cf0b0ebbe0597b0f3fb19e1a0fe82e"
238+
}
239+
],
234240
"licenses": [
235241
{
236242
"license": {
@@ -280,7 +286,7 @@
280286
"properties": [
281287
{
282288
"name": "release_date",
283-
"value": "2025-03-12T01:42:47Z"
289+
"value": "2025-07-03T22:54:42Z"
284290
},
285291
{
286292
"name": "language",
@@ -4109,7 +4115,7 @@
41094115
"type": "library",
41104116
"bom-ref": "62-narwhals",
41114117
"name": "narwhals",
4112-
"version": "1.45.0",
4118+
"version": "1.46.0",
41134119
"supplier": {
41144120
"name": "Marco Gorelli",
41154121
"contact": [
@@ -4118,8 +4124,14 @@
41184124
}
41194125
]
41204126
},
4121-
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:1.45.0:*:*:*:*:*:*:*",
4127+
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:1.46.0:*:*:*:*:*:*:*",
41224128
"description": "Extremely lightweight compatibility layer between dataframe libraries",
4129+
"hashes": [
4130+
{
4131+
"alg": "SHA-256",
4132+
"content": "f15d2255695d7e99f624f76aa5b765eb3fff8a509d3215049707af3a3feebc90"
4133+
}
4134+
],
41234135
"licenses": [
41244136
{
41254137
"license": {
@@ -4136,7 +4148,7 @@
41364148
"comment": "Home page for project"
41374149
},
41384150
{
4139-
"url": "https://pypi.org/project/narwhals/1.45.0/#files",
4151+
"url": "https://pypi.org/project/narwhals/1.46.0/#files",
41404152
"type": "distribution",
41414153
"comment": "Download location for component"
41424154
},
@@ -4153,11 +4165,11 @@
41534165
"type": "issue-tracker"
41544166
}
41554167
],
4156-
"purl": "pkg:pypi/narwhals@1.45.0",
4168+
"purl": "pkg:pypi/narwhals@1.46.0",
41574169
"properties": [
41584170
{
41594171
"name": "release_date",
4160-
"value": "2025-06-26T16:20:40Z"
4172+
"value": "2025-07-07T11:34:42Z"
41614173
},
41624174
{
41634175
"name": "language",
@@ -4446,7 +4458,7 @@
44464458
"type": "library",
44474459
"bom-ref": "67-certifi",
44484460
"name": "certifi",
4449-
"version": "2025.6.15",
4461+
"version": "2025.7.9",
44504462
"supplier": {
44514463
"name": "Kenneth Reitz",
44524464
"contact": [
@@ -4455,12 +4467,12 @@
44554467
}
44564468
]
44574469
},
4458-
"cpe": "cpe:2.3:a:kenneth_reitz:certifi:2025.6.15:*:*:*:*:*:*:*",
4470+
"cpe": "cpe:2.3:a:kenneth_reitz:certifi:2025.7.9:*:*:*:*:*:*:*",
44594471
"description": "Python package for providing Mozilla's CA Bundle.",
44604472
"hashes": [
44614473
{
44624474
"alg": "SHA-256",
4463-
"content": "2e0c7ce7cb5d8f8634ca55d2ba7e6ec2689a2fd6537d8dec1296a477a4910057"
4475+
"content": "d842783a14f8fdd646895ac26f719a061408834473cfc10203f6a575beb15d39"
44644476
}
44654477
],
44664478
"licenses": [
@@ -4479,7 +4491,7 @@
44794491
"comment": "Home page for project"
44804492
},
44814493
{
4482-
"url": "https://pypi.org/project/certifi/2025.6.15/#files",
4494+
"url": "https://pypi.org/project/certifi/2025.7.9/#files",
44834495
"type": "distribution",
44844496
"comment": "Download location for component"
44854497
},
@@ -4488,11 +4500,11 @@
44884500
"type": "vcs"
44894501
}
44904502
],
4491-
"purl": "pkg:pypi/certifi@2025.6.15",
4503+
"purl": "pkg:pypi/certifi@2025.7.9",
44924504
"properties": [
44934505
{
44944506
"name": "release_date",
4495-
"value": "2025-06-15T02:45:49Z"
4507+
"value": "2025-07-09T02:13:57Z"
44964508
},
44974509
{
44984510
"name": "language",

sbom/cve-bin-tool-py3.10.spdx

Lines changed: 21 additions & 19 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-4fd0947e-d80b-48fb-9b53-f6fc3be425a0
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-e9c00b5d-e18a-489d-be4d-9ba1ea8303f1
66
LicenseListVersion: 3.25
77
Creator: Tool: sbom4python-0.12.4
8-
Created: 2025-07-07T00:43:23Z
8+
Created: 2025-07-14T00:45:32Z
99
CreatorComment: <text>SBOM Type: Build - This document has been automatically generated.</text>
1010
#####
1111

@@ -27,18 +27,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.4.1:*:*:*:*:*
2727

2828
PackageName: aiohttp
2929
SPDXID: SPDXRef-2-aiohttp
30-
PackageVersion: 3.12.13
30+
PackageVersion: 3.12.14
3131
PrimaryPackagePurpose: LIBRARY
3232
PackageSupplier: NOASSERTION
33-
PackageDownloadLocation: https://pypi.org/project/aiohttp/3.12.13/#files
33+
PackageDownloadLocation: https://pypi.org/project/aiohttp/3.12.14/#files
3434
FilesAnalyzed: false
3535
PackageHomePage: https://github.com/aio-libs/aiohttp
36-
PackageChecksum: SHA256: 5421af8f22a98f640261ee48aae3a37f0c41371e99412d55eaf2f8a46d5dad29
36+
PackageChecksum: SHA256: 906d5075b5ba0dd1c66fcaaf60eb09926a9fef3ca92d912d2a0bbdbecf8b1248
3737
PackageLicenseDeclared: Apache-2.0
3838
PackageLicenseConcluded: Apache-2.0
3939
PackageCopyrightText: NOASSERTION
4040
PackageSummary: <text>Async http client/server framework (asyncio)</text>
41-
ReleaseDate: 2025-06-14T15:12:58Z
41+
ReleaseDate: 2025-07-10T13:02:38Z
4242
ExternalRef: OTHER other https://matrix.to/#/#aio-libs:matrix.org
4343
ExternalRef: OTHER other https://matrix.to/#/#aio-libs-space:matrix.org
4444
ExternalRef: OTHER build-system https://github.com/aio-libs/aiohttp/actions?query=workflow%3ACI
@@ -47,7 +47,7 @@ ExternalRef: OTHER log https://docs.aiohttp.org/en/stable/changes.html
4747
ExternalRef: OTHER other https://docs.aiohttp.org
4848
ExternalRef: OTHER issue-tracker https://github.com/aio-libs/aiohttp/issues
4949
ExternalRef: OTHER vcs https://github.com/aio-libs/aiohttp
50-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/aiohttp@3.12.13
50+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/aiohttp@3.12.14
5151
#####
5252

5353
PackageName: aiohappyeyeballs
@@ -79,12 +79,13 @@ PackageSupplier: NOASSERTION
7979
PackageDownloadLocation: https://pypi.org/project/aiosignal/1.4.0/#files
8080
FilesAnalyzed: false
8181
PackageHomePage: https://github.com/aio-libs/aiosignal
82+
PackageChecksum: SHA256: 053243f8b92b990551949e63930a839ff0cf0b0ebbe0597b0f3fb19e1a0fe82e
8283
PackageLicenseDeclared: NOASSERTION
8384
PackageLicenseConcluded: Apache-2.0
8485
PackageLicenseComments: <text>aiosignal declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
8586
PackageCopyrightText: NOASSERTION
8687
PackageSummary: <text>aiosignal: a list of registered asynchronous callbacks</text>
87-
ReleaseDate: 2025-03-12T01:42:47Z
88+
ReleaseDate: 2025-07-03T22:54:42Z
8889
ExternalRef: OTHER other https://gitter.im/aio-libs/Lobby
8990
ExternalRef: OTHER build-system https://github.com/aio-libs/aiosignal/actions
9091
ExternalRef: OTHER other https://codecov.io/github/aio-libs/aiosignal
@@ -1322,23 +1323,24 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:6.2.0:*:*:*:*:*:*:*
13221323

13231324
PackageName: narwhals
13241325
SPDXID: SPDXRef-62-narwhals
1325-
PackageVersion: 1.45.0
1326+
PackageVersion: 1.46.0
13261327
PrimaryPackagePurpose: LIBRARY
13271328
PackageSupplier: Person: Marco Gorelli (hello_narwhals@proton.me)
1328-
PackageDownloadLocation: https://pypi.org/project/narwhals/1.45.0/#files
1329+
PackageDownloadLocation: https://pypi.org/project/narwhals/1.46.0/#files
13291330
FilesAnalyzed: false
13301331
PackageHomePage: https://github.com/narwhals-dev/narwhals
1332+
PackageChecksum: SHA256: f15d2255695d7e99f624f76aa5b765eb3fff8a509d3215049707af3a3feebc90
13311333
PackageLicenseDeclared: NOASSERTION
13321334
PackageLicenseConcluded: MIT
13331335
PackageLicenseComments: <text>narwhals declares MIT License which is not currently a valid SPDX License identifier or expression.</text>
13341336
PackageCopyrightText: NOASSERTION
13351337
PackageSummary: <text>Extremely lightweight compatibility layer between dataframe libraries</text>
1336-
ReleaseDate: 2025-06-26T16:20:40Z
1338+
ReleaseDate: 2025-07-07T11:34:42Z
13371339
ExternalRef: OTHER documentation https://narwhals-dev.github.io/narwhals/
13381340
ExternalRef: OTHER vcs https://github.com/narwhals-dev/narwhals
13391341
ExternalRef: OTHER issue-tracker https://github.com/narwhals-dev/narwhals/issues
1340-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@1.45.0
1341-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:1.45.0:*:*:*:*:*:*:*
1342+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@1.46.0
1343+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:1.46.0:*:*:*:*:*:*:*
13421344
#####
13431345

13441346
PackageName: python-gnupg
@@ -1427,21 +1429,21 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_petrov:urllib3:2.5.0:*:*:*:*:*:
14271429

14281430
PackageName: certifi
14291431
SPDXID: SPDXRef-67-certifi
1430-
PackageVersion: 2025.6.15
1432+
PackageVersion: 2025.7.9
14311433
PrimaryPackagePurpose: LIBRARY
14321434
PackageSupplier: Person: Kenneth Reitz (me@kennethreitz.com)
1433-
PackageDownloadLocation: https://pypi.org/project/certifi/2025.6.15/#files
1435+
PackageDownloadLocation: https://pypi.org/project/certifi/2025.7.9/#files
14341436
FilesAnalyzed: false
14351437
PackageHomePage: https://github.com/certifi/python-certifi
1436-
PackageChecksum: SHA256: 2e0c7ce7cb5d8f8634ca55d2ba7e6ec2689a2fd6537d8dec1296a477a4910057
1438+
PackageChecksum: SHA256: d842783a14f8fdd646895ac26f719a061408834473cfc10203f6a575beb15d39
14371439
PackageLicenseDeclared: MPL-2.0
14381440
PackageLicenseConcluded: MPL-2.0
14391441
PackageCopyrightText: NOASSERTION
14401442
PackageSummary: <text>Python package for providing Mozilla's CA Bundle.</text>
1441-
ReleaseDate: 2025-06-15T02:45:49Z
1443+
ReleaseDate: 2025-07-09T02:13:57Z
14421444
ExternalRef: OTHER vcs https://github.com/certifi/python-certifi
1443-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/certifi@2025.6.15
1444-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:certifi:2025.6.15:*:*:*:*:*:*:*
1445+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/certifi@2025.7.9
1446+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:certifi:2025.7.9:*:*:*:*:*:*:*
14451447
#####
14461448

14471449
PackageName: rpmfile

0 commit comments

Comments
 (0)