Skip to content

Commit c9d1b32

Browse files
chore: update SBOM for Python 3.9 (#5147)
Co-authored-by: GitHub <noreply@github.com>
1 parent 1f7da3b commit c9d1b32

File tree

2 files changed

+101
-94
lines changed

2 files changed

+101
-94
lines changed

sbom/cve-bin-tool-py3.9.json

Lines changed: 53 additions & 47 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:4a56dddb-a60e-493e-9986-7d39cd1e54b5",
5+
"serialNumber": "urn:uuid:fd15e6cd-7f46-4ab9-81bc-e8e62b3a992a",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-06-09T00:44:41Z",
8+
"timestamp": "2025-06-16T00:44:06Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -31,7 +31,7 @@
3131
"type": "application",
3232
"bom-ref": "1-cve-bin-tool",
3333
"name": "cve-bin-tool",
34-
"version": "3.4",
34+
"version": "3.4.1rc0",
3535
"supplier": {
3636
"name": "Terri Oda",
3737
"contact": [
@@ -40,12 +40,12 @@
4040
}
4141
]
4242
},
43-
"cpe": "cpe:2.3:a:terri_oda:cve-bin-tool:3.4:*:*:*:*:*:*:*",
43+
"cpe": "cpe:2.3:a:terri_oda:cve-bin-tool:3.4.1rc0:*:*:*:*:*:*:*",
4444
"description": "CVE Binary Checker Tool",
4545
"hashes": [
4646
{
4747
"alg": "SHA-256",
48-
"content": "48c897ea59b84ee3142b3353f0bc5689232a5f464e4106ac9b7f1e5f691f888d"
48+
"content": "93d666f2742df44dc5ca76e61b72884cb1f95378cc253d505b18b1f0a13a501b"
4949
}
5050
],
5151
"licenses": [
@@ -64,16 +64,16 @@
6464
"comment": "Home page for project"
6565
},
6666
{
67-
"url": "https://pypi.org/project/cve-bin-tool/3.4/#files",
67+
"url": "https://pypi.org/project/cve-bin-tool/3.4.1rc0/#files",
6868
"type": "distribution",
6969
"comment": "Download location for component"
7070
}
7171
],
72-
"purl": "pkg:pypi/cve-bin-tool@3.4",
72+
"purl": "pkg:pypi/cve-bin-tool@3.4.1rc0",
7373
"properties": [
7474
{
7575
"name": "release_date",
76-
"value": "2024-09-17T18:57:44Z"
76+
"value": "2025-06-13T18:33:45Z"
7777
},
7878
{
7979
"name": "language",
@@ -89,12 +89,12 @@
8989
"type": "library",
9090
"bom-ref": "2-aiohttp",
9191
"name": "aiohttp",
92-
"version": "3.12.11",
92+
"version": "3.12.13",
9393
"description": "Async http client/server framework (asyncio)",
9494
"hashes": [
9595
{
9696
"alg": "SHA-256",
97-
"content": "ff576cb82b995ff213e58255bc776a06ebd5ebb94a587aab2fb5df8ee4e3f967"
97+
"content": "5421af8f22a98f640261ee48aae3a37f0c41371e99412d55eaf2f8a46d5dad29"
9898
}
9999
],
100100
"licenses": [
@@ -113,7 +113,7 @@
113113
"comment": "Home page for project"
114114
},
115115
{
116-
"url": "https://pypi.org/project/aiohttp/3.12.11/#files",
116+
"url": "https://pypi.org/project/aiohttp/3.12.13/#files",
117117
"type": "distribution",
118118
"comment": "Download location for component"
119119
},
@@ -150,11 +150,11 @@
150150
"type": "vcs"
151151
}
152152
],
153-
"purl": "pkg:pypi/aiohttp@3.12.11",
153+
"purl": "pkg:pypi/aiohttp@3.12.13",
154154
"properties": [
155155
{
156156
"name": "release_date",
157-
"value": "2025-06-07T15:50:24Z"
157+
"value": "2025-06-14T15:12:58Z"
158158
},
159159
{
160160
"name": "language",
@@ -316,12 +316,12 @@
316316
"type": "library",
317317
"bom-ref": "5-frozenlist",
318318
"name": "frozenlist",
319-
"version": "1.6.2",
319+
"version": "1.7.0",
320320
"description": "A list-like structure which implements collections.abc.MutableSequence",
321321
"hashes": [
322322
{
323323
"alg": "SHA-256",
324-
"content": "92836b9903e52f787f4f4bfc6cf3b03cf19de4cbc09f5969e58806f876d8647f"
324+
"content": "cc4df77d638aa2ed703b878dd093725b72a824c3c546c076e8fdf276f78ee84a"
325325
}
326326
],
327327
"licenses": [
@@ -340,7 +340,7 @@
340340
"comment": "Home page for project"
341341
},
342342
{
343-
"url": "https://pypi.org/project/frozenlist/1.6.2/#files",
343+
"url": "https://pypi.org/project/frozenlist/1.7.0/#files",
344344
"type": "distribution",
345345
"comment": "Download location for component"
346346
},
@@ -381,11 +381,11 @@
381381
"type": "vcs"
382382
}
383383
],
384-
"purl": "pkg:pypi/frozenlist@1.6.2",
384+
"purl": "pkg:pypi/frozenlist@1.7.0",
385385
"properties": [
386386
{
387387
"name": "release_date",
388-
"value": "2025-06-03T21:45:13Z"
388+
"value": "2025-06-09T22:59:46Z"
389389
},
390390
{
391391
"name": "language",
@@ -714,7 +714,7 @@
714714
"type": "library",
715715
"bom-ref": "10-propcache",
716716
"name": "propcache",
717-
"version": "0.3.1",
717+
"version": "0.3.2",
718718
"supplier": {
719719
"name": "Andrew Svetlov",
720720
"contact": [
@@ -723,12 +723,12 @@
723723
}
724724
]
725725
},
726-
"cpe": "cpe:2.3:a:andrew_svetlov:propcache:0.3.1:*:*:*:*:*:*:*",
726+
"cpe": "cpe:2.3:a:andrew_svetlov:propcache:0.3.2:*:*:*:*:*:*:*",
727727
"description": "Accelerated property cache",
728728
"hashes": [
729729
{
730730
"alg": "SHA-256",
731-
"content": "f27785888d2fdd918bc36de8b8739f2d6c791399552333721b58193f68ea3e98"
731+
"content": "22d9962a358aedbb7a2e36187ff273adeaab9743373a272976d2e348d08c7770"
732732
}
733733
],
734734
"licenses": [
@@ -747,7 +747,7 @@
747747
"comment": "Home page for project"
748748
},
749749
{
750-
"url": "https://pypi.org/project/propcache/0.3.1/#files",
750+
"url": "https://pypi.org/project/propcache/0.3.2/#files",
751751
"type": "distribution",
752752
"comment": "Download location for component"
753753
},
@@ -788,11 +788,11 @@
788788
"type": "vcs"
789789
}
790790
],
791-
"purl": "pkg:pypi/propcache@0.3.1",
791+
"purl": "pkg:pypi/propcache@0.3.2",
792792
"properties": [
793793
{
794794
"name": "release_date",
795-
"value": "2025-03-26T03:03:35Z"
795+
"value": "2025-06-09T22:53:40Z"
796796
},
797797
{
798798
"name": "language",
@@ -808,7 +808,7 @@
808808
"type": "library",
809809
"bom-ref": "11-yarl",
810810
"name": "yarl",
811-
"version": "1.20.0",
811+
"version": "1.20.1",
812812
"supplier": {
813813
"name": "Andrew Svetlov",
814814
"contact": [
@@ -817,12 +817,12 @@
817817
}
818818
]
819819
},
820-
"cpe": "cpe:2.3:a:andrew_svetlov:yarl:1.20.0:*:*:*:*:*:*:*",
820+
"cpe": "cpe:2.3:a:andrew_svetlov:yarl:1.20.1:*:*:*:*:*:*:*",
821821
"description": "Yet another URL library",
822822
"hashes": [
823823
{
824824
"alg": "SHA-256",
825-
"content": "f1f6670b9ae3daedb325fa55fbe31c22c8228f6e0b513772c2e1c623caa6ab22"
825+
"content": "6032e6da6abd41e4acda34d75a816012717000fa6839f37124a47fcefc49bec4"
826826
}
827827
],
828828
"licenses": [
@@ -841,7 +841,7 @@
841841
"comment": "Home page for project"
842842
},
843843
{
844-
"url": "https://pypi.org/project/yarl/1.20.0/#files",
844+
"url": "https://pypi.org/project/yarl/1.20.1/#files",
845845
"type": "distribution",
846846
"comment": "Download location for component"
847847
},
@@ -882,11 +882,11 @@
882882
"type": "vcs"
883883
}
884884
],
885-
"purl": "pkg:pypi/yarl@1.20.0",
885+
"purl": "pkg:pypi/yarl@1.20.1",
886886
"properties": [
887887
{
888888
"name": "release_date",
889-
"value": "2025-04-17T00:41:27Z"
889+
"value": "2025-06-10T00:42:31Z"
890890
},
891891
{
892892
"name": "language",
@@ -3016,6 +3016,12 @@
30163016
},
30173017
"cpe": "cpe:2.3:a:jason_r.:zipp:3.23.0:*:*:*:*:*:*:*",
30183018
"description": "Backport of pathlib-compatible object wrapper for zip files",
3019+
"hashes": [
3020+
{
3021+
"alg": "SHA-256",
3022+
"content": "071652d6115ed432f5ce1d34c336c0adfd6a884660d1e9712a256d3d3bd4b14e"
3023+
}
3024+
],
30193025
"externalReferences": [
30203026
{
30213027
"url": "https://pypi.org/project/zipp/3.23.0/#files",
@@ -3031,7 +3037,7 @@
30313037
"properties": [
30323038
{
30333039
"name": "release_date",
3034-
"value": "2025-04-27T15:29:00Z"
3040+
"value": "2025-06-08T17:06:38Z"
30353041
},
30363042
{
30373043
"name": "language",
@@ -4228,7 +4234,7 @@
42284234
"type": "library",
42294235
"bom-ref": "64-narwhals",
42304236
"name": "narwhals",
4231-
"version": "1.41.1",
4237+
"version": "1.42.1",
42324238
"supplier": {
42334239
"name": "Marco Gorelli",
42344240
"contact": [
@@ -4237,7 +4243,7 @@
42374243
}
42384244
]
42394245
},
4240-
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:1.41.1:*:*:*:*:*:*:*",
4246+
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:1.42.1:*:*:*:*:*:*:*",
42414247
"description": "Extremely lightweight compatibility layer between dataframe libraries",
42424248
"licenses": [
42434249
{
@@ -4255,7 +4261,7 @@
42554261
"comment": "Home page for project"
42564262
},
42574263
{
4258-
"url": "https://pypi.org/project/narwhals/1.41.1/#files",
4264+
"url": "https://pypi.org/project/narwhals/1.42.1/#files",
42594265
"type": "distribution",
42604266
"comment": "Download location for component"
42614267
},
@@ -4272,7 +4278,7 @@
42724278
"type": "issue-tracker"
42734279
}
42744280
],
4275-
"purl": "pkg:pypi/narwhals@1.41.1",
4281+
"purl": "pkg:pypi/narwhals@1.42.1",
42764282
"properties": [
42774283
{
42784284
"name": "release_date",
@@ -4370,7 +4376,7 @@
43704376
"type": "library",
43714377
"bom-ref": "66-requests",
43724378
"name": "requests",
4373-
"version": "2.32.3",
4379+
"version": "2.32.4",
43744380
"supplier": {
43754381
"name": "Kenneth Reitz",
43764382
"contact": [
@@ -4379,12 +4385,12 @@
43794385
}
43804386
]
43814387
},
4382-
"cpe": "cpe:2.3:a:kenneth_reitz:requests:2.32.3:*:*:*:*:*:*:*",
4388+
"cpe": "cpe:2.3:a:kenneth_reitz:requests:2.32.4:*:*:*:*:*:*:*",
43834389
"description": "Python HTTP for Humans.",
43844390
"hashes": [
43854391
{
43864392
"alg": "SHA-256",
4387-
"content": "70761cfe03c773ceb22aa2f671b4757976145175cdfca038c02654d061d6dcc6"
4393+
"content": "27babd3cda2a6d50b30443204ee89830707d396671944c998b5975b031ac2b2c"
43884394
}
43894395
],
43904396
"licenses": [
@@ -4403,7 +4409,7 @@
44034409
"comment": "Home page for project"
44044410
},
44054411
{
4406-
"url": "https://pypi.org/project/requests/2.32.3/#files",
4412+
"url": "https://pypi.org/project/requests/2.32.4/#files",
44074413
"type": "distribution",
44084414
"comment": "Download location for component"
44094415
},
@@ -4416,11 +4422,11 @@
44164422
"type": "vcs"
44174423
}
44184424
],
4419-
"purl": "pkg:pypi/requests@2.32.3",
4425+
"purl": "pkg:pypi/requests@2.32.4",
44204426
"properties": [
44214427
{
44224428
"name": "release_date",
4423-
"value": "2024-05-29T15:37:47Z"
4429+
"value": "2025-06-09T16:43:05Z"
44244430
},
44254431
{
44264432
"name": "language",
@@ -4565,7 +4571,7 @@
45654571
"type": "library",
45664572
"bom-ref": "69-certifi",
45674573
"name": "certifi",
4568-
"version": "2025.4.26",
4574+
"version": "2025.6.15",
45694575
"supplier": {
45704576
"name": "Kenneth Reitz",
45714577
"contact": [
@@ -4574,12 +4580,12 @@
45744580
}
45754581
]
45764582
},
4577-
"cpe": "cpe:2.3:a:kenneth_reitz:certifi:2025.4.26:*:*:*:*:*:*:*",
4583+
"cpe": "cpe:2.3:a:kenneth_reitz:certifi:2025.6.15:*:*:*:*:*:*:*",
45784584
"description": "Python package for providing Mozilla's CA Bundle.",
45794585
"hashes": [
45804586
{
45814587
"alg": "SHA-256",
4582-
"content": "30350364dfe371162649852c63336a15c70c6510c2ad5015b21c2345311805f3"
4588+
"content": "2e0c7ce7cb5d8f8634ca55d2ba7e6ec2689a2fd6537d8dec1296a477a4910057"
45834589
}
45844590
],
45854591
"licenses": [
@@ -4598,7 +4604,7 @@
45984604
"comment": "Home page for project"
45994605
},
46004606
{
4601-
"url": "https://pypi.org/project/certifi/2025.4.26/#files",
4607+
"url": "https://pypi.org/project/certifi/2025.6.15/#files",
46024608
"type": "distribution",
46034609
"comment": "Download location for component"
46044610
},
@@ -4607,11 +4613,11 @@
46074613
"type": "vcs"
46084614
}
46094615
],
4610-
"purl": "pkg:pypi/certifi@2025.4.26",
4616+
"purl": "pkg:pypi/certifi@2025.6.15",
46114617
"properties": [
46124618
{
46134619
"name": "release_date",
4614-
"value": "2025-04-26T02:12:27Z"
4620+
"value": "2025-06-15T02:45:49Z"
46154621
},
46164622
{
46174623
"name": "language",

0 commit comments

Comments
 (0)