Skip to content

Commit 2d6b337

Browse files
chore: update SBOM for Python 3.12 (#5289)
Co-authored-by: GitHub <[email protected]>
1 parent 7e8e0b3 commit 2d6b337

File tree

2 files changed

+91
-116
lines changed

2 files changed

+91
-116
lines changed

sbom/cve-bin-tool-py3.12.json

Lines changed: 46 additions & 69 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:7cbb7314-5643-4a0a-af4a-a3de69de0d0e",
5+
"serialNumber": "urn:uuid:36d9d13b-553e-408e-a9ad-8fb6f8c7944a",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-08-11T00:44:59Z",
8+
"timestamp": "2025-08-18T00:44:47Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -521,7 +521,7 @@
521521
"type": "library",
522522
"bom-ref": "8-multidict",
523523
"name": "multidict",
524-
"version": "6.6.3",
524+
"version": "6.6.4",
525525
"supplier": {
526526
"name": "Andrew Svetlov",
527527
"contact": [
@@ -530,12 +530,12 @@
530530
}
531531
]
532532
},
533-
"cpe": "cpe:2.3:a:andrew_svetlov:multidict:6.6.3:*:*:*:*:*:*:*",
533+
"cpe": "cpe:2.3:a:andrew_svetlov:multidict:6.6.4:*:*:*:*:*:*:*",
534534
"description": "multidict implementation",
535535
"hashes": [
536536
{
537537
"alg": "SHA-256",
538-
"content": "a2be5b7b35271f7fff1397204ba6708365e3d773579fe2a30625e16c4b4ce817"
538+
"content": "b8aa6f0bd8125ddd04a6593437bad6a7e70f300ff4180a531654aa2ab3f6d58f"
539539
}
540540
],
541541
"licenses": [
@@ -554,7 +554,7 @@
554554
"comment": "Home page for project"
555555
},
556556
{
557-
"url": "https://pypi.org/project/multidict/6.6.3/#files",
557+
"url": "https://pypi.org/project/multidict/6.6.4/#files",
558558
"type": "distribution",
559559
"comment": "Download location for component"
560560
},
@@ -595,11 +595,11 @@
595595
"type": "vcs"
596596
}
597597
],
598-
"purl": "pkg:pypi/[email protected].3",
598+
"purl": "pkg:pypi/[email protected].4",
599599
"properties": [
600600
{
601601
"name": "release_date",
602-
"value": "2025-06-30T15:50:58Z"
602+
"value": "2025-08-11T12:06:02Z"
603603
},
604604
{
605605
"name": "language",
@@ -1462,25 +1462,16 @@
14621462
"type": "library",
14631463
"bom-ref": "21-fasteners",
14641464
"name": "fasteners",
1465-
"version": "0.19",
1465+
"version": "0.20",
14661466
"supplier": {
14671467
"name": "Joshua Harlow"
14681468
},
1469-
"cpe": "cpe:2.3:a:joshua_harlow:fasteners:0.19:*:*:*:*:*:*:*",
1469+
"cpe": "cpe:2.3:a:joshua_harlow:fasteners:0.20:*:*:*:*:*:*:*",
14701470
"description": "A python package that provides useful locks",
14711471
"hashes": [
14721472
{
14731473
"alg": "SHA-256",
1474-
"content": "758819cb5d94cdedf4e836988b74de396ceacb8e2794d21f82d131fd9ee77237"
1475-
}
1476-
],
1477-
"licenses": [
1478-
{
1479-
"license": {
1480-
"id": "Apache-2.0",
1481-
"url": "https://www.apache.org/licenses/LICENSE-2.0",
1482-
"acknowledgement": "concluded"
1483-
}
1474+
"content": "9422c40d1e350e4259f509fb2e608d6bc43c0136f79a00db1b49046029d0b3b7"
14841475
}
14851476
],
14861477
"externalReferences": [
@@ -1490,16 +1481,16 @@
14901481
"comment": "Home page for project"
14911482
},
14921483
{
1493-
"url": "https://pypi.org/project/fasteners/0.19/#files",
1484+
"url": "https://pypi.org/project/fasteners/0.20/#files",
14941485
"type": "distribution",
14951486
"comment": "Download location for component"
14961487
}
14971488
],
1498-
"purl": "pkg:pypi/fasteners@0.19",
1489+
"purl": "pkg:pypi/fasteners@0.20",
14991490
"properties": [
15001491
{
15011492
"name": "release_date",
1502-
"value": "2023-09-19T17:11:18Z"
1493+
"value": "2025-08-11T10:19:35Z"
15031494
},
15041495
{
15051496
"name": "language",
@@ -3512,7 +3503,7 @@
35123503
"type": "library",
35133504
"bom-ref": "53-elementpath",
35143505
"name": "elementpath",
3515-
"version": "5.0.3",
3506+
"version": "5.0.4",
35163507
"supplier": {
35173508
"name": "Davide Brunato",
35183509
"contact": [
@@ -3521,12 +3512,12 @@
35213512
}
35223513
]
35233514
},
3524-
"cpe": "cpe:2.3:a:davide_brunato:elementpath:5.0.3:*:*:*:*:*:*:*",
3515+
"cpe": "cpe:2.3:a:davide_brunato:elementpath:5.0.4:*:*:*:*:*:*:*",
35253516
"description": "XPath 1.0/2.0/3.0/3.1 parsers and selectors for ElementTree and lxml",
35263517
"hashes": [
35273518
{
35283519
"alg": "SHA-256",
3529-
"content": "8c93540556f743835b3c682a7bdb2d97371ee1e151430ff35498b59f2c14e5a0"
3520+
"content": "75d6f31c614d57e50eb749fc50806e3102880cd1f6552da3f2265f8eb8d3bbc6"
35303521
}
35313522
],
35323523
"externalReferences": [
@@ -3536,16 +3527,16 @@
35363527
"comment": "Home page for project"
35373528
},
35383529
{
3539-
"url": "https://pypi.org/project/elementpath/5.0.3/#files",
3530+
"url": "https://pypi.org/project/elementpath/5.0.4/#files",
35403531
"type": "distribution",
35413532
"comment": "Download location for component"
35423533
}
35433534
],
3544-
"purl": "pkg:pypi/[email protected].3",
3535+
"purl": "pkg:pypi/[email protected].4",
35453536
"properties": [
35463537
{
35473538
"name": "release_date",
3548-
"value": "2025-06-28T06:20:35Z"
3539+
"value": "2025-08-16T18:19:52Z"
35493540
},
35503541
{
35513542
"name": "language",
@@ -3792,7 +3783,7 @@
37923783
"type": "library",
37933784
"bom-ref": "58-markdown-it-py",
37943785
"name": "markdown-it-py",
3795-
"version": "3.0.0",
3786+
"version": "4.0.0",
37963787
"supplier": {
37973788
"name": "Chris Sewell",
37983789
"contact": [
@@ -3801,12 +3792,12 @@
38013792
}
38023793
]
38033794
},
3804-
"cpe": "cpe:2.3:a:chris_sewell:markdown-it-py:3.0.0:*:*:*:*:*:*:*",
3795+
"cpe": "cpe:2.3:a:chris_sewell:markdown-it-py:4.0.0:*:*:*:*:*:*:*",
38053796
"description": "Python port of markdown-it. Markdown parsing, done right!",
38063797
"hashes": [
38073798
{
38083799
"alg": "SHA-256",
3809-
"content": "355216845c60bd96232cd8d8c40e8f9765cc86f46880e43a8fd22dc1a1a8cab1"
3800+
"content": "87327c59b172c5011896038353a81343b6754500a08cd7a4973bb48c6d578147"
38103801
}
38113802
],
38123803
"licenses": [
@@ -3825,7 +3816,7 @@
38253816
"comment": "Home page for project"
38263817
},
38273818
{
3828-
"url": "https://pypi.org/project/markdown-it-py/3.0.0/#files",
3819+
"url": "https://pypi.org/project/markdown-it-py/4.0.0/#files",
38293820
"type": "distribution",
38303821
"comment": "Download location for component"
38313822
},
@@ -3834,11 +3825,11 @@
38343825
"type": "documentation"
38353826
}
38363827
],
3837-
"purl": "pkg:pypi/markdown-it-py@3.0.0",
3828+
"purl": "pkg:pypi/markdown-it-py@4.0.0",
38383829
"properties": [
38393830
{
38403831
"name": "release_date",
3841-
"value": "2023-06-03T06:41:11Z"
3832+
"value": "2025-08-11T12:57:51Z"
38423833
},
38433834
{
38443835
"name": "language",
@@ -4056,7 +4047,7 @@
40564047
"type": "library",
40574048
"bom-ref": "62-plotly",
40584049
"name": "plotly",
4059-
"version": "6.2.0",
4050+
"version": "6.3.0",
40604051
"supplier": {
40614052
"name": "Chris P",
40624053
"contact": [
@@ -4065,12 +4056,12 @@
40654056
}
40664057
]
40674058
},
4068-
"cpe": "cpe:2.3:a:chris_p:plotly:6.2.0:*:*:*:*:*:*:*",
4059+
"cpe": "cpe:2.3:a:chris_p:plotly:6.3.0:*:*:*:*:*:*:*",
40694060
"description": "An open-source interactive data visualization library for Python",
40704061
"hashes": [
40714062
{
40724063
"alg": "SHA-256",
4073-
"content": "32c444d4c940887219cb80738317040363deefdfee4f354498cc0b6dab8978bd"
4064+
"content": "7ad806edce9d3cdd882eaebaf97c0c9e252043ed1ed3d382c3e3520ec07806d4"
40744065
}
40754066
],
40764067
"externalReferences": [
@@ -4080,7 +4071,7 @@
40804071
"comment": "Home page for project"
40814072
},
40824073
{
4083-
"url": "https://pypi.org/project/plotly/6.2.0/#files",
4074+
"url": "https://pypi.org/project/plotly/6.3.0/#files",
40844075
"type": "distribution",
40854076
"comment": "Download location for component"
40864077
},
@@ -4097,11 +4088,11 @@
40974088
"type": "log"
40984089
}
40994090
],
4100-
"purl": "pkg:pypi/plotly@6.2.0",
4091+
"purl": "pkg:pypi/plotly@6.3.0",
41014092
"properties": [
41024093
{
41034094
"name": "release_date",
4104-
"value": "2025-06-26T16:20:40Z"
4095+
"value": "2025-08-12T20:22:09Z"
41054096
},
41064097
{
41074098
"name": "language",
@@ -4121,7 +4112,7 @@
41214112
"type": "library",
41224113
"bom-ref": "63-narwhals",
41234114
"name": "narwhals",
4124-
"version": "2.0.1",
4115+
"version": "2.1.2",
41254116
"supplier": {
41264117
"name": "Marco Gorelli",
41274118
"contact": [
@@ -4130,14 +4121,8 @@
41304121
}
41314122
]
41324123
},
4133-
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:2.0.1:*:*:*:*:*:*:*",
4124+
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:2.1.2:*:*:*:*:*:*:*",
41344125
"description": "Extremely lightweight compatibility layer between dataframe libraries",
4135-
"hashes": [
4136-
{
4137-
"alg": "SHA-256",
4138-
"content": "837457e36a2ba1710c881fb69e1f79ce44fb81728c92ac378f70892a53af8ddb"
4139-
}
4140-
],
41414126
"licenses": [
41424127
{
41434128
"license": {
@@ -4154,7 +4139,7 @@
41544139
"comment": "Home page for project"
41554140
},
41564141
{
4157-
"url": "https://pypi.org/project/narwhals/2.0.1/#files",
4142+
"url": "https://pypi.org/project/narwhals/2.1.2/#files",
41584143
"type": "distribution",
41594144
"comment": "Download location for component"
41604145
},
@@ -4171,11 +4156,11 @@
41714156
"type": "issue-tracker"
41724157
}
41734158
],
4174-
"purl": "pkg:pypi/narwhals@2.0.1",
4159+
"purl": "pkg:pypi/narwhals@2.1.2",
41754160
"properties": [
41764161
{
41774162
"name": "release_date",
4178-
"value": "2025-07-29T08:39:03Z"
4163+
"value": "2025-08-12T20:22:09Z"
41794164
},
41804165
{
41814166
"name": "language",
@@ -4688,7 +4673,7 @@
46884673
"type": "library",
46894674
"bom-ref": "72-zstandard",
46904675
"name": "zstandard",
4691-
"version": "0.23.0",
4676+
"version": "0.24.0",
46924677
"supplier": {
46934678
"name": "Gregory Szorc",
46944679
"contact": [
@@ -4697,14 +4682,8 @@
46974682
}
46984683
]
46994684
},
4700-
"cpe": "cpe:2.3:a:gregory_szorc:zstandard:0.23.0:*:*:*:*:*:*:*",
4685+
"cpe": "cpe:2.3:a:gregory_szorc:zstandard:0.24.0:*:*:*:*:*:*:*",
47014686
"description": "Zstandard bindings for Python",
4702-
"hashes": [
4703-
{
4704-
"alg": "SHA-256",
4705-
"content": "bf0a05b6059c0528477fba9054d09179beb63744355cab9f38059548fedd46a9"
4706-
}
4707-
],
47084687
"licenses": [
47094688
{
47104689
"license": {
@@ -4721,16 +4700,20 @@
47214700
"comment": "Home page for project"
47224701
},
47234702
{
4724-
"url": "https://pypi.org/project/zstandard/0.23.0/#files",
4703+
"url": "https://pypi.org/project/zstandard/0.24.0/#files",
47254704
"type": "distribution",
47264705
"comment": "Download location for component"
4706+
},
4707+
{
4708+
"url": "https://python-zstandard.readthedocs.io/en/latest/",
4709+
"type": "documentation"
47274710
}
47284711
],
4729-
"purl": "pkg:pypi/zstandard@0.23.0",
4712+
"purl": "pkg:pypi/zstandard@0.24.0",
47304713
"properties": [
47314714
{
47324715
"name": "release_date",
4733-
"value": "2024-07-15T00:13:27Z"
4716+
"value": "2025-06-08T17:06:38Z"
47344717
},
47354718
{
47364719
"name": "language",
@@ -5026,12 +5009,6 @@
50265009
"67-urllib3",
50275010
"68-certifi"
50285011
]
5029-
},
5030-
{
5031-
"ref": "72-zstandard",
5032-
"dependsOn": [
5033-
"35-cffi"
5034-
]
50355012
}
50365013
]
50375014
}

0 commit comments

Comments
 (0)