Skip to content

Commit 30791f7

Browse files
web-flowgithub-actions[bot]
authored andcommitted
chore: update SBOM for Python 3.10
1 parent 118245d commit 30791f7

File tree

2 files changed

+48
-48
lines changed

2 files changed

+48
-48
lines changed

sbom/cve-bin-tool-py3.10.json

Lines changed: 24 additions & 24 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.7.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.7",
5-
"serialNumber": "urn:uuid:3afa9eb1-4948-472a-bffc-204138519a06",
5+
"serialNumber": "urn:uuid:0595a1e4-2ef0-4dc2-841a-966f4551abd7",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-11-10T00:43:04Z",
8+
"timestamp": "2025-11-17T00:42:47Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -3219,7 +3219,7 @@
32193219
"type": "library",
32203220
"bom-ref": "49-rpds-py",
32213221
"name": "rpds-py",
3222-
"version": "0.28.0",
3222+
"version": "0.29.0",
32233223
"supplier": {
32243224
"name": "Julian Berman",
32253225
"contact": [
@@ -3228,12 +3228,12 @@
32283228
}
32293229
]
32303230
},
3231-
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.28.0:*:*:*:*:*:*:*",
3231+
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.29.0:*:*:*:*:*:*:*",
32323232
"description": "Python bindings to Rust's persistent data structures (rpds)",
32333233
"hashes": [
32343234
{
32353235
"alg": "SHA-256",
3236-
"content": "7b6013db815417eeb56b2d9d7324e64fcd4fa289caeee6e7a78b2e11fc9b438a"
3236+
"content": "4ae4b88c6617e1b9e5038ab3fccd7bac0842fdda2b703117b2aa99bc85379113"
32373237
}
32383238
],
32393239
"externalReferences": [
@@ -3243,7 +3243,7 @@
32433243
"comment": "Home page for project"
32443244
},
32453245
{
3246-
"url": "https://pypi.org/project/rpds-py/0.28.0/#files",
3246+
"url": "https://pypi.org/project/rpds-py/0.29.0/#files",
32473247
"type": "distribution",
32483248
"comment": "Download location for component"
32493249
},
@@ -3272,11 +3272,11 @@
32723272
"type": "other"
32733273
}
32743274
],
3275-
"purl": "pkg:pypi/rpds-py@0.28.0",
3275+
"purl": "pkg:pypi/rpds-py@0.29.0",
32763276
"properties": [
32773277
{
32783278
"name": "release_date",
3279-
"value": "2025-10-22T22:21:15Z"
3279+
"value": "2025-11-16T14:47:36Z"
32803280
},
32813281
{
32823282
"name": "language",
@@ -3292,7 +3292,7 @@
32923292
"type": "library",
32933293
"bom-ref": "50-lib4sbom",
32943294
"name": "lib4sbom",
3295-
"version": "0.9.0",
3295+
"version": "0.9.1",
32963296
"supplier": {
32973297
"name": "Anthony Harrison",
32983298
"contact": [
@@ -3301,12 +3301,12 @@
33013301
}
33023302
]
33033303
},
3304-
"cpe": "cpe:2.3:a:anthony_harrison:lib4sbom:0.9.0:*:*:*:*:*:*:*",
3304+
"cpe": "cpe:2.3:a:anthony_harrison:lib4sbom:0.9.1:*:*:*:*:*:*:*",
33053305
"description": "Software Bill of Material (SBOM) generator and consumer library",
33063306
"hashes": [
33073307
{
33083308
"alg": "SHA-256",
3309-
"content": "78b8584d10fc7fa28fc3c17c0afcb2967f3c2b96974e4bdbb60b3eb3744d01fd"
3309+
"content": "f2423d5e06a82f5462b05d0c5b9273d6e3674753ade9f5a0d4abdcf73f799117"
33103310
}
33113311
],
33123312
"licenses": [
@@ -3325,16 +3325,16 @@
33253325
"comment": "Home page for project"
33263326
},
33273327
{
3328-
"url": "https://pypi.org/project/lib4sbom/0.9.0/#files",
3328+
"url": "https://pypi.org/project/lib4sbom/0.9.1/#files",
33293329
"type": "distribution",
33303330
"comment": "Download location for component"
33313331
}
33323332
],
3333-
"purl": "pkg:pypi/[email protected].0",
3333+
"purl": "pkg:pypi/[email protected].1",
33343334
"properties": [
33353335
{
33363336
"name": "release_date",
3337-
"value": "2025-10-28T09:09:40Z"
3337+
"value": "2025-11-13T20:07:13Z"
33383338
},
33393339
{
33403340
"name": "language",
@@ -4210,7 +4210,7 @@
42104210
"type": "library",
42114211
"bom-ref": "65-narwhals",
42124212
"name": "narwhals",
4213-
"version": "2.10.2",
4213+
"version": "2.11.0",
42144214
"supplier": {
42154215
"name": "Marco Gorelli",
42164216
"contact": [
@@ -4219,7 +4219,7 @@
42194219
}
42204220
]
42214221
},
4222-
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:2.10.2:*:*:*:*:*:*:*",
4222+
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:2.11.0:*:*:*:*:*:*:*",
42234223
"description": "Extremely lightweight compatibility layer between dataframe libraries",
42244224
"licenses": [
42254225
{
@@ -4237,7 +4237,7 @@
42374237
"comment": "Home page for project"
42384238
},
42394239
{
4240-
"url": "https://pypi.org/project/narwhals/2.10.2/#files",
4240+
"url": "https://pypi.org/project/narwhals/2.11.0/#files",
42414241
"type": "distribution",
42424242
"comment": "Download location for component"
42434243
},
@@ -4254,7 +4254,7 @@
42544254
"type": "issue-tracker"
42554255
}
42564256
],
4257-
"purl": "pkg:pypi/narwhals@2.10.2",
4257+
"purl": "pkg:pypi/narwhals@2.11.0",
42584258
"properties": [
42594259
{
42604260
"name": "release_date",
@@ -4547,7 +4547,7 @@
45474547
"type": "library",
45484548
"bom-ref": "70-certifi",
45494549
"name": "certifi",
4550-
"version": "2025.10.5",
4550+
"version": "2025.11.12",
45514551
"supplier": {
45524552
"name": "Kenneth Reitz",
45534553
"contact": [
@@ -4556,12 +4556,12 @@
45564556
}
45574557
]
45584558
},
4559-
"cpe": "cpe:2.3:a:kenneth_reitz:certifi:2025.10.5:*:*:*:*:*:*:*",
4559+
"cpe": "cpe:2.3:a:kenneth_reitz:certifi:2025.11.12:*:*:*:*:*:*:*",
45604560
"description": "Python package for providing Mozilla's CA Bundle.",
45614561
"hashes": [
45624562
{
45634563
"alg": "SHA-256",
4564-
"content": "0f212c2744a9bb6de0c56639a6f68afe01ecd92d91f14ae897c4fe7bbeeef0de"
4564+
"content": "97de8790030bbd5c2d96b7ec782fc2f7820ef8dba6db909ccf95449f2d062d4b"
45654565
}
45664566
],
45674567
"licenses": [
@@ -4580,7 +4580,7 @@
45804580
"comment": "Home page for project"
45814581
},
45824582
{
4583-
"url": "https://pypi.org/project/certifi/2025.10.5/#files",
4583+
"url": "https://pypi.org/project/certifi/2025.11.12/#files",
45844584
"type": "distribution",
45854585
"comment": "Download location for component"
45864586
},
@@ -4589,11 +4589,11 @@
45894589
"type": "vcs"
45904590
}
45914591
],
4592-
"purl": "pkg:pypi/certifi@2025.10.5",
4592+
"purl": "pkg:pypi/certifi@2025.11.12",
45934593
"properties": [
45944594
{
45954595
"name": "release_date",
4596-
"value": "2025-10-05T04:12:14Z"
4596+
"value": "2025-11-12T02:54:49Z"
45974597
},
45984598
{
45994599
"name": "language",

sbom/cve-bin-tool-py3.10.spdx

Lines changed: 24 additions & 24 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-c37a6b38-02c7-4b17-a90d-c51629ac5075
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-3cf9e13c-a1da-4f19-9ebd-5cb8dcc5e4c7
66
LicenseListVersion: 3.26
77
Creator: Tool: sbom4python-0.12.4
8-
Created: 2025-11-10T00:42:54Z
8+
Created: 2025-11-17T00:42:37Z
99
CreatorComment: <text>SBOM Type: Build - This document has been automatically generated.</text>
1010
#####
1111

@@ -1010,44 +1010,44 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:referencing:0.37.0:*:*:*
10101010

10111011
PackageName: rpds-py
10121012
SPDXID: SPDXRef-49-rpds-py
1013-
PackageVersion: 0.28.0
1013+
PackageVersion: 0.29.0
10141014
PrimaryPackagePurpose: LIBRARY
10151015
PackageSupplier: Person: Julian Berman ([email protected])
1016-
PackageDownloadLocation: https://pypi.org/project/rpds-py/0.28.0/#files
1016+
PackageDownloadLocation: https://pypi.org/project/rpds-py/0.29.0/#files
10171017
FilesAnalyzed: false
10181018
PackageHomePage: https://github.com/crate-py/rpds
1019-
PackageChecksum: SHA256: 7b6013db815417eeb56b2d9d7324e64fcd4fa289caeee6e7a78b2e11fc9b438a
1019+
PackageChecksum: SHA256: 4ae4b88c6617e1b9e5038ab3fccd7bac0842fdda2b703117b2aa99bc85379113
10201020
PackageLicenseDeclared: NOASSERTION
10211021
PackageLicenseConcluded: NOASSERTION
10221022
PackageCopyrightText: NOASSERTION
10231023
PackageSummary: <text>Python bindings to Rust's persistent data structures (rpds)</text>
1024-
ReleaseDate: 2025-10-22T22:21:15Z
1024+
ReleaseDate: 2025-11-16T14:47:36Z
10251025
ExternalRef: OTHER documentation https://rpds.readthedocs.io/
10261026
ExternalRef: OTHER issue-tracker https://github.com/crate-py/rpds/issues/
10271027
ExternalRef: OTHER other https://github.com/sponsors/Julian
10281028
ExternalRef: OTHER other https://tidelift.com/subscription/pkg/pypi-rpds-py?utm_source=pypi-rpds-py&utm_medium=referral&utm_campaign=pypi-link
10291029
ExternalRef: OTHER vcs https://github.com/crate-py/rpds
10301030
ExternalRef: OTHER other https://github.com/orium/rpds
1031-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rpds-py@0.28.0
1032-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.28.0:*:*:*:*:*:*:*
1031+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rpds-py@0.29.0
1032+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.29.0:*:*:*:*:*:*:*
10331033
#####
10341034

10351035
PackageName: lib4sbom
10361036
SPDXID: SPDXRef-50-lib4sbom
1037-
PackageVersion: 0.9.0
1037+
PackageVersion: 0.9.1
10381038
PrimaryPackagePurpose: LIBRARY
10391039
PackageSupplier: Person: Anthony Harrison ([email protected])
1040-
PackageDownloadLocation: https://pypi.org/project/lib4sbom/0.9.0/#files
1040+
PackageDownloadLocation: https://pypi.org/project/lib4sbom/0.9.1/#files
10411041
FilesAnalyzed: false
10421042
PackageHomePage: https://github.com/anthonyharrison/lib4sbom
1043-
PackageChecksum: SHA256: 78b8584d10fc7fa28fc3c17c0afcb2967f3c2b96974e4bdbb60b3eb3744d01fd
1043+
PackageChecksum: SHA256: f2423d5e06a82f5462b05d0c5b9273d6e3674753ade9f5a0d4abdcf73f799117
10441044
PackageLicenseDeclared: Apache-2.0
10451045
PackageLicenseConcluded: Apache-2.0
10461046
PackageCopyrightText: NOASSERTION
10471047
PackageSummary: <text>Software Bill of Material (SBOM) generator and consumer library</text>
1048-
ReleaseDate: 2025-10-28T09:09:40Z
1049-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].0
1050-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:anthony_harrison:lib4sbom:0.9.0:*:*:*:*:*:*:*
1048+
ReleaseDate: 2025-11-13T20:07:13Z
1049+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].1
1050+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:anthony_harrison:lib4sbom:0.9.1:*:*:*:*:*:*:*
10511051
#####
10521052

10531053
PackageName: pyyaml
@@ -1346,10 +1346,10 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:6.4.0:*:*:*:*:*:*:*
13461346

13471347
PackageName: narwhals
13481348
SPDXID: SPDXRef-65-narwhals
1349-
PackageVersion: 2.10.2
1349+
PackageVersion: 2.11.0
13501350
PrimaryPackagePurpose: LIBRARY
13511351
PackageSupplier: Person: Marco Gorelli ([email protected])
1352-
PackageDownloadLocation: https://pypi.org/project/narwhals/2.10.2/#files
1352+
PackageDownloadLocation: https://pypi.org/project/narwhals/2.11.0/#files
13531353
FilesAnalyzed: false
13541354
PackageHomePage: https://github.com/narwhals-dev/narwhals
13551355
PackageLicenseDeclared: NOASSERTION
@@ -1361,8 +1361,8 @@ ReleaseDate: 2025-11-04T17:59:22Z
13611361
ExternalRef: OTHER documentation https://narwhals-dev.github.io/narwhals/
13621362
ExternalRef: OTHER vcs https://github.com/narwhals-dev/narwhals
13631363
ExternalRef: OTHER issue-tracker https://github.com/narwhals-dev/narwhals/issues
1364-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@2.10.2
1365-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:2.10.2:*:*:*:*:*:*:*
1364+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@2.11.0
1365+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:2.11.0:*:*:*:*:*:*:*
13661366
#####
13671367

13681368
PackageName: python-gnupg
@@ -1451,21 +1451,21 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_petrov:urllib3:2.5.0:*:*:*:*:*:
14511451

14521452
PackageName: certifi
14531453
SPDXID: SPDXRef-70-certifi
1454-
PackageVersion: 2025.10.5
1454+
PackageVersion: 2025.11.12
14551455
PrimaryPackagePurpose: LIBRARY
14561456
PackageSupplier: Person: Kenneth Reitz ([email protected])
1457-
PackageDownloadLocation: https://pypi.org/project/certifi/2025.10.5/#files
1457+
PackageDownloadLocation: https://pypi.org/project/certifi/2025.11.12/#files
14581458
FilesAnalyzed: false
14591459
PackageHomePage: https://github.com/certifi/python-certifi
1460-
PackageChecksum: SHA256: 0f212c2744a9bb6de0c56639a6f68afe01ecd92d91f14ae897c4fe7bbeeef0de
1460+
PackageChecksum: SHA256: 97de8790030bbd5c2d96b7ec782fc2f7820ef8dba6db909ccf95449f2d062d4b
14611461
PackageLicenseDeclared: MPL-2.0
14621462
PackageLicenseConcluded: MPL-2.0
14631463
PackageCopyrightText: NOASSERTION
14641464
PackageSummary: <text>Python package for providing Mozilla's CA Bundle.</text>
1465-
ReleaseDate: 2025-10-05T04:12:14Z
1465+
ReleaseDate: 2025-11-12T02:54:49Z
14661466
ExternalRef: OTHER vcs https://github.com/certifi/python-certifi
1467-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/certifi@2025.10.5
1468-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:certifi:2025.10.5:*:*:*:*:*:*:*
1467+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/certifi@2025.11.12
1468+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:certifi:2025.11.12:*:*:*:*:*:*:*
14691469
#####
14701470

14711471
PackageName: rpmfile

0 commit comments

Comments
 (0)