Skip to content

Commit 48ed23d

Browse files
web-flowgithub-actions[bot]
authored andcommitted
chore: update SBOM for Python 3.9
1 parent 118245d commit 48ed23d

File tree

2 files changed

+72
-79
lines changed

2 files changed

+72
-79
lines changed

sbom/cve-bin-tool-py3.9.json

Lines changed: 36 additions & 42 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.7.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.7",
5-
"serialNumber": "urn:uuid:d190d704-123d-4c29-92f1-59ac8bf44db5",
5+
"serialNumber": "urn:uuid:926383b1-3b8c-48f1-8db1-043a4f27904a",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-11-10T00:41:52Z",
8+
"timestamp": "2025-12-01T00:49:21Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -948,7 +948,7 @@
948948
"type": "library",
949949
"bom-ref": "13-beautifulsoup4",
950950
"name": "beautifulsoup4",
951-
"version": "4.14.2",
951+
"version": "4.14.3",
952952
"supplier": {
953953
"name": "Leonard Richardson",
954954
"contact": [
@@ -957,14 +957,8 @@
957957
}
958958
]
959959
},
960-
"cpe": "cpe:2.3:a:leonard_richardson:beautifulsoup4:4.14.2:*:*:*:*:*:*:*",
960+
"cpe": "cpe:2.3:a:leonard_richardson:beautifulsoup4:4.14.3:*:*:*:*:*:*:*",
961961
"description": "Screen-scraping library",
962-
"hashes": [
963-
{
964-
"alg": "SHA-256",
965-
"content": "5ef6fa3a8cbece8488d66985560f97ed091e22bbc4e9c2338508a9d5de6d4515"
966-
}
967-
],
968962
"licenses": [
969963
{
970964
"license": {
@@ -981,7 +975,7 @@
981975
"comment": "Home page for project"
982976
},
983977
{
984-
"url": "https://pypi.org/project/beautifulsoup4/4.14.2/#files",
978+
"url": "https://pypi.org/project/beautifulsoup4/4.14.3/#files",
985979
"type": "distribution",
986980
"comment": "Download location for component"
987981
},
@@ -990,11 +984,11 @@
990984
"type": "other"
991985
}
992986
],
993-
"purl": "pkg:pypi/beautifulsoup4@4.14.2",
987+
"purl": "pkg:pypi/beautifulsoup4@4.14.3",
994988
"properties": [
995989
{
996990
"name": "release_date",
997-
"value": "2025-09-29T10:05:43Z"
991+
"value": "2025-10-12T14:55:18Z"
998992
},
999993
{
1000994
"name": "language",
@@ -3401,7 +3395,7 @@
34013395
"type": "library",
34023396
"bom-ref": "52-lib4sbom",
34033397
"name": "lib4sbom",
3404-
"version": "0.9.0",
3398+
"version": "0.9.1",
34053399
"supplier": {
34063400
"name": "Anthony Harrison",
34073401
"contact": [
@@ -3410,12 +3404,12 @@
34103404
}
34113405
]
34123406
},
3413-
"cpe": "cpe:2.3:a:anthony_harrison:lib4sbom:0.9.0:*:*:*:*:*:*:*",
3407+
"cpe": "cpe:2.3:a:anthony_harrison:lib4sbom:0.9.1:*:*:*:*:*:*:*",
34143408
"description": "Software Bill of Material (SBOM) generator and consumer library",
34153409
"hashes": [
34163410
{
34173411
"alg": "SHA-256",
3418-
"content": "78b8584d10fc7fa28fc3c17c0afcb2967f3c2b96974e4bdbb60b3eb3744d01fd"
3412+
"content": "f2423d5e06a82f5462b05d0c5b9273d6e3674753ade9f5a0d4abdcf73f799117"
34193413
}
34203414
],
34213415
"licenses": [
@@ -3434,16 +3428,16 @@
34343428
"comment": "Home page for project"
34353429
},
34363430
{
3437-
"url": "https://pypi.org/project/lib4sbom/0.9.0/#files",
3431+
"url": "https://pypi.org/project/lib4sbom/0.9.1/#files",
34383432
"type": "distribution",
34393433
"comment": "Download location for component"
34403434
}
34413435
],
3442-
"purl": "pkg:pypi/lib4sbom@0.9.0",
3436+
"purl": "pkg:pypi/lib4sbom@0.9.1",
34433437
"properties": [
34443438
{
34453439
"name": "release_date",
3446-
"value": "2025-10-28T09:09:40Z"
3440+
"value": "2025-11-13T20:07:13Z"
34473441
},
34483442
{
34493443
"name": "language",
@@ -3875,16 +3869,16 @@
38753869
"type": "library",
38763870
"bom-ref": "60-packageurl-python",
38773871
"name": "packageurl-python",
3878-
"version": "0.17.5",
3872+
"version": "0.17.6",
38793873
"supplier": {
38803874
"name": "the purl authors"
38813875
},
3882-
"cpe": "cpe:2.3:a:the_purl_authors:packageurl-python:0.17.5:*:*:*:*:*:*:*",
3876+
"cpe": "cpe:2.3:a:the_purl_authors:packageurl-python:0.17.6:*:*:*:*:*:*:*",
38833877
"description": "A purl aka. Package URL parser and builder",
38843878
"hashes": [
38853879
{
38863880
"alg": "SHA-256",
3887-
"content": "f0e55452ab37b5c192c443de1458e3f3b4d8ac27f747df6e8c48adeab081d321"
3881+
"content": "31a85c2717bc41dd818f3c62908685ff9eebcb68588213745b14a6ee9e7df7c9"
38883882
}
38893883
],
38903884
"licenses": [
@@ -3903,16 +3897,16 @@
39033897
"comment": "Home page for project"
39043898
},
39053899
{
3906-
"url": "https://pypi.org/project/packageurl-python/0.17.5/#files",
3900+
"url": "https://pypi.org/project/packageurl-python/0.17.6/#files",
39073901
"type": "distribution",
39083902
"comment": "Download location for component"
39093903
}
39103904
],
3911-
"purl": "pkg:pypi/packageurl-python@0.17.5",
3905+
"purl": "pkg:pypi/packageurl-python@0.17.6",
39123906
"properties": [
39133907
{
39143908
"name": "release_date",
3915-
"value": "2025-08-06T14:08:19Z"
3909+
"value": "2025-11-24T15:20:16Z"
39163910
},
39173911
{
39183912
"name": "language",
@@ -4254,7 +4248,7 @@
42544248
"type": "library",
42554249
"bom-ref": "66-plotly",
42564250
"name": "plotly",
4257-
"version": "6.4.0",
4251+
"version": "6.5.0",
42584252
"supplier": {
42594253
"name": "Chris P",
42604254
"contact": [
@@ -4263,12 +4257,12 @@
42634257
}
42644258
]
42654259
},
4266-
"cpe": "cpe:2.3:a:chris_p:plotly:6.4.0:*:*:*:*:*:*:*",
4260+
"cpe": "cpe:2.3:a:chris_p:plotly:6.5.0:*:*:*:*:*:*:*",
42674261
"description": "An open-source interactive data visualization library for Python",
42684262
"hashes": [
42694263
{
42704264
"alg": "SHA-256",
4271-
"content": "a1062eafbdc657976c2eedd276c90e184ccd6c21282a5e9ee8f20efca9c9a4c5"
4265+
"content": "5ac851e100367735250206788a2b1325412aa4a4917a4fe3e6f0bc5aa6f3d90a"
42724266
}
42734267
],
42744268
"externalReferences": [
@@ -4278,7 +4272,7 @@
42784272
"comment": "Home page for project"
42794273
},
42804274
{
4281-
"url": "https://pypi.org/project/plotly/6.4.0/#files",
4275+
"url": "https://pypi.org/project/plotly/6.5.0/#files",
42824276
"type": "distribution",
42834277
"comment": "Download location for component"
42844278
},
@@ -4295,11 +4289,11 @@
42954289
"type": "log"
42964290
}
42974291
],
4298-
"purl": "pkg:pypi/plotly@6.4.0",
4292+
"purl": "pkg:pypi/plotly@6.5.0",
42994293
"properties": [
43004294
{
43014295
"name": "release_date",
4302-
"value": "2025-11-04T17:59:22Z"
4296+
"value": "2025-11-17T18:39:20Z"
43034297
},
43044298
{
43054299
"name": "language",
@@ -4319,7 +4313,7 @@
43194313
"type": "library",
43204314
"bom-ref": "67-narwhals",
43214315
"name": "narwhals",
4322-
"version": "2.10.2",
4316+
"version": "2.12.0",
43234317
"supplier": {
43244318
"name": "Marco Gorelli",
43254319
"contact": [
@@ -4328,7 +4322,7 @@
43284322
}
43294323
]
43304324
},
4331-
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:2.10.2:*:*:*:*:*:*:*",
4325+
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:2.12.0:*:*:*:*:*:*:*",
43324326
"description": "Extremely lightweight compatibility layer between dataframe libraries",
43334327
"licenses": [
43344328
{
@@ -4346,7 +4340,7 @@
43464340
"comment": "Home page for project"
43474341
},
43484342
{
4349-
"url": "https://pypi.org/project/narwhals/2.10.2/#files",
4343+
"url": "https://pypi.org/project/narwhals/2.12.0/#files",
43504344
"type": "distribution",
43514345
"comment": "Download location for component"
43524346
},
@@ -4363,11 +4357,11 @@
43634357
"type": "issue-tracker"
43644358
}
43654359
],
4366-
"purl": "pkg:pypi/narwhals@2.10.2",
4360+
"purl": "pkg:pypi/narwhals@2.12.0",
43674361
"properties": [
43684362
{
43694363
"name": "release_date",
4370-
"value": "2025-11-04T17:59:22Z"
4364+
"value": "2025-11-17T18:39:20Z"
43714365
},
43724366
{
43734367
"name": "language",
@@ -4656,7 +4650,7 @@
46564650
"type": "library",
46574651
"bom-ref": "72-certifi",
46584652
"name": "certifi",
4659-
"version": "2025.10.5",
4653+
"version": "2025.11.12",
46604654
"supplier": {
46614655
"name": "Kenneth Reitz",
46624656
"contact": [
@@ -4665,12 +4659,12 @@
46654659
}
46664660
]
46674661
},
4668-
"cpe": "cpe:2.3:a:kenneth_reitz:certifi:2025.10.5:*:*:*:*:*:*:*",
4662+
"cpe": "cpe:2.3:a:kenneth_reitz:certifi:2025.11.12:*:*:*:*:*:*:*",
46694663
"description": "Python package for providing Mozilla's CA Bundle.",
46704664
"hashes": [
46714665
{
46724666
"alg": "SHA-256",
4673-
"content": "0f212c2744a9bb6de0c56639a6f68afe01ecd92d91f14ae897c4fe7bbeeef0de"
4667+
"content": "97de8790030bbd5c2d96b7ec782fc2f7820ef8dba6db909ccf95449f2d062d4b"
46744668
}
46754669
],
46764670
"licenses": [
@@ -4689,7 +4683,7 @@
46894683
"comment": "Home page for project"
46904684
},
46914685
{
4692-
"url": "https://pypi.org/project/certifi/2025.10.5/#files",
4686+
"url": "https://pypi.org/project/certifi/2025.11.12/#files",
46934687
"type": "distribution",
46944688
"comment": "Download location for component"
46954689
},
@@ -4698,11 +4692,11 @@
46984692
"type": "vcs"
46994693
}
47004694
],
4701-
"purl": "pkg:pypi/certifi@2025.10.5",
4695+
"purl": "pkg:pypi/certifi@2025.11.12",
47024696
"properties": [
47034697
{
47044698
"name": "release_date",
4705-
"value": "2025-10-05T04:12:14Z"
4699+
"value": "2025-11-12T02:54:49Z"
47064700
},
47074701
{
47084702
"name": "language",

0 commit comments

Comments
 (0)