Skip to content

Commit 60885bc

Browse files
web-flowgithub-actions[bot]
authored andcommitted
chore: update SBOM for Python 3.13
1 parent 118245d commit 60885bc

File tree

2 files changed

+62
-62
lines changed

2 files changed

+62
-62
lines changed

sbom/cve-bin-tool-py3.13.json

Lines changed: 31 additions & 31 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.7.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.7",
5-
"serialNumber": "urn:uuid:6911f5a8-a56b-4fb0-b17c-4acb66c36c96",
5+
"serialNumber": "urn:uuid:5a0b5baf-9390-46c6-8e11-63bc28d768af",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-11-10T00:41:52Z",
8+
"timestamp": "2025-11-24T00:44:20Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -3137,7 +3137,7 @@
31373137
"type": "library",
31383138
"bom-ref": "48-rpds-py",
31393139
"name": "rpds-py",
3140-
"version": "0.28.0",
3140+
"version": "0.29.0",
31413141
"supplier": {
31423142
"name": "Julian Berman",
31433143
"contact": [
@@ -3146,12 +3146,12 @@
31463146
}
31473147
]
31483148
},
3149-
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.28.0:*:*:*:*:*:*:*",
3149+
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.29.0:*:*:*:*:*:*:*",
31503150
"description": "Python bindings to Rust's persistent data structures (rpds)",
31513151
"hashes": [
31523152
{
31533153
"alg": "SHA-256",
3154-
"content": "7b6013db815417eeb56b2d9d7324e64fcd4fa289caeee6e7a78b2e11fc9b438a"
3154+
"content": "4ae4b88c6617e1b9e5038ab3fccd7bac0842fdda2b703117b2aa99bc85379113"
31553155
}
31563156
],
31573157
"externalReferences": [
@@ -3161,7 +3161,7 @@
31613161
"comment": "Home page for project"
31623162
},
31633163
{
3164-
"url": "https://pypi.org/project/rpds-py/0.28.0/#files",
3164+
"url": "https://pypi.org/project/rpds-py/0.29.0/#files",
31653165
"type": "distribution",
31663166
"comment": "Download location for component"
31673167
},
@@ -3190,11 +3190,11 @@
31903190
"type": "other"
31913191
}
31923192
],
3193-
"purl": "pkg:pypi/rpds-py@0.28.0",
3193+
"purl": "pkg:pypi/rpds-py@0.29.0",
31943194
"properties": [
31953195
{
31963196
"name": "release_date",
3197-
"value": "2025-10-22T22:21:15Z"
3197+
"value": "2025-11-16T14:47:36Z"
31983198
},
31993199
{
32003200
"name": "language",
@@ -3210,7 +3210,7 @@
32103210
"type": "library",
32113211
"bom-ref": "49-lib4sbom",
32123212
"name": "lib4sbom",
3213-
"version": "0.9.0",
3213+
"version": "0.9.1",
32143214
"supplier": {
32153215
"name": "Anthony Harrison",
32163216
"contact": [
@@ -3219,12 +3219,12 @@
32193219
}
32203220
]
32213221
},
3222-
"cpe": "cpe:2.3:a:anthony_harrison:lib4sbom:0.9.0:*:*:*:*:*:*:*",
3222+
"cpe": "cpe:2.3:a:anthony_harrison:lib4sbom:0.9.1:*:*:*:*:*:*:*",
32233223
"description": "Software Bill of Material (SBOM) generator and consumer library",
32243224
"hashes": [
32253225
{
32263226
"alg": "SHA-256",
3227-
"content": "78b8584d10fc7fa28fc3c17c0afcb2967f3c2b96974e4bdbb60b3eb3744d01fd"
3227+
"content": "f2423d5e06a82f5462b05d0c5b9273d6e3674753ade9f5a0d4abdcf73f799117"
32283228
}
32293229
],
32303230
"licenses": [
@@ -3243,16 +3243,16 @@
32433243
"comment": "Home page for project"
32443244
},
32453245
{
3246-
"url": "https://pypi.org/project/lib4sbom/0.9.0/#files",
3246+
"url": "https://pypi.org/project/lib4sbom/0.9.1/#files",
32473247
"type": "distribution",
32483248
"comment": "Download location for component"
32493249
}
32503250
],
3251-
"purl": "pkg:pypi/lib4sbom@0.9.0",
3251+
"purl": "pkg:pypi/lib4sbom@0.9.1",
32523252
"properties": [
32533253
{
32543254
"name": "release_date",
3255-
"value": "2025-10-28T09:09:40Z"
3255+
"value": "2025-11-13T20:07:13Z"
32563256
},
32573257
{
32583258
"name": "language",
@@ -4063,7 +4063,7 @@
40634063
"type": "library",
40644064
"bom-ref": "63-plotly",
40654065
"name": "plotly",
4066-
"version": "6.4.0",
4066+
"version": "6.5.0",
40674067
"supplier": {
40684068
"name": "Chris P",
40694069
"contact": [
@@ -4072,12 +4072,12 @@
40724072
}
40734073
]
40744074
},
4075-
"cpe": "cpe:2.3:a:chris_p:plotly:6.4.0:*:*:*:*:*:*:*",
4075+
"cpe": "cpe:2.3:a:chris_p:plotly:6.5.0:*:*:*:*:*:*:*",
40764076
"description": "An open-source interactive data visualization library for Python",
40774077
"hashes": [
40784078
{
40794079
"alg": "SHA-256",
4080-
"content": "a1062eafbdc657976c2eedd276c90e184ccd6c21282a5e9ee8f20efca9c9a4c5"
4080+
"content": "5ac851e100367735250206788a2b1325412aa4a4917a4fe3e6f0bc5aa6f3d90a"
40814081
}
40824082
],
40834083
"externalReferences": [
@@ -4087,7 +4087,7 @@
40874087
"comment": "Home page for project"
40884088
},
40894089
{
4090-
"url": "https://pypi.org/project/plotly/6.4.0/#files",
4090+
"url": "https://pypi.org/project/plotly/6.5.0/#files",
40914091
"type": "distribution",
40924092
"comment": "Download location for component"
40934093
},
@@ -4104,11 +4104,11 @@
41044104
"type": "log"
41054105
}
41064106
],
4107-
"purl": "pkg:pypi/plotly@6.4.0",
4107+
"purl": "pkg:pypi/plotly@6.5.0",
41084108
"properties": [
41094109
{
41104110
"name": "release_date",
4111-
"value": "2025-11-04T17:59:22Z"
4111+
"value": "2025-11-17T18:39:20Z"
41124112
},
41134113
{
41144114
"name": "language",
@@ -4128,7 +4128,7 @@
41284128
"type": "library",
41294129
"bom-ref": "64-narwhals",
41304130
"name": "narwhals",
4131-
"version": "2.10.2",
4131+
"version": "2.12.0",
41324132
"supplier": {
41334133
"name": "Marco Gorelli",
41344134
"contact": [
@@ -4137,7 +4137,7 @@
41374137
}
41384138
]
41394139
},
4140-
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:2.10.2:*:*:*:*:*:*:*",
4140+
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:2.12.0:*:*:*:*:*:*:*",
41414141
"description": "Extremely lightweight compatibility layer between dataframe libraries",
41424142
"licenses": [
41434143
{
@@ -4155,7 +4155,7 @@
41554155
"comment": "Home page for project"
41564156
},
41574157
{
4158-
"url": "https://pypi.org/project/narwhals/2.10.2/#files",
4158+
"url": "https://pypi.org/project/narwhals/2.12.0/#files",
41594159
"type": "distribution",
41604160
"comment": "Download location for component"
41614161
},
@@ -4172,11 +4172,11 @@
41724172
"type": "issue-tracker"
41734173
}
41744174
],
4175-
"purl": "pkg:pypi/narwhals@2.10.2",
4175+
"purl": "pkg:pypi/narwhals@2.12.0",
41764176
"properties": [
41774177
{
41784178
"name": "release_date",
4179-
"value": "2025-11-04T17:59:22Z"
4179+
"value": "2025-11-17T18:39:20Z"
41804180
},
41814181
{
41824182
"name": "language",
@@ -4465,7 +4465,7 @@
44654465
"type": "library",
44664466
"bom-ref": "69-certifi",
44674467
"name": "certifi",
4468-
"version": "2025.10.5",
4468+
"version": "2025.11.12",
44694469
"supplier": {
44704470
"name": "Kenneth Reitz",
44714471
"contact": [
@@ -4474,12 +4474,12 @@
44744474
}
44754475
]
44764476
},
4477-
"cpe": "cpe:2.3:a:kenneth_reitz:certifi:2025.10.5:*:*:*:*:*:*:*",
4477+
"cpe": "cpe:2.3:a:kenneth_reitz:certifi:2025.11.12:*:*:*:*:*:*:*",
44784478
"description": "Python package for providing Mozilla's CA Bundle.",
44794479
"hashes": [
44804480
{
44814481
"alg": "SHA-256",
4482-
"content": "0f212c2744a9bb6de0c56639a6f68afe01ecd92d91f14ae897c4fe7bbeeef0de"
4482+
"content": "97de8790030bbd5c2d96b7ec782fc2f7820ef8dba6db909ccf95449f2d062d4b"
44834483
}
44844484
],
44854485
"licenses": [
@@ -4498,7 +4498,7 @@
44984498
"comment": "Home page for project"
44994499
},
45004500
{
4501-
"url": "https://pypi.org/project/certifi/2025.10.5/#files",
4501+
"url": "https://pypi.org/project/certifi/2025.11.12/#files",
45024502
"type": "distribution",
45034503
"comment": "Download location for component"
45044504
},
@@ -4507,11 +4507,11 @@
45074507
"type": "vcs"
45084508
}
45094509
],
4510-
"purl": "pkg:pypi/certifi@2025.10.5",
4510+
"purl": "pkg:pypi/certifi@2025.11.12",
45114511
"properties": [
45124512
{
45134513
"name": "release_date",
4514-
"value": "2025-10-05T04:12:14Z"
4514+
"value": "2025-11-12T02:54:49Z"
45154515
},
45164516
{
45174517
"name": "language",

sbom/cve-bin-tool-py3.13.spdx

Lines changed: 31 additions & 31 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-887b9b7c-2e29-49c2-b60d-fb137ac69b91
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-a7a66328-a037-44e0-a536-ef77820d3795
66
LicenseListVersion: 3.26
77
Creator: Tool: sbom4python-0.12.4
8-
Created: 2025-11-10T00:41:40Z
8+
Created: 2025-11-24T00:44:10Z
99
CreatorComment: <text>SBOM Type: Build - This document has been automatically generated.</text>
1010
#####
1111

@@ -986,44 +986,44 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:referencing:0.37.0:*:*:*
986986

987987
PackageName: rpds-py
988988
SPDXID: SPDXRef-48-rpds-py
989-
PackageVersion: 0.28.0
989+
PackageVersion: 0.29.0
990990
PrimaryPackagePurpose: LIBRARY
991991
PackageSupplier: Person: Julian Berman (Julian+rpds@GrayVines.com)
992-
PackageDownloadLocation: https://pypi.org/project/rpds-py/0.28.0/#files
992+
PackageDownloadLocation: https://pypi.org/project/rpds-py/0.29.0/#files
993993
FilesAnalyzed: false
994994
PackageHomePage: https://github.com/crate-py/rpds
995-
PackageChecksum: SHA256: 7b6013db815417eeb56b2d9d7324e64fcd4fa289caeee6e7a78b2e11fc9b438a
995+
PackageChecksum: SHA256: 4ae4b88c6617e1b9e5038ab3fccd7bac0842fdda2b703117b2aa99bc85379113
996996
PackageLicenseDeclared: NOASSERTION
997997
PackageLicenseConcluded: NOASSERTION
998998
PackageCopyrightText: NOASSERTION
999999
PackageSummary: <text>Python bindings to Rust's persistent data structures (rpds)</text>
1000-
ReleaseDate: 2025-10-22T22:21:15Z
1000+
ReleaseDate: 2025-11-16T14:47:36Z
10011001
ExternalRef: OTHER documentation https://rpds.readthedocs.io/
10021002
ExternalRef: OTHER issue-tracker https://github.com/crate-py/rpds/issues/
10031003
ExternalRef: OTHER other https://github.com/sponsors/Julian
10041004
ExternalRef: OTHER other https://tidelift.com/subscription/pkg/pypi-rpds-py?utm_source=pypi-rpds-py&utm_medium=referral&utm_campaign=pypi-link
10051005
ExternalRef: OTHER vcs https://github.com/crate-py/rpds
10061006
ExternalRef: OTHER other https://github.com/orium/rpds
1007-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rpds-py@0.28.0
1008-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.28.0:*:*:*:*:*:*:*
1007+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rpds-py@0.29.0
1008+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.29.0:*:*:*:*:*:*:*
10091009
#####
10101010

10111011
PackageName: lib4sbom
10121012
SPDXID: SPDXRef-49-lib4sbom
1013-
PackageVersion: 0.9.0
1013+
PackageVersion: 0.9.1
10141014
PrimaryPackagePurpose: LIBRARY
10151015
PackageSupplier: Person: Anthony Harrison (anthony.p.harrison@gmail.com)
1016-
PackageDownloadLocation: https://pypi.org/project/lib4sbom/0.9.0/#files
1016+
PackageDownloadLocation: https://pypi.org/project/lib4sbom/0.9.1/#files
10171017
FilesAnalyzed: false
10181018
PackageHomePage: https://github.com/anthonyharrison/lib4sbom
1019-
PackageChecksum: SHA256: 78b8584d10fc7fa28fc3c17c0afcb2967f3c2b96974e4bdbb60b3eb3744d01fd
1019+
PackageChecksum: SHA256: f2423d5e06a82f5462b05d0c5b9273d6e3674753ade9f5a0d4abdcf73f799117
10201020
PackageLicenseDeclared: Apache-2.0
10211021
PackageLicenseConcluded: Apache-2.0
10221022
PackageCopyrightText: NOASSERTION
10231023
PackageSummary: <text>Software Bill of Material (SBOM) generator and consumer library</text>
1024-
ReleaseDate: 2025-10-28T09:09:40Z
1025-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/lib4sbom@0.9.0
1026-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:anthony_harrison:lib4sbom:0.9.0:*:*:*:*:*:*:*
1024+
ReleaseDate: 2025-11-13T20:07:13Z
1025+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/lib4sbom@0.9.1
1026+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:anthony_harrison:lib4sbom:0.9.1:*:*:*:*:*:*:*
10271027
#####
10281028

10291029
PackageName: pyyaml
@@ -1279,13 +1279,13 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:donald_stufft:packaging:25.0:*:*:*:*:*
12791279

12801280
PackageName: plotly
12811281
SPDXID: SPDXRef-63-plotly
1282-
PackageVersion: 6.4.0
1282+
PackageVersion: 6.5.0
12831283
PrimaryPackagePurpose: LIBRARY
12841284
PackageSupplier: Person: Chris P (chris@plot.ly)
1285-
PackageDownloadLocation: https://pypi.org/project/plotly/6.4.0/#files
1285+
PackageDownloadLocation: https://pypi.org/project/plotly/6.5.0/#files
12861286
FilesAnalyzed: false
12871287
PackageHomePage: https://plotly.com/python/
1288-
PackageChecksum: SHA256: a1062eafbdc657976c2eedd276c90e184ccd6c21282a5e9ee8f20efca9c9a4c5
1288+
PackageChecksum: SHA256: 5ac851e100367735250206788a2b1325412aa4a4917a4fe3e6f0bc5aa6f3d90a
12891289
PackageLicenseDeclared: NOASSERTION
12901290
PackageLicenseConcluded: NOASSERTION
12911291
PackageLicenseComments: <text>plotly declares MIT License
@@ -1312,33 +1312,33 @@ THE SOFTWARE.
13121312
which is not currently a valid SPDX License identifier or expression.</text>
13131313
PackageCopyrightText: NOASSERTION
13141314
PackageSummary: <text>An open-source interactive data visualization library for Python</text>
1315-
ReleaseDate: 2025-11-04T17:59:22Z
1315+
ReleaseDate: 2025-11-17T18:39:20Z
13161316
ExternalRef: OTHER documentation https://plotly.com/python/
13171317
ExternalRef: OTHER vcs https://github.com/plotly/plotly.py
13181318
ExternalRef: OTHER log https://github.com/plotly/plotly.py/blob/main/CHANGELOG.md
1319-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/plotly@6.4.0
1320-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:6.4.0:*:*:*:*:*:*:*
1319+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/plotly@6.5.0
1320+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:6.5.0:*:*:*:*:*:*:*
13211321
#####
13221322

13231323
PackageName: narwhals
13241324
SPDXID: SPDXRef-64-narwhals
1325-
PackageVersion: 2.10.2
1325+
PackageVersion: 2.12.0
13261326
PrimaryPackagePurpose: LIBRARY
13271327
PackageSupplier: Person: Marco Gorelli (hello_narwhals@proton.me)
1328-
PackageDownloadLocation: https://pypi.org/project/narwhals/2.10.2/#files
1328+
PackageDownloadLocation: https://pypi.org/project/narwhals/2.12.0/#files
13291329
FilesAnalyzed: false
13301330
PackageHomePage: https://github.com/narwhals-dev/narwhals
13311331
PackageLicenseDeclared: NOASSERTION
13321332
PackageLicenseConcluded: MIT
13331333
PackageLicenseComments: <text>narwhals declares MIT License which is not currently a valid SPDX License identifier or expression.</text>
13341334
PackageCopyrightText: NOASSERTION
13351335
PackageSummary: <text>Extremely lightweight compatibility layer between dataframe libraries</text>
1336-
ReleaseDate: 2025-11-04T17:59:22Z
1336+
ReleaseDate: 2025-11-17T18:39:20Z
13371337
ExternalRef: OTHER documentation https://narwhals-dev.github.io/narwhals/
13381338
ExternalRef: OTHER vcs https://github.com/narwhals-dev/narwhals
13391339
ExternalRef: OTHER issue-tracker https://github.com/narwhals-dev/narwhals/issues
1340-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@2.10.2
1341-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:2.10.2:*:*:*:*:*:*:*
1340+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@2.12.0
1341+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:2.12.0:*:*:*:*:*:*:*
13421342
#####
13431343

13441344
PackageName: python-gnupg
@@ -1427,21 +1427,21 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_petrov:urllib3:2.5.0:*:*:*:*:*:
14271427

14281428
PackageName: certifi
14291429
SPDXID: SPDXRef-69-certifi
1430-
PackageVersion: 2025.10.5
1430+
PackageVersion: 2025.11.12
14311431
PrimaryPackagePurpose: LIBRARY
14321432
PackageSupplier: Person: Kenneth Reitz (me@kennethreitz.com)
1433-
PackageDownloadLocation: https://pypi.org/project/certifi/2025.10.5/#files
1433+
PackageDownloadLocation: https://pypi.org/project/certifi/2025.11.12/#files
14341434
FilesAnalyzed: false
14351435
PackageHomePage: https://github.com/certifi/python-certifi
1436-
PackageChecksum: SHA256: 0f212c2744a9bb6de0c56639a6f68afe01ecd92d91f14ae897c4fe7bbeeef0de
1436+
PackageChecksum: SHA256: 97de8790030bbd5c2d96b7ec782fc2f7820ef8dba6db909ccf95449f2d062d4b
14371437
PackageLicenseDeclared: MPL-2.0
14381438
PackageLicenseConcluded: MPL-2.0
14391439
PackageCopyrightText: NOASSERTION
14401440
PackageSummary: <text>Python package for providing Mozilla's CA Bundle.</text>
1441-
ReleaseDate: 2025-10-05T04:12:14Z
1441+
ReleaseDate: 2025-11-12T02:54:49Z
14421442
ExternalRef: OTHER vcs https://github.com/certifi/python-certifi
1443-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/certifi@2025.10.5
1444-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:certifi:2025.10.5:*:*:*:*:*:*:*
1443+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/certifi@2025.11.12
1444+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:certifi:2025.11.12:*:*:*:*:*:*:*
14451445
#####
14461446

14471447
PackageName: rpmfile

0 commit comments

Comments
 (0)