Skip to content

Commit 667e4a9

Browse files
web-flowgithub-actions[bot]
authored andcommitted
chore: update SBOM for Python 3.12
1 parent 118245d commit 667e4a9

File tree

2 files changed

+48
-48
lines changed

2 files changed

+48
-48
lines changed

sbom/cve-bin-tool-py3.12.json

Lines changed: 24 additions & 24 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.7.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.7",
5-
"serialNumber": "urn:uuid:20de284a-3847-45ac-8489-a0be951dcff0",
5+
"serialNumber": "urn:uuid:4e1cafc5-a4b8-40fa-8127-6d533fccdbdf",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-11-10T00:41:52Z",
8+
"timestamp": "2025-11-17T00:41:37Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -3137,7 +3137,7 @@
31373137
"type": "library",
31383138
"bom-ref": "48-rpds-py",
31393139
"name": "rpds-py",
3140-
"version": "0.28.0",
3140+
"version": "0.29.0",
31413141
"supplier": {
31423142
"name": "Julian Berman",
31433143
"contact": [
@@ -3146,12 +3146,12 @@
31463146
}
31473147
]
31483148
},
3149-
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.28.0:*:*:*:*:*:*:*",
3149+
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.29.0:*:*:*:*:*:*:*",
31503150
"description": "Python bindings to Rust's persistent data structures (rpds)",
31513151
"hashes": [
31523152
{
31533153
"alg": "SHA-256",
3154-
"content": "7b6013db815417eeb56b2d9d7324e64fcd4fa289caeee6e7a78b2e11fc9b438a"
3154+
"content": "4ae4b88c6617e1b9e5038ab3fccd7bac0842fdda2b703117b2aa99bc85379113"
31553155
}
31563156
],
31573157
"externalReferences": [
@@ -3161,7 +3161,7 @@
31613161
"comment": "Home page for project"
31623162
},
31633163
{
3164-
"url": "https://pypi.org/project/rpds-py/0.28.0/#files",
3164+
"url": "https://pypi.org/project/rpds-py/0.29.0/#files",
31653165
"type": "distribution",
31663166
"comment": "Download location for component"
31673167
},
@@ -3190,11 +3190,11 @@
31903190
"type": "other"
31913191
}
31923192
],
3193-
"purl": "pkg:pypi/rpds-py@0.28.0",
3193+
"purl": "pkg:pypi/rpds-py@0.29.0",
31943194
"properties": [
31953195
{
31963196
"name": "release_date",
3197-
"value": "2025-10-22T22:21:15Z"
3197+
"value": "2025-11-16T14:47:36Z"
31983198
},
31993199
{
32003200
"name": "language",
@@ -3210,7 +3210,7 @@
32103210
"type": "library",
32113211
"bom-ref": "49-lib4sbom",
32123212
"name": "lib4sbom",
3213-
"version": "0.9.0",
3213+
"version": "0.9.1",
32143214
"supplier": {
32153215
"name": "Anthony Harrison",
32163216
"contact": [
@@ -3219,12 +3219,12 @@
32193219
}
32203220
]
32213221
},
3222-
"cpe": "cpe:2.3:a:anthony_harrison:lib4sbom:0.9.0:*:*:*:*:*:*:*",
3222+
"cpe": "cpe:2.3:a:anthony_harrison:lib4sbom:0.9.1:*:*:*:*:*:*:*",
32233223
"description": "Software Bill of Material (SBOM) generator and consumer library",
32243224
"hashes": [
32253225
{
32263226
"alg": "SHA-256",
3227-
"content": "78b8584d10fc7fa28fc3c17c0afcb2967f3c2b96974e4bdbb60b3eb3744d01fd"
3227+
"content": "f2423d5e06a82f5462b05d0c5b9273d6e3674753ade9f5a0d4abdcf73f799117"
32283228
}
32293229
],
32303230
"licenses": [
@@ -3243,16 +3243,16 @@
32433243
"comment": "Home page for project"
32443244
},
32453245
{
3246-
"url": "https://pypi.org/project/lib4sbom/0.9.0/#files",
3246+
"url": "https://pypi.org/project/lib4sbom/0.9.1/#files",
32473247
"type": "distribution",
32483248
"comment": "Download location for component"
32493249
}
32503250
],
3251-
"purl": "pkg:pypi/lib4sbom@0.9.0",
3251+
"purl": "pkg:pypi/lib4sbom@0.9.1",
32523252
"properties": [
32533253
{
32543254
"name": "release_date",
3255-
"value": "2025-10-28T09:09:40Z"
3255+
"value": "2025-11-13T20:07:13Z"
32563256
},
32573257
{
32583258
"name": "language",
@@ -4128,7 +4128,7 @@
41284128
"type": "library",
41294129
"bom-ref": "64-narwhals",
41304130
"name": "narwhals",
4131-
"version": "2.10.2",
4131+
"version": "2.11.0",
41324132
"supplier": {
41334133
"name": "Marco Gorelli",
41344134
"contact": [
@@ -4137,7 +4137,7 @@
41374137
}
41384138
]
41394139
},
4140-
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:2.10.2:*:*:*:*:*:*:*",
4140+
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:2.11.0:*:*:*:*:*:*:*",
41414141
"description": "Extremely lightweight compatibility layer between dataframe libraries",
41424142
"licenses": [
41434143
{
@@ -4155,7 +4155,7 @@
41554155
"comment": "Home page for project"
41564156
},
41574157
{
4158-
"url": "https://pypi.org/project/narwhals/2.10.2/#files",
4158+
"url": "https://pypi.org/project/narwhals/2.11.0/#files",
41594159
"type": "distribution",
41604160
"comment": "Download location for component"
41614161
},
@@ -4172,7 +4172,7 @@
41724172
"type": "issue-tracker"
41734173
}
41744174
],
4175-
"purl": "pkg:pypi/narwhals@2.10.2",
4175+
"purl": "pkg:pypi/narwhals@2.11.0",
41764176
"properties": [
41774177
{
41784178
"name": "release_date",
@@ -4465,7 +4465,7 @@
44654465
"type": "library",
44664466
"bom-ref": "69-certifi",
44674467
"name": "certifi",
4468-
"version": "2025.10.5",
4468+
"version": "2025.11.12",
44694469
"supplier": {
44704470
"name": "Kenneth Reitz",
44714471
"contact": [
@@ -4474,12 +4474,12 @@
44744474
}
44754475
]
44764476
},
4477-
"cpe": "cpe:2.3:a:kenneth_reitz:certifi:2025.10.5:*:*:*:*:*:*:*",
4477+
"cpe": "cpe:2.3:a:kenneth_reitz:certifi:2025.11.12:*:*:*:*:*:*:*",
44784478
"description": "Python package for providing Mozilla's CA Bundle.",
44794479
"hashes": [
44804480
{
44814481
"alg": "SHA-256",
4482-
"content": "0f212c2744a9bb6de0c56639a6f68afe01ecd92d91f14ae897c4fe7bbeeef0de"
4482+
"content": "97de8790030bbd5c2d96b7ec782fc2f7820ef8dba6db909ccf95449f2d062d4b"
44834483
}
44844484
],
44854485
"licenses": [
@@ -4498,7 +4498,7 @@
44984498
"comment": "Home page for project"
44994499
},
45004500
{
4501-
"url": "https://pypi.org/project/certifi/2025.10.5/#files",
4501+
"url": "https://pypi.org/project/certifi/2025.11.12/#files",
45024502
"type": "distribution",
45034503
"comment": "Download location for component"
45044504
},
@@ -4507,11 +4507,11 @@
45074507
"type": "vcs"
45084508
}
45094509
],
4510-
"purl": "pkg:pypi/certifi@2025.10.5",
4510+
"purl": "pkg:pypi/certifi@2025.11.12",
45114511
"properties": [
45124512
{
45134513
"name": "release_date",
4514-
"value": "2025-10-05T04:12:14Z"
4514+
"value": "2025-11-12T02:54:49Z"
45154515
},
45164516
{
45174517
"name": "language",

sbom/cve-bin-tool-py3.12.spdx

Lines changed: 24 additions & 24 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-be94c513-94c6-4fd2-906e-21bab8481b6b
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-c8ca6192-0408-4590-a2d7-4fb26557b180
66
LicenseListVersion: 3.26
77
Creator: Tool: sbom4python-0.12.4
8-
Created: 2025-11-10T00:41:40Z
8+
Created: 2025-11-17T00:41:26Z
99
CreatorComment: <text>SBOM Type: Build - This document has been automatically generated.</text>
1010
#####
1111

@@ -986,44 +986,44 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:referencing:0.37.0:*:*:*
986986

987987
PackageName: rpds-py
988988
SPDXID: SPDXRef-48-rpds-py
989-
PackageVersion: 0.28.0
989+
PackageVersion: 0.29.0
990990
PrimaryPackagePurpose: LIBRARY
991991
PackageSupplier: Person: Julian Berman (Julian+rpds@GrayVines.com)
992-
PackageDownloadLocation: https://pypi.org/project/rpds-py/0.28.0/#files
992+
PackageDownloadLocation: https://pypi.org/project/rpds-py/0.29.0/#files
993993
FilesAnalyzed: false
994994
PackageHomePage: https://github.com/crate-py/rpds
995-
PackageChecksum: SHA256: 7b6013db815417eeb56b2d9d7324e64fcd4fa289caeee6e7a78b2e11fc9b438a
995+
PackageChecksum: SHA256: 4ae4b88c6617e1b9e5038ab3fccd7bac0842fdda2b703117b2aa99bc85379113
996996
PackageLicenseDeclared: NOASSERTION
997997
PackageLicenseConcluded: NOASSERTION
998998
PackageCopyrightText: NOASSERTION
999999
PackageSummary: <text>Python bindings to Rust's persistent data structures (rpds)</text>
1000-
ReleaseDate: 2025-10-22T22:21:15Z
1000+
ReleaseDate: 2025-11-16T14:47:36Z
10011001
ExternalRef: OTHER documentation https://rpds.readthedocs.io/
10021002
ExternalRef: OTHER issue-tracker https://github.com/crate-py/rpds/issues/
10031003
ExternalRef: OTHER other https://github.com/sponsors/Julian
10041004
ExternalRef: OTHER other https://tidelift.com/subscription/pkg/pypi-rpds-py?utm_source=pypi-rpds-py&utm_medium=referral&utm_campaign=pypi-link
10051005
ExternalRef: OTHER vcs https://github.com/crate-py/rpds
10061006
ExternalRef: OTHER other https://github.com/orium/rpds
1007-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rpds-py@0.28.0
1008-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.28.0:*:*:*:*:*:*:*
1007+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rpds-py@0.29.0
1008+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.29.0:*:*:*:*:*:*:*
10091009
#####
10101010

10111011
PackageName: lib4sbom
10121012
SPDXID: SPDXRef-49-lib4sbom
1013-
PackageVersion: 0.9.0
1013+
PackageVersion: 0.9.1
10141014
PrimaryPackagePurpose: LIBRARY
10151015
PackageSupplier: Person: Anthony Harrison (anthony.p.harrison@gmail.com)
1016-
PackageDownloadLocation: https://pypi.org/project/lib4sbom/0.9.0/#files
1016+
PackageDownloadLocation: https://pypi.org/project/lib4sbom/0.9.1/#files
10171017
FilesAnalyzed: false
10181018
PackageHomePage: https://github.com/anthonyharrison/lib4sbom
1019-
PackageChecksum: SHA256: 78b8584d10fc7fa28fc3c17c0afcb2967f3c2b96974e4bdbb60b3eb3744d01fd
1019+
PackageChecksum: SHA256: f2423d5e06a82f5462b05d0c5b9273d6e3674753ade9f5a0d4abdcf73f799117
10201020
PackageLicenseDeclared: Apache-2.0
10211021
PackageLicenseConcluded: Apache-2.0
10221022
PackageCopyrightText: NOASSERTION
10231023
PackageSummary: <text>Software Bill of Material (SBOM) generator and consumer library</text>
1024-
ReleaseDate: 2025-10-28T09:09:40Z
1025-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/lib4sbom@0.9.0
1026-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:anthony_harrison:lib4sbom:0.9.0:*:*:*:*:*:*:*
1024+
ReleaseDate: 2025-11-13T20:07:13Z
1025+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/lib4sbom@0.9.1
1026+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:anthony_harrison:lib4sbom:0.9.1:*:*:*:*:*:*:*
10271027
#####
10281028

10291029
PackageName: pyyaml
@@ -1322,10 +1322,10 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:6.4.0:*:*:*:*:*:*:*
13221322

13231323
PackageName: narwhals
13241324
SPDXID: SPDXRef-64-narwhals
1325-
PackageVersion: 2.10.2
1325+
PackageVersion: 2.11.0
13261326
PrimaryPackagePurpose: LIBRARY
13271327
PackageSupplier: Person: Marco Gorelli (hello_narwhals@proton.me)
1328-
PackageDownloadLocation: https://pypi.org/project/narwhals/2.10.2/#files
1328+
PackageDownloadLocation: https://pypi.org/project/narwhals/2.11.0/#files
13291329
FilesAnalyzed: false
13301330
PackageHomePage: https://github.com/narwhals-dev/narwhals
13311331
PackageLicenseDeclared: NOASSERTION
@@ -1337,8 +1337,8 @@ ReleaseDate: 2025-11-04T17:59:22Z
13371337
ExternalRef: OTHER documentation https://narwhals-dev.github.io/narwhals/
13381338
ExternalRef: OTHER vcs https://github.com/narwhals-dev/narwhals
13391339
ExternalRef: OTHER issue-tracker https://github.com/narwhals-dev/narwhals/issues
1340-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@2.10.2
1341-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:2.10.2:*:*:*:*:*:*:*
1340+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@2.11.0
1341+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:2.11.0:*:*:*:*:*:*:*
13421342
#####
13431343

13441344
PackageName: python-gnupg
@@ -1427,21 +1427,21 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_petrov:urllib3:2.5.0:*:*:*:*:*:
14271427

14281428
PackageName: certifi
14291429
SPDXID: SPDXRef-69-certifi
1430-
PackageVersion: 2025.10.5
1430+
PackageVersion: 2025.11.12
14311431
PrimaryPackagePurpose: LIBRARY
14321432
PackageSupplier: Person: Kenneth Reitz (me@kennethreitz.com)
1433-
PackageDownloadLocation: https://pypi.org/project/certifi/2025.10.5/#files
1433+
PackageDownloadLocation: https://pypi.org/project/certifi/2025.11.12/#files
14341434
FilesAnalyzed: false
14351435
PackageHomePage: https://github.com/certifi/python-certifi
1436-
PackageChecksum: SHA256: 0f212c2744a9bb6de0c56639a6f68afe01ecd92d91f14ae897c4fe7bbeeef0de
1436+
PackageChecksum: SHA256: 97de8790030bbd5c2d96b7ec782fc2f7820ef8dba6db909ccf95449f2d062d4b
14371437
PackageLicenseDeclared: MPL-2.0
14381438
PackageLicenseConcluded: MPL-2.0
14391439
PackageCopyrightText: NOASSERTION
14401440
PackageSummary: <text>Python package for providing Mozilla's CA Bundle.</text>
1441-
ReleaseDate: 2025-10-05T04:12:14Z
1441+
ReleaseDate: 2025-11-12T02:54:49Z
14421442
ExternalRef: OTHER vcs https://github.com/certifi/python-certifi
1443-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/certifi@2025.10.5
1444-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:certifi:2025.10.5:*:*:*:*:*:*:*
1443+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/certifi@2025.11.12
1444+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:certifi:2025.11.12:*:*:*:*:*:*:*
14451445
#####
14461446

14471447
PackageName: rpmfile

0 commit comments

Comments
 (0)