Skip to content

Commit 78ec745

Browse files
web-flowgithub-actions[bot]
authored andcommitted
chore: update SBOM for Python 3.10
1 parent 118245d commit 78ec745

File tree

2 files changed

+84
-91
lines changed

2 files changed

+84
-91
lines changed

sbom/cve-bin-tool-py3.10.json

Lines changed: 42 additions & 48 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.7.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.7",
5-
"serialNumber": "urn:uuid:3afa9eb1-4948-472a-bffc-204138519a06",
5+
"serialNumber": "urn:uuid:cd22d31c-b615-423e-852f-a2bc53d2c9b3",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-11-10T00:43:04Z",
8+
"timestamp": "2025-12-01T00:49:21Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -948,7 +948,7 @@
948948
"type": "library",
949949
"bom-ref": "13-beautifulsoup4",
950950
"name": "beautifulsoup4",
951-
"version": "4.14.2",
951+
"version": "4.14.3",
952952
"supplier": {
953953
"name": "Leonard Richardson",
954954
"contact": [
@@ -957,14 +957,8 @@
957957
}
958958
]
959959
},
960-
"cpe": "cpe:2.3:a:leonard_richardson:beautifulsoup4:4.14.2:*:*:*:*:*:*:*",
960+
"cpe": "cpe:2.3:a:leonard_richardson:beautifulsoup4:4.14.3:*:*:*:*:*:*:*",
961961
"description": "Screen-scraping library",
962-
"hashes": [
963-
{
964-
"alg": "SHA-256",
965-
"content": "5ef6fa3a8cbece8488d66985560f97ed091e22bbc4e9c2338508a9d5de6d4515"
966-
}
967-
],
968962
"licenses": [
969963
{
970964
"license": {
@@ -981,7 +975,7 @@
981975
"comment": "Home page for project"
982976
},
983977
{
984-
"url": "https://pypi.org/project/beautifulsoup4/4.14.2/#files",
978+
"url": "https://pypi.org/project/beautifulsoup4/4.14.3/#files",
985979
"type": "distribution",
986980
"comment": "Download location for component"
987981
},
@@ -990,11 +984,11 @@
990984
"type": "other"
991985
}
992986
],
993-
"purl": "pkg:pypi/beautifulsoup4@4.14.2",
987+
"purl": "pkg:pypi/beautifulsoup4@4.14.3",
994988
"properties": [
995989
{
996990
"name": "release_date",
997-
"value": "2025-09-29T10:05:43Z"
991+
"value": "2025-10-12T14:55:18Z"
998992
},
999993
{
1000994
"name": "language",
@@ -3219,7 +3213,7 @@
32193213
"type": "library",
32203214
"bom-ref": "49-rpds-py",
32213215
"name": "rpds-py",
3222-
"version": "0.28.0",
3216+
"version": "0.30.0",
32233217
"supplier": {
32243218
"name": "Julian Berman",
32253219
"contact": [
@@ -3228,12 +3222,12 @@
32283222
}
32293223
]
32303224
},
3231-
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.28.0:*:*:*:*:*:*:*",
3225+
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.30.0:*:*:*:*:*:*:*",
32323226
"description": "Python bindings to Rust's persistent data structures (rpds)",
32333227
"hashes": [
32343228
{
32353229
"alg": "SHA-256",
3236-
"content": "7b6013db815417eeb56b2d9d7324e64fcd4fa289caeee6e7a78b2e11fc9b438a"
3230+
"content": "679ae98e00c0e8d68a7fda324e16b90fd5260945b45d3b824c892cec9eea3288"
32373231
}
32383232
],
32393233
"externalReferences": [
@@ -3243,7 +3237,7 @@
32433237
"comment": "Home page for project"
32443238
},
32453239
{
3246-
"url": "https://pypi.org/project/rpds-py/0.28.0/#files",
3240+
"url": "https://pypi.org/project/rpds-py/0.30.0/#files",
32473241
"type": "distribution",
32483242
"comment": "Download location for component"
32493243
},
@@ -3272,11 +3266,11 @@
32723266
"type": "other"
32733267
}
32743268
],
3275-
"purl": "pkg:pypi/rpds-py@0.28.0",
3269+
"purl": "pkg:pypi/rpds-py@0.30.0",
32763270
"properties": [
32773271
{
32783272
"name": "release_date",
3279-
"value": "2025-10-22T22:21:15Z"
3273+
"value": "2025-11-30T20:21:33Z"
32803274
},
32813275
{
32823276
"name": "language",
@@ -3292,7 +3286,7 @@
32923286
"type": "library",
32933287
"bom-ref": "50-lib4sbom",
32943288
"name": "lib4sbom",
3295-
"version": "0.9.0",
3289+
"version": "0.9.1",
32963290
"supplier": {
32973291
"name": "Anthony Harrison",
32983292
"contact": [
@@ -3301,12 +3295,12 @@
33013295
}
33023296
]
33033297
},
3304-
"cpe": "cpe:2.3:a:anthony_harrison:lib4sbom:0.9.0:*:*:*:*:*:*:*",
3298+
"cpe": "cpe:2.3:a:anthony_harrison:lib4sbom:0.9.1:*:*:*:*:*:*:*",
33053299
"description": "Software Bill of Material (SBOM) generator and consumer library",
33063300
"hashes": [
33073301
{
33083302
"alg": "SHA-256",
3309-
"content": "78b8584d10fc7fa28fc3c17c0afcb2967f3c2b96974e4bdbb60b3eb3744d01fd"
3303+
"content": "f2423d5e06a82f5462b05d0c5b9273d6e3674753ade9f5a0d4abdcf73f799117"
33103304
}
33113305
],
33123306
"licenses": [
@@ -3325,16 +3319,16 @@
33253319
"comment": "Home page for project"
33263320
},
33273321
{
3328-
"url": "https://pypi.org/project/lib4sbom/0.9.0/#files",
3322+
"url": "https://pypi.org/project/lib4sbom/0.9.1/#files",
33293323
"type": "distribution",
33303324
"comment": "Download location for component"
33313325
}
33323326
],
3333-
"purl": "pkg:pypi/lib4sbom@0.9.0",
3327+
"purl": "pkg:pypi/lib4sbom@0.9.1",
33343328
"properties": [
33353329
{
33363330
"name": "release_date",
3337-
"value": "2025-10-28T09:09:40Z"
3331+
"value": "2025-11-13T20:07:13Z"
33383332
},
33393333
{
33403334
"name": "language",
@@ -3766,16 +3760,16 @@
37663760
"type": "library",
37673761
"bom-ref": "58-packageurl-python",
37683762
"name": "packageurl-python",
3769-
"version": "0.17.5",
3763+
"version": "0.17.6",
37703764
"supplier": {
37713765
"name": "the purl authors"
37723766
},
3773-
"cpe": "cpe:2.3:a:the_purl_authors:packageurl-python:0.17.5:*:*:*:*:*:*:*",
3767+
"cpe": "cpe:2.3:a:the_purl_authors:packageurl-python:0.17.6:*:*:*:*:*:*:*",
37743768
"description": "A purl aka. Package URL parser and builder",
37753769
"hashes": [
37763770
{
37773771
"alg": "SHA-256",
3778-
"content": "f0e55452ab37b5c192c443de1458e3f3b4d8ac27f747df6e8c48adeab081d321"
3772+
"content": "31a85c2717bc41dd818f3c62908685ff9eebcb68588213745b14a6ee9e7df7c9"
37793773
}
37803774
],
37813775
"licenses": [
@@ -3794,16 +3788,16 @@
37943788
"comment": "Home page for project"
37953789
},
37963790
{
3797-
"url": "https://pypi.org/project/packageurl-python/0.17.5/#files",
3791+
"url": "https://pypi.org/project/packageurl-python/0.17.6/#files",
37983792
"type": "distribution",
37993793
"comment": "Download location for component"
38003794
}
38013795
],
3802-
"purl": "pkg:pypi/packageurl-python@0.17.5",
3796+
"purl": "pkg:pypi/packageurl-python@0.17.6",
38033797
"properties": [
38043798
{
38053799
"name": "release_date",
3806-
"value": "2025-08-06T14:08:19Z"
3800+
"value": "2025-11-24T15:20:16Z"
38073801
},
38083802
{
38093803
"name": "language",
@@ -4145,7 +4139,7 @@
41454139
"type": "library",
41464140
"bom-ref": "64-plotly",
41474141
"name": "plotly",
4148-
"version": "6.4.0",
4142+
"version": "6.5.0",
41494143
"supplier": {
41504144
"name": "Chris P",
41514145
"contact": [
@@ -4154,12 +4148,12 @@
41544148
}
41554149
]
41564150
},
4157-
"cpe": "cpe:2.3:a:chris_p:plotly:6.4.0:*:*:*:*:*:*:*",
4151+
"cpe": "cpe:2.3:a:chris_p:plotly:6.5.0:*:*:*:*:*:*:*",
41584152
"description": "An open-source interactive data visualization library for Python",
41594153
"hashes": [
41604154
{
41614155
"alg": "SHA-256",
4162-
"content": "a1062eafbdc657976c2eedd276c90e184ccd6c21282a5e9ee8f20efca9c9a4c5"
4156+
"content": "5ac851e100367735250206788a2b1325412aa4a4917a4fe3e6f0bc5aa6f3d90a"
41634157
}
41644158
],
41654159
"externalReferences": [
@@ -4169,7 +4163,7 @@
41694163
"comment": "Home page for project"
41704164
},
41714165
{
4172-
"url": "https://pypi.org/project/plotly/6.4.0/#files",
4166+
"url": "https://pypi.org/project/plotly/6.5.0/#files",
41734167
"type": "distribution",
41744168
"comment": "Download location for component"
41754169
},
@@ -4186,11 +4180,11 @@
41864180
"type": "log"
41874181
}
41884182
],
4189-
"purl": "pkg:pypi/plotly@6.4.0",
4183+
"purl": "pkg:pypi/plotly@6.5.0",
41904184
"properties": [
41914185
{
41924186
"name": "release_date",
4193-
"value": "2025-11-04T17:59:22Z"
4187+
"value": "2025-11-17T18:39:20Z"
41944188
},
41954189
{
41964190
"name": "language",
@@ -4210,7 +4204,7 @@
42104204
"type": "library",
42114205
"bom-ref": "65-narwhals",
42124206
"name": "narwhals",
4213-
"version": "2.10.2",
4207+
"version": "2.12.0",
42144208
"supplier": {
42154209
"name": "Marco Gorelli",
42164210
"contact": [
@@ -4219,7 +4213,7 @@
42194213
}
42204214
]
42214215
},
4222-
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:2.10.2:*:*:*:*:*:*:*",
4216+
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:2.12.0:*:*:*:*:*:*:*",
42234217
"description": "Extremely lightweight compatibility layer between dataframe libraries",
42244218
"licenses": [
42254219
{
@@ -4237,7 +4231,7 @@
42374231
"comment": "Home page for project"
42384232
},
42394233
{
4240-
"url": "https://pypi.org/project/narwhals/2.10.2/#files",
4234+
"url": "https://pypi.org/project/narwhals/2.12.0/#files",
42414235
"type": "distribution",
42424236
"comment": "Download location for component"
42434237
},
@@ -4254,11 +4248,11 @@
42544248
"type": "issue-tracker"
42554249
}
42564250
],
4257-
"purl": "pkg:pypi/narwhals@2.10.2",
4251+
"purl": "pkg:pypi/narwhals@2.12.0",
42584252
"properties": [
42594253
{
42604254
"name": "release_date",
4261-
"value": "2025-11-04T17:59:22Z"
4255+
"value": "2025-11-17T18:39:20Z"
42624256
},
42634257
{
42644258
"name": "language",
@@ -4547,7 +4541,7 @@
45474541
"type": "library",
45484542
"bom-ref": "70-certifi",
45494543
"name": "certifi",
4550-
"version": "2025.10.5",
4544+
"version": "2025.11.12",
45514545
"supplier": {
45524546
"name": "Kenneth Reitz",
45534547
"contact": [
@@ -4556,12 +4550,12 @@
45564550
}
45574551
]
45584552
},
4559-
"cpe": "cpe:2.3:a:kenneth_reitz:certifi:2025.10.5:*:*:*:*:*:*:*",
4553+
"cpe": "cpe:2.3:a:kenneth_reitz:certifi:2025.11.12:*:*:*:*:*:*:*",
45604554
"description": "Python package for providing Mozilla's CA Bundle.",
45614555
"hashes": [
45624556
{
45634557
"alg": "SHA-256",
4564-
"content": "0f212c2744a9bb6de0c56639a6f68afe01ecd92d91f14ae897c4fe7bbeeef0de"
4558+
"content": "97de8790030bbd5c2d96b7ec782fc2f7820ef8dba6db909ccf95449f2d062d4b"
45654559
}
45664560
],
45674561
"licenses": [
@@ -4580,7 +4574,7 @@
45804574
"comment": "Home page for project"
45814575
},
45824576
{
4583-
"url": "https://pypi.org/project/certifi/2025.10.5/#files",
4577+
"url": "https://pypi.org/project/certifi/2025.11.12/#files",
45844578
"type": "distribution",
45854579
"comment": "Download location for component"
45864580
},
@@ -4589,11 +4583,11 @@
45894583
"type": "vcs"
45904584
}
45914585
],
4592-
"purl": "pkg:pypi/certifi@2025.10.5",
4586+
"purl": "pkg:pypi/certifi@2025.11.12",
45934587
"properties": [
45944588
{
45954589
"name": "release_date",
4596-
"value": "2025-10-05T04:12:14Z"
4590+
"value": "2025-11-12T02:54:49Z"
45974591
},
45984592
{
45994593
"name": "language",

0 commit comments

Comments
 (0)