Skip to content

Commit 9395ff8

Browse files
web-flowgithub-actions[bot]
authored andcommitted
chore: update SBOM for Python 3.11
1 parent 118245d commit 9395ff8

File tree

2 files changed

+84
-91
lines changed

2 files changed

+84
-91
lines changed

sbom/cve-bin-tool-py3.11.json

Lines changed: 42 additions & 48 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.7.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.7",
5-
"serialNumber": "urn:uuid:4a902649-ff6d-4934-be86-2eb8dd79be62",
5+
"serialNumber": "urn:uuid:f3a236a6-c2fc-48a2-b2c7-353553fca5e8",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-11-10T00:41:52Z",
8+
"timestamp": "2025-12-01T00:50:12Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -866,7 +866,7 @@
866866
"type": "library",
867867
"bom-ref": "12-beautifulsoup4",
868868
"name": "beautifulsoup4",
869-
"version": "4.14.2",
869+
"version": "4.14.3",
870870
"supplier": {
871871
"name": "Leonard Richardson",
872872
"contact": [
@@ -875,14 +875,8 @@
875875
}
876876
]
877877
},
878-
"cpe": "cpe:2.3:a:leonard_richardson:beautifulsoup4:4.14.2:*:*:*:*:*:*:*",
878+
"cpe": "cpe:2.3:a:leonard_richardson:beautifulsoup4:4.14.3:*:*:*:*:*:*:*",
879879
"description": "Screen-scraping library",
880-
"hashes": [
881-
{
882-
"alg": "SHA-256",
883-
"content": "5ef6fa3a8cbece8488d66985560f97ed091e22bbc4e9c2338508a9d5de6d4515"
884-
}
885-
],
886880
"licenses": [
887881
{
888882
"license": {
@@ -899,7 +893,7 @@
899893
"comment": "Home page for project"
900894
},
901895
{
902-
"url": "https://pypi.org/project/beautifulsoup4/4.14.2/#files",
896+
"url": "https://pypi.org/project/beautifulsoup4/4.14.3/#files",
903897
"type": "distribution",
904898
"comment": "Download location for component"
905899
},
@@ -908,11 +902,11 @@
908902
"type": "other"
909903
}
910904
],
911-
"purl": "pkg:pypi/beautifulsoup4@4.14.2",
905+
"purl": "pkg:pypi/beautifulsoup4@4.14.3",
912906
"properties": [
913907
{
914908
"name": "release_date",
915-
"value": "2025-09-29T10:05:43Z"
909+
"value": "2025-10-12T14:55:18Z"
916910
},
917911
{
918912
"name": "language",
@@ -3137,7 +3131,7 @@
31373131
"type": "library",
31383132
"bom-ref": "48-rpds-py",
31393133
"name": "rpds-py",
3140-
"version": "0.28.0",
3134+
"version": "0.30.0",
31413135
"supplier": {
31423136
"name": "Julian Berman",
31433137
"contact": [
@@ -3146,12 +3140,12 @@
31463140
}
31473141
]
31483142
},
3149-
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.28.0:*:*:*:*:*:*:*",
3143+
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.30.0:*:*:*:*:*:*:*",
31503144
"description": "Python bindings to Rust's persistent data structures (rpds)",
31513145
"hashes": [
31523146
{
31533147
"alg": "SHA-256",
3154-
"content": "7b6013db815417eeb56b2d9d7324e64fcd4fa289caeee6e7a78b2e11fc9b438a"
3148+
"content": "679ae98e00c0e8d68a7fda324e16b90fd5260945b45d3b824c892cec9eea3288"
31553149
}
31563150
],
31573151
"externalReferences": [
@@ -3161,7 +3155,7 @@
31613155
"comment": "Home page for project"
31623156
},
31633157
{
3164-
"url": "https://pypi.org/project/rpds-py/0.28.0/#files",
3158+
"url": "https://pypi.org/project/rpds-py/0.30.0/#files",
31653159
"type": "distribution",
31663160
"comment": "Download location for component"
31673161
},
@@ -3190,11 +3184,11 @@
31903184
"type": "other"
31913185
}
31923186
],
3193-
"purl": "pkg:pypi/rpds-py@0.28.0",
3187+
"purl": "pkg:pypi/rpds-py@0.30.0",
31943188
"properties": [
31953189
{
31963190
"name": "release_date",
3197-
"value": "2025-10-22T22:21:15Z"
3191+
"value": "2025-11-30T20:21:33Z"
31983192
},
31993193
{
32003194
"name": "language",
@@ -3210,7 +3204,7 @@
32103204
"type": "library",
32113205
"bom-ref": "49-lib4sbom",
32123206
"name": "lib4sbom",
3213-
"version": "0.9.0",
3207+
"version": "0.9.1",
32143208
"supplier": {
32153209
"name": "Anthony Harrison",
32163210
"contact": [
@@ -3219,12 +3213,12 @@
32193213
}
32203214
]
32213215
},
3222-
"cpe": "cpe:2.3:a:anthony_harrison:lib4sbom:0.9.0:*:*:*:*:*:*:*",
3216+
"cpe": "cpe:2.3:a:anthony_harrison:lib4sbom:0.9.1:*:*:*:*:*:*:*",
32233217
"description": "Software Bill of Material (SBOM) generator and consumer library",
32243218
"hashes": [
32253219
{
32263220
"alg": "SHA-256",
3227-
"content": "78b8584d10fc7fa28fc3c17c0afcb2967f3c2b96974e4bdbb60b3eb3744d01fd"
3221+
"content": "f2423d5e06a82f5462b05d0c5b9273d6e3674753ade9f5a0d4abdcf73f799117"
32283222
}
32293223
],
32303224
"licenses": [
@@ -3243,16 +3237,16 @@
32433237
"comment": "Home page for project"
32443238
},
32453239
{
3246-
"url": "https://pypi.org/project/lib4sbom/0.9.0/#files",
3240+
"url": "https://pypi.org/project/lib4sbom/0.9.1/#files",
32473241
"type": "distribution",
32483242
"comment": "Download location for component"
32493243
}
32503244
],
3251-
"purl": "pkg:pypi/lib4sbom@0.9.0",
3245+
"purl": "pkg:pypi/lib4sbom@0.9.1",
32523246
"properties": [
32533247
{
32543248
"name": "release_date",
3255-
"value": "2025-10-28T09:09:40Z"
3249+
"value": "2025-11-13T20:07:13Z"
32563250
},
32573251
{
32583252
"name": "language",
@@ -3684,16 +3678,16 @@
36843678
"type": "library",
36853679
"bom-ref": "57-packageurl-python",
36863680
"name": "packageurl-python",
3687-
"version": "0.17.5",
3681+
"version": "0.17.6",
36883682
"supplier": {
36893683
"name": "the purl authors"
36903684
},
3691-
"cpe": "cpe:2.3:a:the_purl_authors:packageurl-python:0.17.5:*:*:*:*:*:*:*",
3685+
"cpe": "cpe:2.3:a:the_purl_authors:packageurl-python:0.17.6:*:*:*:*:*:*:*",
36923686
"description": "A purl aka. Package URL parser and builder",
36933687
"hashes": [
36943688
{
36953689
"alg": "SHA-256",
3696-
"content": "f0e55452ab37b5c192c443de1458e3f3b4d8ac27f747df6e8c48adeab081d321"
3690+
"content": "31a85c2717bc41dd818f3c62908685ff9eebcb68588213745b14a6ee9e7df7c9"
36973691
}
36983692
],
36993693
"licenses": [
@@ -3712,16 +3706,16 @@
37123706
"comment": "Home page for project"
37133707
},
37143708
{
3715-
"url": "https://pypi.org/project/packageurl-python/0.17.5/#files",
3709+
"url": "https://pypi.org/project/packageurl-python/0.17.6/#files",
37163710
"type": "distribution",
37173711
"comment": "Download location for component"
37183712
}
37193713
],
3720-
"purl": "pkg:pypi/packageurl-python@0.17.5",
3714+
"purl": "pkg:pypi/packageurl-python@0.17.6",
37213715
"properties": [
37223716
{
37233717
"name": "release_date",
3724-
"value": "2025-08-06T14:08:19Z"
3718+
"value": "2025-11-24T15:20:16Z"
37253719
},
37263720
{
37273721
"name": "language",
@@ -4063,7 +4057,7 @@
40634057
"type": "library",
40644058
"bom-ref": "63-plotly",
40654059
"name": "plotly",
4066-
"version": "6.4.0",
4060+
"version": "6.5.0",
40674061
"supplier": {
40684062
"name": "Chris P",
40694063
"contact": [
@@ -4072,12 +4066,12 @@
40724066
}
40734067
]
40744068
},
4075-
"cpe": "cpe:2.3:a:chris_p:plotly:6.4.0:*:*:*:*:*:*:*",
4069+
"cpe": "cpe:2.3:a:chris_p:plotly:6.5.0:*:*:*:*:*:*:*",
40764070
"description": "An open-source interactive data visualization library for Python",
40774071
"hashes": [
40784072
{
40794073
"alg": "SHA-256",
4080-
"content": "a1062eafbdc657976c2eedd276c90e184ccd6c21282a5e9ee8f20efca9c9a4c5"
4074+
"content": "5ac851e100367735250206788a2b1325412aa4a4917a4fe3e6f0bc5aa6f3d90a"
40814075
}
40824076
],
40834077
"externalReferences": [
@@ -4087,7 +4081,7 @@
40874081
"comment": "Home page for project"
40884082
},
40894083
{
4090-
"url": "https://pypi.org/project/plotly/6.4.0/#files",
4084+
"url": "https://pypi.org/project/plotly/6.5.0/#files",
40914085
"type": "distribution",
40924086
"comment": "Download location for component"
40934087
},
@@ -4104,11 +4098,11 @@
41044098
"type": "log"
41054099
}
41064100
],
4107-
"purl": "pkg:pypi/plotly@6.4.0",
4101+
"purl": "pkg:pypi/plotly@6.5.0",
41084102
"properties": [
41094103
{
41104104
"name": "release_date",
4111-
"value": "2025-11-04T17:59:22Z"
4105+
"value": "2025-11-17T18:39:20Z"
41124106
},
41134107
{
41144108
"name": "language",
@@ -4128,7 +4122,7 @@
41284122
"type": "library",
41294123
"bom-ref": "64-narwhals",
41304124
"name": "narwhals",
4131-
"version": "2.10.2",
4125+
"version": "2.12.0",
41324126
"supplier": {
41334127
"name": "Marco Gorelli",
41344128
"contact": [
@@ -4137,7 +4131,7 @@
41374131
}
41384132
]
41394133
},
4140-
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:2.10.2:*:*:*:*:*:*:*",
4134+
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:2.12.0:*:*:*:*:*:*:*",
41414135
"description": "Extremely lightweight compatibility layer between dataframe libraries",
41424136
"licenses": [
41434137
{
@@ -4155,7 +4149,7 @@
41554149
"comment": "Home page for project"
41564150
},
41574151
{
4158-
"url": "https://pypi.org/project/narwhals/2.10.2/#files",
4152+
"url": "https://pypi.org/project/narwhals/2.12.0/#files",
41594153
"type": "distribution",
41604154
"comment": "Download location for component"
41614155
},
@@ -4172,11 +4166,11 @@
41724166
"type": "issue-tracker"
41734167
}
41744168
],
4175-
"purl": "pkg:pypi/narwhals@2.10.2",
4169+
"purl": "pkg:pypi/narwhals@2.12.0",
41764170
"properties": [
41774171
{
41784172
"name": "release_date",
4179-
"value": "2025-11-04T17:59:22Z"
4173+
"value": "2025-11-17T18:39:20Z"
41804174
},
41814175
{
41824176
"name": "language",
@@ -4465,7 +4459,7 @@
44654459
"type": "library",
44664460
"bom-ref": "69-certifi",
44674461
"name": "certifi",
4468-
"version": "2025.10.5",
4462+
"version": "2025.11.12",
44694463
"supplier": {
44704464
"name": "Kenneth Reitz",
44714465
"contact": [
@@ -4474,12 +4468,12 @@
44744468
}
44754469
]
44764470
},
4477-
"cpe": "cpe:2.3:a:kenneth_reitz:certifi:2025.10.5:*:*:*:*:*:*:*",
4471+
"cpe": "cpe:2.3:a:kenneth_reitz:certifi:2025.11.12:*:*:*:*:*:*:*",
44784472
"description": "Python package for providing Mozilla's CA Bundle.",
44794473
"hashes": [
44804474
{
44814475
"alg": "SHA-256",
4482-
"content": "0f212c2744a9bb6de0c56639a6f68afe01ecd92d91f14ae897c4fe7bbeeef0de"
4476+
"content": "97de8790030bbd5c2d96b7ec782fc2f7820ef8dba6db909ccf95449f2d062d4b"
44834477
}
44844478
],
44854479
"licenses": [
@@ -4498,7 +4492,7 @@
44984492
"comment": "Home page for project"
44994493
},
45004494
{
4501-
"url": "https://pypi.org/project/certifi/2025.10.5/#files",
4495+
"url": "https://pypi.org/project/certifi/2025.11.12/#files",
45024496
"type": "distribution",
45034497
"comment": "Download location for component"
45044498
},
@@ -4507,11 +4501,11 @@
45074501
"type": "vcs"
45084502
}
45094503
],
4510-
"purl": "pkg:pypi/certifi@2025.10.5",
4504+
"purl": "pkg:pypi/certifi@2025.11.12",
45114505
"properties": [
45124506
{
45134507
"name": "release_date",
4514-
"value": "2025-10-05T04:12:14Z"
4508+
"value": "2025-11-12T02:54:49Z"
45154509
},
45164510
{
45174511
"name": "language",

0 commit comments

Comments
 (0)