Skip to content

Commit fa64e34

Browse files
web-flowgithub-actions[bot]
authored andcommitted
chore: update SBOM for Python 3.9
1 parent 118245d commit fa64e34

File tree

2 files changed

+50
-50
lines changed

2 files changed

+50
-50
lines changed

sbom/cve-bin-tool-py3.9.json

Lines changed: 25 additions & 25 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.7.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.7",
5-
"serialNumber": "urn:uuid:d190d704-123d-4c29-92f1-59ac8bf44db5",
5+
"serialNumber": "urn:uuid:7bf8bca8-2d53-45ec-a71e-22609c7476b9",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-11-10T00:41:52Z",
8+
"timestamp": "2025-11-24T00:43:25Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -3401,7 +3401,7 @@
34013401
"type": "library",
34023402
"bom-ref": "52-lib4sbom",
34033403
"name": "lib4sbom",
3404-
"version": "0.9.0",
3404+
"version": "0.9.1",
34053405
"supplier": {
34063406
"name": "Anthony Harrison",
34073407
"contact": [
@@ -3410,12 +3410,12 @@
34103410
}
34113411
]
34123412
},
3413-
"cpe": "cpe:2.3:a:anthony_harrison:lib4sbom:0.9.0:*:*:*:*:*:*:*",
3413+
"cpe": "cpe:2.3:a:anthony_harrison:lib4sbom:0.9.1:*:*:*:*:*:*:*",
34143414
"description": "Software Bill of Material (SBOM) generator and consumer library",
34153415
"hashes": [
34163416
{
34173417
"alg": "SHA-256",
3418-
"content": "78b8584d10fc7fa28fc3c17c0afcb2967f3c2b96974e4bdbb60b3eb3744d01fd"
3418+
"content": "f2423d5e06a82f5462b05d0c5b9273d6e3674753ade9f5a0d4abdcf73f799117"
34193419
}
34203420
],
34213421
"licenses": [
@@ -3434,16 +3434,16 @@
34343434
"comment": "Home page for project"
34353435
},
34363436
{
3437-
"url": "https://pypi.org/project/lib4sbom/0.9.0/#files",
3437+
"url": "https://pypi.org/project/lib4sbom/0.9.1/#files",
34383438
"type": "distribution",
34393439
"comment": "Download location for component"
34403440
}
34413441
],
3442-
"purl": "pkg:pypi/lib4sbom@0.9.0",
3442+
"purl": "pkg:pypi/lib4sbom@0.9.1",
34433443
"properties": [
34443444
{
34453445
"name": "release_date",
3446-
"value": "2025-10-28T09:09:40Z"
3446+
"value": "2025-11-13T20:07:13Z"
34473447
},
34483448
{
34493449
"name": "language",
@@ -4254,7 +4254,7 @@
42544254
"type": "library",
42554255
"bom-ref": "66-plotly",
42564256
"name": "plotly",
4257-
"version": "6.4.0",
4257+
"version": "6.5.0",
42584258
"supplier": {
42594259
"name": "Chris P",
42604260
"contact": [
@@ -4263,12 +4263,12 @@
42634263
}
42644264
]
42654265
},
4266-
"cpe": "cpe:2.3:a:chris_p:plotly:6.4.0:*:*:*:*:*:*:*",
4266+
"cpe": "cpe:2.3:a:chris_p:plotly:6.5.0:*:*:*:*:*:*:*",
42674267
"description": "An open-source interactive data visualization library for Python",
42684268
"hashes": [
42694269
{
42704270
"alg": "SHA-256",
4271-
"content": "a1062eafbdc657976c2eedd276c90e184ccd6c21282a5e9ee8f20efca9c9a4c5"
4271+
"content": "5ac851e100367735250206788a2b1325412aa4a4917a4fe3e6f0bc5aa6f3d90a"
42724272
}
42734273
],
42744274
"externalReferences": [
@@ -4278,7 +4278,7 @@
42784278
"comment": "Home page for project"
42794279
},
42804280
{
4281-
"url": "https://pypi.org/project/plotly/6.4.0/#files",
4281+
"url": "https://pypi.org/project/plotly/6.5.0/#files",
42824282
"type": "distribution",
42834283
"comment": "Download location for component"
42844284
},
@@ -4295,11 +4295,11 @@
42954295
"type": "log"
42964296
}
42974297
],
4298-
"purl": "pkg:pypi/plotly@6.4.0",
4298+
"purl": "pkg:pypi/plotly@6.5.0",
42994299
"properties": [
43004300
{
43014301
"name": "release_date",
4302-
"value": "2025-11-04T17:59:22Z"
4302+
"value": "2025-11-17T18:39:20Z"
43034303
},
43044304
{
43054305
"name": "language",
@@ -4319,7 +4319,7 @@
43194319
"type": "library",
43204320
"bom-ref": "67-narwhals",
43214321
"name": "narwhals",
4322-
"version": "2.10.2",
4322+
"version": "2.12.0",
43234323
"supplier": {
43244324
"name": "Marco Gorelli",
43254325
"contact": [
@@ -4328,7 +4328,7 @@
43284328
}
43294329
]
43304330
},
4331-
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:2.10.2:*:*:*:*:*:*:*",
4331+
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:2.12.0:*:*:*:*:*:*:*",
43324332
"description": "Extremely lightweight compatibility layer between dataframe libraries",
43334333
"licenses": [
43344334
{
@@ -4346,7 +4346,7 @@
43464346
"comment": "Home page for project"
43474347
},
43484348
{
4349-
"url": "https://pypi.org/project/narwhals/2.10.2/#files",
4349+
"url": "https://pypi.org/project/narwhals/2.12.0/#files",
43504350
"type": "distribution",
43514351
"comment": "Download location for component"
43524352
},
@@ -4363,11 +4363,11 @@
43634363
"type": "issue-tracker"
43644364
}
43654365
],
4366-
"purl": "pkg:pypi/narwhals@2.10.2",
4366+
"purl": "pkg:pypi/narwhals@2.12.0",
43674367
"properties": [
43684368
{
43694369
"name": "release_date",
4370-
"value": "2025-11-04T17:59:22Z"
4370+
"value": "2025-11-17T18:39:20Z"
43714371
},
43724372
{
43734373
"name": "language",
@@ -4656,7 +4656,7 @@
46564656
"type": "library",
46574657
"bom-ref": "72-certifi",
46584658
"name": "certifi",
4659-
"version": "2025.10.5",
4659+
"version": "2025.11.12",
46604660
"supplier": {
46614661
"name": "Kenneth Reitz",
46624662
"contact": [
@@ -4665,12 +4665,12 @@
46654665
}
46664666
]
46674667
},
4668-
"cpe": "cpe:2.3:a:kenneth_reitz:certifi:2025.10.5:*:*:*:*:*:*:*",
4668+
"cpe": "cpe:2.3:a:kenneth_reitz:certifi:2025.11.12:*:*:*:*:*:*:*",
46694669
"description": "Python package for providing Mozilla's CA Bundle.",
46704670
"hashes": [
46714671
{
46724672
"alg": "SHA-256",
4673-
"content": "0f212c2744a9bb6de0c56639a6f68afe01ecd92d91f14ae897c4fe7bbeeef0de"
4673+
"content": "97de8790030bbd5c2d96b7ec782fc2f7820ef8dba6db909ccf95449f2d062d4b"
46744674
}
46754675
],
46764676
"licenses": [
@@ -4689,7 +4689,7 @@
46894689
"comment": "Home page for project"
46904690
},
46914691
{
4692-
"url": "https://pypi.org/project/certifi/2025.10.5/#files",
4692+
"url": "https://pypi.org/project/certifi/2025.11.12/#files",
46934693
"type": "distribution",
46944694
"comment": "Download location for component"
46954695
},
@@ -4698,11 +4698,11 @@
46984698
"type": "vcs"
46994699
}
47004700
],
4701-
"purl": "pkg:pypi/certifi@2025.10.5",
4701+
"purl": "pkg:pypi/certifi@2025.11.12",
47024702
"properties": [
47034703
{
47044704
"name": "release_date",
4705-
"value": "2025-10-05T04:12:14Z"
4705+
"value": "2025-11-12T02:54:49Z"
47064706
},
47074707
{
47084708
"name": "language",

sbom/cve-bin-tool-py3.9.spdx

Lines changed: 25 additions & 25 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-57009a0b-d4a9-4bf8-9a82-3341168a260c
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-b5de8e1b-b5b1-4d95-9165-d5ec3d0cfd10
66
LicenseListVersion: 3.26
77
Creator: Tool: sbom4python-0.12.4
8-
Created: 2025-11-10T00:41:40Z
8+
Created: 2025-11-24T00:43:15Z
99
CreatorComment: <text>SBOM Type: Build - This document has been automatically generated.</text>
1010
#####
1111

@@ -1071,20 +1071,20 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.27.1:*:*:*:*:*
10711071

10721072
PackageName: lib4sbom
10731073
SPDXID: SPDXRef-52-lib4sbom
1074-
PackageVersion: 0.9.0
1074+
PackageVersion: 0.9.1
10751075
PrimaryPackagePurpose: LIBRARY
10761076
PackageSupplier: Person: Anthony Harrison (anthony.p.harrison@gmail.com)
1077-
PackageDownloadLocation: https://pypi.org/project/lib4sbom/0.9.0/#files
1077+
PackageDownloadLocation: https://pypi.org/project/lib4sbom/0.9.1/#files
10781078
FilesAnalyzed: false
10791079
PackageHomePage: https://github.com/anthonyharrison/lib4sbom
1080-
PackageChecksum: SHA256: 78b8584d10fc7fa28fc3c17c0afcb2967f3c2b96974e4bdbb60b3eb3744d01fd
1080+
PackageChecksum: SHA256: f2423d5e06a82f5462b05d0c5b9273d6e3674753ade9f5a0d4abdcf73f799117
10811081
PackageLicenseDeclared: Apache-2.0
10821082
PackageLicenseConcluded: Apache-2.0
10831083
PackageCopyrightText: NOASSERTION
10841084
PackageSummary: <text>Software Bill of Material (SBOM) generator and consumer library</text>
1085-
ReleaseDate: 2025-10-28T09:09:40Z
1086-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/lib4sbom@0.9.0
1087-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:anthony_harrison:lib4sbom:0.9.0:*:*:*:*:*:*:*
1085+
ReleaseDate: 2025-11-13T20:07:13Z
1086+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/lib4sbom@0.9.1
1087+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:anthony_harrison:lib4sbom:0.9.1:*:*:*:*:*:*:*
10881088
#####
10891089

10901090
PackageName: pyyaml
@@ -1340,13 +1340,13 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:donald_stufft:packaging:25.0:*:*:*:*:*
13401340

13411341
PackageName: plotly
13421342
SPDXID: SPDXRef-66-plotly
1343-
PackageVersion: 6.4.0
1343+
PackageVersion: 6.5.0
13441344
PrimaryPackagePurpose: LIBRARY
13451345
PackageSupplier: Person: Chris P (chris@plot.ly)
1346-
PackageDownloadLocation: https://pypi.org/project/plotly/6.4.0/#files
1346+
PackageDownloadLocation: https://pypi.org/project/plotly/6.5.0/#files
13471347
FilesAnalyzed: false
13481348
PackageHomePage: https://plotly.com/python/
1349-
PackageChecksum: SHA256: a1062eafbdc657976c2eedd276c90e184ccd6c21282a5e9ee8f20efca9c9a4c5
1349+
PackageChecksum: SHA256: 5ac851e100367735250206788a2b1325412aa4a4917a4fe3e6f0bc5aa6f3d90a
13501350
PackageLicenseDeclared: NOASSERTION
13511351
PackageLicenseConcluded: NOASSERTION
13521352
PackageLicenseComments: <text>plotly declares MIT License
@@ -1373,33 +1373,33 @@ THE SOFTWARE.
13731373
which is not currently a valid SPDX License identifier or expression.</text>
13741374
PackageCopyrightText: NOASSERTION
13751375
PackageSummary: <text>An open-source interactive data visualization library for Python</text>
1376-
ReleaseDate: 2025-11-04T17:59:22Z
1376+
ReleaseDate: 2025-11-17T18:39:20Z
13771377
ExternalRef: OTHER documentation https://plotly.com/python/
13781378
ExternalRef: OTHER vcs https://github.com/plotly/plotly.py
13791379
ExternalRef: OTHER log https://github.com/plotly/plotly.py/blob/main/CHANGELOG.md
1380-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/plotly@6.4.0
1381-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:6.4.0:*:*:*:*:*:*:*
1380+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/plotly@6.5.0
1381+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:6.5.0:*:*:*:*:*:*:*
13821382
#####
13831383

13841384
PackageName: narwhals
13851385
SPDXID: SPDXRef-67-narwhals
1386-
PackageVersion: 2.10.2
1386+
PackageVersion: 2.12.0
13871387
PrimaryPackagePurpose: LIBRARY
13881388
PackageSupplier: Person: Marco Gorelli (hello_narwhals@proton.me)
1389-
PackageDownloadLocation: https://pypi.org/project/narwhals/2.10.2/#files
1389+
PackageDownloadLocation: https://pypi.org/project/narwhals/2.12.0/#files
13901390
FilesAnalyzed: false
13911391
PackageHomePage: https://github.com/narwhals-dev/narwhals
13921392
PackageLicenseDeclared: NOASSERTION
13931393
PackageLicenseConcluded: MIT
13941394
PackageLicenseComments: <text>narwhals declares MIT License which is not currently a valid SPDX License identifier or expression.</text>
13951395
PackageCopyrightText: NOASSERTION
13961396
PackageSummary: <text>Extremely lightweight compatibility layer between dataframe libraries</text>
1397-
ReleaseDate: 2025-11-04T17:59:22Z
1397+
ReleaseDate: 2025-11-17T18:39:20Z
13981398
ExternalRef: OTHER documentation https://narwhals-dev.github.io/narwhals/
13991399
ExternalRef: OTHER vcs https://github.com/narwhals-dev/narwhals
14001400
ExternalRef: OTHER issue-tracker https://github.com/narwhals-dev/narwhals/issues
1401-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@2.10.2
1402-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:2.10.2:*:*:*:*:*:*:*
1401+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@2.12.0
1402+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:2.12.0:*:*:*:*:*:*:*
14031403
#####
14041404

14051405
PackageName: python-gnupg
@@ -1488,21 +1488,21 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_petrov:urllib3:2.5.0:*:*:*:*:*:
14881488

14891489
PackageName: certifi
14901490
SPDXID: SPDXRef-72-certifi
1491-
PackageVersion: 2025.10.5
1491+
PackageVersion: 2025.11.12
14921492
PrimaryPackagePurpose: LIBRARY
14931493
PackageSupplier: Person: Kenneth Reitz (me@kennethreitz.com)
1494-
PackageDownloadLocation: https://pypi.org/project/certifi/2025.10.5/#files
1494+
PackageDownloadLocation: https://pypi.org/project/certifi/2025.11.12/#files
14951495
FilesAnalyzed: false
14961496
PackageHomePage: https://github.com/certifi/python-certifi
1497-
PackageChecksum: SHA256: 0f212c2744a9bb6de0c56639a6f68afe01ecd92d91f14ae897c4fe7bbeeef0de
1497+
PackageChecksum: SHA256: 97de8790030bbd5c2d96b7ec782fc2f7820ef8dba6db909ccf95449f2d062d4b
14981498
PackageLicenseDeclared: MPL-2.0
14991499
PackageLicenseConcluded: MPL-2.0
15001500
PackageCopyrightText: NOASSERTION
15011501
PackageSummary: <text>Python package for providing Mozilla's CA Bundle.</text>
1502-
ReleaseDate: 2025-10-05T04:12:14Z
1502+
ReleaseDate: 2025-11-12T02:54:49Z
15031503
ExternalRef: OTHER vcs https://github.com/certifi/python-certifi
1504-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/certifi@2025.10.5
1505-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:certifi:2025.10.5:*:*:*:*:*:*:*
1504+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/certifi@2025.11.12
1505+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:certifi:2025.11.12:*:*:*:*:*:*:*
15061506
#####
15071507

15081508
PackageName: rpmfile

0 commit comments

Comments
 (0)