Skip to content

Commit 2eaea15

Browse files
web-flowgithub-actions[bot]
authored andcommitted
chore: update SBOM for Python 3.9
1 parent d146836 commit 2eaea15

File tree

2 files changed

+105
-88
lines changed

2 files changed

+105
-88
lines changed

sbom/cve-bin-tool-py3.9.json

Lines changed: 60 additions & 45 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,11 @@
11
{
2-
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
2+
"$schema": "http://cyclonedx.org/schema/bom-1.7.schema.json",
33
"bomFormat": "CycloneDX",
4-
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:0fa43716-8c8f-48a5-9055-05a17bd14ee1",
4+
"specVersion": "1.7",
5+
"serialNumber": "urn:uuid:7bb811f5-d63f-44b6-878c-8a666158e40e",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-10-13T00:40:50Z",
8+
"timestamp": "2025-11-03T00:42:18Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -24,6 +24,9 @@
2424
"type": "application",
2525
"bom-ref": "CDXRef-DOCUMENT",
2626
"name": "Python-cve-bin-tool"
27+
},
28+
"distributionConstraints": {
29+
"tlp": "CLEAR"
2730
}
2831
},
2932
"components": [
@@ -79,12 +82,12 @@
7982
"type": "library",
8083
"bom-ref": "2-aiohttp",
8184
"name": "aiohttp",
82-
"version": "3.13.0",
85+
"version": "3.13.2",
8386
"description": "Async http client/server framework (asyncio)",
8487
"hashes": [
8588
{
8689
"alg": "SHA-256",
87-
"content": "ca69ec38adf5cadcc21d0b25e2144f6a25b7db7bea7e730bac25075bc305eff0"
90+
"content": "2372b15a5f62ed37789a6b383ff7344fc5b9f243999b0cd9b629d8bc5f5b4155"
8891
}
8992
],
9093
"licenses": [
@@ -100,7 +103,7 @@
100103
"comment": "Home page for project"
101104
},
102105
{
103-
"url": "https://pypi.org/project/aiohttp/3.13.0/#files",
106+
"url": "https://pypi.org/project/aiohttp/3.13.2/#files",
104107
"type": "distribution",
105108
"comment": "Download location for component"
106109
},
@@ -137,11 +140,11 @@
137140
"type": "vcs"
138141
}
139142
],
140-
"purl": "pkg:pypi/[email protected].0",
143+
"purl": "pkg:pypi/[email protected].2",
141144
"properties": [
142145
{
143146
"name": "release_date",
144-
"value": "2025-10-06T19:54:40Z"
147+
"value": "2025-10-28T20:55:27Z"
145148
},
146149
{
147150
"name": "language",
@@ -305,6 +308,12 @@
305308
"name": "frozenlist",
306309
"version": "1.8.0",
307310
"description": "A list-like structure which implements collections.abc.MutableSequence",
311+
"hashes": [
312+
{
313+
"alg": "SHA-256",
314+
"content": "b37f6d31b3dcea7deb5e9696e529a6aa4a898adc33db82da12e4c60a7c4d2011"
315+
}
316+
],
308317
"licenses": [
309318
{
310319
"license": {
@@ -366,7 +375,7 @@
366375
"properties": [
367376
{
368377
"name": "release_date",
369-
"value": "2025-07-03T22:54:42Z"
378+
"value": "2025-10-06T05:35:23Z"
370379
},
371380
{
372381
"name": "language",
@@ -894,6 +903,12 @@
894903
},
895904
"cpe": "cpe:2.3:a:kim_davies:idna:3.11:*:*:*:*:*:*:*",
896905
"description": "Internationalized Domain Names in Applications (IDNA)",
906+
"hashes": [
907+
{
908+
"alg": "SHA-256",
909+
"content": "771a87f49d9defaf64091e6e6fe9c18d4833f140bd19464795bc32d966ca37ea"
910+
}
911+
],
897912
"externalReferences": [
898913
{
899914
"url": "https://pypi.org/project/idna/3.11/#files",
@@ -917,7 +932,7 @@
917932
"properties": [
918933
{
919934
"name": "release_date",
920-
"value": "2025-10-06T14:08:42Z"
935+
"value": "2025-10-12T14:55:18Z"
921936
},
922937
{
923938
"name": "language",
@@ -1383,7 +1398,7 @@
13831398
"type": "library",
13841399
"bom-ref": "20-argcomplete",
13851400
"name": "argcomplete",
1386-
"version": "3.6.2",
1401+
"version": "3.6.3",
13871402
"supplier": {
13881403
"name": "Andrey Kislyuk",
13891404
"contact": [
@@ -1392,12 +1407,12 @@
13921407
}
13931408
]
13941409
},
1395-
"cpe": "cpe:2.3:a:andrey_kislyuk:argcomplete:3.6.2:*:*:*:*:*:*:*",
1410+
"cpe": "cpe:2.3:a:andrey_kislyuk:argcomplete:3.6.3:*:*:*:*:*:*:*",
13961411
"description": "Bash tab completion for argparse",
13971412
"hashes": [
13981413
{
13991414
"alg": "SHA-256",
1400-
"content": "65b3133a29ad53fb42c48cf5114752c7ab66c1c38544fdf6460f450c09b42591"
1415+
"content": "f5007b3a600ccac5d25bbce33089211dfd49eab4a7718da3f10e3082525a92ce"
14011416
}
14021417
],
14031418
"licenses": [
@@ -1416,7 +1431,7 @@
14161431
"comment": "Home page for project"
14171432
},
14181433
{
1419-
"url": "https://pypi.org/project/argcomplete/3.6.2/#files",
1434+
"url": "https://pypi.org/project/argcomplete/3.6.3/#files",
14201435
"type": "distribution",
14211436
"comment": "Download location for component"
14221437
},
@@ -1437,11 +1452,11 @@
14371452
"type": "log"
14381453
}
14391454
],
1440-
"purl": "pkg:pypi/[email protected].2",
1455+
"purl": "pkg:pypi/[email protected].3",
14411456
"properties": [
14421457
{
14431458
"name": "release_date",
1444-
"value": "2025-04-03T04:57:01Z"
1459+
"value": "2025-10-20T03:33:33Z"
14451460
},
14461461
{
14471462
"name": "language",
@@ -2680,7 +2695,7 @@
26802695
"type": "library",
26812696
"bom-ref": "41-google-auth-httplib2",
26822697
"name": "google-auth-httplib2",
2683-
"version": "0.2.0",
2698+
"version": "0.2.1",
26842699
"supplier": {
26852700
"name": "Google Cloud Platform",
26862701
"contact": [
@@ -2689,12 +2704,12 @@
26892704
}
26902705
]
26912706
},
2692-
"cpe": "cpe:2.3:a:google_cloud_platform:google-auth-httplib2:0.2.0:*:*:*:*:*:*:*",
2707+
"cpe": "cpe:2.3:a:google_cloud_platform:google-auth-httplib2:0.2.1:*:*:*:*:*:*:*",
26932708
"description": "Google Authentication Library: httplib2 transport",
26942709
"hashes": [
26952710
{
26962711
"alg": "SHA-256",
2697-
"content": "b65a0a2123300dd71281a7bf6e64d65a0759287df52729bdd1ae2e47dc311a3d"
2712+
"content": "1be94c611db91c01f9703e7f62b0a59bbd5587a95571c7b6fade510d648bc08b"
26982713
}
26992714
],
27002715
"licenses": [
@@ -2713,16 +2728,16 @@
27132728
"comment": "Home page for project"
27142729
},
27152730
{
2716-
"url": "https://pypi.org/project/google-auth-httplib2/0.2.0/#files",
2731+
"url": "https://pypi.org/project/google-auth-httplib2/0.2.1/#files",
27172732
"type": "distribution",
27182733
"comment": "Download location for component"
27192734
}
27202735
],
2721-
"purl": "pkg:pypi/[email protected].0",
2736+
"purl": "pkg:pypi/[email protected].1",
27222737
"properties": [
27232738
{
27242739
"name": "release_date",
2725-
"value": "2023-12-12T17:40:13Z"
2740+
"value": "2025-10-30T21:13:15Z"
27262741
},
27272742
{
27282743
"name": "language",
@@ -3386,7 +3401,7 @@
33863401
"type": "library",
33873402
"bom-ref": "52-lib4sbom",
33883403
"name": "lib4sbom",
3389-
"version": "0.8.8",
3404+
"version": "0.9.0",
33903405
"supplier": {
33913406
"name": "Anthony Harrison",
33923407
"contact": [
@@ -3395,12 +3410,12 @@
33953410
}
33963411
]
33973412
},
3398-
"cpe": "cpe:2.3:a:anthony_harrison:lib4sbom:0.8.8:*:*:*:*:*:*:*",
3413+
"cpe": "cpe:2.3:a:anthony_harrison:lib4sbom:0.9.0:*:*:*:*:*:*:*",
33993414
"description": "Software Bill of Material (SBOM) generator and consumer library",
34003415
"hashes": [
34013416
{
34023417
"alg": "SHA-256",
3403-
"content": "c8622549fddd568ac473e085be8d08d8eeb3338bd813612f50da189645cdaccf"
3418+
"content": "78b8584d10fc7fa28fc3c17c0afcb2967f3c2b96974e4bdbb60b3eb3744d01fd"
34043419
}
34053420
],
34063421
"licenses": [
@@ -3419,16 +3434,16 @@
34193434
"comment": "Home page for project"
34203435
},
34213436
{
3422-
"url": "https://pypi.org/project/lib4sbom/0.8.8/#files",
3437+
"url": "https://pypi.org/project/lib4sbom/0.9.0/#files",
34233438
"type": "distribution",
34243439
"comment": "Download location for component"
34253440
}
34263441
],
3427-
"purl": "pkg:pypi/lib4sbom@0.8.8",
3442+
"purl": "pkg:pypi/lib4sbom@0.9.0",
34283443
"properties": [
34293444
{
34303445
"name": "release_date",
3431-
"value": "2025-08-29T17:06:49Z"
3446+
"value": "2025-10-28T09:09:40Z"
34323447
},
34333448
{
34343449
"name": "language",
@@ -3646,7 +3661,7 @@
36463661
"type": "library",
36473662
"bom-ref": "56-xmlschema",
36483663
"name": "xmlschema",
3649-
"version": "4.1.0",
3664+
"version": "4.2.0",
36503665
"supplier": {
36513666
"name": "Davide Brunato",
36523667
"contact": [
@@ -3655,12 +3670,12 @@
36553670
}
36563671
]
36573672
},
3658-
"cpe": "cpe:2.3:a:davide_brunato:xmlschema:4.1.0:*:*:*:*:*:*:*",
3673+
"cpe": "cpe:2.3:a:davide_brunato:xmlschema:4.2.0:*:*:*:*:*:*:*",
36593674
"description": "An XML Schema validator and decoder",
36603675
"hashes": [
36613676
{
36623677
"alg": "SHA-256",
3663-
"content": "eabf610f398a58700bc4ac94380ad9ce558297a3f9ca8b7722ed3f7888eb4498"
3678+
"content": "82d24a50eea5e7f2d603312813848cd66fddf8fa2b6730839c6aa3d66312e3b6"
36643679
}
36653680
],
36663681
"externalReferences": [
@@ -3670,16 +3685,16 @@
36703685
"comment": "Home page for project"
36713686
},
36723687
{
3673-
"url": "https://pypi.org/project/xmlschema/4.1.0/#files",
3688+
"url": "https://pypi.org/project/xmlschema/4.2.0/#files",
36743689
"type": "distribution",
36753690
"comment": "Download location for component"
36763691
}
36773692
],
3678-
"purl": "pkg:pypi/xmlschema@4.1.0",
3693+
"purl": "pkg:pypi/xmlschema@4.2.0",
36793694
"properties": [
36803695
{
36813696
"name": "release_date",
3682-
"value": "2025-06-05T21:17:35Z"
3697+
"value": "2025-10-14T09:19:28Z"
36833698
},
36843699
{
36853700
"name": "language",
@@ -4304,7 +4319,7 @@
43044319
"type": "library",
43054320
"bom-ref": "67-narwhals",
43064321
"name": "narwhals",
4307-
"version": "2.7.0",
4322+
"version": "2.10.1",
43084323
"supplier": {
43094324
"name": "Marco Gorelli",
43104325
"contact": [
@@ -4313,7 +4328,7 @@
43134328
}
43144329
]
43154330
},
4316-
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:2.7.0:*:*:*:*:*:*:*",
4331+
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:2.10.1:*:*:*:*:*:*:*",
43174332
"description": "Extremely lightweight compatibility layer between dataframe libraries",
43184333
"licenses": [
43194334
{
@@ -4331,7 +4346,7 @@
43314346
"comment": "Home page for project"
43324347
},
43334348
{
4334-
"url": "https://pypi.org/project/narwhals/2.7.0/#files",
4349+
"url": "https://pypi.org/project/narwhals/2.10.1/#files",
43354350
"type": "distribution",
43364351
"comment": "Download location for component"
43374352
},
@@ -4348,7 +4363,7 @@
43484363
"type": "issue-tracker"
43494364
}
43504365
],
4351-
"purl": "pkg:pypi/narwhals@2.7.0",
4366+
"purl": "pkg:pypi/narwhals@2.10.1",
43524367
"properties": [
43534368
{
43544369
"name": "release_date",
@@ -4512,7 +4527,7 @@
45124527
"type": "library",
45134528
"bom-ref": "70-charset-normalizer",
45144529
"name": "charset-normalizer",
4515-
"version": "3.4.3",
4530+
"version": "3.4.4",
45164531
"supplier": {
45174532
"name": "Ahmed R .",
45184533
"contact": [
@@ -4521,12 +4536,12 @@
45214536
}
45224537
]
45234538
},
4524-
"cpe": "cpe:2.3:a:ahmed_r.:charset-normalizer:3.4.3:*:*:*:*:*:*:*",
4539+
"cpe": "cpe:2.3:a:ahmed_r.:charset-normalizer:3.4.4:*:*:*:*:*:*:*",
45254540
"description": "The Real First Universal Charset Detector. Open, modern and actively maintained alternative to Chardet.",
45264541
"hashes": [
45274542
{
45284543
"alg": "SHA-256",
4529-
"content": "fb7f67a1bfa6e40b438170ebdc8158b78dc465a5a67b6dde178a46987b244a72"
4544+
"content": "e824f1492727fa856dd6eda4f7cee25f8518a12f3c4a56a74e8095695089cf6d"
45304545
}
45314546
],
45324547
"licenses": [
@@ -4540,7 +4555,7 @@
45404555
],
45414556
"externalReferences": [
45424557
{
4543-
"url": "https://pypi.org/project/charset-normalizer/3.4.3/#files",
4558+
"url": "https://pypi.org/project/charset-normalizer/3.4.4/#files",
45444559
"type": "distribution",
45454560
"comment": "Download location for component"
45464561
},
@@ -4561,11 +4576,11 @@
45614576
"type": "issue-tracker"
45624577
}
45634578
],
4564-
"purl": "pkg:pypi/[email protected].3",
4579+
"purl": "pkg:pypi/[email protected].4",
45654580
"properties": [
45664581
{
45674582
"name": "release_date",
4568-
"value": "2025-08-09T07:55:36Z"
4583+
"value": "2025-10-14T04:40:11Z"
45694584
},
45704585
{
45714586
"name": "language",

0 commit comments

Comments
 (0)