Skip to content

Commit e6d99f7

Browse files
web-flowgithub-actions[bot]
authored andcommitted
chore: update SBOM for Python 3.9
1 parent d146836 commit e6d99f7

File tree

2 files changed

+64
-50
lines changed

2 files changed

+64
-50
lines changed

sbom/cve-bin-tool-py3.9.json

Lines changed: 37 additions & 25 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:0fa43716-8c8f-48a5-9055-05a17bd14ee1",
5+
"serialNumber": "urn:uuid:fa996397-5c8b-43a4-acc5-438711dddcb5",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-10-13T00:40:50Z",
8+
"timestamp": "2025-10-20T00:42:12Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -79,12 +79,12 @@
7979
"type": "library",
8080
"bom-ref": "2-aiohttp",
8181
"name": "aiohttp",
82-
"version": "3.13.0",
82+
"version": "3.13.1",
8383
"description": "Async http client/server framework (asyncio)",
8484
"hashes": [
8585
{
8686
"alg": "SHA-256",
87-
"content": "ca69ec38adf5cadcc21d0b25e2144f6a25b7db7bea7e730bac25075bc305eff0"
87+
"content": "2349a6b642020bf20116a8a5c83bae8ba071acf1461c7cbe45fc7fafd552e7e2"
8888
}
8989
],
9090
"licenses": [
@@ -100,7 +100,7 @@
100100
"comment": "Home page for project"
101101
},
102102
{
103-
"url": "https://pypi.org/project/aiohttp/3.13.0/#files",
103+
"url": "https://pypi.org/project/aiohttp/3.13.1/#files",
104104
"type": "distribution",
105105
"comment": "Download location for component"
106106
},
@@ -137,11 +137,11 @@
137137
"type": "vcs"
138138
}
139139
],
140-
"purl": "pkg:pypi/[email protected].0",
140+
"purl": "pkg:pypi/[email protected].1",
141141
"properties": [
142142
{
143143
"name": "release_date",
144-
"value": "2025-10-06T19:54:40Z"
144+
"value": "2025-10-17T13:58:56Z"
145145
},
146146
{
147147
"name": "language",
@@ -894,6 +894,12 @@
894894
},
895895
"cpe": "cpe:2.3:a:kim_davies:idna:3.11:*:*:*:*:*:*:*",
896896
"description": "Internationalized Domain Names in Applications (IDNA)",
897+
"hashes": [
898+
{
899+
"alg": "SHA-256",
900+
"content": "771a87f49d9defaf64091e6e6fe9c18d4833f140bd19464795bc32d966ca37ea"
901+
}
902+
],
897903
"externalReferences": [
898904
{
899905
"url": "https://pypi.org/project/idna/3.11/#files",
@@ -917,7 +923,7 @@
917923
"properties": [
918924
{
919925
"name": "release_date",
920-
"value": "2025-10-06T14:08:42Z"
926+
"value": "2025-10-12T14:55:18Z"
921927
},
922928
{
923929
"name": "language",
@@ -3646,7 +3652,7 @@
36463652
"type": "library",
36473653
"bom-ref": "56-xmlschema",
36483654
"name": "xmlschema",
3649-
"version": "4.1.0",
3655+
"version": "4.2.0",
36503656
"supplier": {
36513657
"name": "Davide Brunato",
36523658
"contact": [
@@ -3655,12 +3661,12 @@
36553661
}
36563662
]
36573663
},
3658-
"cpe": "cpe:2.3:a:davide_brunato:xmlschema:4.1.0:*:*:*:*:*:*:*",
3664+
"cpe": "cpe:2.3:a:davide_brunato:xmlschema:4.2.0:*:*:*:*:*:*:*",
36593665
"description": "An XML Schema validator and decoder",
36603666
"hashes": [
36613667
{
36623668
"alg": "SHA-256",
3663-
"content": "eabf610f398a58700bc4ac94380ad9ce558297a3f9ca8b7722ed3f7888eb4498"
3669+
"content": "82d24a50eea5e7f2d603312813848cd66fddf8fa2b6730839c6aa3d66312e3b6"
36643670
}
36653671
],
36663672
"externalReferences": [
@@ -3670,16 +3676,16 @@
36703676
"comment": "Home page for project"
36713677
},
36723678
{
3673-
"url": "https://pypi.org/project/xmlschema/4.1.0/#files",
3679+
"url": "https://pypi.org/project/xmlschema/4.2.0/#files",
36743680
"type": "distribution",
36753681
"comment": "Download location for component"
36763682
}
36773683
],
3678-
"purl": "pkg:pypi/xmlschema@4.1.0",
3684+
"purl": "pkg:pypi/xmlschema@4.2.0",
36793685
"properties": [
36803686
{
36813687
"name": "release_date",
3682-
"value": "2025-06-05T21:17:35Z"
3688+
"value": "2025-10-14T09:19:28Z"
36833689
},
36843690
{
36853691
"name": "language",
@@ -4304,7 +4310,7 @@
43044310
"type": "library",
43054311
"bom-ref": "67-narwhals",
43064312
"name": "narwhals",
4307-
"version": "2.7.0",
4313+
"version": "2.8.0",
43084314
"supplier": {
43094315
"name": "Marco Gorelli",
43104316
"contact": [
@@ -4313,8 +4319,14 @@
43134319
}
43144320
]
43154321
},
4316-
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:2.7.0:*:*:*:*:*:*:*",
4322+
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:2.8.0:*:*:*:*:*:*:*",
43174323
"description": "Extremely lightweight compatibility layer between dataframe libraries",
4324+
"hashes": [
4325+
{
4326+
"alg": "SHA-256",
4327+
"content": "6304856676ba4a79fd34148bda63aed8060dd6edb1227edf3659ce5e091de73c"
4328+
}
4329+
],
43184330
"licenses": [
43194331
{
43204332
"license": {
@@ -4331,7 +4343,7 @@
43314343
"comment": "Home page for project"
43324344
},
43334345
{
4334-
"url": "https://pypi.org/project/narwhals/2.7.0/#files",
4346+
"url": "https://pypi.org/project/narwhals/2.8.0/#files",
43354347
"type": "distribution",
43364348
"comment": "Download location for component"
43374349
},
@@ -4348,11 +4360,11 @@
43484360
"type": "issue-tracker"
43494361
}
43504362
],
4351-
"purl": "pkg:pypi/narwhals@2.7.0",
4363+
"purl": "pkg:pypi/narwhals@2.8.0",
43524364
"properties": [
43534365
{
43544366
"name": "release_date",
4355-
"value": "2025-10-02T16:10:22Z"
4367+
"value": "2025-10-13T08:44:25Z"
43564368
},
43574369
{
43584370
"name": "language",
@@ -4512,7 +4524,7 @@
45124524
"type": "library",
45134525
"bom-ref": "70-charset-normalizer",
45144526
"name": "charset-normalizer",
4515-
"version": "3.4.3",
4527+
"version": "3.4.4",
45164528
"supplier": {
45174529
"name": "Ahmed R .",
45184530
"contact": [
@@ -4521,12 +4533,12 @@
45214533
}
45224534
]
45234535
},
4524-
"cpe": "cpe:2.3:a:ahmed_r.:charset-normalizer:3.4.3:*:*:*:*:*:*:*",
4536+
"cpe": "cpe:2.3:a:ahmed_r.:charset-normalizer:3.4.4:*:*:*:*:*:*:*",
45254537
"description": "The Real First Universal Charset Detector. Open, modern and actively maintained alternative to Chardet.",
45264538
"hashes": [
45274539
{
45284540
"alg": "SHA-256",
4529-
"content": "fb7f67a1bfa6e40b438170ebdc8158b78dc465a5a67b6dde178a46987b244a72"
4541+
"content": "e824f1492727fa856dd6eda4f7cee25f8518a12f3c4a56a74e8095695089cf6d"
45304542
}
45314543
],
45324544
"licenses": [
@@ -4540,7 +4552,7 @@
45404552
],
45414553
"externalReferences": [
45424554
{
4543-
"url": "https://pypi.org/project/charset-normalizer/3.4.3/#files",
4555+
"url": "https://pypi.org/project/charset-normalizer/3.4.4/#files",
45444556
"type": "distribution",
45454557
"comment": "Download location for component"
45464558
},
@@ -4561,11 +4573,11 @@
45614573
"type": "issue-tracker"
45624574
}
45634575
],
4564-
"purl": "pkg:pypi/[email protected].3",
4576+
"purl": "pkg:pypi/[email protected].4",
45654577
"properties": [
45664578
{
45674579
"name": "release_date",
4568-
"value": "2025-08-09T07:55:36Z"
4580+
"value": "2025-10-14T04:40:11Z"
45694581
},
45704582
{
45714583
"name": "language",

sbom/cve-bin-tool-py3.9.spdx

Lines changed: 27 additions & 25 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-389e7e0c-72a5-4fd1-81e1-a7100edeee49
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-6f3240c3-2796-4fa6-b32e-a2ca8c00d5be
66
LicenseListVersion: 3.26
77
Creator: Tool: sbom4python-0.12.4
8-
Created: 2025-10-13T00:40:32Z
8+
Created: 2025-10-20T00:41:59Z
99
CreatorComment: <text>SBOM Type: Build - This document has been automatically generated.</text>
1010
#####
1111

@@ -27,18 +27,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.4.1:*:*:*:*:*
2727

2828
PackageName: aiohttp
2929
SPDXID: SPDXRef-2-aiohttp
30-
PackageVersion: 3.13.0
30+
PackageVersion: 3.13.1
3131
PrimaryPackagePurpose: LIBRARY
3232
PackageSupplier: NOASSERTION
33-
PackageDownloadLocation: https://pypi.org/project/aiohttp/3.13.0/#files
33+
PackageDownloadLocation: https://pypi.org/project/aiohttp/3.13.1/#files
3434
FilesAnalyzed: false
3535
PackageHomePage: https://github.com/aio-libs/aiohttp
36-
PackageChecksum: SHA256: ca69ec38adf5cadcc21d0b25e2144f6a25b7db7bea7e730bac25075bc305eff0
36+
PackageChecksum: SHA256: 2349a6b642020bf20116a8a5c83bae8ba071acf1461c7cbe45fc7fafd552e7e2
3737
PackageLicenseDeclared: Apache-2.0 AND MIT
3838
PackageLicenseConcluded: Apache-2.0 AND MIT
3939
PackageCopyrightText: NOASSERTION
4040
PackageSummary: <text>Async http client/server framework (asyncio)</text>
41-
ReleaseDate: 2025-10-06T19:54:40Z
41+
ReleaseDate: 2025-10-17T13:58:56Z
4242
ExternalRef: OTHER other https://matrix.to/#/#aio-libs:matrix.org
4343
ExternalRef: OTHER other https://matrix.to/#/#aio-libs-space:matrix.org
4444
ExternalRef: OTHER build-system https://github.com/aio-libs/aiohttp/actions?query=workflow%3ACI
@@ -47,7 +47,7 @@ ExternalRef: OTHER log https://docs.aiohttp.org/en/stable/changes.html
4747
ExternalRef: OTHER other https://docs.aiohttp.org
4848
ExternalRef: OTHER issue-tracker https://github.com/aio-libs/aiohttp/issues
4949
ExternalRef: OTHER vcs https://github.com/aio-libs/aiohttp
50-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].0
50+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].1
5151
#####
5252

5353
PackageName: aiohappyeyeballs
@@ -278,11 +278,12 @@ PrimaryPackagePurpose: LIBRARY
278278
PackageSupplier: Person: Kim Davies ([email protected])
279279
PackageDownloadLocation: https://pypi.org/project/idna/3.11/#files
280280
FilesAnalyzed: false
281+
PackageChecksum: SHA256: 771a87f49d9defaf64091e6e6fe9c18d4833f140bd19464795bc32d966ca37ea
281282
PackageLicenseDeclared: NOASSERTION
282283
PackageLicenseConcluded: NOASSERTION
283284
PackageCopyrightText: NOASSERTION
284285
PackageSummary: <text>Internationalized Domain Names in Applications (IDNA)</text>
285-
ReleaseDate: 2025-10-06T14:08:42Z
286+
ReleaseDate: 2025-10-12T14:55:18Z
286287
ExternalRef: OTHER log https://github.com/kjd/idna/blob/master/HISTORY.rst
287288
ExternalRef: OTHER issue-tracker https://github.com/kjd/idna/issues
288289
ExternalRef: OTHER vcs https://github.com/kjd/idna
@@ -1148,20 +1149,20 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:michal_horejsek:fastjsonschema:2.21.2:
11481149

11491150
PackageName: xmlschema
11501151
SPDXID: SPDXRef-56-xmlschema
1151-
PackageVersion: 4.1.0
1152+
PackageVersion: 4.2.0
11521153
PrimaryPackagePurpose: LIBRARY
11531154
PackageSupplier: Person: Davide Brunato ([email protected])
1154-
PackageDownloadLocation: https://pypi.org/project/xmlschema/4.1.0/#files
1155+
PackageDownloadLocation: https://pypi.org/project/xmlschema/4.2.0/#files
11551156
FilesAnalyzed: false
11561157
PackageHomePage: https://github.com/sissaschool/xmlschema
1157-
PackageChecksum: SHA256: eabf610f398a58700bc4ac94380ad9ce558297a3f9ca8b7722ed3f7888eb4498
1158+
PackageChecksum: SHA256: 82d24a50eea5e7f2d603312813848cd66fddf8fa2b6730839c6aa3d66312e3b6
11581159
PackageLicenseDeclared: NOASSERTION
11591160
PackageLicenseConcluded: NOASSERTION
11601161
PackageCopyrightText: NOASSERTION
11611162
PackageSummary: <text>An XML Schema validator and decoder</text>
1162-
ReleaseDate: 2025-06-05T21:17:35Z
1163-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/xmlschema@4.1.0
1164-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:davide_brunato:xmlschema:4.1.0:*:*:*:*:*:*:*
1163+
ReleaseDate: 2025-10-14T09:19:28Z
1164+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/xmlschema@4.2.0
1165+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:davide_brunato:xmlschema:4.2.0:*:*:*:*:*:*:*
11651166
#####
11661167

11671168
PackageName: elementpath
@@ -1381,23 +1382,24 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:6.3.1:*:*:*:*:*:*:*
13811382

13821383
PackageName: narwhals
13831384
SPDXID: SPDXRef-67-narwhals
1384-
PackageVersion: 2.7.0
1385+
PackageVersion: 2.8.0
13851386
PrimaryPackagePurpose: LIBRARY
13861387
PackageSupplier: Person: Marco Gorelli ([email protected])
1387-
PackageDownloadLocation: https://pypi.org/project/narwhals/2.7.0/#files
1388+
PackageDownloadLocation: https://pypi.org/project/narwhals/2.8.0/#files
13881389
FilesAnalyzed: false
13891390
PackageHomePage: https://github.com/narwhals-dev/narwhals
1391+
PackageChecksum: SHA256: 6304856676ba4a79fd34148bda63aed8060dd6edb1227edf3659ce5e091de73c
13901392
PackageLicenseDeclared: NOASSERTION
13911393
PackageLicenseConcluded: MIT
13921394
PackageLicenseComments: <text>narwhals declares MIT License which is not currently a valid SPDX License identifier or expression.</text>
13931395
PackageCopyrightText: NOASSERTION
13941396
PackageSummary: <text>Extremely lightweight compatibility layer between dataframe libraries</text>
1395-
ReleaseDate: 2025-10-02T16:10:22Z
1397+
ReleaseDate: 2025-10-13T08:44:25Z
13961398
ExternalRef: OTHER documentation https://narwhals-dev.github.io/narwhals/
13971399
ExternalRef: OTHER vcs https://github.com/narwhals-dev/narwhals
13981400
ExternalRef: OTHER issue-tracker https://github.com/narwhals-dev/narwhals/issues
1399-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@2.7.0
1400-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:2.7.0:*:*:*:*:*:*:*
1401+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@2.8.0
1402+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:2.8.0:*:*:*:*:*:*:*
14011403
#####
14021404

14031405
PackageName: python-gnupg
@@ -1444,23 +1446,23 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:requests:2.32.5:*:*:*:*:
14441446

14451447
PackageName: charset-normalizer
14461448
SPDXID: SPDXRef-70-charset-normalizer
1447-
PackageVersion: 3.4.3
1449+
PackageVersion: 3.4.4
14481450
PrimaryPackagePurpose: LIBRARY
14491451
PackageSupplier: Organization: Ahmed R. ([email protected])
1450-
PackageDownloadLocation: https://pypi.org/project/charset-normalizer/3.4.3/#files
1452+
PackageDownloadLocation: https://pypi.org/project/charset-normalizer/3.4.4/#files
14511453
FilesAnalyzed: false
1452-
PackageChecksum: SHA256: fb7f67a1bfa6e40b438170ebdc8158b78dc465a5a67b6dde178a46987b244a72
1454+
PackageChecksum: SHA256: e824f1492727fa856dd6eda4f7cee25f8518a12f3c4a56a74e8095695089cf6d
14531455
PackageLicenseDeclared: MIT
14541456
PackageLicenseConcluded: MIT
14551457
PackageCopyrightText: NOASSERTION
14561458
PackageSummary: <text>The Real First Universal Charset Detector. Open, modern and actively maintained alternative to Chardet.</text>
1457-
ReleaseDate: 2025-08-09T07:55:36Z
1459+
ReleaseDate: 2025-10-14T04:40:11Z
14581460
ExternalRef: OTHER log https://github.com/jawah/charset_normalizer/blob/master/CHANGELOG.md
14591461
ExternalRef: OTHER documentation https://charset-normalizer.readthedocs.io/
14601462
ExternalRef: OTHER vcs https://github.com/jawah/charset_normalizer
14611463
ExternalRef: OTHER issue-tracker https://github.com/jawah/charset_normalizer/issues
1462-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].3
1463-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:ahmed_r.:charset-normalizer:3.4.3:*:*:*:*:*:*:*
1464+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].4
1465+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:ahmed_r.:charset-normalizer:3.4.4:*:*:*:*:*:*:*
14641466
#####
14651467

14661468
PackageName: urllib3

0 commit comments

Comments
 (0)