Skip to content

Commit f5a5527

Browse files
web-flowgithub-actions[bot]
authored andcommitted
chore: update SBOM for Python 3.10
1 parent d146836 commit f5a5527

File tree

2 files changed

+76
-62
lines changed

2 files changed

+76
-62
lines changed

sbom/cve-bin-tool-py3.10.json

Lines changed: 43 additions & 31 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:6ce0712e-57c1-4da1-8f57-ae9246ca17c5",
5+
"serialNumber": "urn:uuid:7dc0b8b8-34db-4e8a-a7ff-9f0c511a1cec",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-10-13T00:45:34Z",
8+
"timestamp": "2025-10-20T00:42:29Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -79,12 +79,12 @@
7979
"type": "library",
8080
"bom-ref": "2-aiohttp",
8181
"name": "aiohttp",
82-
"version": "3.13.0",
82+
"version": "3.13.1",
8383
"description": "Async http client/server framework (asyncio)",
8484
"hashes": [
8585
{
8686
"alg": "SHA-256",
87-
"content": "ca69ec38adf5cadcc21d0b25e2144f6a25b7db7bea7e730bac25075bc305eff0"
87+
"content": "2349a6b642020bf20116a8a5c83bae8ba071acf1461c7cbe45fc7fafd552e7e2"
8888
}
8989
],
9090
"licenses": [
@@ -100,7 +100,7 @@
100100
"comment": "Home page for project"
101101
},
102102
{
103-
"url": "https://pypi.org/project/aiohttp/3.13.0/#files",
103+
"url": "https://pypi.org/project/aiohttp/3.13.1/#files",
104104
"type": "distribution",
105105
"comment": "Download location for component"
106106
},
@@ -137,11 +137,11 @@
137137
"type": "vcs"
138138
}
139139
],
140-
"purl": "pkg:pypi/[email protected].0",
140+
"purl": "pkg:pypi/[email protected].1",
141141
"properties": [
142142
{
143143
"name": "release_date",
144-
"value": "2025-10-06T19:54:40Z"
144+
"value": "2025-10-17T13:58:56Z"
145145
},
146146
{
147147
"name": "language",
@@ -894,6 +894,12 @@
894894
},
895895
"cpe": "cpe:2.3:a:kim_davies:idna:3.11:*:*:*:*:*:*:*",
896896
"description": "Internationalized Domain Names in Applications (IDNA)",
897+
"hashes": [
898+
{
899+
"alg": "SHA-256",
900+
"content": "771a87f49d9defaf64091e6e6fe9c18d4833f140bd19464795bc32d966ca37ea"
901+
}
902+
],
897903
"externalReferences": [
898904
{
899905
"url": "https://pypi.org/project/idna/3.11/#files",
@@ -917,7 +923,7 @@
917923
"properties": [
918924
{
919925
"name": "release_date",
920-
"value": "2025-10-06T14:08:42Z"
926+
"value": "2025-10-12T14:55:18Z"
921927
},
922928
{
923929
"name": "language",
@@ -3131,7 +3137,7 @@
31313137
"type": "library",
31323138
"bom-ref": "48-referencing",
31333139
"name": "referencing",
3134-
"version": "0.36.2",
3140+
"version": "0.37.0",
31353141
"supplier": {
31363142
"name": "Julian Berman",
31373143
"contact": [
@@ -3140,12 +3146,12 @@
31403146
}
31413147
]
31423148
},
3143-
"cpe": "cpe:2.3:a:julian_berman:referencing:0.36.2:*:*:*:*:*:*:*",
3149+
"cpe": "cpe:2.3:a:julian_berman:referencing:0.37.0:*:*:*:*:*:*:*",
31443150
"description": "JSON Referencing + Python",
31453151
"hashes": [
31463152
{
31473153
"alg": "SHA-256",
3148-
"content": "e8699adbbf8b5c7de96d8ffa0eb5c158b3beafce084968e2ea8bb08c6794dcd0"
3154+
"content": "381329a9f99628c9069361716891d34ad94af76e461dcb0335825aecc7692231"
31493155
}
31503156
],
31513157
"externalReferences": [
@@ -3155,7 +3161,7 @@
31553161
"comment": "Home page for project"
31563162
},
31573163
{
3158-
"url": "https://pypi.org/project/referencing/0.36.2/#files",
3164+
"url": "https://pypi.org/project/referencing/0.37.0/#files",
31593165
"type": "distribution",
31603166
"comment": "Download location for component"
31613167
},
@@ -3184,11 +3190,11 @@
31843190
"type": "vcs"
31853191
}
31863192
],
3187-
"purl": "pkg:pypi/referencing@0.36.2",
3193+
"purl": "pkg:pypi/referencing@0.37.0",
31883194
"properties": [
31893195
{
31903196
"name": "release_date",
3191-
"value": "2025-01-25T08:48:14Z"
3197+
"value": "2025-10-13T15:30:47Z"
31923198
},
31933199
{
31943200
"name": "language",
@@ -3537,7 +3543,7 @@
35373543
"type": "library",
35383544
"bom-ref": "54-xmlschema",
35393545
"name": "xmlschema",
3540-
"version": "4.1.0",
3546+
"version": "4.2.0",
35413547
"supplier": {
35423548
"name": "Davide Brunato",
35433549
"contact": [
@@ -3546,12 +3552,12 @@
35463552
}
35473553
]
35483554
},
3549-
"cpe": "cpe:2.3:a:davide_brunato:xmlschema:4.1.0:*:*:*:*:*:*:*",
3555+
"cpe": "cpe:2.3:a:davide_brunato:xmlschema:4.2.0:*:*:*:*:*:*:*",
35503556
"description": "An XML Schema validator and decoder",
35513557
"hashes": [
35523558
{
35533559
"alg": "SHA-256",
3554-
"content": "eabf610f398a58700bc4ac94380ad9ce558297a3f9ca8b7722ed3f7888eb4498"
3560+
"content": "82d24a50eea5e7f2d603312813848cd66fddf8fa2b6730839c6aa3d66312e3b6"
35553561
}
35563562
],
35573563
"externalReferences": [
@@ -3561,16 +3567,16 @@
35613567
"comment": "Home page for project"
35623568
},
35633569
{
3564-
"url": "https://pypi.org/project/xmlschema/4.1.0/#files",
3570+
"url": "https://pypi.org/project/xmlschema/4.2.0/#files",
35653571
"type": "distribution",
35663572
"comment": "Download location for component"
35673573
}
35683574
],
3569-
"purl": "pkg:pypi/xmlschema@4.1.0",
3575+
"purl": "pkg:pypi/xmlschema@4.2.0",
35703576
"properties": [
35713577
{
35723578
"name": "release_date",
3573-
"value": "2025-06-05T21:17:35Z"
3579+
"value": "2025-10-14T09:19:28Z"
35743580
},
35753581
{
35763582
"name": "language",
@@ -4195,7 +4201,7 @@
41954201
"type": "library",
41964202
"bom-ref": "65-narwhals",
41974203
"name": "narwhals",
4198-
"version": "2.7.0",
4204+
"version": "2.8.0",
41994205
"supplier": {
42004206
"name": "Marco Gorelli",
42014207
"contact": [
@@ -4204,8 +4210,14 @@
42044210
}
42054211
]
42064212
},
4207-
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:2.7.0:*:*:*:*:*:*:*",
4213+
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:2.8.0:*:*:*:*:*:*:*",
42084214
"description": "Extremely lightweight compatibility layer between dataframe libraries",
4215+
"hashes": [
4216+
{
4217+
"alg": "SHA-256",
4218+
"content": "6304856676ba4a79fd34148bda63aed8060dd6edb1227edf3659ce5e091de73c"
4219+
}
4220+
],
42094221
"licenses": [
42104222
{
42114223
"license": {
@@ -4222,7 +4234,7 @@
42224234
"comment": "Home page for project"
42234235
},
42244236
{
4225-
"url": "https://pypi.org/project/narwhals/2.7.0/#files",
4237+
"url": "https://pypi.org/project/narwhals/2.8.0/#files",
42264238
"type": "distribution",
42274239
"comment": "Download location for component"
42284240
},
@@ -4239,11 +4251,11 @@
42394251
"type": "issue-tracker"
42404252
}
42414253
],
4242-
"purl": "pkg:pypi/narwhals@2.7.0",
4254+
"purl": "pkg:pypi/narwhals@2.8.0",
42434255
"properties": [
42444256
{
42454257
"name": "release_date",
4246-
"value": "2025-10-02T16:10:22Z"
4258+
"value": "2025-10-13T08:44:25Z"
42474259
},
42484260
{
42494261
"name": "language",
@@ -4403,7 +4415,7 @@
44034415
"type": "library",
44044416
"bom-ref": "68-charset-normalizer",
44054417
"name": "charset-normalizer",
4406-
"version": "3.4.3",
4418+
"version": "3.4.4",
44074419
"supplier": {
44084420
"name": "Ahmed R .",
44094421
"contact": [
@@ -4412,12 +4424,12 @@
44124424
}
44134425
]
44144426
},
4415-
"cpe": "cpe:2.3:a:ahmed_r.:charset-normalizer:3.4.3:*:*:*:*:*:*:*",
4427+
"cpe": "cpe:2.3:a:ahmed_r.:charset-normalizer:3.4.4:*:*:*:*:*:*:*",
44164428
"description": "The Real First Universal Charset Detector. Open, modern and actively maintained alternative to Chardet.",
44174429
"hashes": [
44184430
{
44194431
"alg": "SHA-256",
4420-
"content": "fb7f67a1bfa6e40b438170ebdc8158b78dc465a5a67b6dde178a46987b244a72"
4432+
"content": "e824f1492727fa856dd6eda4f7cee25f8518a12f3c4a56a74e8095695089cf6d"
44214433
}
44224434
],
44234435
"licenses": [
@@ -4431,7 +4443,7 @@
44314443
],
44324444
"externalReferences": [
44334445
{
4434-
"url": "https://pypi.org/project/charset-normalizer/3.4.3/#files",
4446+
"url": "https://pypi.org/project/charset-normalizer/3.4.4/#files",
44354447
"type": "distribution",
44364448
"comment": "Download location for component"
44374449
},
@@ -4452,11 +4464,11 @@
44524464
"type": "issue-tracker"
44534465
}
44544466
],
4455-
"purl": "pkg:pypi/[email protected].3",
4467+
"purl": "pkg:pypi/[email protected].4",
44564468
"properties": [
44574469
{
44584470
"name": "release_date",
4459-
"value": "2025-08-09T07:55:36Z"
4471+
"value": "2025-10-14T04:40:11Z"
44604472
},
44614473
{
44624474
"name": "language",

0 commit comments

Comments
 (0)