Skip to content

Commit 036e8a3

Browse files
chore: update SBOM for Python 3.9 (#5307)
Co-authored-by: GitHub <[email protected]>
1 parent e966594 commit 036e8a3

File tree

2 files changed

+49
-42
lines changed

2 files changed

+49
-42
lines changed

sbom/cve-bin-tool-py3.9.json

Lines changed: 27 additions & 21 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:8d43bb02-7713-4031-9086-da6767d198d2",
5+
"serialNumber": "urn:uuid:275d9d61-3398-4ebd-bb86-1a266a901a44",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-08-18T00:44:13Z",
8+
"timestamp": "2025-08-25T00:45:31Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -958,7 +958,7 @@
958958
"type": "library",
959959
"bom-ref": "13-beautifulsoup4",
960960
"name": "beautifulsoup4",
961-
"version": "4.13.4",
961+
"version": "4.13.5",
962962
"supplier": {
963963
"name": "Leonard Richardson",
964964
"contact": [
@@ -967,12 +967,12 @@
967967
}
968968
]
969969
},
970-
"cpe": "cpe:2.3:a:leonard_richardson:beautifulsoup4:4.13.4:*:*:*:*:*:*:*",
970+
"cpe": "cpe:2.3:a:leonard_richardson:beautifulsoup4:4.13.5:*:*:*:*:*:*:*",
971971
"description": "Screen-scraping library",
972972
"hashes": [
973973
{
974974
"alg": "SHA-256",
975-
"content": "9bbbb14bfde9d79f38b8cd5f8c7c85f4b8f2523190ebed90e950a8dea4cb1c4b"
975+
"content": "642085eaa22233aceadff9c69651bc51e8bf3f874fb6d7104ece2beb24b47c4a"
976976
}
977977
],
978978
"licenses": [
@@ -991,7 +991,7 @@
991991
"comment": "Home page for project"
992992
},
993993
{
994-
"url": "https://pypi.org/project/beautifulsoup4/4.13.4/#files",
994+
"url": "https://pypi.org/project/beautifulsoup4/4.13.5/#files",
995995
"type": "distribution",
996996
"comment": "Download location for component"
997997
},
@@ -1000,11 +1000,11 @@
10001000
"type": "other"
10011001
}
10021002
],
1003-
"purl": "pkg:pypi/[email protected].4",
1003+
"purl": "pkg:pypi/[email protected].5",
10041004
"properties": [
10051005
{
10061006
"name": "release_date",
1007-
"value": "2025-04-15T17:05:12Z"
1007+
"value": "2025-08-24T14:06:14Z"
10081008
},
10091009
{
10101010
"name": "language",
@@ -3159,7 +3159,7 @@
31593159
"type": "library",
31603160
"bom-ref": "48-jsonschema",
31613161
"name": "jsonschema",
3162-
"version": "4.25.0",
3162+
"version": "4.25.1",
31633163
"supplier": {
31643164
"name": "Julian Berman",
31653165
"contact": [
@@ -3168,12 +3168,12 @@
31683168
}
31693169
]
31703170
},
3171-
"cpe": "cpe:2.3:a:julian_berman:jsonschema:4.25.0:*:*:*:*:*:*:*",
3171+
"cpe": "cpe:2.3:a:julian_berman:jsonschema:4.25.1:*:*:*:*:*:*:*",
31723172
"description": "An implementation of JSON Schema validation for Python",
31733173
"hashes": [
31743174
{
31753175
"alg": "SHA-256",
3176-
"content": "24c2e8da302de79c8b9382fee3e76b355e44d2a4364bb207159ce10b517bd716"
3176+
"content": "3fba0169e345c7175110351d456342c364814cfcf3b964ba4587f22915230a63"
31773177
}
31783178
],
31793179
"externalReferences": [
@@ -3183,7 +3183,7 @@
31833183
"comment": "Home page for project"
31843184
},
31853185
{
3186-
"url": "https://pypi.org/project/jsonschema/4.25.0/#files",
3186+
"url": "https://pypi.org/project/jsonschema/4.25.1/#files",
31873187
"type": "distribution",
31883188
"comment": "Download location for component"
31893189
},
@@ -3212,11 +3212,11 @@
32123212
"type": "vcs"
32133213
}
32143214
],
3215-
"purl": "pkg:pypi/[email protected].0",
3215+
"purl": "pkg:pypi/[email protected].1",
32163216
"properties": [
32173217
{
32183218
"name": "release_date",
3219-
"value": "2025-07-18T15:39:42Z"
3219+
"value": "2025-08-18T17:03:48Z"
32203220
},
32213221
{
32223222
"name": "language",
@@ -4445,7 +4445,7 @@
44454445
"type": "library",
44464446
"bom-ref": "68-requests",
44474447
"name": "requests",
4448-
"version": "2.32.4",
4448+
"version": "2.32.5",
44494449
"supplier": {
44504450
"name": "Kenneth Reitz",
44514451
"contact": [
@@ -4454,12 +4454,12 @@
44544454
}
44554455
]
44564456
},
4457-
"cpe": "cpe:2.3:a:kenneth_reitz:requests:2.32.4:*:*:*:*:*:*:*",
4457+
"cpe": "cpe:2.3:a:kenneth_reitz:requests:2.32.5:*:*:*:*:*:*:*",
44584458
"description": "Python HTTP for Humans.",
44594459
"hashes": [
44604460
{
44614461
"alg": "SHA-256",
4462-
"content": "27babd3cda2a6d50b30443204ee89830707d396671944c998b5975b031ac2b2c"
4462+
"content": "2462f94637a34fd532264295e186976db0f5d453d1cdd31473c85a6a161affb6"
44634463
}
44644464
],
44654465
"licenses": [
@@ -4478,7 +4478,7 @@
44784478
"comment": "Home page for project"
44794479
},
44804480
{
4481-
"url": "https://pypi.org/project/requests/2.32.4/#files",
4481+
"url": "https://pypi.org/project/requests/2.32.5/#files",
44824482
"type": "distribution",
44834483
"comment": "Download location for component"
44844484
},
@@ -4491,11 +4491,11 @@
44914491
"type": "vcs"
44924492
}
44934493
],
4494-
"purl": "pkg:pypi/[email protected].4",
4494+
"purl": "pkg:pypi/[email protected].5",
44954495
"properties": [
44964496
{
44974497
"name": "release_date",
4498-
"value": "2025-06-09T16:43:05Z"
4498+
"value": "2025-08-18T20:46:00Z"
44994499
},
45004500
{
45014501
"name": "language",
@@ -4885,6 +4885,12 @@
48854885
},
48864886
"cpe": "cpe:2.3:a:gregory_szorc:zstandard:0.24.0:*:*:*:*:*:*:*",
48874887
"description": "Zstandard bindings for Python",
4888+
"hashes": [
4889+
{
4890+
"alg": "SHA-256",
4891+
"content": "af1394c2c5febc44e0bbf0fc6428263fa928b50d1b1982ce1d870dc793a8e5f4"
4892+
}
4893+
],
48884894
"licenses": [
48894895
{
48904896
"license": {
@@ -4914,7 +4920,7 @@
49144920
"properties": [
49154921
{
49164922
"name": "release_date",
4917-
"value": "2020-11-01T01:40:20Z"
4923+
"value": "2025-08-17T18:21:12Z"
49184924
},
49194925
{
49204926
"name": "language",

sbom/cve-bin-tool-py3.9.spdx

Lines changed: 22 additions & 21 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-22592c8c-2e96-4e23-9dd9-6efedccf94d4
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-6b6327f9-c338-44ab-a104-aa61fbd714b1
66
LicenseListVersion: 3.26
77
Creator: Tool: sbom4python-0.12.4
8-
Created: 2025-08-18T00:44:04Z
8+
Created: 2025-08-25T00:45:01Z
99
CreatorComment: <text>SBOM Type: Build - This document has been automatically generated.</text>
1010
#####
1111

@@ -295,22 +295,22 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:kim_davies:idna:3.10:*:*:*:*:*:*:*
295295

296296
PackageName: beautifulsoup4
297297
SPDXID: SPDXRef-13-beautifulsoup4
298-
PackageVersion: 4.13.4
298+
PackageVersion: 4.13.5
299299
PrimaryPackagePurpose: LIBRARY
300300
PackageSupplier: Person: Leonard Richardson ([email protected])
301-
PackageDownloadLocation: https://pypi.org/project/beautifulsoup4/4.13.4/#files
301+
PackageDownloadLocation: https://pypi.org/project/beautifulsoup4/4.13.5/#files
302302
FilesAnalyzed: false
303303
PackageHomePage: https://www.crummy.com/software/BeautifulSoup/bs4/
304-
PackageChecksum: SHA256: 9bbbb14bfde9d79f38b8cd5f8c7c85f4b8f2523190ebed90e950a8dea4cb1c4b
304+
PackageChecksum: SHA256: 642085eaa22233aceadff9c69651bc51e8bf3f874fb6d7104ece2beb24b47c4a
305305
PackageLicenseDeclared: NOASSERTION
306306
PackageLicenseConcluded: MIT
307307
PackageLicenseComments: <text>beautifulsoup4 declares MIT License which is not currently a valid SPDX License identifier or expression.</text>
308308
PackageCopyrightText: NOASSERTION
309309
PackageSummary: <text>Screen-scraping library</text>
310-
ReleaseDate: 2025-04-15T17:05:12Z
310+
ReleaseDate: 2025-08-24T14:06:14Z
311311
ExternalRef: OTHER other https://www.crummy.com/software/BeautifulSoup/bs4/download/
312-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].4
313-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:leonard_richardson:beautifulsoup4:4.13.4:*:*:*:*:*:*:*
312+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].5
313+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:leonard_richardson:beautifulsoup4:4.13.5:*:*:*:*:*:*:*
314314
#####
315315

316316
PackageName: soupsieve
@@ -1008,26 +1008,26 @@ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected]
10081008

10091009
PackageName: jsonschema
10101010
SPDXID: SPDXRef-48-jsonschema
1011-
PackageVersion: 4.25.0
1011+
PackageVersion: 4.25.1
10121012
PrimaryPackagePurpose: LIBRARY
10131013
PackageSupplier: Person: Julian Berman ([email protected])
1014-
PackageDownloadLocation: https://pypi.org/project/jsonschema/4.25.0/#files
1014+
PackageDownloadLocation: https://pypi.org/project/jsonschema/4.25.1/#files
10151015
FilesAnalyzed: false
10161016
PackageHomePage: https://github.com/python-jsonschema/jsonschema
1017-
PackageChecksum: SHA256: 24c2e8da302de79c8b9382fee3e76b355e44d2a4364bb207159ce10b517bd716
1017+
PackageChecksum: SHA256: 3fba0169e345c7175110351d456342c364814cfcf3b964ba4587f22915230a63
10181018
PackageLicenseDeclared: NOASSERTION
10191019
PackageLicenseConcluded: NOASSERTION
10201020
PackageCopyrightText: NOASSERTION
10211021
PackageSummary: <text>An implementation of JSON Schema validation for Python</text>
1022-
ReleaseDate: 2025-07-18T15:39:42Z
1022+
ReleaseDate: 2025-08-18T17:03:48Z
10231023
ExternalRef: OTHER documentation https://python-jsonschema.readthedocs.io/
10241024
ExternalRef: OTHER issue-tracker https://github.com/python-jsonschema/jsonschema/issues/
10251025
ExternalRef: OTHER other https://github.com/sponsors/Julian
10261026
ExternalRef: OTHER other https://tidelift.com/subscription/pkg/pypi-jsonschema?utm_source=pypi-jsonschema&utm_medium=referral&utm_campaign=pypi-link
10271027
ExternalRef: OTHER log https://github.com/python-jsonschema/jsonschema/blob/main/CHANGELOG.rst
10281028
ExternalRef: OTHER vcs https://github.com/python-jsonschema/jsonschema
1029-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].0
1030-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:jsonschema:4.25.0:*:*:*:*:*:*:*
1029+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].1
1030+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:jsonschema:4.25.1:*:*:*:*:*:*:*
10311031
#####
10321032

10331033
PackageName: jsonschema-specifications
@@ -1439,22 +1439,22 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:vinay_sajip:python-gnupg:0.5.5:*:*:*:*
14391439

14401440
PackageName: requests
14411441
SPDXID: SPDXRef-68-requests
1442-
PackageVersion: 2.32.4
1442+
PackageVersion: 2.32.5
14431443
PrimaryPackagePurpose: LIBRARY
14441444
PackageSupplier: Person: Kenneth Reitz ([email protected])
1445-
PackageDownloadLocation: https://pypi.org/project/requests/2.32.4/#files
1445+
PackageDownloadLocation: https://pypi.org/project/requests/2.32.5/#files
14461446
FilesAnalyzed: false
14471447
PackageHomePage: https://requests.readthedocs.io
1448-
PackageChecksum: SHA256: 27babd3cda2a6d50b30443204ee89830707d396671944c998b5975b031ac2b2c
1448+
PackageChecksum: SHA256: 2462f94637a34fd532264295e186976db0f5d453d1cdd31473c85a6a161affb6
14491449
PackageLicenseDeclared: Apache-2.0
14501450
PackageLicenseConcluded: Apache-2.0
14511451
PackageCopyrightText: NOASSERTION
14521452
PackageSummary: <text>Python HTTP for Humans.</text>
1453-
ReleaseDate: 2025-06-09T16:43:05Z
1453+
ReleaseDate: 2025-08-18T20:46:00Z
14541454
ExternalRef: OTHER documentation https://requests.readthedocs.io
14551455
ExternalRef: OTHER vcs https://github.com/psf/requests
1456-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].4
1457-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:requests:2.32.4:*:*:*:*:*:*:*
1456+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].5
1457+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:requests:2.32.5:*:*:*:*:*:*:*
14581458
#####
14591459

14601460
PackageName: charset-normalizer
@@ -1582,12 +1582,13 @@ PackageSupplier: Person: Gregory Szorc ([email protected])
15821582
PackageDownloadLocation: https://pypi.org/project/zstandard/0.24.0/#files
15831583
FilesAnalyzed: false
15841584
PackageHomePage: https://github.com/indygreg/python-zstandard
1585+
PackageChecksum: SHA256: af1394c2c5febc44e0bbf0fc6428263fa928b50d1b1982ce1d870dc793a8e5f4
15851586
PackageLicenseDeclared: NOASSERTION
15861587
PackageLicenseConcluded: BSD-3-Clause
15871588
PackageLicenseComments: <text>zstandard declares BSD which is not currently a valid SPDX License identifier or expression.</text>
15881589
PackageCopyrightText: NOASSERTION
15891590
PackageSummary: <text>Zstandard bindings for Python</text>
1590-
ReleaseDate: 2020-11-01T01:40:20Z
1591+
ReleaseDate: 2025-08-17T18:21:12Z
15911592
ExternalRef: OTHER documentation https://python-zstandard.readthedocs.io/en/latest/
15921593
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected]
15931594
ExternalRef: SECURITY cpe23Type cpe:2.3:a:gregory_szorc:zstandard:0.24.0:*:*:*:*:*:*:*

0 commit comments

Comments
 (0)