Skip to content

Commit 110eb4b

Browse files
chore: update SBOM for Python 3.10 (#5306)
Co-authored-by: GitHub <[email protected]>
1 parent 036e8a3 commit 110eb4b

File tree

2 files changed

+49
-42
lines changed

2 files changed

+49
-42
lines changed

sbom/cve-bin-tool-py3.10.json

Lines changed: 27 additions & 21 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:6b34574a-35b0-4e05-a03e-28ee0af94232",
5+
"serialNumber": "urn:uuid:ea198997-0707-405f-a689-a21afd663cff",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-08-18T00:44:14Z",
8+
"timestamp": "2025-08-25T00:45:29Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -958,7 +958,7 @@
958958
"type": "library",
959959
"bom-ref": "13-beautifulsoup4",
960960
"name": "beautifulsoup4",
961-
"version": "4.13.4",
961+
"version": "4.13.5",
962962
"supplier": {
963963
"name": "Leonard Richardson",
964964
"contact": [
@@ -967,12 +967,12 @@
967967
}
968968
]
969969
},
970-
"cpe": "cpe:2.3:a:leonard_richardson:beautifulsoup4:4.13.4:*:*:*:*:*:*:*",
970+
"cpe": "cpe:2.3:a:leonard_richardson:beautifulsoup4:4.13.5:*:*:*:*:*:*:*",
971971
"description": "Screen-scraping library",
972972
"hashes": [
973973
{
974974
"alg": "SHA-256",
975-
"content": "9bbbb14bfde9d79f38b8cd5f8c7c85f4b8f2523190ebed90e950a8dea4cb1c4b"
975+
"content": "642085eaa22233aceadff9c69651bc51e8bf3f874fb6d7104ece2beb24b47c4a"
976976
}
977977
],
978978
"licenses": [
@@ -991,7 +991,7 @@
991991
"comment": "Home page for project"
992992
},
993993
{
994-
"url": "https://pypi.org/project/beautifulsoup4/4.13.4/#files",
994+
"url": "https://pypi.org/project/beautifulsoup4/4.13.5/#files",
995995
"type": "distribution",
996996
"comment": "Download location for component"
997997
},
@@ -1000,11 +1000,11 @@
10001000
"type": "other"
10011001
}
10021002
],
1003-
"purl": "pkg:pypi/[email protected].4",
1003+
"purl": "pkg:pypi/[email protected].5",
10041004
"properties": [
10051005
{
10061006
"name": "release_date",
1007-
"value": "2025-04-15T17:05:12Z"
1007+
"value": "2025-08-24T14:06:14Z"
10081008
},
10091009
{
10101010
"name": "language",
@@ -3050,7 +3050,7 @@
30503050
"type": "library",
30513051
"bom-ref": "46-jsonschema",
30523052
"name": "jsonschema",
3053-
"version": "4.25.0",
3053+
"version": "4.25.1",
30543054
"supplier": {
30553055
"name": "Julian Berman",
30563056
"contact": [
@@ -3059,12 +3059,12 @@
30593059
}
30603060
]
30613061
},
3062-
"cpe": "cpe:2.3:a:julian_berman:jsonschema:4.25.0:*:*:*:*:*:*:*",
3062+
"cpe": "cpe:2.3:a:julian_berman:jsonschema:4.25.1:*:*:*:*:*:*:*",
30633063
"description": "An implementation of JSON Schema validation for Python",
30643064
"hashes": [
30653065
{
30663066
"alg": "SHA-256",
3067-
"content": "24c2e8da302de79c8b9382fee3e76b355e44d2a4364bb207159ce10b517bd716"
3067+
"content": "3fba0169e345c7175110351d456342c364814cfcf3b964ba4587f22915230a63"
30683068
}
30693069
],
30703070
"externalReferences": [
@@ -3074,7 +3074,7 @@
30743074
"comment": "Home page for project"
30753075
},
30763076
{
3077-
"url": "https://pypi.org/project/jsonschema/4.25.0/#files",
3077+
"url": "https://pypi.org/project/jsonschema/4.25.1/#files",
30783078
"type": "distribution",
30793079
"comment": "Download location for component"
30803080
},
@@ -3103,11 +3103,11 @@
31033103
"type": "vcs"
31043104
}
31053105
],
3106-
"purl": "pkg:pypi/[email protected].0",
3106+
"purl": "pkg:pypi/[email protected].1",
31073107
"properties": [
31083108
{
31093109
"name": "release_date",
3110-
"value": "2025-07-18T15:39:42Z"
3110+
"value": "2025-08-18T17:03:48Z"
31113111
},
31123112
{
31133113
"name": "language",
@@ -4336,7 +4336,7 @@
43364336
"type": "library",
43374337
"bom-ref": "66-requests",
43384338
"name": "requests",
4339-
"version": "2.32.4",
4339+
"version": "2.32.5",
43404340
"supplier": {
43414341
"name": "Kenneth Reitz",
43424342
"contact": [
@@ -4345,12 +4345,12 @@
43454345
}
43464346
]
43474347
},
4348-
"cpe": "cpe:2.3:a:kenneth_reitz:requests:2.32.4:*:*:*:*:*:*:*",
4348+
"cpe": "cpe:2.3:a:kenneth_reitz:requests:2.32.5:*:*:*:*:*:*:*",
43494349
"description": "Python HTTP for Humans.",
43504350
"hashes": [
43514351
{
43524352
"alg": "SHA-256",
4353-
"content": "27babd3cda2a6d50b30443204ee89830707d396671944c998b5975b031ac2b2c"
4353+
"content": "2462f94637a34fd532264295e186976db0f5d453d1cdd31473c85a6a161affb6"
43544354
}
43554355
],
43564356
"licenses": [
@@ -4369,7 +4369,7 @@
43694369
"comment": "Home page for project"
43704370
},
43714371
{
4372-
"url": "https://pypi.org/project/requests/2.32.4/#files",
4372+
"url": "https://pypi.org/project/requests/2.32.5/#files",
43734373
"type": "distribution",
43744374
"comment": "Download location for component"
43754375
},
@@ -4382,11 +4382,11 @@
43824382
"type": "vcs"
43834383
}
43844384
],
4385-
"purl": "pkg:pypi/[email protected].4",
4385+
"purl": "pkg:pypi/[email protected].5",
43864386
"properties": [
43874387
{
43884388
"name": "release_date",
4389-
"value": "2025-06-09T16:43:05Z"
4389+
"value": "2025-08-18T20:46:00Z"
43904390
},
43914391
{
43924392
"name": "language",
@@ -4824,6 +4824,12 @@
48244824
},
48254825
"cpe": "cpe:2.3:a:gregory_szorc:zstandard:0.24.0:*:*:*:*:*:*:*",
48264826
"description": "Zstandard bindings for Python",
4827+
"hashes": [
4828+
{
4829+
"alg": "SHA-256",
4830+
"content": "af1394c2c5febc44e0bbf0fc6428263fa928b50d1b1982ce1d870dc793a8e5f4"
4831+
}
4832+
],
48274833
"licenses": [
48284834
{
48294835
"license": {
@@ -4853,7 +4859,7 @@
48534859
"properties": [
48544860
{
48554861
"name": "release_date",
4856-
"value": "2025-06-08T17:06:38Z"
4862+
"value": "2025-08-17T18:21:12Z"
48574863
},
48584864
{
48594865
"name": "language",

sbom/cve-bin-tool-py3.10.spdx

Lines changed: 22 additions & 21 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-df214721-68d6-422c-a6a1-6e497cdfca1e
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-0c3869b5-8163-4621-9e19-1aaaa24ae250
66
LicenseListVersion: 3.26
77
Creator: Tool: sbom4python-0.12.4
8-
Created: 2025-08-18T00:44:05Z
8+
Created: 2025-08-25T00:45:01Z
99
CreatorComment: <text>SBOM Type: Build - This document has been automatically generated.</text>
1010
#####
1111

@@ -295,22 +295,22 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:kim_davies:idna:3.10:*:*:*:*:*:*:*
295295

296296
PackageName: beautifulsoup4
297297
SPDXID: SPDXRef-13-beautifulsoup4
298-
PackageVersion: 4.13.4
298+
PackageVersion: 4.13.5
299299
PrimaryPackagePurpose: LIBRARY
300300
PackageSupplier: Person: Leonard Richardson ([email protected])
301-
PackageDownloadLocation: https://pypi.org/project/beautifulsoup4/4.13.4/#files
301+
PackageDownloadLocation: https://pypi.org/project/beautifulsoup4/4.13.5/#files
302302
FilesAnalyzed: false
303303
PackageHomePage: https://www.crummy.com/software/BeautifulSoup/bs4/
304-
PackageChecksum: SHA256: 9bbbb14bfde9d79f38b8cd5f8c7c85f4b8f2523190ebed90e950a8dea4cb1c4b
304+
PackageChecksum: SHA256: 642085eaa22233aceadff9c69651bc51e8bf3f874fb6d7104ece2beb24b47c4a
305305
PackageLicenseDeclared: NOASSERTION
306306
PackageLicenseConcluded: MIT
307307
PackageLicenseComments: <text>beautifulsoup4 declares MIT License which is not currently a valid SPDX License identifier or expression.</text>
308308
PackageCopyrightText: NOASSERTION
309309
PackageSummary: <text>Screen-scraping library</text>
310-
ReleaseDate: 2025-04-15T17:05:12Z
310+
ReleaseDate: 2025-08-24T14:06:14Z
311311
ExternalRef: OTHER other https://www.crummy.com/software/BeautifulSoup/bs4/download/
312-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].4
313-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:leonard_richardson:beautifulsoup4:4.13.4:*:*:*:*:*:*:*
312+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].5
313+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:leonard_richardson:beautifulsoup4:4.13.5:*:*:*:*:*:*:*
314314
#####
315315

316316
PackageName: soupsieve
@@ -971,26 +971,26 @@ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected]
971971

972972
PackageName: jsonschema
973973
SPDXID: SPDXRef-46-jsonschema
974-
PackageVersion: 4.25.0
974+
PackageVersion: 4.25.1
975975
PrimaryPackagePurpose: LIBRARY
976976
PackageSupplier: Person: Julian Berman ([email protected])
977-
PackageDownloadLocation: https://pypi.org/project/jsonschema/4.25.0/#files
977+
PackageDownloadLocation: https://pypi.org/project/jsonschema/4.25.1/#files
978978
FilesAnalyzed: false
979979
PackageHomePage: https://github.com/python-jsonschema/jsonschema
980-
PackageChecksum: SHA256: 24c2e8da302de79c8b9382fee3e76b355e44d2a4364bb207159ce10b517bd716
980+
PackageChecksum: SHA256: 3fba0169e345c7175110351d456342c364814cfcf3b964ba4587f22915230a63
981981
PackageLicenseDeclared: NOASSERTION
982982
PackageLicenseConcluded: NOASSERTION
983983
PackageCopyrightText: NOASSERTION
984984
PackageSummary: <text>An implementation of JSON Schema validation for Python</text>
985-
ReleaseDate: 2025-07-18T15:39:42Z
985+
ReleaseDate: 2025-08-18T17:03:48Z
986986
ExternalRef: OTHER documentation https://python-jsonschema.readthedocs.io/
987987
ExternalRef: OTHER issue-tracker https://github.com/python-jsonschema/jsonschema/issues/
988988
ExternalRef: OTHER other https://github.com/sponsors/Julian
989989
ExternalRef: OTHER other https://tidelift.com/subscription/pkg/pypi-jsonschema?utm_source=pypi-jsonschema&utm_medium=referral&utm_campaign=pypi-link
990990
ExternalRef: OTHER log https://github.com/python-jsonschema/jsonschema/blob/main/CHANGELOG.rst
991991
ExternalRef: OTHER vcs https://github.com/python-jsonschema/jsonschema
992-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].0
993-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:jsonschema:4.25.0:*:*:*:*:*:*:*
992+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].1
993+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:jsonschema:4.25.1:*:*:*:*:*:*:*
994994
#####
995995

996996
PackageName: jsonschema-specifications
@@ -1402,22 +1402,22 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:vinay_sajip:python-gnupg:0.5.5:*:*:*:*
14021402

14031403
PackageName: requests
14041404
SPDXID: SPDXRef-66-requests
1405-
PackageVersion: 2.32.4
1405+
PackageVersion: 2.32.5
14061406
PrimaryPackagePurpose: LIBRARY
14071407
PackageSupplier: Person: Kenneth Reitz ([email protected])
1408-
PackageDownloadLocation: https://pypi.org/project/requests/2.32.4/#files
1408+
PackageDownloadLocation: https://pypi.org/project/requests/2.32.5/#files
14091409
FilesAnalyzed: false
14101410
PackageHomePage: https://requests.readthedocs.io
1411-
PackageChecksum: SHA256: 27babd3cda2a6d50b30443204ee89830707d396671944c998b5975b031ac2b2c
1411+
PackageChecksum: SHA256: 2462f94637a34fd532264295e186976db0f5d453d1cdd31473c85a6a161affb6
14121412
PackageLicenseDeclared: Apache-2.0
14131413
PackageLicenseConcluded: Apache-2.0
14141414
PackageCopyrightText: NOASSERTION
14151415
PackageSummary: <text>Python HTTP for Humans.</text>
1416-
ReleaseDate: 2025-06-09T16:43:05Z
1416+
ReleaseDate: 2025-08-18T20:46:00Z
14171417
ExternalRef: OTHER documentation https://requests.readthedocs.io
14181418
ExternalRef: OTHER vcs https://github.com/psf/requests
1419-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].4
1420-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:requests:2.32.4:*:*:*:*:*:*:*
1419+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].5
1420+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:requests:2.32.5:*:*:*:*:*:*:*
14211421
#####
14221422

14231423
PackageName: charset-normalizer
@@ -1563,12 +1563,13 @@ PackageSupplier: Person: Gregory Szorc ([email protected])
15631563
PackageDownloadLocation: https://pypi.org/project/zstandard/0.24.0/#files
15641564
FilesAnalyzed: false
15651565
PackageHomePage: https://github.com/indygreg/python-zstandard
1566+
PackageChecksum: SHA256: af1394c2c5febc44e0bbf0fc6428263fa928b50d1b1982ce1d870dc793a8e5f4
15661567
PackageLicenseDeclared: NOASSERTION
15671568
PackageLicenseConcluded: BSD-3-Clause
15681569
PackageLicenseComments: <text>zstandard declares BSD which is not currently a valid SPDX License identifier or expression.</text>
15691570
PackageCopyrightText: NOASSERTION
15701571
PackageSummary: <text>Zstandard bindings for Python</text>
1571-
ReleaseDate: 2025-06-08T17:06:38Z
1572+
ReleaseDate: 2025-08-17T18:21:12Z
15721573
ExternalRef: OTHER documentation https://python-zstandard.readthedocs.io/en/latest/
15731574
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected]
15741575
ExternalRef: SECURITY cpe23Type cpe:2.3:a:gregory_szorc:zstandard:0.24.0:*:*:*:*:*:*:*

0 commit comments

Comments
 (0)