Skip to content

Commit 6f1f245

Browse files
chore: update SBOM for Python 3.13 (#5303)
Co-authored-by: GitHub <[email protected]>
1 parent 390e261 commit 6f1f245

File tree

2 files changed

+49
-42
lines changed

2 files changed

+49
-42
lines changed

sbom/cve-bin-tool-py3.13.json

Lines changed: 27 additions & 21 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:f5b969ef-0c1a-4852-bdfc-486576854280",
5+
"serialNumber": "urn:uuid:76457dbe-442c-4a99-a82e-bf83c7281648",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-08-18T00:47:20Z",
8+
"timestamp": "2025-08-25T00:45:25Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -876,7 +876,7 @@
876876
"type": "library",
877877
"bom-ref": "12-beautifulsoup4",
878878
"name": "beautifulsoup4",
879-
"version": "4.13.4",
879+
"version": "4.13.5",
880880
"supplier": {
881881
"name": "Leonard Richardson",
882882
"contact": [
@@ -885,12 +885,12 @@
885885
}
886886
]
887887
},
888-
"cpe": "cpe:2.3:a:leonard_richardson:beautifulsoup4:4.13.4:*:*:*:*:*:*:*",
888+
"cpe": "cpe:2.3:a:leonard_richardson:beautifulsoup4:4.13.5:*:*:*:*:*:*:*",
889889
"description": "Screen-scraping library",
890890
"hashes": [
891891
{
892892
"alg": "SHA-256",
893-
"content": "9bbbb14bfde9d79f38b8cd5f8c7c85f4b8f2523190ebed90e950a8dea4cb1c4b"
893+
"content": "642085eaa22233aceadff9c69651bc51e8bf3f874fb6d7104ece2beb24b47c4a"
894894
}
895895
],
896896
"licenses": [
@@ -909,7 +909,7 @@
909909
"comment": "Home page for project"
910910
},
911911
{
912-
"url": "https://pypi.org/project/beautifulsoup4/4.13.4/#files",
912+
"url": "https://pypi.org/project/beautifulsoup4/4.13.5/#files",
913913
"type": "distribution",
914914
"comment": "Download location for component"
915915
},
@@ -918,11 +918,11 @@
918918
"type": "other"
919919
}
920920
],
921-
"purl": "pkg:pypi/[email protected].4",
921+
"purl": "pkg:pypi/[email protected].5",
922922
"properties": [
923923
{
924924
"name": "release_date",
925-
"value": "2025-04-15T17:05:12Z"
925+
"value": "2025-08-24T14:06:14Z"
926926
},
927927
{
928928
"name": "language",
@@ -2968,7 +2968,7 @@
29682968
"type": "library",
29692969
"bom-ref": "45-jsonschema",
29702970
"name": "jsonschema",
2971-
"version": "4.25.0",
2971+
"version": "4.25.1",
29722972
"supplier": {
29732973
"name": "Julian Berman",
29742974
"contact": [
@@ -2977,12 +2977,12 @@
29772977
}
29782978
]
29792979
},
2980-
"cpe": "cpe:2.3:a:julian_berman:jsonschema:4.25.0:*:*:*:*:*:*:*",
2980+
"cpe": "cpe:2.3:a:julian_berman:jsonschema:4.25.1:*:*:*:*:*:*:*",
29812981
"description": "An implementation of JSON Schema validation for Python",
29822982
"hashes": [
29832983
{
29842984
"alg": "SHA-256",
2985-
"content": "24c2e8da302de79c8b9382fee3e76b355e44d2a4364bb207159ce10b517bd716"
2985+
"content": "3fba0169e345c7175110351d456342c364814cfcf3b964ba4587f22915230a63"
29862986
}
29872987
],
29882988
"externalReferences": [
@@ -2992,7 +2992,7 @@
29922992
"comment": "Home page for project"
29932993
},
29942994
{
2995-
"url": "https://pypi.org/project/jsonschema/4.25.0/#files",
2995+
"url": "https://pypi.org/project/jsonschema/4.25.1/#files",
29962996
"type": "distribution",
29972997
"comment": "Download location for component"
29982998
},
@@ -3021,11 +3021,11 @@
30213021
"type": "vcs"
30223022
}
30233023
],
3024-
"purl": "pkg:pypi/[email protected].0",
3024+
"purl": "pkg:pypi/[email protected].1",
30253025
"properties": [
30263026
{
30273027
"name": "release_date",
3028-
"value": "2025-07-18T15:39:42Z"
3028+
"value": "2025-08-18T17:03:48Z"
30293029
},
30303030
{
30313031
"name": "language",
@@ -4254,7 +4254,7 @@
42544254
"type": "library",
42554255
"bom-ref": "65-requests",
42564256
"name": "requests",
4257-
"version": "2.32.4",
4257+
"version": "2.32.5",
42584258
"supplier": {
42594259
"name": "Kenneth Reitz",
42604260
"contact": [
@@ -4263,12 +4263,12 @@
42634263
}
42644264
]
42654265
},
4266-
"cpe": "cpe:2.3:a:kenneth_reitz:requests:2.32.4:*:*:*:*:*:*:*",
4266+
"cpe": "cpe:2.3:a:kenneth_reitz:requests:2.32.5:*:*:*:*:*:*:*",
42674267
"description": "Python HTTP for Humans.",
42684268
"hashes": [
42694269
{
42704270
"alg": "SHA-256",
4271-
"content": "27babd3cda2a6d50b30443204ee89830707d396671944c998b5975b031ac2b2c"
4271+
"content": "2462f94637a34fd532264295e186976db0f5d453d1cdd31473c85a6a161affb6"
42724272
}
42734273
],
42744274
"licenses": [
@@ -4287,7 +4287,7 @@
42874287
"comment": "Home page for project"
42884288
},
42894289
{
4290-
"url": "https://pypi.org/project/requests/2.32.4/#files",
4290+
"url": "https://pypi.org/project/requests/2.32.5/#files",
42914291
"type": "distribution",
42924292
"comment": "Download location for component"
42934293
},
@@ -4300,11 +4300,11 @@
43004300
"type": "vcs"
43014301
}
43024302
],
4303-
"purl": "pkg:pypi/[email protected].4",
4303+
"purl": "pkg:pypi/[email protected].5",
43044304
"properties": [
43054305
{
43064306
"name": "release_date",
4307-
"value": "2025-06-09T16:43:05Z"
4307+
"value": "2025-08-18T20:46:00Z"
43084308
},
43094309
{
43104310
"name": "language",
@@ -4684,6 +4684,12 @@
46844684
},
46854685
"cpe": "cpe:2.3:a:gregory_szorc:zstandard:0.24.0:*:*:*:*:*:*:*",
46864686
"description": "Zstandard bindings for Python",
4687+
"hashes": [
4688+
{
4689+
"alg": "SHA-256",
4690+
"content": "af1394c2c5febc44e0bbf0fc6428263fa928b50d1b1982ce1d870dc793a8e5f4"
4691+
}
4692+
],
46874693
"licenses": [
46884694
{
46894695
"license": {
@@ -4713,7 +4719,7 @@
47134719
"properties": [
47144720
{
47154721
"name": "release_date",
4716-
"value": "2025-06-08T17:06:38Z"
4722+
"value": "2025-08-17T18:21:12Z"
47174723
},
47184724
{
47194725
"name": "language",

sbom/cve-bin-tool-py3.13.spdx

Lines changed: 22 additions & 21 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-f91bd2a1-e043-4620-87fc-5caf34c25365
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-4038cf48-d707-4dcb-8db5-02699976019a
66
LicenseListVersion: 3.26
77
Creator: Tool: sbom4python-0.12.4
8-
Created: 2025-08-18T00:47:04Z
8+
Created: 2025-08-25T00:45:01Z
99
CreatorComment: <text>SBOM Type: Build - This document has been automatically generated.</text>
1010
#####
1111

@@ -271,22 +271,22 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:kim_davies:idna:3.10:*:*:*:*:*:*:*
271271

272272
PackageName: beautifulsoup4
273273
SPDXID: SPDXRef-12-beautifulsoup4
274-
PackageVersion: 4.13.4
274+
PackageVersion: 4.13.5
275275
PrimaryPackagePurpose: LIBRARY
276276
PackageSupplier: Person: Leonard Richardson ([email protected])
277-
PackageDownloadLocation: https://pypi.org/project/beautifulsoup4/4.13.4/#files
277+
PackageDownloadLocation: https://pypi.org/project/beautifulsoup4/4.13.5/#files
278278
FilesAnalyzed: false
279279
PackageHomePage: https://www.crummy.com/software/BeautifulSoup/bs4/
280-
PackageChecksum: SHA256: 9bbbb14bfde9d79f38b8cd5f8c7c85f4b8f2523190ebed90e950a8dea4cb1c4b
280+
PackageChecksum: SHA256: 642085eaa22233aceadff9c69651bc51e8bf3f874fb6d7104ece2beb24b47c4a
281281
PackageLicenseDeclared: NOASSERTION
282282
PackageLicenseConcluded: MIT
283283
PackageLicenseComments: <text>beautifulsoup4 declares MIT License which is not currently a valid SPDX License identifier or expression.</text>
284284
PackageCopyrightText: NOASSERTION
285285
PackageSummary: <text>Screen-scraping library</text>
286-
ReleaseDate: 2025-04-15T17:05:12Z
286+
ReleaseDate: 2025-08-24T14:06:14Z
287287
ExternalRef: OTHER other https://www.crummy.com/software/BeautifulSoup/bs4/download/
288-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].4
289-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:leonard_richardson:beautifulsoup4:4.13.4:*:*:*:*:*:*:*
288+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].5
289+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:leonard_richardson:beautifulsoup4:4.13.5:*:*:*:*:*:*:*
290290
#####
291291

292292
PackageName: soupsieve
@@ -947,26 +947,26 @@ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected]
947947

948948
PackageName: jsonschema
949949
SPDXID: SPDXRef-45-jsonschema
950-
PackageVersion: 4.25.0
950+
PackageVersion: 4.25.1
951951
PrimaryPackagePurpose: LIBRARY
952952
PackageSupplier: Person: Julian Berman ([email protected])
953-
PackageDownloadLocation: https://pypi.org/project/jsonschema/4.25.0/#files
953+
PackageDownloadLocation: https://pypi.org/project/jsonschema/4.25.1/#files
954954
FilesAnalyzed: false
955955
PackageHomePage: https://github.com/python-jsonschema/jsonschema
956-
PackageChecksum: SHA256: 24c2e8da302de79c8b9382fee3e76b355e44d2a4364bb207159ce10b517bd716
956+
PackageChecksum: SHA256: 3fba0169e345c7175110351d456342c364814cfcf3b964ba4587f22915230a63
957957
PackageLicenseDeclared: NOASSERTION
958958
PackageLicenseConcluded: NOASSERTION
959959
PackageCopyrightText: NOASSERTION
960960
PackageSummary: <text>An implementation of JSON Schema validation for Python</text>
961-
ReleaseDate: 2025-07-18T15:39:42Z
961+
ReleaseDate: 2025-08-18T17:03:48Z
962962
ExternalRef: OTHER documentation https://python-jsonschema.readthedocs.io/
963963
ExternalRef: OTHER issue-tracker https://github.com/python-jsonschema/jsonschema/issues/
964964
ExternalRef: OTHER other https://github.com/sponsors/Julian
965965
ExternalRef: OTHER other https://tidelift.com/subscription/pkg/pypi-jsonschema?utm_source=pypi-jsonschema&utm_medium=referral&utm_campaign=pypi-link
966966
ExternalRef: OTHER log https://github.com/python-jsonschema/jsonschema/blob/main/CHANGELOG.rst
967967
ExternalRef: OTHER vcs https://github.com/python-jsonschema/jsonschema
968-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].0
969-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:jsonschema:4.25.0:*:*:*:*:*:*:*
968+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].1
969+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:jsonschema:4.25.1:*:*:*:*:*:*:*
970970
#####
971971

972972
PackageName: jsonschema-specifications
@@ -1378,22 +1378,22 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:vinay_sajip:python-gnupg:0.5.5:*:*:*:*
13781378

13791379
PackageName: requests
13801380
SPDXID: SPDXRef-65-requests
1381-
PackageVersion: 2.32.4
1381+
PackageVersion: 2.32.5
13821382
PrimaryPackagePurpose: LIBRARY
13831383
PackageSupplier: Person: Kenneth Reitz ([email protected])
1384-
PackageDownloadLocation: https://pypi.org/project/requests/2.32.4/#files
1384+
PackageDownloadLocation: https://pypi.org/project/requests/2.32.5/#files
13851385
FilesAnalyzed: false
13861386
PackageHomePage: https://requests.readthedocs.io
1387-
PackageChecksum: SHA256: 27babd3cda2a6d50b30443204ee89830707d396671944c998b5975b031ac2b2c
1387+
PackageChecksum: SHA256: 2462f94637a34fd532264295e186976db0f5d453d1cdd31473c85a6a161affb6
13881388
PackageLicenseDeclared: Apache-2.0
13891389
PackageLicenseConcluded: Apache-2.0
13901390
PackageCopyrightText: NOASSERTION
13911391
PackageSummary: <text>Python HTTP for Humans.</text>
1392-
ReleaseDate: 2025-06-09T16:43:05Z
1392+
ReleaseDate: 2025-08-18T20:46:00Z
13931393
ExternalRef: OTHER documentation https://requests.readthedocs.io
13941394
ExternalRef: OTHER vcs https://github.com/psf/requests
1395-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].4
1396-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:requests:2.32.4:*:*:*:*:*:*:*
1395+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].5
1396+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:requests:2.32.5:*:*:*:*:*:*:*
13971397
#####
13981398

13991399
PackageName: charset-normalizer
@@ -1521,12 +1521,13 @@ PackageSupplier: Person: Gregory Szorc ([email protected])
15211521
PackageDownloadLocation: https://pypi.org/project/zstandard/0.24.0/#files
15221522
FilesAnalyzed: false
15231523
PackageHomePage: https://github.com/indygreg/python-zstandard
1524+
PackageChecksum: SHA256: af1394c2c5febc44e0bbf0fc6428263fa928b50d1b1982ce1d870dc793a8e5f4
15241525
PackageLicenseDeclared: NOASSERTION
15251526
PackageLicenseConcluded: BSD-3-Clause
15261527
PackageLicenseComments: <text>zstandard declares BSD which is not currently a valid SPDX License identifier or expression.</text>
15271528
PackageCopyrightText: NOASSERTION
15281529
PackageSummary: <text>Zstandard bindings for Python</text>
1529-
ReleaseDate: 2025-06-08T17:06:38Z
1530+
ReleaseDate: 2025-08-17T18:21:12Z
15301531
ExternalRef: OTHER documentation https://python-zstandard.readthedocs.io/en/latest/
15311532
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected]
15321533
ExternalRef: SECURITY cpe23Type cpe:2.3:a:gregory_szorc:zstandard:0.24.0:*:*:*:*:*:*:*

0 commit comments

Comments
 (0)