Skip to content

Commit a74abb7

Browse files
web-flowgithub-actions[bot]
authored andcommitted
chore: update SBOM for Python 3.10
1 parent 259bf9b commit a74abb7

File tree

2 files changed

+86
-93
lines changed

2 files changed

+86
-93
lines changed

sbom/cve-bin-tool-py3.10.json

Lines changed: 43 additions & 49 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:be712b38-b12d-4fda-ad6b-691f2ded015d",
5+
"serialNumber": "urn:uuid:d1cb08d7-d436-4c83-9b43-2425f88fbf8b",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-09-29T00:38:37Z",
8+
"timestamp": "2025-10-06T00:39:17Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -701,7 +701,7 @@
701701
"type": "library",
702702
"bom-ref": "10-propcache",
703703
"name": "propcache",
704-
"version": "0.3.2",
704+
"version": "0.4.0",
705705
"supplier": {
706706
"name": "Andrew Svetlov",
707707
"contact": [
@@ -710,12 +710,12 @@
710710
}
711711
]
712712
},
713-
"cpe": "cpe:2.3:a:andrew_svetlov:propcache:0.3.2:*:*:*:*:*:*:*",
713+
"cpe": "cpe:2.3:a:andrew_svetlov:propcache:0.4.0:*:*:*:*:*:*:*",
714714
"description": "Accelerated property cache",
715715
"hashes": [
716716
{
717717
"alg": "SHA-256",
718-
"content": "22d9962a358aedbb7a2e36187ff273adeaab9743373a272976d2e348d08c7770"
718+
"content": "779aaae64089e2f4992e993faea801925395d26bb5de4a47df7ef7f942c14f80"
719719
}
720720
],
721721
"licenses": [
@@ -734,7 +734,7 @@
734734
"comment": "Home page for project"
735735
},
736736
{
737-
"url": "https://pypi.org/project/propcache/0.3.2/#files",
737+
"url": "https://pypi.org/project/propcache/0.4.0/#files",
738738
"type": "distribution",
739739
"comment": "Download location for component"
740740
},
@@ -775,11 +775,11 @@
775775
"type": "vcs"
776776
}
777777
],
778-
"purl": "pkg:pypi/propcache@0.3.2",
778+
"purl": "pkg:pypi/propcache@0.4.0",
779779
"properties": [
780780
{
781781
"name": "release_date",
782-
"value": "2025-06-09T22:53:40Z"
782+
"value": "2025-10-04T21:54:49Z"
783783
},
784784
{
785785
"name": "language",
@@ -795,7 +795,7 @@
795795
"type": "library",
796796
"bom-ref": "11-yarl",
797797
"name": "yarl",
798-
"version": "1.20.1",
798+
"version": "1.21.0",
799799
"supplier": {
800800
"name": "Andrew Svetlov",
801801
"contact": [
@@ -804,14 +804,8 @@
804804
}
805805
]
806806
},
807-
"cpe": "cpe:2.3:a:andrew_svetlov:yarl:1.20.1:*:*:*:*:*:*:*",
807+
"cpe": "cpe:2.3:a:andrew_svetlov:yarl:1.21.0:*:*:*:*:*:*:*",
808808
"description": "Yet another URL library",
809-
"hashes": [
810-
{
811-
"alg": "SHA-256",
812-
"content": "6032e6da6abd41e4acda34d75a816012717000fa6839f37124a47fcefc49bec4"
813-
}
814-
],
815809
"licenses": [
816810
{
817811
"license": {
@@ -828,7 +822,7 @@
828822
"comment": "Home page for project"
829823
},
830824
{
831-
"url": "https://pypi.org/project/yarl/1.20.1/#files",
825+
"url": "https://pypi.org/project/yarl/1.21.0/#files",
832826
"type": "distribution",
833827
"comment": "Download location for component"
834828
},
@@ -869,11 +863,11 @@
869863
"type": "vcs"
870864
}
871865
],
872-
"purl": "pkg:pypi/yarl@1.20.1",
866+
"purl": "pkg:pypi/yarl@1.21.0",
873867
"properties": [
874868
{
875869
"name": "release_date",
876-
"value": "2025-06-10T00:42:31Z"
870+
"value": "2025-10-04T21:54:49Z"
877871
},
878872
{
879873
"name": "language",
@@ -958,7 +952,7 @@
958952
"type": "library",
959953
"bom-ref": "13-beautifulsoup4",
960954
"name": "beautifulsoup4",
961-
"version": "4.14.0",
955+
"version": "4.14.2",
962956
"supplier": {
963957
"name": "Leonard Richardson",
964958
"contact": [
@@ -967,12 +961,12 @@
967961
}
968962
]
969963
},
970-
"cpe": "cpe:2.3:a:leonard_richardson:beautifulsoup4:4.14.0:*:*:*:*:*:*:*",
964+
"cpe": "cpe:2.3:a:leonard_richardson:beautifulsoup4:4.14.2:*:*:*:*:*:*:*",
971965
"description": "Screen-scraping library",
972966
"hashes": [
973967
{
974968
"alg": "SHA-256",
975-
"content": "aee96fbccdf2d2a8d1288b2afa51fc76bb60823b7881a50fb1ed5f711d1a7d73"
969+
"content": "5ef6fa3a8cbece8488d66985560f97ed091e22bbc4e9c2338508a9d5de6d4515"
976970
}
977971
],
978972
"licenses": [
@@ -991,7 +985,7 @@
991985
"comment": "Home page for project"
992986
},
993987
{
994-
"url": "https://pypi.org/project/beautifulsoup4/4.14.0/#files",
988+
"url": "https://pypi.org/project/beautifulsoup4/4.14.2/#files",
995989
"type": "distribution",
996990
"comment": "Download location for component"
997991
},
@@ -1000,11 +994,11 @@
1000994
"type": "other"
1001995
}
1002996
],
1003-
"purl": "pkg:pypi/[email protected].0",
997+
"purl": "pkg:pypi/[email protected].2",
1004998
"properties": [
1005999
{
10061000
"name": "release_date",
1007-
"value": "2025-09-27T17:22:16Z"
1001+
"value": "2025-09-29T10:05:43Z"
10081002
},
10091003
{
10101004
"name": "language",
@@ -3660,7 +3654,7 @@
36603654
"type": "library",
36613655
"bom-ref": "56-lib4vex",
36623656
"name": "lib4vex",
3663-
"version": "0.2.0",
3657+
"version": "0.2.1",
36643658
"supplier": {
36653659
"name": "Anthony Harrison",
36663660
"contact": [
@@ -3669,12 +3663,12 @@
36693663
}
36703664
]
36713665
},
3672-
"cpe": "cpe:2.3:a:anthony_harrison:lib4vex:0.2.0:*:*:*:*:*:*:*",
3666+
"cpe": "cpe:2.3:a:anthony_harrison:lib4vex:0.2.1:*:*:*:*:*:*:*",
36733667
"description": "VEX generator and consumer library",
36743668
"hashes": [
36753669
{
36763670
"alg": "SHA-256",
3677-
"content": "bbe730148c1a7629473067ba9702b673af11e225fcd76e6431b881f0731f52ce"
3671+
"content": "7277b368807507b2808332954480c968f73a5f51edf0218f13260cbe7110a341"
36783672
}
36793673
],
36803674
"licenses": [
@@ -3693,16 +3687,16 @@
36933687
"comment": "Home page for project"
36943688
},
36953689
{
3696-
"url": "https://pypi.org/project/lib4vex/0.2.0/#files",
3690+
"url": "https://pypi.org/project/lib4vex/0.2.1/#files",
36973691
"type": "distribution",
36983692
"comment": "Download location for component"
36993693
}
37003694
],
3701-
"purl": "pkg:pypi/[email protected].0",
3695+
"purl": "pkg:pypi/[email protected].1",
37023696
"properties": [
37033697
{
37043698
"name": "release_date",
3705-
"value": "2024-08-29T20:36:52Z"
3699+
"value": "2025-10-02T10:35:09Z"
37063700
},
37073701
{
37083702
"name": "language",
@@ -4155,7 +4149,7 @@
41554149
"type": "library",
41564150
"bom-ref": "64-plotly",
41574151
"name": "plotly",
4158-
"version": "6.3.0",
4152+
"version": "6.3.1",
41594153
"supplier": {
41604154
"name": "Chris P",
41614155
"contact": [
@@ -4164,12 +4158,12 @@
41644158
}
41654159
]
41664160
},
4167-
"cpe": "cpe:2.3:a:chris_p:plotly:6.3.0:*:*:*:*:*:*:*",
4161+
"cpe": "cpe:2.3:a:chris_p:plotly:6.3.1:*:*:*:*:*:*:*",
41684162
"description": "An open-source interactive data visualization library for Python",
41694163
"hashes": [
41704164
{
41714165
"alg": "SHA-256",
4172-
"content": "7ad806edce9d3cdd882eaebaf97c0c9e252043ed1ed3d382c3e3520ec07806d4"
4166+
"content": "8b4420d1dcf2b040f5983eed433f95732ed24930e496d36eb70d211923532e64"
41734167
}
41744168
],
41754169
"externalReferences": [
@@ -4179,7 +4173,7 @@
41794173
"comment": "Home page for project"
41804174
},
41814175
{
4182-
"url": "https://pypi.org/project/plotly/6.3.0/#files",
4176+
"url": "https://pypi.org/project/plotly/6.3.1/#files",
41834177
"type": "distribution",
41844178
"comment": "Download location for component"
41854179
},
@@ -4196,11 +4190,11 @@
41964190
"type": "log"
41974191
}
41984192
],
4199-
"purl": "pkg:pypi/[email protected].0",
4193+
"purl": "pkg:pypi/[email protected].1",
42004194
"properties": [
42014195
{
42024196
"name": "release_date",
4203-
"value": "2025-08-12T20:22:09Z"
4197+
"value": "2025-10-02T16:10:22Z"
42044198
},
42054199
{
42064200
"name": "language",
@@ -4220,7 +4214,7 @@
42204214
"type": "library",
42214215
"bom-ref": "65-narwhals",
42224216
"name": "narwhals",
4223-
"version": "2.5.0",
4217+
"version": "2.6.0",
42244218
"supplier": {
42254219
"name": "Marco Gorelli",
42264220
"contact": [
@@ -4229,12 +4223,12 @@
42294223
}
42304224
]
42314225
},
4232-
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:2.5.0:*:*:*:*:*:*:*",
4226+
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:2.6.0:*:*:*:*:*:*:*",
42334227
"description": "Extremely lightweight compatibility layer between dataframe libraries",
42344228
"hashes": [
42354229
{
42364230
"alg": "SHA-256",
4237-
"content": "7e213f9ca7db3f8bf6f7eff35eaee6a1cf80902997e1b78d49b7755775d8f423"
4231+
"content": "3215ea42afb452c6c8527e79cefbe542b674aa08d7e2e99d46b2c9708870e0d4"
42384232
}
42394233
],
42404234
"licenses": [
@@ -4253,7 +4247,7 @@
42534247
"comment": "Home page for project"
42544248
},
42554249
{
4256-
"url": "https://pypi.org/project/narwhals/2.5.0/#files",
4250+
"url": "https://pypi.org/project/narwhals/2.6.0/#files",
42574251
"type": "distribution",
42584252
"comment": "Download location for component"
42594253
},
@@ -4270,11 +4264,11 @@
42704264
"type": "issue-tracker"
42714265
}
42724266
],
4273-
"purl": "pkg:pypi/narwhals@2.5.0",
4267+
"purl": "pkg:pypi/narwhals@2.6.0",
42744268
"properties": [
42754269
{
42764270
"name": "release_date",
4277-
"value": "2025-09-12T10:04:22Z"
4271+
"value": "2025-09-29T09:08:54Z"
42784272
},
42794273
{
42804274
"name": "language",
@@ -4563,7 +4557,7 @@
45634557
"type": "library",
45644558
"bom-ref": "70-certifi",
45654559
"name": "certifi",
4566-
"version": "2025.8.3",
4560+
"version": "2025.10.5",
45674561
"supplier": {
45684562
"name": "Kenneth Reitz",
45694563
"contact": [
@@ -4572,12 +4566,12 @@
45724566
}
45734567
]
45744568
},
4575-
"cpe": "cpe:2.3:a:kenneth_reitz:certifi:2025.8.3:*:*:*:*:*:*:*",
4569+
"cpe": "cpe:2.3:a:kenneth_reitz:certifi:2025.10.5:*:*:*:*:*:*:*",
45764570
"description": "Python package for providing Mozilla's CA Bundle.",
45774571
"hashes": [
45784572
{
45794573
"alg": "SHA-256",
4580-
"content": "f6c12493cfb1b06ba2ff328595af9350c65d6644968e5d3a2ffd78699af217a5"
4574+
"content": "0f212c2744a9bb6de0c56639a6f68afe01ecd92d91f14ae897c4fe7bbeeef0de"
45814575
}
45824576
],
45834577
"licenses": [
@@ -4596,7 +4590,7 @@
45964590
"comment": "Home page for project"
45974591
},
45984592
{
4599-
"url": "https://pypi.org/project/certifi/2025.8.3/#files",
4593+
"url": "https://pypi.org/project/certifi/2025.10.5/#files",
46004594
"type": "distribution",
46014595
"comment": "Download location for component"
46024596
},
@@ -4605,11 +4599,11 @@
46054599
"type": "vcs"
46064600
}
46074601
],
4608-
"purl": "pkg:pypi/certifi@2025.8.3",
4602+
"purl": "pkg:pypi/certifi@2025.10.5",
46094603
"properties": [
46104604
{
46114605
"name": "release_date",
4612-
"value": "2025-08-03T03:07:45Z"
4606+
"value": "2025-10-05T04:12:14Z"
46134607
},
46144608
{
46154609
"name": "language",

0 commit comments

Comments
 (0)