Skip to content

Commit 07f8c31

Browse files
web-flowgithub-actions[bot]
authored andcommitted
chore: update SBOM for Python 3.11
1 parent 5ecff54 commit 07f8c31

File tree

2 files changed

+116
-123
lines changed

2 files changed

+116
-123
lines changed

sbom/cve-bin-tool-py3.11.json

Lines changed: 63 additions & 71 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:885f3a82-ae54-4f86-8648-534e88d262bf",
5+
"serialNumber": "urn:uuid:a87ad4e8-6fda-4f66-b0d5-185a98726c29",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-01-20T00:37:48Z",
8+
"timestamp": "2025-02-03T00:35:26Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -402,7 +402,7 @@
402402
"type": "library",
403403
"bom-ref": "6-attrs",
404404
"name": "attrs",
405-
"version": "24.3.0",
405+
"version": "25.1.0",
406406
"supplier": {
407407
"name": "Hynek Schlawack",
408408
"contact": [
@@ -411,17 +411,17 @@
411411
}
412412
]
413413
},
414-
"cpe": "cpe:2.3:a:hynek_schlawack:attrs:24.3.0:*:*:*:*:*:*:*",
414+
"cpe": "cpe:2.3:a:hynek_schlawack:attrs:25.1.0:*:*:*:*:*:*:*",
415415
"description": "Classes Without Boilerplate",
416416
"hashes": [
417417
{
418418
"alg": "SHA-256",
419-
"content": "ac96cd038792094f438ad1f6ff80837353805ac950cd2aa0e0625ef19850c308"
419+
"content": "c75a69e28a550a7e93789579c22aa26b0f5b83b75dc4e08fe092980051e1090a"
420420
}
421421
],
422422
"externalReferences": [
423423
{
424-
"url": "https://pypi.org/project/attrs/24.3.0/#files",
424+
"url": "https://pypi.org/project/attrs/25.1.0/#files",
425425
"type": "distribution",
426426
"comment": "Download location for component"
427427
},
@@ -446,11 +446,11 @@
446446
"type": "other"
447447
}
448448
],
449-
"purl": "pkg:pypi/attrs@24.3.0",
449+
"purl": "pkg:pypi/attrs@25.1.0",
450450
"properties": [
451451
{
452452
"name": "release_date",
453-
"value": "2024-12-16T06:59:26Z"
453+
"value": "2025-01-25T11:30:10Z"
454454
},
455455
{
456456
"name": "language",
@@ -873,7 +873,7 @@
873873
"type": "library",
874874
"bom-ref": "12-beautifulsoup4",
875875
"name": "beautifulsoup4",
876-
"version": "4.12.3",
876+
"version": "4.13.0",
877877
"supplier": {
878878
"name": "Leonard Richardson",
879879
"contact": [
@@ -882,14 +882,8 @@
882882
}
883883
]
884884
},
885-
"cpe": "cpe:2.3:a:leonard_richardson:beautifulsoup4:4.12.3:*:*:*:*:*:*:*",
885+
"cpe": "cpe:2.3:a:leonard_richardson:beautifulsoup4:4.13.0:*:*:*:*:*:*:*",
886886
"description": "Screen-scraping library",
887-
"hashes": [
888-
{
889-
"alg": "SHA-256",
890-
"content": "b80878c9f40111313e55da8ba20bdba06d8fa3969fc68304167741bbf9e082ed"
891-
}
892-
],
893887
"licenses": [
894888
{
895889
"license": {
@@ -906,7 +900,7 @@
906900
"comment": "Home page for project"
907901
},
908902
{
909-
"url": "https://pypi.org/project/beautifulsoup4/4.12.3/#files",
903+
"url": "https://pypi.org/project/beautifulsoup4/4.13.0/#files",
910904
"type": "distribution",
911905
"comment": "Download location for component"
912906
},
@@ -915,11 +909,11 @@
915909
"type": "other"
916910
}
917911
],
918-
"purl": "pkg:pypi/beautifulsoup4@4.12.3",
912+
"purl": "pkg:pypi/beautifulsoup4@4.13.0",
919913
"properties": [
920914
{
921915
"name": "release_date",
922-
"value": "2024-01-17T16:53:12Z"
916+
"value": "2024-09-15T18:07:37Z"
923917
},
924918
{
925919
"name": "language",
@@ -2520,7 +2514,7 @@
25202514
"type": "library",
25212515
"bom-ref": "39-cachetools",
25222516
"name": "cachetools",
2523-
"version": "5.5.0",
2517+
"version": "5.5.1",
25242518
"supplier": {
25252519
"name": "Thomas Kemmer",
25262520
"contact": [
@@ -2529,12 +2523,12 @@
25292523
}
25302524
]
25312525
},
2532-
"cpe": "cpe:2.3:a:thomas_kemmer:cachetools:5.5.0:*:*:*:*:*:*:*",
2526+
"cpe": "cpe:2.3:a:thomas_kemmer:cachetools:5.5.1:*:*:*:*:*:*:*",
25332527
"description": "Extensible memoizing collections and decorators",
25342528
"hashes": [
25352529
{
25362530
"alg": "SHA-256",
2537-
"content": "02134e8439cdc2ffb62023ce1debca2944c3f289d66bb17ead3ab3dede74b292"
2531+
"content": "b76651fdc3b24ead3c648bbdeeb940c1b04d365b38b4af66788f9ec4a81d42bb"
25382532
}
25392533
],
25402534
"licenses": [
@@ -2553,16 +2547,16 @@
25532547
"comment": "Home page for project"
25542548
},
25552549
{
2556-
"url": "https://pypi.org/project/cachetools/5.5.0/#files",
2550+
"url": "https://pypi.org/project/cachetools/5.5.1/#files",
25572551
"type": "distribution",
25582552
"comment": "Download location for component"
25592553
}
25602554
],
2561-
"purl": "pkg:pypi/[email protected].0",
2555+
"purl": "pkg:pypi/[email protected].1",
25622556
"properties": [
25632557
{
25642558
"name": "release_date",
2565-
"value": "2024-08-18T20:28:43Z"
2559+
"value": "2025-01-21T21:27:54Z"
25662560
},
25672561
{
25682562
"name": "language",
@@ -3109,7 +3103,7 @@
31093103
"type": "library",
31103104
"bom-ref": "49-referencing",
31113105
"name": "referencing",
3112-
"version": "0.36.1",
3106+
"version": "0.36.2",
31133107
"supplier": {
31143108
"name": "Julian Berman",
31153109
"contact": [
@@ -3118,12 +3112,12 @@
31183112
}
31193113
]
31203114
},
3121-
"cpe": "cpe:2.3:a:julian_berman:referencing:0.36.1:*:*:*:*:*:*:*",
3115+
"cpe": "cpe:2.3:a:julian_berman:referencing:0.36.2:*:*:*:*:*:*:*",
31223116
"description": "JSON Referencing + Python",
31233117
"hashes": [
31243118
{
31253119
"alg": "SHA-256",
3126-
"content": "363d9c65f080d0d70bc41c721dce3c7f3e77fc09f269cd5c8813da18069a6794"
3120+
"content": "e8699adbbf8b5c7de96d8ffa0eb5c158b3beafce084968e2ea8bb08c6794dcd0"
31273121
}
31283122
],
31293123
"externalReferences": [
@@ -3133,7 +3127,7 @@
31333127
"comment": "Home page for project"
31343128
},
31353129
{
3136-
"url": "https://pypi.org/project/referencing/0.36.1/#files",
3130+
"url": "https://pypi.org/project/referencing/0.36.2/#files",
31373131
"type": "distribution",
31383132
"comment": "Download location for component"
31393133
},
@@ -3162,11 +3156,11 @@
31623156
"type": "vcs"
31633157
}
31643158
],
3165-
"purl": "pkg:pypi/[email protected].1",
3159+
"purl": "pkg:pypi/[email protected].2",
31663160
"properties": [
31673161
{
31683162
"name": "release_date",
3169-
"value": "2025-01-17T02:22:02Z"
3163+
"value": "2025-01-25T08:48:14Z"
31703164
},
31713165
{
31723166
"name": "language",
@@ -3978,7 +3972,7 @@
39783972
"type": "library",
39793973
"bom-ref": "63-plotly",
39803974
"name": "plotly",
3981-
"version": "5.24.1",
3975+
"version": "6.0.0",
39823976
"supplier": {
39833977
"name": "Chris P",
39843978
"contact": [
@@ -3987,12 +3981,12 @@
39873981
}
39883982
]
39893983
},
3990-
"cpe": "cpe:2.3:a:chris_p:plotly:5.24.1:*:*:*:*:*:*:*",
3984+
"cpe": "cpe:2.3:a:chris_p:plotly:6.0.0:*:*:*:*:*:*:*",
39913985
"description": "An open-source, interactive data visualization library for Python",
39923986
"hashes": [
39933987
{
39943988
"alg": "SHA-256",
3995-
"content": "f67073a1e637eb0dc3e46324d9d51e2fe76e9727c892dde64ddf1e1b51f29089"
3989+
"content": "f708871c3a9349a68791ff943a5781b1ec04de7769ea69068adcd9202e57653a"
39963990
}
39973991
],
39983992
"licenses": [
@@ -4011,7 +4005,7 @@
40114005
"comment": "Home page for project"
40124006
},
40134007
{
4014-
"url": "https://pypi.org/project/plotly/5.24.1/#files",
4008+
"url": "https://pypi.org/project/plotly/6.0.0/#files",
40154009
"type": "distribution",
40164010
"comment": "Download location for component"
40174011
},
@@ -4028,11 +4022,11 @@
40284022
"type": "log"
40294023
}
40304024
],
4031-
"purl": "pkg:pypi/plotly@5.24.1",
4025+
"purl": "pkg:pypi/plotly@6.0.0",
40324026
"properties": [
40334027
{
40344028
"name": "release_date",
4035-
"value": "2024-09-12T15:36:24Z"
4029+
"value": "2025-01-28T19:33:47Z"
40364030
},
40374031
{
40384032
"name": "language",
@@ -4046,51 +4040,48 @@
40464040
},
40474041
{
40484042
"type": "library",
4049-
"bom-ref": "64-tenacity",
4050-
"name": "tenacity",
4051-
"version": "9.0.0",
4043+
"bom-ref": "64-narwhals",
4044+
"name": "narwhals",
4045+
"version": "1.24.2",
40524046
"supplier": {
4053-
"name": "Julien Danjou",
4047+
"name": "Marco Gorelli",
40544048
"contact": [
40554049
{
4056-
"email": "[email protected]"
4050+
"email": "[email protected]"
40574051
}
40584052
]
40594053
},
4060-
"cpe": "cpe:2.3:a:julien_danjou:tenacity:9.0.0:*:*:*:*:*:*:*",
4061-
"description": "Retry code until it succeeds",
4062-
"hashes": [
4063-
{
4064-
"alg": "SHA-256",
4065-
"content": "93de0c98785b27fcf659856aa9f54bfbd399e29969b0621bc7f762bd441b4539"
4066-
}
4067-
],
4068-
"licenses": [
4069-
{
4070-
"license": {
4071-
"id": "Apache-2.0",
4072-
"url": "https://www.apache.org/licenses/LICENSE-2.0",
4073-
"acknowledgement": "concluded"
4074-
}
4075-
}
4076-
],
4054+
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:1.24.2:*:*:*:*:*:*:*",
4055+
"description": "Extremely lightweight compatibility layer between dataframe libraries",
40774056
"externalReferences": [
40784057
{
4079-
"url": "https://github.com/jd/tenacity",
4058+
"url": "https://github.com/narwhals-dev/narwhals",
40804059
"type": "website",
40814060
"comment": "Home page for project"
40824061
},
40834062
{
4084-
"url": "https://pypi.org/project/tenacity/9.0.0/#files",
4063+
"url": "https://pypi.org/project/narwhals/1.24.2/#files",
40854064
"type": "distribution",
40864065
"comment": "Download location for component"
4066+
},
4067+
{
4068+
"url": "https://narwhals-dev.github.io/narwhals/",
4069+
"type": "documentation"
4070+
},
4071+
{
4072+
"url": "https://github.com/narwhals-dev/narwhals",
4073+
"type": "vcs"
4074+
},
4075+
{
4076+
"url": "https://github.com/narwhals-dev/narwhals/issues",
4077+
"type": "issue-tracker"
40874078
}
40884079
],
4089-
"purl": "pkg:pypi/[email protected]",
4080+
"purl": "pkg:pypi/[email protected]",
40904081
"properties": [
40914082
{
40924083
"name": "release_date",
4093-
"value": "2024-07-29T12:12:25Z"
4084+
"value": "2025-01-28T19:33:47Z"
40944085
},
40954086
{
40964087
"name": "language",
@@ -4301,7 +4292,7 @@
43014292
"type": "library",
43024293
"bom-ref": "68-certifi",
43034294
"name": "certifi",
4304-
"version": "2024.12.14",
4295+
"version": "2025.1.31",
43054296
"supplier": {
43064297
"name": "Kenneth Reitz",
43074298
"contact": [
@@ -4310,12 +4301,12 @@
43104301
}
43114302
]
43124303
},
4313-
"cpe": "cpe:2.3:a:kenneth_reitz:certifi:2024.12.14:*:*:*:*:*:*:*",
4304+
"cpe": "cpe:2.3:a:kenneth_reitz:certifi:2025.1.31:*:*:*:*:*:*:*",
43144305
"description": "Python package for providing Mozilla's CA Bundle.",
43154306
"hashes": [
43164307
{
43174308
"alg": "SHA-256",
4318-
"content": "1275f7a45be9464efc1173084eaa30f866fe2e47d389406136d332ed4967ec56"
4309+
"content": "ca78db4565a652026a4db2bcdf68f2fb589ea80d0be70e03929ed730746b84fe"
43194310
}
43204311
],
43214312
"licenses": [
@@ -4334,7 +4325,7 @@
43344325
"comment": "Home page for project"
43354326
},
43364327
{
4337-
"url": "https://pypi.org/project/certifi/2024.12.14/#files",
4328+
"url": "https://pypi.org/project/certifi/2025.1.31/#files",
43384329
"type": "distribution",
43394330
"comment": "Download location for component"
43404331
},
@@ -4343,11 +4334,11 @@
43434334
"type": "vcs"
43444335
}
43454336
],
4346-
"purl": "pkg:pypi/certifi@2024.12.14",
4337+
"purl": "pkg:pypi/certifi@2025.1.31",
43474338
"properties": [
43484339
{
43494340
"name": "release_date",
4350-
"value": "2024-12-14T13:52:36Z"
4341+
"value": "2025-01-31T02:16:45Z"
43514342
},
43524343
{
43534344
"name": "language",
@@ -4720,7 +4711,8 @@
47204711
{
47214712
"ref": "12-beautifulsoup4",
47224713
"dependsOn": [
4723-
"13-soupsieve"
4714+
"13-soupsieve",
4715+
"8-typing-extensions"
47244716
]
47254717
},
47264718
{
@@ -4908,7 +4900,7 @@
49084900
{
49094901
"ref": "63-plotly",
49104902
"dependsOn": [
4911-
"64-tenacity",
4903+
"64-narwhals",
49124904
"62-packaging"
49134905
]
49144906
},

0 commit comments

Comments
 (0)