Skip to content

Commit c20813b

Browse files
chore: update SBOM for Python 3.10 (#4962)
Co-authored-by: GitHub <[email protected]>
1 parent b023acf commit c20813b

File tree

2 files changed

+117
-111
lines changed

2 files changed

+117
-111
lines changed

sbom/cve-bin-tool-py3.10.json

Lines changed: 49 additions & 64 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:338fbd27-8b9f-447f-8487-4b1e2ebcc9fe",
5+
"serialNumber": "urn:uuid:796a191c-088b-45d2-bd13-4d623246be88",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-03-17T00:38:38Z",
8+
"timestamp": "2025-03-24T00:38:31Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -89,12 +89,12 @@
8989
"type": "library",
9090
"bom-ref": "2-aiohttp",
9191
"name": "aiohttp",
92-
"version": "3.11.13",
92+
"version": "3.11.14",
9393
"description": "Async http client/server framework (asyncio)",
9494
"hashes": [
9595
{
9696
"alg": "SHA-256",
97-
"content": "a4fe27dbbeec445e6e1291e61d61eb212ee9fed6e47998b27de71d70d3e8777d"
97+
"content": "e2bc827c01f75803de77b134afdbf74fa74b62970eafdf190f3244931d7a5c0d"
9898
}
9999
],
100100
"licenses": [
@@ -113,7 +113,7 @@
113113
"comment": "Home page for project"
114114
},
115115
{
116-
"url": "https://pypi.org/project/aiohttp/3.11.13/#files",
116+
"url": "https://pypi.org/project/aiohttp/3.11.14/#files",
117117
"type": "distribution",
118118
"comment": "Download location for component"
119119
},
@@ -150,11 +150,11 @@
150150
"type": "vcs"
151151
}
152152
],
153-
"purl": "pkg:pypi/[email protected].13",
153+
"purl": "pkg:pypi/[email protected].14",
154154
"properties": [
155155
{
156156
"name": "release_date",
157-
"value": "2025-02-24T15:58:53Z"
157+
"value": "2025-03-17T02:42:42Z"
158158
},
159159
{
160160
"name": "language",
@@ -181,6 +181,12 @@
181181
},
182182
"cpe": "cpe:2.3:a:j._nick_koston:aiohappyeyeballs:2.6.1:*:*:*:*:*:*:*",
183183
"description": "Happy Eyeballs for asyncio",
184+
"hashes": [
185+
{
186+
"alg": "SHA-256",
187+
"content": "f349ba8f4b75cb25c99c5c2d84e997e485204d2902a9597802b0371f09331fb8"
188+
}
189+
],
184190
"licenses": [
185191
{
186192
"license": {
@@ -217,7 +223,7 @@
217223
"properties": [
218224
{
219225
"name": "release_date",
220-
"value": "2025-02-24T15:58:53Z"
226+
"value": "2025-03-12T01:42:47Z"
221227
},
222228
{
223229
"name": "language",
@@ -533,7 +539,7 @@
533539
"type": "library",
534540
"bom-ref": "8-multidict",
535541
"name": "multidict",
536-
"version": "6.1.0",
542+
"version": "6.2.0",
537543
"supplier": {
538544
"name": "Andrew Svetlov",
539545
"contact": [
@@ -542,12 +548,12 @@
542548
}
543549
]
544550
},
545-
"cpe": "cpe:2.3:a:andrew_svetlov:multidict:6.1.0:*:*:*:*:*:*:*",
551+
"cpe": "cpe:2.3:a:andrew_svetlov:multidict:6.2.0:*:*:*:*:*:*:*",
546552
"description": "multidict implementation",
547553
"hashes": [
548554
{
549555
"alg": "SHA-256",
550-
"content": "3380252550e372e8511d49481bd836264c009adb826b23fefcc5dd3c69692f60"
556+
"content": "b9f6392d98c0bd70676ae41474e2eecf4c7150cb419237a41f8f96043fcb81d1"
551557
}
552558
],
553559
"licenses": [
@@ -566,7 +572,7 @@
566572
"comment": "Home page for project"
567573
},
568574
{
569-
"url": "https://pypi.org/project/multidict/6.1.0/#files",
575+
"url": "https://pypi.org/project/multidict/6.2.0/#files",
570576
"type": "distribution",
571577
"comment": "Download location for component"
572578
},
@@ -607,11 +613,11 @@
607613
"type": "vcs"
608614
}
609615
],
610-
"purl": "pkg:pypi/multidict@6.1.0",
616+
"purl": "pkg:pypi/multidict@6.2.0",
611617
"properties": [
612618
{
613619
"name": "release_date",
614-
"value": "2024-09-09T23:47:18Z"
620+
"value": "2025-03-17T16:53:32Z"
615621
},
616622
{
617623
"name": "language",
@@ -1384,7 +1390,7 @@
13841390
"type": "library",
13851391
"bom-ref": "20-argcomplete",
13861392
"name": "argcomplete",
1387-
"version": "3.6.0",
1393+
"version": "3.6.1",
13881394
"supplier": {
13891395
"name": "Andrey Kislyuk",
13901396
"contact": [
@@ -1393,12 +1399,12 @@
13931399
}
13941400
]
13951401
},
1396-
"cpe": "cpe:2.3:a:andrey_kislyuk:argcomplete:3.6.0:*:*:*:*:*:*:*",
1402+
"cpe": "cpe:2.3:a:andrey_kislyuk:argcomplete:3.6.1:*:*:*:*:*:*:*",
13971403
"description": "Bash tab completion for argparse",
13981404
"hashes": [
13991405
{
14001406
"alg": "SHA-256",
1401-
"content": "4e3e4e10beb20e06444dbac0ac8dda650cb6349caeefe980208d3c548708bedd"
1407+
"content": "cef54d7f752560570291214f0f1c48c3b8ef09aca63d65de7747612666725dbc"
14021408
}
14031409
],
14041410
"licenses": [
@@ -1417,7 +1423,7 @@
14171423
"comment": "Home page for project"
14181424
},
14191425
{
1420-
"url": "https://pypi.org/project/argcomplete/3.6.0/#files",
1426+
"url": "https://pypi.org/project/argcomplete/3.6.1/#files",
14211427
"type": "distribution",
14221428
"comment": "Download location for component"
14231429
},
@@ -1438,11 +1444,11 @@
14381444
"type": "log"
14391445
}
14401446
],
1441-
"purl": "pkg:pypi/[email protected].0",
1447+
"purl": "pkg:pypi/[email protected].1",
14421448
"properties": [
14431449
{
14441450
"name": "release_date",
1445-
"value": "2025-03-05T21:31:35Z"
1451+
"value": "2025-03-22T17:31:11Z"
14461452
},
14471453
{
14481454
"name": "language",
@@ -4149,7 +4155,7 @@
41494155
"type": "library",
41504156
"bom-ref": "64-plotly",
41514157
"name": "plotly",
4152-
"version": "6.0.0",
4158+
"version": "6.0.1",
41534159
"supplier": {
41544160
"name": "Chris P",
41554161
"contact": [
@@ -4158,21 +4164,12 @@
41584164
}
41594165
]
41604166
},
4161-
"cpe": "cpe:2.3:a:chris_p:plotly:6.0.0:*:*:*:*:*:*:*",
4162-
"description": "An open-source, interactive data visualization library for Python",
4167+
"cpe": "cpe:2.3:a:chris_p:plotly:6.0.1:*:*:*:*:*:*:*",
4168+
"description": "An open-source interactive data visualization library for Python",
41634169
"hashes": [
41644170
{
41654171
"alg": "SHA-256",
4166-
"content": "f708871c3a9349a68791ff943a5781b1ec04de7769ea69068adcd9202e57653a"
4167-
}
4168-
],
4169-
"licenses": [
4170-
{
4171-
"license": {
4172-
"id": "MIT",
4173-
"url": "https://opensource.org/license/mit/",
4174-
"acknowledgement": "concluded"
4175-
}
4172+
"content": "4714db20fea57a435692c548a4eb4fae454f7daddf15f8d8ba7e1045681d7768"
41764173
}
41774174
],
41784175
"externalReferences": [
@@ -4182,7 +4179,7 @@
41824179
"comment": "Home page for project"
41834180
},
41844181
{
4185-
"url": "https://pypi.org/project/plotly/6.0.0/#files",
4182+
"url": "https://pypi.org/project/plotly/6.0.1/#files",
41864183
"type": "distribution",
41874184
"comment": "Download location for component"
41884185
},
@@ -4199,11 +4196,11 @@
41994196
"type": "log"
42004197
}
42014198
],
4202-
"purl": "pkg:pypi/[email protected].0",
4199+
"purl": "pkg:pypi/[email protected].1",
42034200
"properties": [
42044201
{
42054202
"name": "release_date",
4206-
"value": "2025-01-28T19:33:47Z"
4203+
"value": "2025-03-17T15:02:18Z"
42074204
},
42084205
{
42094206
"name": "language",
@@ -4219,7 +4216,7 @@
42194216
"type": "library",
42204217
"bom-ref": "65-narwhals",
42214218
"name": "narwhals",
4222-
"version": "1.30.0",
4219+
"version": "1.31.0",
42234220
"supplier": {
42244221
"name": "Marco Gorelli",
42254222
"contact": [
@@ -4228,14 +4225,8 @@
42284225
}
42294226
]
42304227
},
4231-
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:1.30.0:*:*:*:*:*:*:*",
4228+
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:1.31.0:*:*:*:*:*:*:*",
42324229
"description": "Extremely lightweight compatibility layer between dataframe libraries",
4233-
"hashes": [
4234-
{
4235-
"alg": "SHA-256",
4236-
"content": "443aa0a1abfae89bc65a6b888a7e310a03d1818bfb2ccd61c150199a5f954c17"
4237-
}
4238-
],
42394230
"licenses": [
42404231
{
42414232
"license": {
@@ -4252,7 +4243,7 @@
42524243
"comment": "Home page for project"
42534244
},
42544245
{
4255-
"url": "https://pypi.org/project/narwhals/1.30.0/#files",
4246+
"url": "https://pypi.org/project/narwhals/1.31.0/#files",
42564247
"type": "distribution",
42574248
"comment": "Download location for component"
42584249
},
@@ -4269,11 +4260,11 @@
42694260
"type": "issue-tracker"
42704261
}
42714262
],
4272-
"purl": "pkg:pypi/narwhals@1.30.0",
4263+
"purl": "pkg:pypi/narwhals@1.31.0",
42734264
"properties": [
42744265
{
42754266
"name": "release_date",
4276-
"value": "2025-03-10T09:52:54Z"
4267+
"value": "2025-03-17T15:02:18Z"
42774268
},
42784269
{
42794270
"name": "language",
@@ -4613,7 +4604,7 @@
46134604
"type": "library",
46144605
"bom-ref": "71-setuptools",
46154606
"name": "setuptools",
4616-
"version": "76.0.0",
4607+
"version": "77.0.3",
46174608
"supplier": {
46184609
"name": "Python Packaging Authority",
46194610
"contact": [
@@ -4622,14 +4613,8 @@
46224613
}
46234614
]
46244615
},
4625-
"cpe": "cpe:2.3:a:python_packaging_authority:setuptools:76.0.0:*:*:*:*:*:*:*",
4616+
"cpe": "cpe:2.3:a:python_packaging_authority:setuptools:77.0.3:*:*:*:*:*:*:*",
46264617
"description": "Easily download, build, install, upgrade, and uninstall Python packages",
4627-
"hashes": [
4628-
{
4629-
"alg": "SHA-256",
4630-
"content": "199466a166ff664970d0ee145839f5582cb9bca7a0a3a2e795b6a9cb2308e9c6"
4631-
}
4632-
],
46334618
"licenses": [
46344619
{
46354620
"license": {
@@ -4641,7 +4626,7 @@
46414626
],
46424627
"externalReferences": [
46434628
{
4644-
"url": "https://pypi.org/project/setuptools/76.0.0/#files",
4629+
"url": "https://pypi.org/project/setuptools/77.0.3/#files",
46454630
"type": "distribution",
46464631
"comment": "Download location for component"
46474632
},
@@ -4658,11 +4643,11 @@
46584643
"type": "log"
46594644
}
46604645
],
4661-
"purl": "pkg:pypi/setuptools@76.0.0",
4646+
"purl": "pkg:pypi/setuptools@77.0.3",
46624647
"properties": [
46634648
{
46644649
"name": "release_date",
4665-
"value": "2025-03-09T13:59:48Z"
4650+
"value": "2024-07-24T21:57:45Z"
46664651
},
46674652
{
46684653
"name": "language",
@@ -4736,7 +4721,7 @@
47364721
"type": "library",
47374722
"bom-ref": "73-xmlschema",
47384723
"name": "xmlschema",
4739-
"version": "3.4.3",
4724+
"version": "3.4.5",
47404725
"supplier": {
47414726
"name": "Davide Brunato",
47424727
"contact": [
@@ -4745,12 +4730,12 @@
47454730
}
47464731
]
47474732
},
4748-
"cpe": "cpe:2.3:a:davide_brunato:xmlschema:3.4.3:*:*:*:*:*:*:*",
4733+
"cpe": "cpe:2.3:a:davide_brunato:xmlschema:3.4.5:*:*:*:*:*:*:*",
47494734
"description": "An XML Schema validator and decoder",
47504735
"hashes": [
47514736
{
47524737
"alg": "SHA-256",
4753-
"content": "eea4e5a1aac041b546ebe7b2eb68eb5eaebf5c5258e573cfc182375676b2e4e3"
4738+
"content": "c91a2fca387dc4e8a2f2cb4a411ed23bef9da539968e5d858a3fe7f76a65464e"
47544739
}
47554740
],
47564741
"licenses": [
@@ -4769,16 +4754,16 @@
47694754
"comment": "Home page for project"
47704755
},
47714756
{
4772-
"url": "https://pypi.org/project/xmlschema/3.4.3/#files",
4757+
"url": "https://pypi.org/project/xmlschema/3.4.5/#files",
47734758
"type": "distribution",
47744759
"comment": "Download location for component"
47754760
}
47764761
],
4777-
"purl": "pkg:pypi/[email protected].3",
4762+
"purl": "pkg:pypi/[email protected].5",
47784763
"properties": [
47794764
{
47804765
"name": "release_date",
4781-
"value": "2024-10-31T09:47:12Z"
4766+
"value": "2025-03-22T07:56:15Z"
47824767
},
47834768
{
47844769
"name": "language",

0 commit comments

Comments
 (0)