Skip to content

Commit ea67abd

Browse files
chore: update SBOM for Python 3.12 (#5086)
Co-authored-by: GitHub <[email protected]>
1 parent 9d54ef9 commit ea67abd

File tree

2 files changed

+52
-59
lines changed

2 files changed

+52
-59
lines changed

sbom/cve-bin-tool-py3.12.json

Lines changed: 26 additions & 32 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:c8ad823f-1c6e-40ea-b11e-91a2d6bc3db0",
5+
"serialNumber": "urn:uuid:375c7931-f1b3-4d44-b69e-b28ee4185320",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-05-12T00:42:32Z",
8+
"timestamp": "2025-05-19T00:44:32Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -3335,7 +3335,7 @@
33353335
"type": "library",
33363336
"bom-ref": "50-rpds-py",
33373337
"name": "rpds-py",
3338-
"version": "0.24.0",
3338+
"version": "0.25.0",
33393339
"supplier": {
33403340
"name": "Julian Berman",
33413341
"contact": [
@@ -3344,12 +3344,12 @@
33443344
}
33453345
]
33463346
},
3347-
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.24.0:*:*:*:*:*:*:*",
3347+
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.25.0:*:*:*:*:*:*:*",
33483348
"description": "Python bindings to Rust's persistent data structures (rpds)",
33493349
"hashes": [
33503350
{
33513351
"alg": "SHA-256",
3352-
"content": "006f4342fe729a368c6df36578d7a348c7c716be1da0a1a0f86e3021f8e98724"
3352+
"content": "c146a24a8f0dc4a7846fb4640b88b3a68986585b8ce8397af15e66b7c5817439"
33533353
}
33543354
],
33553355
"licenses": [
@@ -3368,7 +3368,7 @@
33683368
"comment": "Home page for project"
33693369
},
33703370
{
3371-
"url": "https://pypi.org/project/rpds-py/0.24.0/#files",
3371+
"url": "https://pypi.org/project/rpds-py/0.25.0/#files",
33723372
"type": "distribution",
33733373
"comment": "Download location for component"
33743374
},
@@ -3397,11 +3397,11 @@
33973397
"type": "other"
33983398
}
33993399
],
3400-
"purl": "pkg:pypi/rpds-py@0.24.0",
3400+
"purl": "pkg:pypi/rpds-py@0.25.0",
34013401
"properties": [
34023402
{
34033403
"name": "release_date",
3404-
"value": "2025-03-26T14:52:41Z"
3404+
"value": "2025-05-15T13:38:11Z"
34053405
},
34063406
{
34073407
"name": "language",
@@ -4109,7 +4109,7 @@
41094109
"type": "library",
41104110
"bom-ref": "62-plotly",
41114111
"name": "plotly",
4112-
"version": "6.0.1",
4112+
"version": "6.1.0",
41134113
"supplier": {
41144114
"name": "Chris P",
41154115
"contact": [
@@ -4118,12 +4118,12 @@
41184118
}
41194119
]
41204120
},
4121-
"cpe": "cpe:2.3:a:chris_p:plotly:6.0.1:*:*:*:*:*:*:*",
4121+
"cpe": "cpe:2.3:a:chris_p:plotly:6.1.0:*:*:*:*:*:*:*",
41224122
"description": "An open-source interactive data visualization library for Python",
41234123
"hashes": [
41244124
{
41254125
"alg": "SHA-256",
4126-
"content": "4714db20fea57a435692c548a4eb4fae454f7daddf15f8d8ba7e1045681d7768"
4126+
"content": "a29d3ed523c9d7960095693af1ee52689830df0f9c6bae3e5e92c20c4f5684c3"
41274127
}
41284128
],
41294129
"externalReferences": [
@@ -4133,7 +4133,7 @@
41334133
"comment": "Home page for project"
41344134
},
41354135
{
4136-
"url": "https://pypi.org/project/plotly/6.0.1/#files",
4136+
"url": "https://pypi.org/project/plotly/6.1.0/#files",
41374137
"type": "distribution",
41384138
"comment": "Download location for component"
41394139
},
@@ -4146,15 +4146,15 @@
41464146
"type": "vcs"
41474147
},
41484148
{
4149-
"url": "https://github.com/plotly/plotly.py/blob/master/CHANGELOG.md",
4149+
"url": "https://github.com/plotly/plotly.py/blob/main/CHANGELOG.md",
41504150
"type": "log"
41514151
}
41524152
],
4153-
"purl": "pkg:pypi/plotly@6.0.1",
4153+
"purl": "pkg:pypi/plotly@6.1.0",
41544154
"properties": [
41554155
{
41564156
"name": "release_date",
4157-
"value": "2025-03-17T15:02:18Z"
4157+
"value": "2025-05-15T16:04:30Z"
41584158
},
41594159
{
41604160
"name": "language",
@@ -4174,7 +4174,7 @@
41744174
"type": "library",
41754175
"bom-ref": "63-narwhals",
41764176
"name": "narwhals",
4177-
"version": "1.38.2",
4177+
"version": "1.39.1",
41784178
"supplier": {
41794179
"name": "Marco Gorelli",
41804180
"contact": [
@@ -4183,12 +4183,12 @@
41834183
}
41844184
]
41854185
},
4186-
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:1.38.2:*:*:*:*:*:*:*",
4186+
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:1.39.1:*:*:*:*:*:*:*",
41874187
"description": "Extremely lightweight compatibility layer between dataframe libraries",
41884188
"hashes": [
41894189
{
41904190
"alg": "SHA-256",
4191-
"content": "a33a182e32f18d794a04e7828a5c401fb26ce9083f609993e7e5064aace641c7"
4191+
"content": "68d0f29c760f1a9419ada537f35f21ff202b0be1419e6d22135a0352c6d96deb"
41924192
}
41934193
],
41944194
"licenses": [
@@ -4207,7 +4207,7 @@
42074207
"comment": "Home page for project"
42084208
},
42094209
{
4210-
"url": "https://pypi.org/project/narwhals/1.38.2/#files",
4210+
"url": "https://pypi.org/project/narwhals/1.39.1/#files",
42114211
"type": "distribution",
42124212
"comment": "Download location for component"
42134213
},
@@ -4224,11 +4224,11 @@
42244224
"type": "issue-tracker"
42254225
}
42264226
],
4227-
"purl": "pkg:pypi/narwhals@1.38.2",
4227+
"purl": "pkg:pypi/narwhals@1.39.1",
42284228
"properties": [
42294229
{
42304230
"name": "release_date",
4231-
"value": "2025-05-08T17:02:25Z"
4231+
"value": "2025-05-15T17:45:07Z"
42324232
},
42334233
{
42344234
"name": "language",
@@ -4637,7 +4637,7 @@
46374637
"type": "library",
46384638
"bom-ref": "70-setuptools",
46394639
"name": "setuptools",
4640-
"version": "80.4.0",
4640+
"version": "80.7.1",
46414641
"supplier": {
46424642
"name": "Python Packaging Authority",
46434643
"contact": [
@@ -4646,17 +4646,11 @@
46464646
}
46474647
]
46484648
},
4649-
"cpe": "cpe:2.3:a:python_packaging_authority:setuptools:80.4.0:*:*:*:*:*:*:*",
4649+
"cpe": "cpe:2.3:a:python_packaging_authority:setuptools:80.7.1:*:*:*:*:*:*:*",
46504650
"description": "Easily download, build, install, upgrade, and uninstall Python packages",
4651-
"hashes": [
4652-
{
4653-
"alg": "SHA-256",
4654-
"content": "6cdc8cb9a7d590b237dbe4493614a9b75d0559b888047c1f67d49ba50fc3edb2"
4655-
}
4656-
],
46574651
"externalReferences": [
46584652
{
4659-
"url": "https://pypi.org/project/setuptools/80.4.0/#files",
4653+
"url": "https://pypi.org/project/setuptools/80.7.1/#files",
46604654
"type": "distribution",
46614655
"comment": "Download location for component"
46624656
},
@@ -4673,11 +4667,11 @@
46734667
"type": "log"
46744668
}
46754669
],
4676-
"purl": "pkg:pypi/setuptools@80.4.0",
4670+
"purl": "pkg:pypi/setuptools@80.7.1",
46774671
"properties": [
46784672
{
46794673
"name": "release_date",
4680-
"value": "2025-05-09T20:42:25Z"
4674+
"value": "2024-07-24T21:57:45Z"
46814675
},
46824676
{
46834677
"name": "language",

sbom/cve-bin-tool-py3.12.spdx

Lines changed: 26 additions & 27 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-0cd5b59c-16bd-45cc-b896-dbfc4a2479c1
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-a8082802-8577-4ddc-9116-43cc8776ba73
66
LicenseListVersion: 3.25
77
Creator: Tool: sbom4python-0.12.3
8-
Created: 2025-05-12T00:42:26Z
8+
Created: 2025-05-19T00:44:21Z
99
CreatorComment: <text>SBOM Type: Build - This document has been automatically generated.</text>
1010
#####
1111

@@ -1058,26 +1058,26 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:referencing:0.36.2:*:*:*
10581058

10591059
PackageName: rpds-py
10601060
SPDXID: SPDXRef-50-rpds-py
1061-
PackageVersion: 0.24.0
1061+
PackageVersion: 0.25.0
10621062
PrimaryPackagePurpose: LIBRARY
10631063
PackageSupplier: Person: Julian Berman ([email protected])
1064-
PackageDownloadLocation: https://pypi.org/project/rpds-py/0.24.0/#files
1064+
PackageDownloadLocation: https://pypi.org/project/rpds-py/0.25.0/#files
10651065
FilesAnalyzed: false
10661066
PackageHomePage: https://github.com/crate-py/rpds
1067-
PackageChecksum: SHA256: 006f4342fe729a368c6df36578d7a348c7c716be1da0a1a0f86e3021f8e98724
1067+
PackageChecksum: SHA256: c146a24a8f0dc4a7846fb4640b88b3a68986585b8ce8397af15e66b7c5817439
10681068
PackageLicenseDeclared: MIT
10691069
PackageLicenseConcluded: MIT
10701070
PackageCopyrightText: NOASSERTION
10711071
PackageSummary: <text>Python bindings to Rust's persistent data structures (rpds)</text>
1072-
ReleaseDate: 2025-03-26T14:52:41Z
1072+
ReleaseDate: 2025-05-15T13:38:11Z
10731073
ExternalRef: OTHER documentation https://rpds.readthedocs.io/
10741074
ExternalRef: OTHER issue-tracker https://github.com/crate-py/rpds/issues/
10751075
ExternalRef: OTHER other https://github.com/sponsors/Julian
10761076
ExternalRef: OTHER other https://tidelift.com/subscription/pkg/pypi-rpds-py?utm_source=pypi-rpds-py&utm_medium=referral&utm_campaign=pypi-link
10771077
ExternalRef: OTHER vcs https://github.com/crate-py/rpds
10781078
ExternalRef: OTHER other https://github.com/orium/rpds
1079-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rpds-py@0.24.0
1080-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.24.0:*:*:*:*:*:*:*
1079+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rpds-py@0.25.0
1080+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.25.0:*:*:*:*:*:*:*
10811081
#####
10821082

10831083
PackageName: lib4sbom
@@ -1296,13 +1296,13 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:donald_stufft:packaging:25.0:*:*:*:*:*
12961296

12971297
PackageName: plotly
12981298
SPDXID: SPDXRef-62-plotly
1299-
PackageVersion: 6.0.1
1299+
PackageVersion: 6.1.0
13001300
PrimaryPackagePurpose: LIBRARY
13011301
PackageSupplier: Person: Chris P ([email protected])
1302-
PackageDownloadLocation: https://pypi.org/project/plotly/6.0.1/#files
1302+
PackageDownloadLocation: https://pypi.org/project/plotly/6.1.0/#files
13031303
FilesAnalyzed: false
13041304
PackageHomePage: https://plotly.com/python/
1305-
PackageChecksum: SHA256: 4714db20fea57a435692c548a4eb4fae454f7daddf15f8d8ba7e1045681d7768
1305+
PackageChecksum: SHA256: a29d3ed523c9d7960095693af1ee52689830df0f9c6bae3e5e92c20c4f5684c3
13061306
PackageLicenseDeclared: NOASSERTION
13071307
PackageLicenseConcluded: NOASSERTION
13081308
PackageLicenseComments: <text>plotly declares MIT License
@@ -1329,34 +1329,34 @@ THE SOFTWARE.
13291329
which is not currently a valid SPDX License identifier or expression.</text>
13301330
PackageCopyrightText: NOASSERTION
13311331
PackageSummary: <text>An open-source interactive data visualization library for Python</text>
1332-
ReleaseDate: 2025-03-17T15:02:18Z
1332+
ReleaseDate: 2025-05-15T16:04:30Z
13331333
ExternalRef: OTHER documentation https://plotly.com/python/
13341334
ExternalRef: OTHER vcs https://github.com/plotly/plotly.py
1335-
ExternalRef: OTHER log https://github.com/plotly/plotly.py/blob/master/CHANGELOG.md
1336-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/plotly@6.0.1
1337-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:6.0.1:*:*:*:*:*:*:*
1335+
ExternalRef: OTHER log https://github.com/plotly/plotly.py/blob/main/CHANGELOG.md
1336+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/plotly@6.1.0
1337+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:6.1.0:*:*:*:*:*:*:*
13381338
#####
13391339

13401340
PackageName: narwhals
13411341
SPDXID: SPDXRef-63-narwhals
1342-
PackageVersion: 1.38.2
1342+
PackageVersion: 1.39.1
13431343
PrimaryPackagePurpose: LIBRARY
13441344
PackageSupplier: Person: Marco Gorelli ([email protected])
1345-
PackageDownloadLocation: https://pypi.org/project/narwhals/1.38.2/#files
1345+
PackageDownloadLocation: https://pypi.org/project/narwhals/1.39.1/#files
13461346
FilesAnalyzed: false
13471347
PackageHomePage: https://github.com/narwhals-dev/narwhals
1348-
PackageChecksum: SHA256: a33a182e32f18d794a04e7828a5c401fb26ce9083f609993e7e5064aace641c7
1348+
PackageChecksum: SHA256: 68d0f29c760f1a9419ada537f35f21ff202b0be1419e6d22135a0352c6d96deb
13491349
PackageLicenseDeclared: NOASSERTION
13501350
PackageLicenseConcluded: MIT
13511351
PackageLicenseComments: <text>narwhals declares MIT License which is not currently a valid SPDX License identifier or expression.</text>
13521352
PackageCopyrightText: NOASSERTION
13531353
PackageSummary: <text>Extremely lightweight compatibility layer between dataframe libraries</text>
1354-
ReleaseDate: 2025-05-08T17:02:25Z
1354+
ReleaseDate: 2025-05-15T17:45:07Z
13551355
ExternalRef: OTHER documentation https://narwhals-dev.github.io/narwhals/
13561356
ExternalRef: OTHER vcs https://github.com/narwhals-dev/narwhals
13571357
ExternalRef: OTHER issue-tracker https://github.com/narwhals-dev/narwhals/issues
1358-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@1.38.2
1359-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:1.38.2:*:*:*:*:*:*:*
1358+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@1.39.1
1359+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:1.39.1:*:*:*:*:*:*:*
13601360
#####
13611361

13621362
PackageName: python-gnupg
@@ -1482,22 +1482,21 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:sean_ross:rpmfile:2.1.0:*:*:*:*:*:*:*
14821482

14831483
PackageName: setuptools
14841484
SPDXID: SPDXRef-70-setuptools
1485-
PackageVersion: 80.4.0
1485+
PackageVersion: 80.7.1
14861486
PrimaryPackagePurpose: LIBRARY
14871487
PackageSupplier: Organization: Python Packaging Authority ([email protected])
1488-
PackageDownloadLocation: https://pypi.org/project/setuptools/80.4.0/#files
1488+
PackageDownloadLocation: https://pypi.org/project/setuptools/80.7.1/#files
14891489
FilesAnalyzed: false
1490-
PackageChecksum: SHA256: 6cdc8cb9a7d590b237dbe4493614a9b75d0559b888047c1f67d49ba50fc3edb2
14911490
PackageLicenseDeclared: NOASSERTION
14921491
PackageLicenseConcluded: NOASSERTION
14931492
PackageCopyrightText: NOASSERTION
14941493
PackageSummary: <text>Easily download, build, install, upgrade, and uninstall Python packages</text>
1495-
ReleaseDate: 2025-05-09T20:42:25Z
1494+
ReleaseDate: 2024-07-24T21:57:45Z
14961495
ExternalRef: OTHER vcs https://github.com/pypa/setuptools
14971496
ExternalRef: OTHER documentation https://setuptools.pypa.io/
14981497
ExternalRef: OTHER log https://setuptools.pypa.io/en/stable/history.html
1499-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/setuptools@80.4.0
1500-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:python_packaging_authority:setuptools:80.4.0:*:*:*:*:*:*:*
1498+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/setuptools@80.7.1
1499+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:python_packaging_authority:setuptools:80.7.1:*:*:*:*:*:*:*
15011500
#####
15021501

15031502
PackageName: xmlschema

0 commit comments

Comments
 (0)