Skip to content

Commit 021fbd7

Browse files
web-flowgithub-actions[bot]
authored andcommitted
chore: update SBOM for Python 3.12
1 parent d146836 commit 021fbd7

File tree

2 files changed

+76
-62
lines changed

2 files changed

+76
-62
lines changed

sbom/cve-bin-tool-py3.12.json

Lines changed: 43 additions & 31 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:c66e1e36-4220-4e10-aad5-162385820f20",
5+
"serialNumber": "urn:uuid:e4e54700-c6e1-4400-a54c-6be3008b48cb",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-10-13T00:40:50Z",
8+
"timestamp": "2025-10-20T00:43:33Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -79,12 +79,12 @@
7979
"type": "library",
8080
"bom-ref": "2-aiohttp",
8181
"name": "aiohttp",
82-
"version": "3.13.0",
82+
"version": "3.13.1",
8383
"description": "Async http client/server framework (asyncio)",
8484
"hashes": [
8585
{
8686
"alg": "SHA-256",
87-
"content": "ca69ec38adf5cadcc21d0b25e2144f6a25b7db7bea7e730bac25075bc305eff0"
87+
"content": "2349a6b642020bf20116a8a5c83bae8ba071acf1461c7cbe45fc7fafd552e7e2"
8888
}
8989
],
9090
"licenses": [
@@ -100,7 +100,7 @@
100100
"comment": "Home page for project"
101101
},
102102
{
103-
"url": "https://pypi.org/project/aiohttp/3.13.0/#files",
103+
"url": "https://pypi.org/project/aiohttp/3.13.1/#files",
104104
"type": "distribution",
105105
"comment": "Download location for component"
106106
},
@@ -137,11 +137,11 @@
137137
"type": "vcs"
138138
}
139139
],
140-
"purl": "pkg:pypi/aiohttp@3.13.0",
140+
"purl": "pkg:pypi/aiohttp@3.13.1",
141141
"properties": [
142142
{
143143
"name": "release_date",
144-
"value": "2025-10-06T19:54:40Z"
144+
"value": "2025-10-17T13:58:56Z"
145145
},
146146
{
147147
"name": "language",
@@ -812,6 +812,12 @@
812812
},
813813
"cpe": "cpe:2.3:a:kim_davies:idna:3.11:*:*:*:*:*:*:*",
814814
"description": "Internationalized Domain Names in Applications (IDNA)",
815+
"hashes": [
816+
{
817+
"alg": "SHA-256",
818+
"content": "771a87f49d9defaf64091e6e6fe9c18d4833f140bd19464795bc32d966ca37ea"
819+
}
820+
],
815821
"externalReferences": [
816822
{
817823
"url": "https://pypi.org/project/idna/3.11/#files",
@@ -835,7 +841,7 @@
835841
"properties": [
836842
{
837843
"name": "release_date",
838-
"value": "2025-10-06T14:08:42Z"
844+
"value": "2025-10-12T14:55:18Z"
839845
},
840846
{
841847
"name": "language",
@@ -3049,7 +3055,7 @@
30493055
"type": "library",
30503056
"bom-ref": "47-referencing",
30513057
"name": "referencing",
3052-
"version": "0.36.2",
3058+
"version": "0.37.0",
30533059
"supplier": {
30543060
"name": "Julian Berman",
30553061
"contact": [
@@ -3058,12 +3064,12 @@
30583064
}
30593065
]
30603066
},
3061-
"cpe": "cpe:2.3:a:julian_berman:referencing:0.36.2:*:*:*:*:*:*:*",
3067+
"cpe": "cpe:2.3:a:julian_berman:referencing:0.37.0:*:*:*:*:*:*:*",
30623068
"description": "JSON Referencing + Python",
30633069
"hashes": [
30643070
{
30653071
"alg": "SHA-256",
3066-
"content": "e8699adbbf8b5c7de96d8ffa0eb5c158b3beafce084968e2ea8bb08c6794dcd0"
3072+
"content": "381329a9f99628c9069361716891d34ad94af76e461dcb0335825aecc7692231"
30673073
}
30683074
],
30693075
"externalReferences": [
@@ -3073,7 +3079,7 @@
30733079
"comment": "Home page for project"
30743080
},
30753081
{
3076-
"url": "https://pypi.org/project/referencing/0.36.2/#files",
3082+
"url": "https://pypi.org/project/referencing/0.37.0/#files",
30773083
"type": "distribution",
30783084
"comment": "Download location for component"
30793085
},
@@ -3102,11 +3108,11 @@
31023108
"type": "vcs"
31033109
}
31043110
],
3105-
"purl": "pkg:pypi/referencing@0.36.2",
3111+
"purl": "pkg:pypi/referencing@0.37.0",
31063112
"properties": [
31073113
{
31083114
"name": "release_date",
3109-
"value": "2025-01-25T08:48:14Z"
3115+
"value": "2025-10-13T15:30:47Z"
31103116
},
31113117
{
31123118
"name": "language",
@@ -3455,7 +3461,7 @@
34553461
"type": "library",
34563462
"bom-ref": "53-xmlschema",
34573463
"name": "xmlschema",
3458-
"version": "4.1.0",
3464+
"version": "4.2.0",
34593465
"supplier": {
34603466
"name": "Davide Brunato",
34613467
"contact": [
@@ -3464,12 +3470,12 @@
34643470
}
34653471
]
34663472
},
3467-
"cpe": "cpe:2.3:a:davide_brunato:xmlschema:4.1.0:*:*:*:*:*:*:*",
3473+
"cpe": "cpe:2.3:a:davide_brunato:xmlschema:4.2.0:*:*:*:*:*:*:*",
34683474
"description": "An XML Schema validator and decoder",
34693475
"hashes": [
34703476
{
34713477
"alg": "SHA-256",
3472-
"content": "eabf610f398a58700bc4ac94380ad9ce558297a3f9ca8b7722ed3f7888eb4498"
3478+
"content": "82d24a50eea5e7f2d603312813848cd66fddf8fa2b6730839c6aa3d66312e3b6"
34733479
}
34743480
],
34753481
"externalReferences": [
@@ -3479,16 +3485,16 @@
34793485
"comment": "Home page for project"
34803486
},
34813487
{
3482-
"url": "https://pypi.org/project/xmlschema/4.1.0/#files",
3488+
"url": "https://pypi.org/project/xmlschema/4.2.0/#files",
34833489
"type": "distribution",
34843490
"comment": "Download location for component"
34853491
}
34863492
],
3487-
"purl": "pkg:pypi/xmlschema@4.1.0",
3493+
"purl": "pkg:pypi/xmlschema@4.2.0",
34883494
"properties": [
34893495
{
34903496
"name": "release_date",
3491-
"value": "2025-06-05T21:17:35Z"
3497+
"value": "2025-10-14T09:19:28Z"
34923498
},
34933499
{
34943500
"name": "language",
@@ -4113,7 +4119,7 @@
41134119
"type": "library",
41144120
"bom-ref": "64-narwhals",
41154121
"name": "narwhals",
4116-
"version": "2.7.0",
4122+
"version": "2.8.0",
41174123
"supplier": {
41184124
"name": "Marco Gorelli",
41194125
"contact": [
@@ -4122,8 +4128,14 @@
41224128
}
41234129
]
41244130
},
4125-
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:2.7.0:*:*:*:*:*:*:*",
4131+
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:2.8.0:*:*:*:*:*:*:*",
41264132
"description": "Extremely lightweight compatibility layer between dataframe libraries",
4133+
"hashes": [
4134+
{
4135+
"alg": "SHA-256",
4136+
"content": "6304856676ba4a79fd34148bda63aed8060dd6edb1227edf3659ce5e091de73c"
4137+
}
4138+
],
41274139
"licenses": [
41284140
{
41294141
"license": {
@@ -4140,7 +4152,7 @@
41404152
"comment": "Home page for project"
41414153
},
41424154
{
4143-
"url": "https://pypi.org/project/narwhals/2.7.0/#files",
4155+
"url": "https://pypi.org/project/narwhals/2.8.0/#files",
41444156
"type": "distribution",
41454157
"comment": "Download location for component"
41464158
},
@@ -4157,11 +4169,11 @@
41574169
"type": "issue-tracker"
41584170
}
41594171
],
4160-
"purl": "pkg:pypi/narwhals@2.7.0",
4172+
"purl": "pkg:pypi/narwhals@2.8.0",
41614173
"properties": [
41624174
{
41634175
"name": "release_date",
4164-
"value": "2025-10-02T16:10:22Z"
4176+
"value": "2025-10-13T08:44:25Z"
41654177
},
41664178
{
41674179
"name": "language",
@@ -4321,7 +4333,7 @@
43214333
"type": "library",
43224334
"bom-ref": "67-charset-normalizer",
43234335
"name": "charset-normalizer",
4324-
"version": "3.4.3",
4336+
"version": "3.4.4",
43254337
"supplier": {
43264338
"name": "Ahmed R .",
43274339
"contact": [
@@ -4330,12 +4342,12 @@
43304342
}
43314343
]
43324344
},
4333-
"cpe": "cpe:2.3:a:ahmed_r.:charset-normalizer:3.4.3:*:*:*:*:*:*:*",
4345+
"cpe": "cpe:2.3:a:ahmed_r.:charset-normalizer:3.4.4:*:*:*:*:*:*:*",
43344346
"description": "The Real First Universal Charset Detector. Open, modern and actively maintained alternative to Chardet.",
43354347
"hashes": [
43364348
{
43374349
"alg": "SHA-256",
4338-
"content": "fb7f67a1bfa6e40b438170ebdc8158b78dc465a5a67b6dde178a46987b244a72"
4350+
"content": "e824f1492727fa856dd6eda4f7cee25f8518a12f3c4a56a74e8095695089cf6d"
43394351
}
43404352
],
43414353
"licenses": [
@@ -4349,7 +4361,7 @@
43494361
],
43504362
"externalReferences": [
43514363
{
4352-
"url": "https://pypi.org/project/charset-normalizer/3.4.3/#files",
4364+
"url": "https://pypi.org/project/charset-normalizer/3.4.4/#files",
43534365
"type": "distribution",
43544366
"comment": "Download location for component"
43554367
},
@@ -4370,11 +4382,11 @@
43704382
"type": "issue-tracker"
43714383
}
43724384
],
4373-
"purl": "pkg:pypi/charset-normalizer@3.4.3",
4385+
"purl": "pkg:pypi/charset-normalizer@3.4.4",
43744386
"properties": [
43754387
{
43764388
"name": "release_date",
4377-
"value": "2025-08-09T07:55:36Z"
4389+
"value": "2025-10-14T04:40:11Z"
43784390
},
43794391
{
43804392
"name": "language",

0 commit comments

Comments
 (0)