Skip to content

Commit 40bfc9f

Browse files
web-flowgithub-actions[bot]
authored andcommitted
chore: update SBOM for Python 3.11
1 parent d146836 commit 40bfc9f

File tree

2 files changed

+109
-88
lines changed

2 files changed

+109
-88
lines changed

sbom/cve-bin-tool-py3.11.json

Lines changed: 62 additions & 44 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:47e6a14f-10a8-4eb7-966a-331648defc49",
5+
"serialNumber": "urn:uuid:5120ad42-a307-4215-97b3-1c1b4ff43500",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-10-13T00:40:50Z",
8+
"timestamp": "2025-10-27T00:42:37Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -79,12 +79,12 @@
7979
"type": "library",
8080
"bom-ref": "2-aiohttp",
8181
"name": "aiohttp",
82-
"version": "3.13.0",
82+
"version": "3.13.1",
8383
"description": "Async http client/server framework (asyncio)",
8484
"hashes": [
8585
{
8686
"alg": "SHA-256",
87-
"content": "ca69ec38adf5cadcc21d0b25e2144f6a25b7db7bea7e730bac25075bc305eff0"
87+
"content": "2349a6b642020bf20116a8a5c83bae8ba071acf1461c7cbe45fc7fafd552e7e2"
8888
}
8989
],
9090
"licenses": [
@@ -100,7 +100,7 @@
100100
"comment": "Home page for project"
101101
},
102102
{
103-
"url": "https://pypi.org/project/aiohttp/3.13.0/#files",
103+
"url": "https://pypi.org/project/aiohttp/3.13.1/#files",
104104
"type": "distribution",
105105
"comment": "Download location for component"
106106
},
@@ -137,11 +137,11 @@
137137
"type": "vcs"
138138
}
139139
],
140-
"purl": "pkg:pypi/[email protected].0",
140+
"purl": "pkg:pypi/[email protected].1",
141141
"properties": [
142142
{
143143
"name": "release_date",
144-
"value": "2025-10-06T19:54:40Z"
144+
"value": "2025-10-17T13:58:56Z"
145145
},
146146
{
147147
"name": "language",
@@ -305,6 +305,12 @@
305305
"name": "frozenlist",
306306
"version": "1.8.0",
307307
"description": "A list-like structure which implements collections.abc.MutableSequence",
308+
"hashes": [
309+
{
310+
"alg": "SHA-256",
311+
"content": "b37f6d31b3dcea7deb5e9696e529a6aa4a898adc33db82da12e4c60a7c4d2011"
312+
}
313+
],
308314
"licenses": [
309315
{
310316
"license": {
@@ -366,7 +372,7 @@
366372
"properties": [
367373
{
368374
"name": "release_date",
369-
"value": "2025-07-03T22:54:42Z"
375+
"value": "2025-10-06T05:35:23Z"
370376
},
371377
{
372378
"name": "language",
@@ -812,6 +818,12 @@
812818
},
813819
"cpe": "cpe:2.3:a:kim_davies:idna:3.11:*:*:*:*:*:*:*",
814820
"description": "Internationalized Domain Names in Applications (IDNA)",
821+
"hashes": [
822+
{
823+
"alg": "SHA-256",
824+
"content": "771a87f49d9defaf64091e6e6fe9c18d4833f140bd19464795bc32d966ca37ea"
825+
}
826+
],
815827
"externalReferences": [
816828
{
817829
"url": "https://pypi.org/project/idna/3.11/#files",
@@ -835,7 +847,7 @@
835847
"properties": [
836848
{
837849
"name": "release_date",
838-
"value": "2025-10-06T14:08:42Z"
850+
"value": "2025-10-12T14:55:18Z"
839851
},
840852
{
841853
"name": "language",
@@ -1301,7 +1313,7 @@
13011313
"type": "library",
13021314
"bom-ref": "19-argcomplete",
13031315
"name": "argcomplete",
1304-
"version": "3.6.2",
1316+
"version": "3.6.3",
13051317
"supplier": {
13061318
"name": "Andrey Kislyuk",
13071319
"contact": [
@@ -1310,12 +1322,12 @@
13101322
}
13111323
]
13121324
},
1313-
"cpe": "cpe:2.3:a:andrey_kislyuk:argcomplete:3.6.2:*:*:*:*:*:*:*",
1325+
"cpe": "cpe:2.3:a:andrey_kislyuk:argcomplete:3.6.3:*:*:*:*:*:*:*",
13141326
"description": "Bash tab completion for argparse",
13151327
"hashes": [
13161328
{
13171329
"alg": "SHA-256",
1318-
"content": "65b3133a29ad53fb42c48cf5114752c7ab66c1c38544fdf6460f450c09b42591"
1330+
"content": "f5007b3a600ccac5d25bbce33089211dfd49eab4a7718da3f10e3082525a92ce"
13191331
}
13201332
],
13211333
"licenses": [
@@ -1334,7 +1346,7 @@
13341346
"comment": "Home page for project"
13351347
},
13361348
{
1337-
"url": "https://pypi.org/project/argcomplete/3.6.2/#files",
1349+
"url": "https://pypi.org/project/argcomplete/3.6.3/#files",
13381350
"type": "distribution",
13391351
"comment": "Download location for component"
13401352
},
@@ -1355,11 +1367,11 @@
13551367
"type": "log"
13561368
}
13571369
],
1358-
"purl": "pkg:pypi/[email protected].2",
1370+
"purl": "pkg:pypi/[email protected].3",
13591371
"properties": [
13601372
{
13611373
"name": "release_date",
1362-
"value": "2025-04-03T04:57:01Z"
1374+
"value": "2025-10-20T03:33:33Z"
13631375
},
13641376
{
13651377
"name": "language",
@@ -3049,7 +3061,7 @@
30493061
"type": "library",
30503062
"bom-ref": "47-referencing",
30513063
"name": "referencing",
3052-
"version": "0.36.2",
3064+
"version": "0.37.0",
30533065
"supplier": {
30543066
"name": "Julian Berman",
30553067
"contact": [
@@ -3058,12 +3070,12 @@
30583070
}
30593071
]
30603072
},
3061-
"cpe": "cpe:2.3:a:julian_berman:referencing:0.36.2:*:*:*:*:*:*:*",
3073+
"cpe": "cpe:2.3:a:julian_berman:referencing:0.37.0:*:*:*:*:*:*:*",
30623074
"description": "JSON Referencing + Python",
30633075
"hashes": [
30643076
{
30653077
"alg": "SHA-256",
3066-
"content": "e8699adbbf8b5c7de96d8ffa0eb5c158b3beafce084968e2ea8bb08c6794dcd0"
3078+
"content": "381329a9f99628c9069361716891d34ad94af76e461dcb0335825aecc7692231"
30673079
}
30683080
],
30693081
"externalReferences": [
@@ -3073,7 +3085,7 @@
30733085
"comment": "Home page for project"
30743086
},
30753087
{
3076-
"url": "https://pypi.org/project/referencing/0.36.2/#files",
3088+
"url": "https://pypi.org/project/referencing/0.37.0/#files",
30773089
"type": "distribution",
30783090
"comment": "Download location for component"
30793091
},
@@ -3102,11 +3114,11 @@
31023114
"type": "vcs"
31033115
}
31043116
],
3105-
"purl": "pkg:pypi/referencing@0.36.2",
3117+
"purl": "pkg:pypi/referencing@0.37.0",
31063118
"properties": [
31073119
{
31083120
"name": "release_date",
3109-
"value": "2025-01-25T08:48:14Z"
3121+
"value": "2025-10-13T15:30:47Z"
31103122
},
31113123
{
31123124
"name": "language",
@@ -3122,7 +3134,7 @@
31223134
"type": "library",
31233135
"bom-ref": "48-rpds-py",
31243136
"name": "rpds-py",
3125-
"version": "0.27.1",
3137+
"version": "0.28.0",
31263138
"supplier": {
31273139
"name": "Julian Berman",
31283140
"contact": [
@@ -3131,12 +3143,12 @@
31313143
}
31323144
]
31333145
},
3134-
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.27.1:*:*:*:*:*:*:*",
3146+
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.28.0:*:*:*:*:*:*:*",
31353147
"description": "Python bindings to Rust's persistent data structures (rpds)",
31363148
"hashes": [
31373149
{
31383150
"alg": "SHA-256",
3139-
"content": "68afeec26d42ab3b47e541b272166a0b4400313946871cba3ed3a4fc0cab1cef"
3151+
"content": "7b6013db815417eeb56b2d9d7324e64fcd4fa289caeee6e7a78b2e11fc9b438a"
31403152
}
31413153
],
31423154
"externalReferences": [
@@ -3146,7 +3158,7 @@
31463158
"comment": "Home page for project"
31473159
},
31483160
{
3149-
"url": "https://pypi.org/project/rpds-py/0.27.1/#files",
3161+
"url": "https://pypi.org/project/rpds-py/0.28.0/#files",
31503162
"type": "distribution",
31513163
"comment": "Download location for component"
31523164
},
@@ -3175,11 +3187,11 @@
31753187
"type": "other"
31763188
}
31773189
],
3178-
"purl": "pkg:pypi/rpds-py@0.27.1",
3190+
"purl": "pkg:pypi/rpds-py@0.28.0",
31793191
"properties": [
31803192
{
31813193
"name": "release_date",
3182-
"value": "2025-08-27T12:12:25Z"
3194+
"value": "2025-10-22T22:21:15Z"
31833195
},
31843196
{
31853197
"name": "language",
@@ -3455,7 +3467,7 @@
34553467
"type": "library",
34563468
"bom-ref": "53-xmlschema",
34573469
"name": "xmlschema",
3458-
"version": "4.1.0",
3470+
"version": "4.2.0",
34593471
"supplier": {
34603472
"name": "Davide Brunato",
34613473
"contact": [
@@ -3464,12 +3476,12 @@
34643476
}
34653477
]
34663478
},
3467-
"cpe": "cpe:2.3:a:davide_brunato:xmlschema:4.1.0:*:*:*:*:*:*:*",
3479+
"cpe": "cpe:2.3:a:davide_brunato:xmlschema:4.2.0:*:*:*:*:*:*:*",
34683480
"description": "An XML Schema validator and decoder",
34693481
"hashes": [
34703482
{
34713483
"alg": "SHA-256",
3472-
"content": "eabf610f398a58700bc4ac94380ad9ce558297a3f9ca8b7722ed3f7888eb4498"
3484+
"content": "82d24a50eea5e7f2d603312813848cd66fddf8fa2b6730839c6aa3d66312e3b6"
34733485
}
34743486
],
34753487
"externalReferences": [
@@ -3479,16 +3491,16 @@
34793491
"comment": "Home page for project"
34803492
},
34813493
{
3482-
"url": "https://pypi.org/project/xmlschema/4.1.0/#files",
3494+
"url": "https://pypi.org/project/xmlschema/4.2.0/#files",
34833495
"type": "distribution",
34843496
"comment": "Download location for component"
34853497
}
34863498
],
3487-
"purl": "pkg:pypi/xmlschema@4.1.0",
3499+
"purl": "pkg:pypi/xmlschema@4.2.0",
34883500
"properties": [
34893501
{
34903502
"name": "release_date",
3491-
"value": "2025-06-05T21:17:35Z"
3503+
"value": "2025-10-14T09:19:28Z"
34923504
},
34933505
{
34943506
"name": "language",
@@ -4113,7 +4125,7 @@
41134125
"type": "library",
41144126
"bom-ref": "64-narwhals",
41154127
"name": "narwhals",
4116-
"version": "2.7.0",
4128+
"version": "2.9.0",
41174129
"supplier": {
41184130
"name": "Marco Gorelli",
41194131
"contact": [
@@ -4122,8 +4134,14 @@
41224134
}
41234135
]
41244136
},
4125-
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:2.7.0:*:*:*:*:*:*:*",
4137+
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:2.9.0:*:*:*:*:*:*:*",
41264138
"description": "Extremely lightweight compatibility layer between dataframe libraries",
4139+
"hashes": [
4140+
{
4141+
"alg": "SHA-256",
4142+
"content": "c59f7de4763004ae81691ce16df71b4e55aead0ead7ccde8c8f2ef8c9559c765"
4143+
}
4144+
],
41274145
"licenses": [
41284146
{
41294147
"license": {
@@ -4140,7 +4158,7 @@
41404158
"comment": "Home page for project"
41414159
},
41424160
{
4143-
"url": "https://pypi.org/project/narwhals/2.7.0/#files",
4161+
"url": "https://pypi.org/project/narwhals/2.9.0/#files",
41444162
"type": "distribution",
41454163
"comment": "Download location for component"
41464164
},
@@ -4157,11 +4175,11 @@
41574175
"type": "issue-tracker"
41584176
}
41594177
],
4160-
"purl": "pkg:pypi/narwhals@2.7.0",
4178+
"purl": "pkg:pypi/narwhals@2.9.0",
41614179
"properties": [
41624180
{
41634181
"name": "release_date",
4164-
"value": "2025-10-02T16:10:22Z"
4182+
"value": "2025-10-20T12:19:15Z"
41654183
},
41664184
{
41674185
"name": "language",
@@ -4321,7 +4339,7 @@
43214339
"type": "library",
43224340
"bom-ref": "67-charset-normalizer",
43234341
"name": "charset-normalizer",
4324-
"version": "3.4.3",
4342+
"version": "3.4.4",
43254343
"supplier": {
43264344
"name": "Ahmed R .",
43274345
"contact": [
@@ -4330,12 +4348,12 @@
43304348
}
43314349
]
43324350
},
4333-
"cpe": "cpe:2.3:a:ahmed_r.:charset-normalizer:3.4.3:*:*:*:*:*:*:*",
4351+
"cpe": "cpe:2.3:a:ahmed_r.:charset-normalizer:3.4.4:*:*:*:*:*:*:*",
43344352
"description": "The Real First Universal Charset Detector. Open, modern and actively maintained alternative to Chardet.",
43354353
"hashes": [
43364354
{
43374355
"alg": "SHA-256",
4338-
"content": "fb7f67a1bfa6e40b438170ebdc8158b78dc465a5a67b6dde178a46987b244a72"
4356+
"content": "e824f1492727fa856dd6eda4f7cee25f8518a12f3c4a56a74e8095695089cf6d"
43394357
}
43404358
],
43414359
"licenses": [
@@ -4349,7 +4367,7 @@
43494367
],
43504368
"externalReferences": [
43514369
{
4352-
"url": "https://pypi.org/project/charset-normalizer/3.4.3/#files",
4370+
"url": "https://pypi.org/project/charset-normalizer/3.4.4/#files",
43534371
"type": "distribution",
43544372
"comment": "Download location for component"
43554373
},
@@ -4370,11 +4388,11 @@
43704388
"type": "issue-tracker"
43714389
}
43724390
],
4373-
"purl": "pkg:pypi/[email protected].3",
4391+
"purl": "pkg:pypi/[email protected].4",
43744392
"properties": [
43754393
{
43764394
"name": "release_date",
4377-
"value": "2025-08-09T07:55:36Z"
4395+
"value": "2025-10-14T04:40:11Z"
43784396
},
43794397
{
43804398
"name": "language",

0 commit comments

Comments
 (0)