Skip to content

Commit 039d8e0

Browse files
web-flowgithub-actions[bot]
authored andcommitted
chore: update SBOM for Python 3.10
1 parent d146836 commit 039d8e0

File tree

2 files changed

+109
-88
lines changed

2 files changed

+109
-88
lines changed

sbom/cve-bin-tool-py3.10.json

Lines changed: 62 additions & 44 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:6ce0712e-57c1-4da1-8f57-ae9246ca17c5",
5+
"serialNumber": "urn:uuid:6cd8705c-68f2-410a-94eb-f6a8f2e5ac7f",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-10-13T00:45:34Z",
8+
"timestamp": "2025-10-27T00:42:37Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -79,12 +79,12 @@
7979
"type": "library",
8080
"bom-ref": "2-aiohttp",
8181
"name": "aiohttp",
82-
"version": "3.13.0",
82+
"version": "3.13.1",
8383
"description": "Async http client/server framework (asyncio)",
8484
"hashes": [
8585
{
8686
"alg": "SHA-256",
87-
"content": "ca69ec38adf5cadcc21d0b25e2144f6a25b7db7bea7e730bac25075bc305eff0"
87+
"content": "2349a6b642020bf20116a8a5c83bae8ba071acf1461c7cbe45fc7fafd552e7e2"
8888
}
8989
],
9090
"licenses": [
@@ -100,7 +100,7 @@
100100
"comment": "Home page for project"
101101
},
102102
{
103-
"url": "https://pypi.org/project/aiohttp/3.13.0/#files",
103+
"url": "https://pypi.org/project/aiohttp/3.13.1/#files",
104104
"type": "distribution",
105105
"comment": "Download location for component"
106106
},
@@ -137,11 +137,11 @@
137137
"type": "vcs"
138138
}
139139
],
140-
"purl": "pkg:pypi/aiohttp@3.13.0",
140+
"purl": "pkg:pypi/aiohttp@3.13.1",
141141
"properties": [
142142
{
143143
"name": "release_date",
144-
"value": "2025-10-06T19:54:40Z"
144+
"value": "2025-10-17T13:58:56Z"
145145
},
146146
{
147147
"name": "language",
@@ -305,6 +305,12 @@
305305
"name": "frozenlist",
306306
"version": "1.8.0",
307307
"description": "A list-like structure which implements collections.abc.MutableSequence",
308+
"hashes": [
309+
{
310+
"alg": "SHA-256",
311+
"content": "b37f6d31b3dcea7deb5e9696e529a6aa4a898adc33db82da12e4c60a7c4d2011"
312+
}
313+
],
308314
"licenses": [
309315
{
310316
"license": {
@@ -366,7 +372,7 @@
366372
"properties": [
367373
{
368374
"name": "release_date",
369-
"value": "2025-07-03T22:54:42Z"
375+
"value": "2025-10-06T05:35:23Z"
370376
},
371377
{
372378
"name": "language",
@@ -894,6 +900,12 @@
894900
},
895901
"cpe": "cpe:2.3:a:kim_davies:idna:3.11:*:*:*:*:*:*:*",
896902
"description": "Internationalized Domain Names in Applications (IDNA)",
903+
"hashes": [
904+
{
905+
"alg": "SHA-256",
906+
"content": "771a87f49d9defaf64091e6e6fe9c18d4833f140bd19464795bc32d966ca37ea"
907+
}
908+
],
897909
"externalReferences": [
898910
{
899911
"url": "https://pypi.org/project/idna/3.11/#files",
@@ -917,7 +929,7 @@
917929
"properties": [
918930
{
919931
"name": "release_date",
920-
"value": "2025-10-06T14:08:42Z"
932+
"value": "2025-10-12T14:55:18Z"
921933
},
922934
{
923935
"name": "language",
@@ -1383,7 +1395,7 @@
13831395
"type": "library",
13841396
"bom-ref": "20-argcomplete",
13851397
"name": "argcomplete",
1386-
"version": "3.6.2",
1398+
"version": "3.6.3",
13871399
"supplier": {
13881400
"name": "Andrey Kislyuk",
13891401
"contact": [
@@ -1392,12 +1404,12 @@
13921404
}
13931405
]
13941406
},
1395-
"cpe": "cpe:2.3:a:andrey_kislyuk:argcomplete:3.6.2:*:*:*:*:*:*:*",
1407+
"cpe": "cpe:2.3:a:andrey_kislyuk:argcomplete:3.6.3:*:*:*:*:*:*:*",
13961408
"description": "Bash tab completion for argparse",
13971409
"hashes": [
13981410
{
13991411
"alg": "SHA-256",
1400-
"content": "65b3133a29ad53fb42c48cf5114752c7ab66c1c38544fdf6460f450c09b42591"
1412+
"content": "f5007b3a600ccac5d25bbce33089211dfd49eab4a7718da3f10e3082525a92ce"
14011413
}
14021414
],
14031415
"licenses": [
@@ -1416,7 +1428,7 @@
14161428
"comment": "Home page for project"
14171429
},
14181430
{
1419-
"url": "https://pypi.org/project/argcomplete/3.6.2/#files",
1431+
"url": "https://pypi.org/project/argcomplete/3.6.3/#files",
14201432
"type": "distribution",
14211433
"comment": "Download location for component"
14221434
},
@@ -1437,11 +1449,11 @@
14371449
"type": "log"
14381450
}
14391451
],
1440-
"purl": "pkg:pypi/argcomplete@3.6.2",
1452+
"purl": "pkg:pypi/argcomplete@3.6.3",
14411453
"properties": [
14421454
{
14431455
"name": "release_date",
1444-
"value": "2025-04-03T04:57:01Z"
1456+
"value": "2025-10-20T03:33:33Z"
14451457
},
14461458
{
14471459
"name": "language",
@@ -3131,7 +3143,7 @@
31313143
"type": "library",
31323144
"bom-ref": "48-referencing",
31333145
"name": "referencing",
3134-
"version": "0.36.2",
3146+
"version": "0.37.0",
31353147
"supplier": {
31363148
"name": "Julian Berman",
31373149
"contact": [
@@ -3140,12 +3152,12 @@
31403152
}
31413153
]
31423154
},
3143-
"cpe": "cpe:2.3:a:julian_berman:referencing:0.36.2:*:*:*:*:*:*:*",
3155+
"cpe": "cpe:2.3:a:julian_berman:referencing:0.37.0:*:*:*:*:*:*:*",
31443156
"description": "JSON Referencing + Python",
31453157
"hashes": [
31463158
{
31473159
"alg": "SHA-256",
3148-
"content": "e8699adbbf8b5c7de96d8ffa0eb5c158b3beafce084968e2ea8bb08c6794dcd0"
3160+
"content": "381329a9f99628c9069361716891d34ad94af76e461dcb0335825aecc7692231"
31493161
}
31503162
],
31513163
"externalReferences": [
@@ -3155,7 +3167,7 @@
31553167
"comment": "Home page for project"
31563168
},
31573169
{
3158-
"url": "https://pypi.org/project/referencing/0.36.2/#files",
3170+
"url": "https://pypi.org/project/referencing/0.37.0/#files",
31593171
"type": "distribution",
31603172
"comment": "Download location for component"
31613173
},
@@ -3184,11 +3196,11 @@
31843196
"type": "vcs"
31853197
}
31863198
],
3187-
"purl": "pkg:pypi/referencing@0.36.2",
3199+
"purl": "pkg:pypi/referencing@0.37.0",
31883200
"properties": [
31893201
{
31903202
"name": "release_date",
3191-
"value": "2025-01-25T08:48:14Z"
3203+
"value": "2025-10-13T15:30:47Z"
31923204
},
31933205
{
31943206
"name": "language",
@@ -3204,7 +3216,7 @@
32043216
"type": "library",
32053217
"bom-ref": "49-rpds-py",
32063218
"name": "rpds-py",
3207-
"version": "0.27.1",
3219+
"version": "0.28.0",
32083220
"supplier": {
32093221
"name": "Julian Berman",
32103222
"contact": [
@@ -3213,12 +3225,12 @@
32133225
}
32143226
]
32153227
},
3216-
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.27.1:*:*:*:*:*:*:*",
3228+
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.28.0:*:*:*:*:*:*:*",
32173229
"description": "Python bindings to Rust's persistent data structures (rpds)",
32183230
"hashes": [
32193231
{
32203232
"alg": "SHA-256",
3221-
"content": "68afeec26d42ab3b47e541b272166a0b4400313946871cba3ed3a4fc0cab1cef"
3233+
"content": "7b6013db815417eeb56b2d9d7324e64fcd4fa289caeee6e7a78b2e11fc9b438a"
32223234
}
32233235
],
32243236
"externalReferences": [
@@ -3228,7 +3240,7 @@
32283240
"comment": "Home page for project"
32293241
},
32303242
{
3231-
"url": "https://pypi.org/project/rpds-py/0.27.1/#files",
3243+
"url": "https://pypi.org/project/rpds-py/0.28.0/#files",
32323244
"type": "distribution",
32333245
"comment": "Download location for component"
32343246
},
@@ -3257,11 +3269,11 @@
32573269
"type": "other"
32583270
}
32593271
],
3260-
"purl": "pkg:pypi/rpds-py@0.27.1",
3272+
"purl": "pkg:pypi/rpds-py@0.28.0",
32613273
"properties": [
32623274
{
32633275
"name": "release_date",
3264-
"value": "2025-08-27T12:12:25Z"
3276+
"value": "2025-10-22T22:21:15Z"
32653277
},
32663278
{
32673279
"name": "language",
@@ -3537,7 +3549,7 @@
35373549
"type": "library",
35383550
"bom-ref": "54-xmlschema",
35393551
"name": "xmlschema",
3540-
"version": "4.1.0",
3552+
"version": "4.2.0",
35413553
"supplier": {
35423554
"name": "Davide Brunato",
35433555
"contact": [
@@ -3546,12 +3558,12 @@
35463558
}
35473559
]
35483560
},
3549-
"cpe": "cpe:2.3:a:davide_brunato:xmlschema:4.1.0:*:*:*:*:*:*:*",
3561+
"cpe": "cpe:2.3:a:davide_brunato:xmlschema:4.2.0:*:*:*:*:*:*:*",
35503562
"description": "An XML Schema validator and decoder",
35513563
"hashes": [
35523564
{
35533565
"alg": "SHA-256",
3554-
"content": "eabf610f398a58700bc4ac94380ad9ce558297a3f9ca8b7722ed3f7888eb4498"
3566+
"content": "82d24a50eea5e7f2d603312813848cd66fddf8fa2b6730839c6aa3d66312e3b6"
35553567
}
35563568
],
35573569
"externalReferences": [
@@ -3561,16 +3573,16 @@
35613573
"comment": "Home page for project"
35623574
},
35633575
{
3564-
"url": "https://pypi.org/project/xmlschema/4.1.0/#files",
3576+
"url": "https://pypi.org/project/xmlschema/4.2.0/#files",
35653577
"type": "distribution",
35663578
"comment": "Download location for component"
35673579
}
35683580
],
3569-
"purl": "pkg:pypi/xmlschema@4.1.0",
3581+
"purl": "pkg:pypi/xmlschema@4.2.0",
35703582
"properties": [
35713583
{
35723584
"name": "release_date",
3573-
"value": "2025-06-05T21:17:35Z"
3585+
"value": "2025-10-14T09:19:28Z"
35743586
},
35753587
{
35763588
"name": "language",
@@ -4195,7 +4207,7 @@
41954207
"type": "library",
41964208
"bom-ref": "65-narwhals",
41974209
"name": "narwhals",
4198-
"version": "2.7.0",
4210+
"version": "2.9.0",
41994211
"supplier": {
42004212
"name": "Marco Gorelli",
42014213
"contact": [
@@ -4204,8 +4216,14 @@
42044216
}
42054217
]
42064218
},
4207-
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:2.7.0:*:*:*:*:*:*:*",
4219+
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:2.9.0:*:*:*:*:*:*:*",
42084220
"description": "Extremely lightweight compatibility layer between dataframe libraries",
4221+
"hashes": [
4222+
{
4223+
"alg": "SHA-256",
4224+
"content": "c59f7de4763004ae81691ce16df71b4e55aead0ead7ccde8c8f2ef8c9559c765"
4225+
}
4226+
],
42094227
"licenses": [
42104228
{
42114229
"license": {
@@ -4222,7 +4240,7 @@
42224240
"comment": "Home page for project"
42234241
},
42244242
{
4225-
"url": "https://pypi.org/project/narwhals/2.7.0/#files",
4243+
"url": "https://pypi.org/project/narwhals/2.9.0/#files",
42264244
"type": "distribution",
42274245
"comment": "Download location for component"
42284246
},
@@ -4239,11 +4257,11 @@
42394257
"type": "issue-tracker"
42404258
}
42414259
],
4242-
"purl": "pkg:pypi/narwhals@2.7.0",
4260+
"purl": "pkg:pypi/narwhals@2.9.0",
42434261
"properties": [
42444262
{
42454263
"name": "release_date",
4246-
"value": "2025-10-02T16:10:22Z"
4264+
"value": "2025-10-20T12:19:15Z"
42474265
},
42484266
{
42494267
"name": "language",
@@ -4403,7 +4421,7 @@
44034421
"type": "library",
44044422
"bom-ref": "68-charset-normalizer",
44054423
"name": "charset-normalizer",
4406-
"version": "3.4.3",
4424+
"version": "3.4.4",
44074425
"supplier": {
44084426
"name": "Ahmed R .",
44094427
"contact": [
@@ -4412,12 +4430,12 @@
44124430
}
44134431
]
44144432
},
4415-
"cpe": "cpe:2.3:a:ahmed_r.:charset-normalizer:3.4.3:*:*:*:*:*:*:*",
4433+
"cpe": "cpe:2.3:a:ahmed_r.:charset-normalizer:3.4.4:*:*:*:*:*:*:*",
44164434
"description": "The Real First Universal Charset Detector. Open, modern and actively maintained alternative to Chardet.",
44174435
"hashes": [
44184436
{
44194437
"alg": "SHA-256",
4420-
"content": "fb7f67a1bfa6e40b438170ebdc8158b78dc465a5a67b6dde178a46987b244a72"
4438+
"content": "e824f1492727fa856dd6eda4f7cee25f8518a12f3c4a56a74e8095695089cf6d"
44214439
}
44224440
],
44234441
"licenses": [
@@ -4431,7 +4449,7 @@
44314449
],
44324450
"externalReferences": [
44334451
{
4434-
"url": "https://pypi.org/project/charset-normalizer/3.4.3/#files",
4452+
"url": "https://pypi.org/project/charset-normalizer/3.4.4/#files",
44354453
"type": "distribution",
44364454
"comment": "Download location for component"
44374455
},
@@ -4452,11 +4470,11 @@
44524470
"type": "issue-tracker"
44534471
}
44544472
],
4455-
"purl": "pkg:pypi/charset-normalizer@3.4.3",
4473+
"purl": "pkg:pypi/charset-normalizer@3.4.4",
44564474
"properties": [
44574475
{
44584476
"name": "release_date",
4459-
"value": "2025-08-09T07:55:36Z"
4477+
"value": "2025-10-14T04:40:11Z"
44604478
},
44614479
{
44624480
"name": "language",

0 commit comments

Comments
 (0)