Skip to content

Commit 1290802

Browse files
chore: update SBOM for Python 3.11 (#4824)
Co-authored-by: GitHub <[email protected]>
1 parent ed7f0f6 commit 1290802

File tree

2 files changed

+24
-24
lines changed

2 files changed

+24
-24
lines changed

sbom/cve-bin-tool-py3.11.json

+12-12
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:c48b990b-83ad-4c2f-a385-fbfec8347f47",
5+
"serialNumber": "urn:uuid:40e44969-b259-4931-9ea1-0af3fe41c424",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-02-10T00:36:03Z",
8+
"timestamp": "2025-02-17T00:37:07Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -979,7 +979,7 @@
979979
"type": "library",
980980
"bom-ref": "14-cvss",
981981
"name": "cvss",
982-
"version": "3.3",
982+
"version": "3.4",
983983
"supplier": {
984984
"name": "Stanislav Red Hat Product Security",
985985
"contact": [
@@ -988,12 +988,12 @@
988988
}
989989
]
990990
},
991-
"cpe": "cpe:2.3:a:stanislav_red_hat_product_security:cvss:3.3:*:*:*:*:*:*:*",
991+
"cpe": "cpe:2.3:a:stanislav_red_hat_product_security:cvss:3.4:*:*:*:*:*:*:*",
992992
"description": "CVSS2/3/4 library with interactive calculator for Python 2 and Python 3",
993993
"hashes": [
994994
{
995995
"alg": "SHA-256",
996-
"content": "cc7326afc7585cc63d0a6ca74dab27d74aa2bc99f5f3d5d4bc4d94a3c22bc0a1"
996+
"content": "d9950613758e60820f7fac37ca5f35158712f8f2ea4f6629858a60c4984fe4ef"
997997
}
998998
],
999999
"licenses": [
@@ -1012,7 +1012,7 @@
10121012
"comment": "Home page for project"
10131013
},
10141014
{
1015-
"url": "https://pypi.org/project/cvss/3.3/#files",
1015+
"url": "https://pypi.org/project/cvss/3.4/#files",
10161016
"type": "distribution",
10171017
"comment": "Download location for component"
10181018
},
@@ -1033,11 +1033,11 @@
10331033
"type": "build-system"
10341034
}
10351035
],
1036-
"purl": "pkg:pypi/cvss@3.3",
1036+
"purl": "pkg:pypi/cvss@3.4",
10371037
"properties": [
10381038
{
10391039
"name": "release_date",
1040-
"value": "2024-11-01T10:05:52Z"
1040+
"value": "2025-02-11T17:28:21Z"
10411041
},
10421042
{
10431043
"name": "language",
@@ -4043,7 +4043,7 @@
40434043
"type": "library",
40444044
"bom-ref": "64-narwhals",
40454045
"name": "narwhals",
4046-
"version": "1.25.2",
4046+
"version": "1.26.0",
40474047
"supplier": {
40484048
"name": "Marco Gorelli",
40494049
"contact": [
@@ -4052,7 +4052,7 @@
40524052
}
40534053
]
40544054
},
4055-
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:1.25.2:*:*:*:*:*:*:*",
4055+
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:1.26.0:*:*:*:*:*:*:*",
40564056
"description": "Extremely lightweight compatibility layer between dataframe libraries",
40574057
"externalReferences": [
40584058
{
@@ -4061,7 +4061,7 @@
40614061
"comment": "Home page for project"
40624062
},
40634063
{
4064-
"url": "https://pypi.org/project/narwhals/1.25.2/#files",
4064+
"url": "https://pypi.org/project/narwhals/1.26.0/#files",
40654065
"type": "distribution",
40664066
"comment": "Download location for component"
40674067
},
@@ -4078,7 +4078,7 @@
40784078
"type": "issue-tracker"
40794079
}
40804080
],
4081-
"purl": "pkg:pypi/narwhals@1.25.2",
4081+
"purl": "pkg:pypi/narwhals@1.26.0",
40824082
"properties": [
40834083
{
40844084
"name": "release_date",

sbom/cve-bin-tool-py3.11.spdx

+12-12
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-478d2b06-a80d-4eee-bd62-45fd54106b96
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-5f160352-36eb-4d91-b842-36f9c32fd09d
66
LicenseListVersion: 3.25
77
Creator: Tool: sbom4python-0.12.1
8-
Created: 2025-02-10T00:35:55Z
8+
Created: 2025-02-17T00:37:00Z
99
CreatorComment: <text>This document has been automatically generated.</text>
1010
#####
1111

@@ -311,25 +311,25 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:isaac_muse:soupsieve:2.6:*:*:*:*:*:*:*
311311

312312
PackageName: cvss
313313
SPDXID: SPDXRef-14-cvss
314-
PackageVersion: 3.3
314+
PackageVersion: 3.4
315315
PrimaryPackagePurpose: LIBRARY
316316
PackageSupplier: Organization: Stanislav Red Hat Product Security ([email protected])
317-
PackageDownloadLocation: https://pypi.org/project/cvss/3.3/#files
317+
PackageDownloadLocation: https://pypi.org/project/cvss/3.4/#files
318318
FilesAnalyzed: false
319319
PackageHomePage: https://github.com/RedHatProductSecurity/cvss
320-
PackageChecksum: SHA256: cc7326afc7585cc63d0a6ca74dab27d74aa2bc99f5f3d5d4bc4d94a3c22bc0a1
320+
PackageChecksum: SHA256: d9950613758e60820f7fac37ca5f35158712f8f2ea4f6629858a60c4984fe4ef
321321
PackageLicenseDeclared: NOASSERTION
322322
PackageLicenseConcluded: LGPL-3.0-or-later
323323
PackageLicenseComments: <text>cvss declares LGPLv3+ which is not currently a valid SPDX License identifier or expression.</text>
324324
PackageCopyrightText: NOASSERTION
325325
PackageSummary: <text>CVSS2/3/4 library with interactive calculator for Python 2 and Python 3</text>
326-
ReleaseDate: 2024-11-01T10:05:52Z
326+
ReleaseDate: 2025-02-11T17:28:21Z
327327
ExternalRef: OTHER other https://github.com/RedHatProductSecurity/cvss/releases
328328
ExternalRef: OTHER vcs https://github.com/RedHatProductSecurity/cvss
329329
ExternalRef: OTHER issue-tracker https://github.com/RedHatProductSecurity/cvss/issues
330330
ExternalRef: OTHER build-system https://github.com/RedHatProductSecurity/cvss/actions
331-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/cvss@3.3
332-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:stanislav_red_hat_product_security:cvss:3.3:*:*:*:*:*:*:*
331+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/cvss@3.4
332+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:stanislav_red_hat_product_security:cvss:3.4:*:*:*:*:*:*:*
333333
#####
334334

335335
PackageName: defusedxml
@@ -1331,10 +1331,10 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:6.0.0:*:*:*:*:*:*:*
13311331

13321332
PackageName: narwhals
13331333
SPDXID: SPDXRef-64-narwhals
1334-
PackageVersion: 1.25.2
1334+
PackageVersion: 1.26.0
13351335
PrimaryPackagePurpose: LIBRARY
13361336
PackageSupplier: Person: Marco Gorelli ([email protected])
1337-
PackageDownloadLocation: https://pypi.org/project/narwhals/1.25.2/#files
1337+
PackageDownloadLocation: https://pypi.org/project/narwhals/1.26.0/#files
13381338
FilesAnalyzed: false
13391339
PackageHomePage: https://github.com/narwhals-dev/narwhals
13401340
PackageLicenseDeclared: NOASSERTION
@@ -1345,8 +1345,8 @@ ReleaseDate: 2025-01-28T19:33:47Z
13451345
ExternalRef: OTHER documentation https://narwhals-dev.github.io/narwhals/
13461346
ExternalRef: OTHER vcs https://github.com/narwhals-dev/narwhals
13471347
ExternalRef: OTHER issue-tracker https://github.com/narwhals-dev/narwhals/issues
1348-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@1.25.2
1349-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:1.25.2:*:*:*:*:*:*:*
1348+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@1.26.0
1349+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:1.26.0:*:*:*:*:*:*:*
13501350
#####
13511351

13521352
PackageName: requests

0 commit comments

Comments
 (0)