Skip to content

Commit b8fcf3b

Browse files
chore: update SBOM for Python 3.13 (#5084)
Co-authored-by: GitHub <[email protected]>
1 parent 07c6aaa commit b8fcf3b

File tree

2 files changed

+76
-83
lines changed

2 files changed

+76
-83
lines changed

sbom/cve-bin-tool-py3.13.json

Lines changed: 38 additions & 44 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:dd8ab0b5-d81e-4731-abe3-cb7c5d6c20ef",
5+
"serialNumber": "urn:uuid:acf1f8fe-ed7e-450d-b176-933d8d4b4632",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-05-12T00:42:32Z",
8+
"timestamp": "2025-05-19T00:44:32Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -2222,7 +2222,7 @@
22222222
"type": "library",
22232223
"bom-ref": "33-pyopenssl",
22242224
"name": "pyopenssl",
2225-
"version": "25.0.0",
2225+
"version": "25.1.0",
22262226
"supplier": {
22272227
"name": "The pyOpenSSL developers",
22282228
"contact": [
@@ -2231,12 +2231,12 @@
22312231
}
22322232
]
22332233
},
2234-
"cpe": "cpe:2.3:a:the_pyopenssl_developers:pyopenssl:25.0.0:*:*:*:*:*:*:*",
2234+
"cpe": "cpe:2.3:a:the_pyopenssl_developers:pyopenssl:25.1.0:*:*:*:*:*:*:*",
22352235
"description": "Python wrapper module around the OpenSSL library",
22362236
"hashes": [
22372237
{
22382238
"alg": "SHA-256",
2239-
"content": "424c247065e46e76a37411b9ab1782541c23bb658bf003772c3405fbaa128e90"
2239+
"content": "2b11f239acc47ac2e5aca04fd7fa829800aeee22a2eb30d744572a157bd8a1ab"
22402240
}
22412241
],
22422242
"licenses": [
@@ -2255,7 +2255,7 @@
22552255
"comment": "Home page for project"
22562256
},
22572257
{
2258-
"url": "https://pypi.org/project/pyopenssl/25.0.0/#files",
2258+
"url": "https://pypi.org/project/pyopenssl/25.1.0/#files",
22592259
"type": "distribution",
22602260
"comment": "Download location for component"
22612261
},
@@ -2264,11 +2264,11 @@
22642264
"type": "vcs"
22652265
}
22662266
],
2267-
"purl": "pkg:pypi/pyopenssl@25.0.0",
2267+
"purl": "pkg:pypi/pyopenssl@25.1.0",
22682268
"properties": [
22692269
{
22702270
"name": "release_date",
2271-
"value": "2025-01-12T17:22:43Z"
2271+
"value": "2025-05-17T16:28:29Z"
22722272
},
22732273
{
22742274
"name": "language",
@@ -2288,7 +2288,7 @@
22882288
"type": "library",
22892289
"bom-ref": "34-cryptography",
22902290
"name": "cryptography",
2291-
"version": "44.0.3",
2291+
"version": "45.0.2",
22922292
"supplier": {
22932293
"name": "The cryptography developers The Python Cryptographic Authority and individual contributors",
22942294
"contact": [
@@ -2297,12 +2297,12 @@
22972297
}
22982298
]
22992299
},
2300-
"cpe": "cpe:2.3:a:the_cryptography_developers_the_python_cryptographic_authority_and_individual_contributors:cryptography:44.0.3:*:*:*:*:*:*:*",
2300+
"cpe": "cpe:2.3:a:the_cryptography_developers_the_python_cryptographic_authority_and_individual_contributors:cryptography:45.0.2:*:*:*:*:*:*:*",
23012301
"description": "cryptography is a package which provides cryptographic recipes and primitives to Python developers.",
23022302
"hashes": [
23032303
{
23042304
"alg": "SHA-256",
2305-
"content": "962bc30480a08d133e631e8dfd4783ab71cc9e33d5d7c1e192f0b7c06397bb88"
2305+
"content": "61a8b1bbddd9332917485b2453d1de49f142e6334ce1d97b7916d5a85d179c84"
23062306
}
23072307
],
23082308
"licenses": [
@@ -2317,7 +2317,7 @@
23172317
"comment": "Home page for project"
23182318
},
23192319
{
2320-
"url": "https://pypi.org/project/cryptography/44.0.3/#files",
2320+
"url": "https://pypi.org/project/cryptography/45.0.2/#files",
23212321
"type": "distribution",
23222322
"comment": "Download location for component"
23232323
},
@@ -2338,11 +2338,11 @@
23382338
"type": "log"
23392339
}
23402340
],
2341-
"purl": "pkg:pypi/cryptography@44.0.3",
2341+
"purl": "pkg:pypi/cryptography@45.0.2",
23422342
"properties": [
23432343
{
23442344
"name": "release_date",
2345-
"value": "2025-05-02T19:34:50Z"
2345+
"value": "2025-05-18T02:45:12Z"
23462346
},
23472347
{
23482348
"name": "language",
@@ -3335,7 +3335,7 @@
33353335
"type": "library",
33363336
"bom-ref": "50-rpds-py",
33373337
"name": "rpds-py",
3338-
"version": "0.24.0",
3338+
"version": "0.25.0",
33393339
"supplier": {
33403340
"name": "Julian Berman",
33413341
"contact": [
@@ -3344,12 +3344,12 @@
33443344
}
33453345
]
33463346
},
3347-
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.24.0:*:*:*:*:*:*:*",
3347+
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.25.0:*:*:*:*:*:*:*",
33483348
"description": "Python bindings to Rust's persistent data structures (rpds)",
33493349
"hashes": [
33503350
{
33513351
"alg": "SHA-256",
3352-
"content": "006f4342fe729a368c6df36578d7a348c7c716be1da0a1a0f86e3021f8e98724"
3352+
"content": "c146a24a8f0dc4a7846fb4640b88b3a68986585b8ce8397af15e66b7c5817439"
33533353
}
33543354
],
33553355
"licenses": [
@@ -3368,7 +3368,7 @@
33683368
"comment": "Home page for project"
33693369
},
33703370
{
3371-
"url": "https://pypi.org/project/rpds-py/0.24.0/#files",
3371+
"url": "https://pypi.org/project/rpds-py/0.25.0/#files",
33723372
"type": "distribution",
33733373
"comment": "Download location for component"
33743374
},
@@ -3397,11 +3397,11 @@
33973397
"type": "other"
33983398
}
33993399
],
3400-
"purl": "pkg:pypi/rpds-py@0.24.0",
3400+
"purl": "pkg:pypi/rpds-py@0.25.0",
34013401
"properties": [
34023402
{
34033403
"name": "release_date",
3404-
"value": "2025-03-26T14:52:41Z"
3404+
"value": "2025-05-15T13:38:11Z"
34053405
},
34063406
{
34073407
"name": "language",
@@ -4109,7 +4109,7 @@
41094109
"type": "library",
41104110
"bom-ref": "62-plotly",
41114111
"name": "plotly",
4112-
"version": "6.0.1",
4112+
"version": "6.1.0",
41134113
"supplier": {
41144114
"name": "Chris P",
41154115
"contact": [
@@ -4118,12 +4118,12 @@
41184118
}
41194119
]
41204120
},
4121-
"cpe": "cpe:2.3:a:chris_p:plotly:6.0.1:*:*:*:*:*:*:*",
4121+
"cpe": "cpe:2.3:a:chris_p:plotly:6.1.0:*:*:*:*:*:*:*",
41224122
"description": "An open-source interactive data visualization library for Python",
41234123
"hashes": [
41244124
{
41254125
"alg": "SHA-256",
4126-
"content": "4714db20fea57a435692c548a4eb4fae454f7daddf15f8d8ba7e1045681d7768"
4126+
"content": "a29d3ed523c9d7960095693af1ee52689830df0f9c6bae3e5e92c20c4f5684c3"
41274127
}
41284128
],
41294129
"externalReferences": [
@@ -4133,7 +4133,7 @@
41334133
"comment": "Home page for project"
41344134
},
41354135
{
4136-
"url": "https://pypi.org/project/plotly/6.0.1/#files",
4136+
"url": "https://pypi.org/project/plotly/6.1.0/#files",
41374137
"type": "distribution",
41384138
"comment": "Download location for component"
41394139
},
@@ -4146,15 +4146,15 @@
41464146
"type": "vcs"
41474147
},
41484148
{
4149-
"url": "https://github.com/plotly/plotly.py/blob/master/CHANGELOG.md",
4149+
"url": "https://github.com/plotly/plotly.py/blob/main/CHANGELOG.md",
41504150
"type": "log"
41514151
}
41524152
],
4153-
"purl": "pkg:pypi/plotly@6.0.1",
4153+
"purl": "pkg:pypi/plotly@6.1.0",
41544154
"properties": [
41554155
{
41564156
"name": "release_date",
4157-
"value": "2025-03-17T15:02:18Z"
4157+
"value": "2025-05-15T16:04:30Z"
41584158
},
41594159
{
41604160
"name": "language",
@@ -4174,7 +4174,7 @@
41744174
"type": "library",
41754175
"bom-ref": "63-narwhals",
41764176
"name": "narwhals",
4177-
"version": "1.38.2",
4177+
"version": "1.39.1",
41784178
"supplier": {
41794179
"name": "Marco Gorelli",
41804180
"contact": [
@@ -4183,12 +4183,12 @@
41834183
}
41844184
]
41854185
},
4186-
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:1.38.2:*:*:*:*:*:*:*",
4186+
"cpe": "cpe:2.3:a:marco_gorelli:narwhals:1.39.1:*:*:*:*:*:*:*",
41874187
"description": "Extremely lightweight compatibility layer between dataframe libraries",
41884188
"hashes": [
41894189
{
41904190
"alg": "SHA-256",
4191-
"content": "a33a182e32f18d794a04e7828a5c401fb26ce9083f609993e7e5064aace641c7"
4191+
"content": "68d0f29c760f1a9419ada537f35f21ff202b0be1419e6d22135a0352c6d96deb"
41924192
}
41934193
],
41944194
"licenses": [
@@ -4207,7 +4207,7 @@
42074207
"comment": "Home page for project"
42084208
},
42094209
{
4210-
"url": "https://pypi.org/project/narwhals/1.38.2/#files",
4210+
"url": "https://pypi.org/project/narwhals/1.39.1/#files",
42114211
"type": "distribution",
42124212
"comment": "Download location for component"
42134213
},
@@ -4224,11 +4224,11 @@
42244224
"type": "issue-tracker"
42254225
}
42264226
],
4227-
"purl": "pkg:pypi/narwhals@1.38.2",
4227+
"purl": "pkg:pypi/narwhals@1.39.1",
42284228
"properties": [
42294229
{
42304230
"name": "release_date",
4231-
"value": "2025-05-08T17:02:25Z"
4231+
"value": "2025-05-15T17:45:07Z"
42324232
},
42334233
{
42344234
"name": "language",
@@ -4637,7 +4637,7 @@
46374637
"type": "library",
46384638
"bom-ref": "70-setuptools",
46394639
"name": "setuptools",
4640-
"version": "80.4.0",
4640+
"version": "80.7.1",
46414641
"supplier": {
46424642
"name": "Python Packaging Authority",
46434643
"contact": [
@@ -4646,17 +4646,11 @@
46464646
}
46474647
]
46484648
},
4649-
"cpe": "cpe:2.3:a:python_packaging_authority:setuptools:80.4.0:*:*:*:*:*:*:*",
4649+
"cpe": "cpe:2.3:a:python_packaging_authority:setuptools:80.7.1:*:*:*:*:*:*:*",
46504650
"description": "Easily download, build, install, upgrade, and uninstall Python packages",
4651-
"hashes": [
4652-
{
4653-
"alg": "SHA-256",
4654-
"content": "6cdc8cb9a7d590b237dbe4493614a9b75d0559b888047c1f67d49ba50fc3edb2"
4655-
}
4656-
],
46574651
"externalReferences": [
46584652
{
4659-
"url": "https://pypi.org/project/setuptools/80.4.0/#files",
4653+
"url": "https://pypi.org/project/setuptools/80.7.1/#files",
46604654
"type": "distribution",
46614655
"comment": "Download location for component"
46624656
},
@@ -4673,11 +4667,11 @@
46734667
"type": "log"
46744668
}
46754669
],
4676-
"purl": "pkg:pypi/setuptools@80.4.0",
4670+
"purl": "pkg:pypi/setuptools@80.7.1",
46774671
"properties": [
46784672
{
46794673
"name": "release_date",
4680-
"value": "2025-05-09T20:42:25Z"
4674+
"value": "2024-07-24T21:57:45Z"
46814675
},
46824676
{
46834677
"name": "language",

0 commit comments

Comments
 (0)