Skip to content

Commit 42bffa6

Browse files
chore: update SBOM for Python 3.10 (#5355)
Co-authored-by: GitHub <[email protected]>
1 parent 25081bd commit 42bffa6

File tree

2 files changed

+23
-23
lines changed

2 files changed

+23
-23
lines changed

sbom/cve-bin-tool-py3.10.json

Lines changed: 14 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:7bd2087d-25dd-411f-a943-a49efb881ae4",
5+
"serialNumber": "urn:uuid:d67b0301-6d9a-4df6-b77a-42346db51561",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-09-15T00:42:54Z",
8+
"timestamp": "2025-09-22T00:46:00Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -2084,7 +2084,7 @@
20842084
"type": "library",
20852085
"bom-ref": "31-pyparsing",
20862086
"name": "pyparsing",
2087-
"version": "3.2.4",
2087+
"version": "3.2.5",
20882088
"supplier": {
20892089
"name": "Paul McGuire",
20902090
"contact": [
@@ -2093,31 +2093,25 @@
20932093
}
20942094
]
20952095
},
2096-
"cpe": "cpe:2.3:a:paul_mcguire:pyparsing:3.2.4:*:*:*:*:*:*:*",
2096+
"cpe": "cpe:2.3:a:paul_mcguire:pyparsing:3.2.5:*:*:*:*:*:*:*",
20972097
"description": "pyparsing - Classes and methods to define and execute parsing grammars",
2098-
"hashes": [
2099-
{
2100-
"alg": "SHA-256",
2101-
"content": "91d0fcde680d42cd031daf3a6ba20da3107e08a75de50da58360e7d94ab24d36"
2102-
}
2103-
],
21042098
"externalReferences": [
21052099
{
21062100
"url": "https://github.com/pyparsing/pyparsing/",
21072101
"type": "website",
21082102
"comment": "Home page for project"
21092103
},
21102104
{
2111-
"url": "https://pypi.org/project/pyparsing/3.2.4/#files",
2105+
"url": "https://pypi.org/project/pyparsing/3.2.5/#files",
21122106
"type": "distribution",
21132107
"comment": "Download location for component"
21142108
}
21152109
],
2116-
"purl": "pkg:pypi/[email protected].4",
2110+
"purl": "pkg:pypi/[email protected].5",
21172111
"properties": [
21182112
{
21192113
"name": "release_date",
2120-
"value": "2025-09-13T05:47:17Z"
2114+
"value": "2022-02-03T00:00:29Z"
21212115
},
21222116
{
21232117
"name": "language",
@@ -4860,6 +4854,12 @@
48604854
},
48614855
"cpe": "cpe:2.3:a:gregory_szorc:zstandard:0.25.0:*:*:*:*:*:*:*",
48624856
"description": "Zstandard bindings for Python",
4857+
"hashes": [
4858+
{
4859+
"alg": "SHA-256",
4860+
"content": "e59fdc271772f6686e01e1b3b74537259800f57e24280be3f29c8a0deb1904dd"
4861+
}
4862+
],
48634863
"externalReferences": [
48644864
{
48654865
"url": "https://github.com/indygreg/python-zstandard",
@@ -4880,7 +4880,7 @@
48804880
"properties": [
48814881
{
48824882
"name": "release_date",
4883-
"value": "2025-06-08T17:06:38Z"
4883+
"value": "2025-09-14T22:15:56Z"
48844884
},
48854885
{
48864886
"name": "language",

sbom/cve-bin-tool-py3.10.spdx

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-305175b4-698a-4d03-9da0-eb3bed5f3688
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-5f495315-237a-40dc-861c-10a1a1ceda44
66
LicenseListVersion: 3.26
77
Creator: Tool: sbom4python-0.12.4
8-
Created: 2025-09-15T00:42:41Z
8+
Created: 2025-09-22T00:45:35Z
99
CreatorComment: <text>SBOM Type: Build - This document has been automatically generated.</text>
1010
#####
1111

@@ -643,20 +643,19 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:joe_gregorio:httplib2:0.20.4:*:*:*:*:*
643643

644644
PackageName: pyparsing
645645
SPDXID: SPDXRef-31-pyparsing
646-
PackageVersion: 3.2.4
646+
PackageVersion: 3.2.5
647647
PrimaryPackagePurpose: LIBRARY
648648
PackageSupplier: Person: Paul McGuire ([email protected])
649-
PackageDownloadLocation: https://pypi.org/project/pyparsing/3.2.4/#files
649+
PackageDownloadLocation: https://pypi.org/project/pyparsing/3.2.5/#files
650650
FilesAnalyzed: false
651651
PackageHomePage: https://github.com/pyparsing/pyparsing/
652-
PackageChecksum: SHA256: 91d0fcde680d42cd031daf3a6ba20da3107e08a75de50da58360e7d94ab24d36
653652
PackageLicenseDeclared: NOASSERTION
654653
PackageLicenseConcluded: NOASSERTION
655654
PackageCopyrightText: NOASSERTION
656655
PackageSummary: <text>pyparsing - Classes and methods to define and execute parsing grammars</text>
657-
ReleaseDate: 2025-09-13T05:47:17Z
658-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].4
659-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:paul_mcguire:pyparsing:3.2.4:*:*:*:*:*:*:*
656+
ReleaseDate: 2022-02-03T00:00:29Z
657+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].5
658+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:paul_mcguire:pyparsing:3.2.5:*:*:*:*:*:*:*
660659
#####
661660

662661
PackageName: oauth2client
@@ -1581,11 +1580,12 @@ PackageSupplier: Person: Gregory Szorc ([email protected])
15811580
PackageDownloadLocation: https://pypi.org/project/zstandard/0.25.0/#files
15821581
FilesAnalyzed: false
15831582
PackageHomePage: https://github.com/indygreg/python-zstandard
1583+
PackageChecksum: SHA256: e59fdc271772f6686e01e1b3b74537259800f57e24280be3f29c8a0deb1904dd
15841584
PackageLicenseDeclared: NOASSERTION
15851585
PackageLicenseConcluded: NOASSERTION
15861586
PackageCopyrightText: NOASSERTION
15871587
PackageSummary: <text>Zstandard bindings for Python</text>
1588-
ReleaseDate: 2025-06-08T17:06:38Z
1588+
ReleaseDate: 2025-09-14T22:15:56Z
15891589
ExternalRef: OTHER documentation https://python-zstandard.readthedocs.io/en/latest/
15901590
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected]
15911591
ExternalRef: SECURITY cpe23Type cpe:2.3:a:gregory_szorc:zstandard:0.25.0:*:*:*:*:*:*:*

0 commit comments

Comments
 (0)