Skip to content

Commit ba10c86

Browse files
chore: update SBOM for Python 3.12 (#5356)
Co-authored-by: GitHub <[email protected]>
1 parent fd87460 commit ba10c86

File tree

2 files changed

+24
-25
lines changed

2 files changed

+24
-25
lines changed

sbom/cve-bin-tool-py3.12.json

Lines changed: 14 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:80dd078c-5a7c-4c9e-b901-0824b2f1d13b",
5+
"serialNumber": "urn:uuid:70cb2955-4d80-4b60-bc20-887809b6a3ea",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-09-15T00:42:59Z",
8+
"timestamp": "2025-09-22T00:46:01Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -2002,7 +2002,7 @@
20022002
"type": "library",
20032003
"bom-ref": "30-pyparsing",
20042004
"name": "pyparsing",
2005-
"version": "3.2.4",
2005+
"version": "3.2.5",
20062006
"supplier": {
20072007
"name": "Paul McGuire",
20082008
"contact": [
@@ -2011,31 +2011,25 @@
20112011
}
20122012
]
20132013
},
2014-
"cpe": "cpe:2.3:a:paul_mcguire:pyparsing:3.2.4:*:*:*:*:*:*:*",
2014+
"cpe": "cpe:2.3:a:paul_mcguire:pyparsing:3.2.5:*:*:*:*:*:*:*",
20152015
"description": "pyparsing - Classes and methods to define and execute parsing grammars",
2016-
"hashes": [
2017-
{
2018-
"alg": "SHA-256",
2019-
"content": "91d0fcde680d42cd031daf3a6ba20da3107e08a75de50da58360e7d94ab24d36"
2020-
}
2021-
],
20222016
"externalReferences": [
20232017
{
20242018
"url": "https://github.com/pyparsing/pyparsing/",
20252019
"type": "website",
20262020
"comment": "Home page for project"
20272021
},
20282022
{
2029-
"url": "https://pypi.org/project/pyparsing/3.2.4/#files",
2023+
"url": "https://pypi.org/project/pyparsing/3.2.5/#files",
20302024
"type": "distribution",
20312025
"comment": "Download location for component"
20322026
}
20332027
],
2034-
"purl": "pkg:pypi/[email protected].4",
2028+
"purl": "pkg:pypi/[email protected].5",
20352029
"properties": [
20362030
{
20372031
"name": "release_date",
2038-
"value": "2025-09-13T05:47:17Z"
2032+
"value": "2022-02-03T00:00:29Z"
20392033
},
20402034
{
20412035
"name": "language",
@@ -4720,6 +4714,12 @@
47204714
},
47214715
"cpe": "cpe:2.3:a:gregory_szorc:zstandard:0.25.0:*:*:*:*:*:*:*",
47224716
"description": "Zstandard bindings for Python",
4717+
"hashes": [
4718+
{
4719+
"alg": "SHA-256",
4720+
"content": "e59fdc271772f6686e01e1b3b74537259800f57e24280be3f29c8a0deb1904dd"
4721+
}
4722+
],
47234723
"externalReferences": [
47244724
{
47254725
"url": "https://github.com/indygreg/python-zstandard",
@@ -4740,7 +4740,7 @@
47404740
"properties": [
47414741
{
47424742
"name": "release_date",
4743-
"value": "2025-06-08T17:06:38Z"
4743+
"value": "2025-09-14T22:15:56Z"
47444744
},
47454745
{
47464746
"name": "language",

sbom/cve-bin-tool-py3.12.spdx

Lines changed: 10 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-5bd4e1ff-4530-47bf-b2c2-bcd39c9b9b8a
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-33d6d49b-6aff-4c5e-b8c9-d52bbf0a8b69
66
LicenseListVersion: 3.26
77
Creator: Tool: sbom4python-0.12.4
8-
Created: 2025-09-15T00:42:40Z
8+
Created: 2025-09-22T00:45:34Z
99
CreatorComment: <text>SBOM Type: Build - This document has been automatically generated.</text>
1010
#####
1111

@@ -455,12 +455,11 @@ PackageSupplier: Person: Joshua Harlow
455455
PackageDownloadLocation: https://pypi.org/project/fasteners/0.20/#files
456456
FilesAnalyzed: false
457457
PackageHomePage: https://github.com/harlowja/fasteners
458-
PackageChecksum: SHA256: 9422c40d1e350e4259f509fb2e608d6bc43c0136f79a00db1b49046029d0b3b7
459458
PackageLicenseDeclared: NOASSERTION
460459
PackageLicenseConcluded: NOASSERTION
461460
PackageCopyrightText: NOASSERTION
462461
PackageSummary: <text>A python package that provides useful locks</text>
463-
ReleaseDate: 2025-08-11T10:19:35Z
462+
ReleaseDate: 2010-06-27T14:35:29Z
464463
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected]
465464
ExternalRef: SECURITY cpe23Type cpe:2.3:a:joshua_harlow:fasteners:0.20:*:*:*:*:*:*:*
466465
#####
@@ -619,20 +618,19 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:joe_gregorio:httplib2:0.20.4:*:*:*:*:*
619618

620619
PackageName: pyparsing
621620
SPDXID: SPDXRef-30-pyparsing
622-
PackageVersion: 3.2.4
621+
PackageVersion: 3.2.5
623622
PrimaryPackagePurpose: LIBRARY
624623
PackageSupplier: Person: Paul McGuire ([email protected])
625-
PackageDownloadLocation: https://pypi.org/project/pyparsing/3.2.4/#files
624+
PackageDownloadLocation: https://pypi.org/project/pyparsing/3.2.5/#files
626625
FilesAnalyzed: false
627626
PackageHomePage: https://github.com/pyparsing/pyparsing/
628-
PackageChecksum: SHA256: 91d0fcde680d42cd031daf3a6ba20da3107e08a75de50da58360e7d94ab24d36
629627
PackageLicenseDeclared: NOASSERTION
630628
PackageLicenseConcluded: NOASSERTION
631629
PackageCopyrightText: NOASSERTION
632630
PackageSummary: <text>pyparsing - Classes and methods to define and execute parsing grammars</text>
633-
ReleaseDate: 2025-09-13T05:47:17Z
634-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].4
635-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:paul_mcguire:pyparsing:3.2.4:*:*:*:*:*:*:*
631+
ReleaseDate: 2022-02-03T00:00:29Z
632+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].5
633+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:paul_mcguire:pyparsing:3.2.5:*:*:*:*:*:*:*
636634
#####
637635

638636
PackageName: oauth2client
@@ -1539,11 +1537,12 @@ PackageSupplier: Person: Gregory Szorc ([email protected])
15391537
PackageDownloadLocation: https://pypi.org/project/zstandard/0.25.0/#files
15401538
FilesAnalyzed: false
15411539
PackageHomePage: https://github.com/indygreg/python-zstandard
1540+
PackageChecksum: SHA256: e59fdc271772f6686e01e1b3b74537259800f57e24280be3f29c8a0deb1904dd
15421541
PackageLicenseDeclared: NOASSERTION
15431542
PackageLicenseConcluded: NOASSERTION
15441543
PackageCopyrightText: NOASSERTION
15451544
PackageSummary: <text>Zstandard bindings for Python</text>
1546-
ReleaseDate: 2025-06-08T17:06:38Z
1545+
ReleaseDate: 2025-09-14T22:15:56Z
15471546
ExternalRef: OTHER documentation https://python-zstandard.readthedocs.io/en/latest/
15481547
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected]
15491548
ExternalRef: SECURITY cpe23Type cpe:2.3:a:gregory_szorc:zstandard:0.25.0:*:*:*:*:*:*:*

0 commit comments

Comments
 (0)