Skip to content

Commit f48b672

Browse files
chore: update SBOM for Python 3.13 (#5354)
Co-authored-by: GitHub <[email protected]>
1 parent ba10c86 commit f48b672

File tree

2 files changed

+23
-23
lines changed

2 files changed

+23
-23
lines changed

sbom/cve-bin-tool-py3.13.json

Lines changed: 14 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.6",
5-
"serialNumber": "urn:uuid:fe5225ad-8d82-41ad-b1e0-aa0b1294f956",
5+
"serialNumber": "urn:uuid:8e073784-8a9b-46fe-8a88-6ddf94534847",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2025-09-15T00:43:01Z",
8+
"timestamp": "2025-09-22T00:45:57Z",
99
"lifecycles": [
1010
{
1111
"phase": "build"
@@ -2002,7 +2002,7 @@
20022002
"type": "library",
20032003
"bom-ref": "30-pyparsing",
20042004
"name": "pyparsing",
2005-
"version": "3.2.4",
2005+
"version": "3.2.5",
20062006
"supplier": {
20072007
"name": "Paul McGuire",
20082008
"contact": [
@@ -2011,31 +2011,25 @@
20112011
}
20122012
]
20132013
},
2014-
"cpe": "cpe:2.3:a:paul_mcguire:pyparsing:3.2.4:*:*:*:*:*:*:*",
2014+
"cpe": "cpe:2.3:a:paul_mcguire:pyparsing:3.2.5:*:*:*:*:*:*:*",
20152015
"description": "pyparsing - Classes and methods to define and execute parsing grammars",
2016-
"hashes": [
2017-
{
2018-
"alg": "SHA-256",
2019-
"content": "91d0fcde680d42cd031daf3a6ba20da3107e08a75de50da58360e7d94ab24d36"
2020-
}
2021-
],
20222016
"externalReferences": [
20232017
{
20242018
"url": "https://github.com/pyparsing/pyparsing/",
20252019
"type": "website",
20262020
"comment": "Home page for project"
20272021
},
20282022
{
2029-
"url": "https://pypi.org/project/pyparsing/3.2.4/#files",
2023+
"url": "https://pypi.org/project/pyparsing/3.2.5/#files",
20302024
"type": "distribution",
20312025
"comment": "Download location for component"
20322026
}
20332027
],
2034-
"purl": "pkg:pypi/[email protected].4",
2028+
"purl": "pkg:pypi/[email protected].5",
20352029
"properties": [
20362030
{
20372031
"name": "release_date",
2038-
"value": "2025-09-13T05:47:17Z"
2032+
"value": "2022-02-03T00:00:29Z"
20392033
},
20402034
{
20412035
"name": "language",
@@ -4720,6 +4714,12 @@
47204714
},
47214715
"cpe": "cpe:2.3:a:gregory_szorc:zstandard:0.25.0:*:*:*:*:*:*:*",
47224716
"description": "Zstandard bindings for Python",
4717+
"hashes": [
4718+
{
4719+
"alg": "SHA-256",
4720+
"content": "e59fdc271772f6686e01e1b3b74537259800f57e24280be3f29c8a0deb1904dd"
4721+
}
4722+
],
47234723
"externalReferences": [
47244724
{
47254725
"url": "https://github.com/indygreg/python-zstandard",
@@ -4740,7 +4740,7 @@
47404740
"properties": [
47414741
{
47424742
"name": "release_date",
4743-
"value": "2025-06-08T17:06:38Z"
4743+
"value": "2025-09-14T22:15:56Z"
47444744
},
47454745
{
47464746
"name": "language",

sbom/cve-bin-tool-py3.13.spdx

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-75edad36-2f83-4708-be90-cc4d6f34009c
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-df626266-91c9-4f36-a228-57b53bea7e86
66
LicenseListVersion: 3.26
77
Creator: Tool: sbom4python-0.12.4
8-
Created: 2025-09-15T00:42:41Z
8+
Created: 2025-09-22T00:45:34Z
99
CreatorComment: <text>SBOM Type: Build - This document has been automatically generated.</text>
1010
#####
1111

@@ -619,20 +619,19 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:joe_gregorio:httplib2:0.20.4:*:*:*:*:*
619619

620620
PackageName: pyparsing
621621
SPDXID: SPDXRef-30-pyparsing
622-
PackageVersion: 3.2.4
622+
PackageVersion: 3.2.5
623623
PrimaryPackagePurpose: LIBRARY
624624
PackageSupplier: Person: Paul McGuire ([email protected])
625-
PackageDownloadLocation: https://pypi.org/project/pyparsing/3.2.4/#files
625+
PackageDownloadLocation: https://pypi.org/project/pyparsing/3.2.5/#files
626626
FilesAnalyzed: false
627627
PackageHomePage: https://github.com/pyparsing/pyparsing/
628-
PackageChecksum: SHA256: 91d0fcde680d42cd031daf3a6ba20da3107e08a75de50da58360e7d94ab24d36
629628
PackageLicenseDeclared: NOASSERTION
630629
PackageLicenseConcluded: NOASSERTION
631630
PackageCopyrightText: NOASSERTION
632631
PackageSummary: <text>pyparsing - Classes and methods to define and execute parsing grammars</text>
633-
ReleaseDate: 2025-09-13T05:47:17Z
634-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].4
635-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:paul_mcguire:pyparsing:3.2.4:*:*:*:*:*:*:*
632+
ReleaseDate: 2022-02-03T00:00:29Z
633+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].5
634+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:paul_mcguire:pyparsing:3.2.5:*:*:*:*:*:*:*
636635
#####
637636

638637
PackageName: oauth2client
@@ -1539,11 +1538,12 @@ PackageSupplier: Person: Gregory Szorc ([email protected])
15391538
PackageDownloadLocation: https://pypi.org/project/zstandard/0.25.0/#files
15401539
FilesAnalyzed: false
15411540
PackageHomePage: https://github.com/indygreg/python-zstandard
1541+
PackageChecksum: SHA256: e59fdc271772f6686e01e1b3b74537259800f57e24280be3f29c8a0deb1904dd
15421542
PackageLicenseDeclared: NOASSERTION
15431543
PackageLicenseConcluded: NOASSERTION
15441544
PackageCopyrightText: NOASSERTION
15451545
PackageSummary: <text>Zstandard bindings for Python</text>
1546-
ReleaseDate: 2025-06-08T17:06:38Z
1546+
ReleaseDate: 2025-09-14T22:15:56Z
15471547
ExternalRef: OTHER documentation https://python-zstandard.readthedocs.io/en/latest/
15481548
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected]
15491549
ExternalRef: SECURITY cpe23Type cpe:2.3:a:gregory_szorc:zstandard:0.25.0:*:*:*:*:*:*:*

0 commit comments

Comments
 (0)