Skip to content

ci: bump cyclonedx-bom from 7.3.1 to 7.4.0 - #60

Merged
imran-siddique merged 2 commits into
mainfrom
dependabot/pip/cyclonedx-bom-7.4.0
Sep 21, 2026
Merged

imran-siddique merged 2 commits into
mainfrom
dependabot/pip/cyclonedx-bom-7.4.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 20, 2026

Copy link
Copy Markdown
Contributor

Bumps cyclonedx-bom from 7.3.1 to 7.4.0.

Release notes

Sourced from cyclonedx-bom's releases.

v7.4.0 (2026-09-15)

Features

  • Respect env var SOURCE_DATE_EPOCH when generating reproducible output (#1084, 51813c7)

What's Changed

New Contributors

Full Changelog: CycloneDX/cyclonedx-python@v7.3.1...v7.4.0

Changelog

Sourced from cyclonedx-bom's changelog.

v7.4.0 (2026-09-15)

Features

  • Respect env var SOURCE_DATE_EPOCH when generating reproducible output (#1084, 51813c7)
Commits
  • f6f4941 chore(release): 7.4.0
  • f97a9a9 chore(deps): Bump actions/download-artifact from 7.0.0 to 8.0.1 (#1046)
  • 0fd16c3 chore(deps): Bump actions/upload-artifact from 6.0.0 to 7.0.1 (#1048)
  • d48f71c chore(deps): Bump python from 3.14-slim to 3.14.6-slim (#1065)
  • 2abed0f chore(deps): Bump zizmorcore/zizmor-action from 0.6.2 to 0.6.3 (#1100)
  • 51813c7 feat: respect env var SOURCE_DATE_EPOCH when generating reproducible output...
  • 0e4de7a chore(deps): Bump docker/login-action from 3.7.0 to 4.6.0 (#1092)
  • b51c001 chore(deps): Bump pypa/gh-action-pypi-publish from 1.14.1 to 1.14.2 (#1090)
  • 25bfa4c chore(deps-dev): Update uv requirement from 0.11.32 to 0.12.10 (#1101)
  • 20a8345 chore(deps): Bump zizmorcore/zizmor-action from 0.6.1 to 0.6.2 (#1091)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [cyclonedx-bom](https://github.com/CycloneDX/cyclonedx-python) from 7.3.1 to 7.4.0.
- [Release notes](https://github.com/CycloneDX/cyclonedx-python/releases)
- [Changelog](https://github.com/CycloneDX/cyclonedx-python/blob/main/CHANGELOG.md)
- [Commits](CycloneDX/cyclonedx-python@v7.3.1...v7.4.0)

---
updated-dependencies:
- dependency-name: cyclonedx-bom
  dependency-version: 7.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Sep 20, 2026
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Sep 20, 2026

@imran-siddique imran-siddique left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed at 906cd93. On Windows with Python 3.12, the fresh hash-pinned SBOM install, workflow install sequence, dependency consistency check, and inventory generation passed. Reinstalling the SBOM lock also confirmed generation with rpds-py 0.30.0. Hosted CI and CodeQL passed. The Linux SBOM workflow itself was not run.

@imran-siddique imran-siddique left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reapproved at ac357e1 after updating from main. The update adds only two README lines; the tested dependency files and SBOM workflow are unchanged. Local Python 3.12 installation and inventory-generation results from the previous review still apply.

@imran-siddique
imran-siddique merged commit 16ab8e2 into main Sep 21, 2026
7 checks passed
@imran-siddique
imran-siddique deleted the dependabot/pip/cyclonedx-bom-7.4.0 branch September 21, 2026 04:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant