@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
2
2
DataLicense: CC0-1.0
3
3
SPDXID: SPDXRef-DOCUMENT
4
4
DocumentName: Python-cve-bin-tool
5
- DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-f1f34e30-f49a-4f73-90bd-80e0bdc889b9
5
+ DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-6bb28944-b0e3-45eb-9feb-dc60bec1512c
6
6
LicenseListVersion: 3.22
7
- Creator: Tool: sbom4python-0.10.2
8
- Created: 2023-12-25T00:28:34Z
7
+ Creator: Tool: sbom4python-0.10.3
8
+ Created: 2024-01-04T20:00:41Z
9
9
CreatorComment: <text>This document has been automatically generated.</text>
10
10
#####
11
11
73
73
74
74
PackageName: attrs
75
75
SPDXID: SPDXRef-Package-5-attrs
76
- PackageVersion: 23.1 .0
76
+ PackageVersion: 23.2 .0
77
77
PrimaryPackagePurpose: LIBRARY
78
78
PackageSupplier: Person: Hynek Schlawack (
[email protected] )
79
- PackageDownloadLocation: https://pypi.org/project/attrs/23.1 .0
79
+ PackageDownloadLocation: https://pypi.org/project/attrs/23.2 .0
80
80
FilesAnalyzed: false
81
- PackageChecksum: SHA1: 1e2f6f9cac5cc60f0adab051c14adf09ffe39155
82
81
PackageLicenseDeclared: NOASSERTION
83
82
PackageLicenseConcluded: NOASSERTION
84
83
PackageCopyrightText: NOASSERTION
85
84
PackageSummary: <text>Classes Without Boilerplate</text>
86
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/attrs@23.1 .0
87
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:hynek_schlawack:attrs:23.1 .0:*:*:*:*:*:*:*
85
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/attrs@23.2 .0
86
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:hynek_schlawack:attrs:23.2 .0:*:*:*:*:*:*:*
88
87
#####
89
88
90
89
PackageName: multidict
@@ -464,6 +463,7 @@ PrimaryPackagePurpose: LIBRARY
464
463
PackageSupplier: Organization: The pyOpenSSL developers (
[email protected] )
465
464
PackageDownloadLocation: https://pypi.org/project/pyOpenSSL/23.3.0
466
465
FilesAnalyzed: false
466
+ PackageChecksum: SHA1: 5ba8ce10ed7c318e57516a7ec8447cbb5626d3f9
467
467
PackageLicenseDeclared: NOASSERTION
468
468
PackageLicenseConcluded: Apache-2.0
469
469
PackageLicenseComments: <text>pyOpenSSL declares Apache License, Version 2.0 which is not currently a valid SPDX License identifier or expression.</text>
@@ -556,18 +556,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:craig_citro:google-apitools:0.5.32:*:*
556
556
557
557
PackageName: google-auth
558
558
SPDXID: SPDXRef-Package-35-google-auth
559
- PackageVersion: 2.25.2
559
+ PackageVersion: 2.26.1
560
560
PrimaryPackagePurpose: LIBRARY
561
561
PackageSupplier: Organization: Google Cloud Platform (
[email protected] )
562
- PackageDownloadLocation: https://pypi.org/project/google-auth/2.25.2
562
+ PackageDownloadLocation: https://pypi.org/project/google-auth/2.26.1
563
563
FilesAnalyzed: false
564
564
PackageLicenseDeclared: NOASSERTION
565
565
PackageLicenseConcluded: Apache-2.0
566
566
PackageLicenseComments: <text>google-auth declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
567
567
PackageCopyrightText: NOASSERTION
568
568
PackageSummary: <text>Google Authentication Library</text>
569
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/google-auth@2.25.2
570
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_cloud_platform:google-auth:2.25.2 :*:*:*:*:*:*:*
569
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/google-auth@2.26.1
570
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_cloud_platform:google-auth:2.26.1 :*:*:*:*:*:*:*
571
571
#####
572
572
573
573
PackageName: cachetools
@@ -652,18 +652,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:jsonschema:4.20.0:*:*:*:
652
652
653
653
PackageName: jsonschema-specifications
654
654
SPDXID: SPDXRef-Package-41-jsonschema-specifications
655
- PackageVersion: 2023.11.2
655
+ PackageVersion: 2023.12.1
656
656
PrimaryPackagePurpose: LIBRARY
657
657
PackageSupplier: Person: Julian Berman
658
- PackageDownloadLocation: https://pypi.org/project/jsonschema-specifications/2023.11.2
658
+ PackageDownloadLocation: https://pypi.org/project/jsonschema-specifications/2023.12.1
659
659
FilesAnalyzed: false
660
- PackageChecksum: SHA1: a2fec386cdb2ed38041ccbfff0fc3e8a566997a3
660
+ PackageChecksum: SHA1: 544e0ff86850af1c6d9e533c4b58b76c59542a76
661
661
PackageLicenseDeclared: MIT
662
662
PackageLicenseConcluded: MIT
663
663
PackageCopyrightText: NOASSERTION
664
664
PackageSummary: <text>The JSON Schema meta-schemas and vocabularies, exposed as a Registry</text>
665
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/jsonschema-specifications@2023.11.2
666
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:jsonschema-specifications:2023.11.2 :*:*:*:*:*:*:*
665
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/jsonschema-specifications@2023.12.1
666
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:jsonschema-specifications:2023.12.1 :*:*:*:*:*:*:*
667
667
#####
668
668
669
669
PackageName: referencing
@@ -684,33 +684,32 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:referencing:0.32.0:*:*:*
684
684
685
685
PackageName: rpds-py
686
686
SPDXID: SPDXRef-Package-43-rpds-py
687
- PackageVersion: 0.15 .2
687
+ PackageVersion: 0.16 .2
688
688
PrimaryPackagePurpose: LIBRARY
689
689
PackageSupplier: Person: Julian Berman
690
- PackageDownloadLocation: https://pypi.org/project/rpds-py/0.15 .2
690
+ PackageDownloadLocation: https://pypi.org/project/rpds-py/0.16 .2
691
691
FilesAnalyzed: false
692
692
PackageLicenseDeclared: MIT
693
693
PackageLicenseConcluded: MIT
694
694
PackageCopyrightText: NOASSERTION
695
695
PackageSummary: <text>Python bindings to Rust's persistent data structures (rpds)</text>
696
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rpds-py@0.15 .2
697
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.15 .2:*:*:*:*:*:*:*
696
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rpds-py@0.16 .2
697
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.16 .2:*:*:*:*:*:*:*
698
698
#####
699
699
700
700
PackageName: lib4sbom
701
701
SPDXID: SPDXRef-Package-44-lib4sbom
702
- PackageVersion: 0.5.4
702
+ PackageVersion: 0.6.1
703
703
PrimaryPackagePurpose: LIBRARY
704
704
PackageSupplier: Person: Anthony Harrison (
[email protected] )
705
- PackageDownloadLocation: https://pypi.org/project/lib4sbom/0.5.4
705
+ PackageDownloadLocation: https://pypi.org/project/lib4sbom/0.6.1
706
706
FilesAnalyzed: false
707
- PackageChecksum: SHA1: 3de23e3f3b32c08f9bf8231e2765a06ebb82dc80
708
707
PackageLicenseDeclared: Apache-2.0
709
708
PackageLicenseConcluded: Apache-2.0
710
709
PackageCopyrightText: NOASSERTION
711
710
PackageSummary: <text>Software Bill of Material (SBOM) generator and consumer library</text>
712
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/lib4sbom@0.5.4
713
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:anthony_harrison:lib4sbom:0.5.4 :*:*:*:*:*:*:*
711
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/lib4sbom@0.6.1
712
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:anthony_harrison:lib4sbom:0.6.1 :*:*:*:*:*:*:*
714
713
#####
715
714
716
715
PackageName: pyyaml
0 commit comments