@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
2
2
DataLicense: CC0-1.0
3
3
SPDXID: SPDXRef-DOCUMENT
4
4
DocumentName: Python-cve-bin-tool
5
- DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-e55ebc57-b76a-458c-95c3-ac8d39a01d6f
5
+ DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-7ebf2507-d2e7-4da3-966b-3116faa0d6c1
6
6
LicenseListVersion: 3.22
7
7
Creator: Tool: sbom4python-0.10.4
8
- Created: 2024-05-06T00:26:49Z
8
+ Created: 2024-05-13T00:27:18Z
9
9
CreatorComment: <text>This document has been automatically generated.</text>
10
10
#####
11
11
@@ -189,6 +189,7 @@ PrimaryPackagePurpose: LIBRARY
189
189
PackageSupplier: Organization: Stanislav Red Hat Product Security (
[email protected] )
190
190
PackageDownloadLocation: https://pypi.org/project/cvss/3.1
191
191
FilesAnalyzed: false
192
+ PackageChecksum: SHA1: e4cf69bea6bcfa1cbc38dca13b9ec8bf3363a475
192
193
PackageLicenseDeclared: NOASSERTION
193
194
PackageLicenseConcluded: LGPL-3.0-or-later
194
195
PackageLicenseComments: <text>cvss declares LGPLv3+ which is not currently a valid SPDX License identifier or expression.</text>
@@ -249,18 +250,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:tomas_aparicio:filetype:1.2.0:*:*:*:*:
249
250
250
251
PackageName: gsutil
251
252
SPDXID: SPDXRef-Package-16-gsutil
252
- PackageVersion: 5.28
253
+ PackageVersion: 5.29
253
254
PrimaryPackagePurpose: LIBRARY
254
255
PackageSupplier: Person: Google Inc. (
[email protected] )
255
- PackageDownloadLocation: https://pypi.org/project/gsutil/5.28
256
+ PackageDownloadLocation: https://pypi.org/project/gsutil/5.29
256
257
FilesAnalyzed: false
257
258
PackageLicenseDeclared: NOASSERTION
258
259
PackageLicenseConcluded: Apache-2.0
259
260
PackageLicenseComments: <text>gsutil declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
260
261
PackageCopyrightText: NOASSERTION
261
262
PackageSummary: <text>A command line tool for interacting with cloud storage services.</text>
262
- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/gsutil@5.28
263
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_inc.:gsutil:5.28 :*:*:*:*:*:*:*
263
+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/gsutil@5.29
264
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_inc.:gsutil:5.29 :*:*:*:*:*:*:*
264
265
#####
265
266
266
267
PackageName: argcomplete
@@ -557,17 +558,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_pyopenssl_developers:pyopenssl:24.
557
558
558
559
PackageName: cryptography
559
560
SPDXID: SPDXRef-Package-35-cryptography
560
- PackageVersion: 42.0.6
561
+ PackageVersion: 42.0.7
561
562
PrimaryPackagePurpose: LIBRARY
562
563
PackageSupplier: Organization: The Python Cryptographic Authority and individual contributors (
[email protected] )
563
- PackageDownloadLocation: https://pypi.org/project/cryptography/42.0.6
564
+ PackageDownloadLocation: https://pypi.org/project/cryptography/42.0.7
564
565
FilesAnalyzed: false
565
566
PackageLicenseDeclared: Apache-2.0 OR BSD-3-Clause
566
567
PackageLicenseConcluded: Apache-2.0 OR BSD-3-Clause
567
568
PackageCopyrightText: NOASSERTION
568
569
PackageSummary: <text>cryptography is a package which provides cryptographic recipes and primitives to Python developers.</text>
569
- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/
[email protected] .
6
570
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:42.0.6 :*:*:*:*:*:*:*
570
+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/
[email protected] .
7
571
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:42.0.7 :*:*:*:*:*:*:*
571
572
#####
572
573
573
574
PackageName: cffi
@@ -673,7 +674,6 @@ PrimaryPackagePurpose: LIBRARY
673
674
PackageSupplier: NOASSERTION
674
675
PackageDownloadLocation: https://pypi.org/project/MarkupSafe/2.1.5
675
676
FilesAnalyzed: false
676
- PackageChecksum: SHA1: fbba4acd0312826cec9cfe18371c7df07962cb65
677
677
PackageLicenseDeclared: BSD-3-Clause
678
678
PackageLicenseConcluded: BSD-3-Clause
679
679
PackageCopyrightText: NOASSERTION
@@ -729,17 +729,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:referencing:0.35.1:*:*:*
729
729
730
730
PackageName: rpds-py
731
731
SPDXID: SPDXRef-Package-46-rpds-py
732
- PackageVersion: 0.18.0
732
+ PackageVersion: 0.18.1
733
733
PrimaryPackagePurpose: LIBRARY
734
734
PackageSupplier: Person: Julian Berman
735
- PackageDownloadLocation: https://pypi.org/project/rpds-py/0.18.0
735
+ PackageDownloadLocation: https://pypi.org/project/rpds-py/0.18.1
736
736
FilesAnalyzed: false
737
737
PackageLicenseDeclared: MIT
738
738
PackageLicenseConcluded: MIT
739
739
PackageCopyrightText: NOASSERTION
740
740
PackageSummary: <text>Python bindings to Rust's persistent data structures (rpds)</text>
741
- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/
[email protected] .
0
742
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.18.0 :*:*:*:*:*:*:*
741
+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/
[email protected] .
1
742
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.18.1 :*:*:*:*:*:*:*
743
743
#####
744
744
745
745
PackageName: lib4sbom
@@ -839,19 +839,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:5.22.0:*:*:*:*:*:*:*
839
839
840
840
PackageName: tenacity
841
841
SPDXID: SPDXRef-Package-53-tenacity
842
- PackageVersion: 8.2.3
842
+ PackageVersion: 8.3.0
843
843
PrimaryPackagePurpose: LIBRARY
844
844
PackageSupplier: Person: Julien Danjou (
[email protected] )
845
- PackageDownloadLocation: https://pypi.org/project/tenacity/8.2.3
845
+ PackageDownloadLocation: https://pypi.org/project/tenacity/8.3.0
846
846
FilesAnalyzed: false
847
- PackageChecksum: SHA1: 41ed2420cda8ab7650a39900451099f4730266c3
848
847
PackageLicenseDeclared: NOASSERTION
849
848
PackageLicenseConcluded: Apache-2.0
850
849
PackageLicenseComments: <text>tenacity declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
851
850
PackageCopyrightText: NOASSERTION
852
851
PackageSummary: <text>Retry code until it succeeds</text>
853
- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/tenacity@8.2.3
854
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:julien_danjou:tenacity:8.2.3 :*:*:*:*:*:*:*
852
+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/tenacity@8.3.0
853
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julien_danjou:tenacity:8.3.0 :*:*:*:*:*:*:*
855
854
#####
856
855
857
856
PackageName: python-gnupg
0 commit comments