@@ -2,42 +2,42 @@ SPDXVersion: SPDX-2.3
2
2
DataLicense: CC0-1.0
3
3
SPDXID: SPDXRef-DOCUMENT
4
4
DocumentName: Python-cve-bin-tool
5
- DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-e6f8ebcd-5a53-4c80-8ee1-90be752f102d
5
+ DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-54b655be-6b8b-4720-8b97-b17adec09373
6
6
LicenseListVersion: 3.22
7
7
Creator: Tool: sbom4python-0.10.4
8
- Created: 2024-04-08T00:26:15Z
8
+ Created: 2024-04-15T02:41:54Z
9
9
CreatorComment: <text>This document has been automatically generated.</text>
10
10
#####
11
11
12
12
PackageName: cve-bin-tool
13
13
SPDXID: SPDXRef-Package-1-cve-bin-tool
14
- PackageVersion: 3.3rc2
14
+ PackageVersion: 3.3
15
15
PrimaryPackagePurpose: APPLICATION
16
16
PackageSupplier: Person: Terri Oda (
[email protected] )
17
- PackageDownloadLocation: https://pypi.org/project/cve-bin-tool/3.3rc2
17
+ PackageDownloadLocation: https://pypi.org/project/cve-bin-tool/3.3
18
18
FilesAnalyzed: false
19
- PackageChecksum: SHA1: c491590aeea36235930d1c6b8480d2489a470ece
19
+ PackageChecksum: SHA1: 83e30ee0f640bce7a20d4346c85873d359c05d1f
20
20
PackageLicenseDeclared: GPL-3.0-or-later
21
21
PackageLicenseConcluded: GPL-3.0-or-later
22
22
PackageCopyrightText: NOASSERTION
23
23
PackageSummary: <text>CVE Binary Checker Tool</text>
24
- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/cve-bin-tool@3.3rc2
25
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.3rc2 :*:*:*:*:*:*:*
24
+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/cve-bin-tool@3.3
25
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.3 :*:*:*:*:*:*:*
26
26
#####
27
27
28
28
PackageName: aiohttp
29
29
SPDXID: SPDXRef-Package-2-aiohttp
30
- PackageVersion: 3.9.3
30
+ PackageVersion: 3.9.4
31
31
PrimaryPackagePurpose: LIBRARY
32
32
PackageSupplier: NOASSERTION
33
- PackageDownloadLocation: https://pypi.org/project/aiohttp/3.9.3
33
+ PackageDownloadLocation: https://pypi.org/project/aiohttp/3.9.4
34
34
FilesAnalyzed: false
35
35
PackageLicenseDeclared: NOASSERTION
36
36
PackageLicenseConcluded: Apache-2.0
37
37
PackageLicenseComments: <text>aiohttp declares Apache 2 which is not currently a valid SPDX License identifier or expression.</text>
38
38
PackageCopyrightText: NOASSERTION
39
39
PackageSummary: <text>Async http client/server framework (asyncio)</text>
40
- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/
[email protected] .
3
40
+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/
[email protected] .
4
41
41
#####
42
42
43
43
PackageName: aiosignal
@@ -120,17 +120,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrew_svetlov:yarl:1.9.4:*:*:*:*:*:*:
120
120
121
121
PackageName: idna
122
122
SPDXID: SPDXRef-Package-8-idna
123
- PackageVersion: 3.6
123
+ PackageVersion: 3.7
124
124
PrimaryPackagePurpose: LIBRARY
125
125
PackageSupplier: Person: Kim Davies (
[email protected] )
126
- PackageDownloadLocation: https://pypi.org/project/idna/3.6
126
+ PackageDownloadLocation: https://pypi.org/project/idna/3.7
127
127
FilesAnalyzed: false
128
128
PackageLicenseDeclared: NOASSERTION
129
129
PackageLicenseConcluded: NOASSERTION
130
130
PackageCopyrightText: NOASSERTION
131
131
PackageSummary: <text>Internationalized Domain Names in Applications (IDNA)</text>
132
- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/idna@3.6
133
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:kim_davies:idna:3.6 :*:*:*:*:*:*:*
132
+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/idna@3.7
133
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:kim_davies:idna:3.7 :*:*:*:*:*:*:*
134
134
#####
135
135
136
136
PackageName: beautifulsoup4
@@ -167,19 +167,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:isaac_muse:soupsieve:2.5:*:*:*:*:*:*:*
167
167
168
168
PackageName: cvss
169
169
SPDXID: SPDXRef-Package-11-cvss
170
- PackageVersion: 3.0
170
+ PackageVersion: 3.1
171
171
PrimaryPackagePurpose: LIBRARY
172
172
PackageSupplier: Organization: Stanislav Red Hat Product Security (
[email protected] )
173
- PackageDownloadLocation: https://pypi.org/project/cvss/3.0
173
+ PackageDownloadLocation: https://pypi.org/project/cvss/3.1
174
174
FilesAnalyzed: false
175
- PackageChecksum: SHA1: c637e63a16b7411c6135b5ae8bb5408d06d89b41
176
175
PackageLicenseDeclared: NOASSERTION
177
176
PackageLicenseConcluded: LGPL-3.0-or-later
178
177
PackageLicenseComments: <text>cvss declares LGPLv3+ which is not currently a valid SPDX License identifier or expression.</text>
179
178
PackageCopyrightText: NOASSERTION
180
179
PackageSummary: <text>CVSS2/3/4 library with interactive calculator for Python 2 and Python 3</text>
181
- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/cvss@3.0
182
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:stanislav_red_hat_product_security:cvss:3.0 :*:*:*:*:*:*:*
180
+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/cvss@3.1
181
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:stanislav_red_hat_product_security:cvss:3.1 :*:*:*:*:*:*:*
183
182
#####
184
183
185
184
PackageName: defusedxml
@@ -249,18 +248,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_inc.:gsutil:5.27:*:*:*:*:*:*:*
249
248
250
249
PackageName: argcomplete
251
250
SPDXID: SPDXRef-Package-16-argcomplete
252
- PackageVersion: 3.2.3
251
+ PackageVersion: 3.3.0
253
252
PrimaryPackagePurpose: LIBRARY
254
253
PackageSupplier: Person: Andrey Kislyuk (
[email protected] )
255
- PackageDownloadLocation: https://pypi.org/project/argcomplete/3.2.3
254
+ PackageDownloadLocation: https://pypi.org/project/argcomplete/3.3.0
256
255
FilesAnalyzed: false
257
256
PackageLicenseDeclared: NOASSERTION
258
257
PackageLicenseConcluded: Apache-2.0
259
258
PackageLicenseComments: <text>argcomplete declares Apache Software License which is not currently a valid SPDX License identifier or expression.</text>
260
259
PackageCopyrightText: NOASSERTION
261
260
PackageSummary: <text>Bash tab completion for argparse</text>
262
- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/argcomplete@3.2.3
263
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_kislyuk:argcomplete:3.2.3 :*:*:*:*:*:*:*
261
+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/argcomplete@3.3.0
262
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_kislyuk:argcomplete:3.3.0 :*:*:*:*:*:*:*
264
263
#####
265
264
266
265
PackageName: crcmod
0 commit comments