@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
2
2
DataLicense: CC0-1.0
3
3
SPDXID: SPDXRef-DOCUMENT
4
4
DocumentName: Python-cve-bin-tool
5
- DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-146f1efc-97ef-4b16-b568-084fa08abc52
5
+ DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-f75310d1-b81b-40c2-930d-22699181394d
6
6
LicenseListVersion: 3.22
7
7
Creator: Tool: sbom4python-0.10.4
8
- Created: 2024-05-06T00:26:45Z
8
+ Created: 2024-05-13T00:27:25Z
9
9
CreatorComment: <text>This document has been automatically generated.</text>
10
10
#####
11
11
@@ -189,6 +189,7 @@ PrimaryPackagePurpose: LIBRARY
189
189
PackageSupplier: Organization: Stanislav Red Hat Product Security (
[email protected] )
190
190
PackageDownloadLocation: https://pypi.org/project/cvss/3.1
191
191
FilesAnalyzed: false
192
+ PackageChecksum: SHA1: e4cf69bea6bcfa1cbc38dca13b9ec8bf3363a475
192
193
PackageLicenseDeclared: NOASSERTION
193
194
PackageLicenseConcluded: LGPL-3.0-or-later
194
195
PackageLicenseComments: <text>cvss declares LGPLv3+ which is not currently a valid SPDX License identifier or expression.</text>
@@ -249,18 +250,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:tomas_aparicio:filetype:1.2.0:*:*:*:*:
249
250
250
251
PackageName: gsutil
251
252
SPDXID: SPDXRef-Package-16-gsutil
252
- PackageVersion: 5.28
253
+ PackageVersion: 5.29
253
254
PrimaryPackagePurpose: LIBRARY
254
255
PackageSupplier: Person: Google Inc. (
[email protected] )
255
- PackageDownloadLocation: https://pypi.org/project/gsutil/5.28
256
+ PackageDownloadLocation: https://pypi.org/project/gsutil/5.29
256
257
FilesAnalyzed: false
257
258
PackageLicenseDeclared: NOASSERTION
258
259
PackageLicenseConcluded: Apache-2.0
259
260
PackageLicenseComments: <text>gsutil declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
260
261
PackageCopyrightText: NOASSERTION
261
262
PackageSummary: <text>A command line tool for interacting with cloud storage services.</text>
262
- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/gsutil@5.28
263
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_inc.:gsutil:5.28 :*:*:*:*:*:*:*
263
+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/gsutil@5.29
264
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_inc.:gsutil:5.29 :*:*:*:*:*:*:*
264
265
#####
265
266
266
267
PackageName: argcomplete
@@ -557,17 +558,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_pyopenssl_developers:pyopenssl:24.
557
558
558
559
PackageName: cryptography
559
560
SPDXID: SPDXRef-Package-35-cryptography
560
- PackageVersion: 42.0.6
561
+ PackageVersion: 42.0.7
561
562
PrimaryPackagePurpose: LIBRARY
562
563
PackageSupplier: Organization: The Python Cryptographic Authority and individual contributors (
[email protected] )
563
- PackageDownloadLocation: https://pypi.org/project/cryptography/42.0.6
564
+ PackageDownloadLocation: https://pypi.org/project/cryptography/42.0.7
564
565
FilesAnalyzed: false
565
566
PackageLicenseDeclared: Apache-2.0 OR BSD-3-Clause
566
567
PackageLicenseConcluded: Apache-2.0 OR BSD-3-Clause
567
568
PackageCopyrightText: NOASSERTION
568
569
PackageSummary: <text>cryptography is a package which provides cryptographic recipes and primitives to Python developers.</text>
569
- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/
[email protected] .
6
570
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:42.0.6 :*:*:*:*:*:*:*
570
+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/
[email protected] .
7
571
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:42.0.7 :*:*:*:*:*:*:*
571
572
#####
572
573
573
574
PackageName: cffi
@@ -705,7 +706,6 @@ PrimaryPackagePurpose: LIBRARY
705
706
PackageSupplier: NOASSERTION
706
707
PackageDownloadLocation: https://pypi.org/project/MarkupSafe/2.1.5
707
708
FilesAnalyzed: false
708
- PackageChecksum: SHA1: fbba4acd0312826cec9cfe18371c7df07962cb65
709
709
PackageLicenseDeclared: BSD-3-Clause
710
710
PackageLicenseConcluded: BSD-3-Clause
711
711
PackageCopyrightText: NOASSERTION
@@ -761,17 +761,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:referencing:0.35.1:*:*:*
761
761
762
762
PackageName: rpds-py
763
763
SPDXID: SPDXRef-Package-48-rpds-py
764
- PackageVersion: 0.18.0
764
+ PackageVersion: 0.18.1
765
765
PrimaryPackagePurpose: LIBRARY
766
766
PackageSupplier: Person: Julian Berman
767
- PackageDownloadLocation: https://pypi.org/project/rpds-py/0.18.0
767
+ PackageDownloadLocation: https://pypi.org/project/rpds-py/0.18.1
768
768
FilesAnalyzed: false
769
769
PackageLicenseDeclared: MIT
770
770
PackageLicenseConcluded: MIT
771
771
PackageCopyrightText: NOASSERTION
772
772
PackageSummary: <text>Python bindings to Rust's persistent data structures (rpds)</text>
773
- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/
[email protected] .
0
774
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.18.0 :*:*:*:*:*:*:*
773
+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/
[email protected] .
1
774
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.18.1 :*:*:*:*:*:*:*
775
775
#####
776
776
777
777
PackageName: lib4sbom
@@ -871,19 +871,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:5.22.0:*:*:*:*:*:*:*
871
871
872
872
PackageName: tenacity
873
873
SPDXID: SPDXRef-Package-55-tenacity
874
- PackageVersion: 8.2.3
874
+ PackageVersion: 8.3.0
875
875
PrimaryPackagePurpose: LIBRARY
876
876
PackageSupplier: Person: Julien Danjou (
[email protected] )
877
- PackageDownloadLocation: https://pypi.org/project/tenacity/8.2.3
877
+ PackageDownloadLocation: https://pypi.org/project/tenacity/8.3.0
878
878
FilesAnalyzed: false
879
- PackageChecksum: SHA1: 41ed2420cda8ab7650a39900451099f4730266c3
880
879
PackageLicenseDeclared: NOASSERTION
881
880
PackageLicenseConcluded: Apache-2.0
882
881
PackageLicenseComments: <text>tenacity declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
883
882
PackageCopyrightText: NOASSERTION
884
883
PackageSummary: <text>Retry code until it succeeds</text>
885
- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/tenacity@8.2.3
886
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:julien_danjou:tenacity:8.2.3 :*:*:*:*:*:*:*
884
+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/tenacity@8.3.0
885
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julien_danjou:tenacity:8.3.0 :*:*:*:*:*:*:*
887
886
#####
888
887
889
888
PackageName: python-gnupg
0 commit comments