@@ -2,42 +2,42 @@ SPDXVersion: SPDX-2.3
2
2
DataLicense: CC0-1.0
3
3
SPDXID: SPDXRef-DOCUMENT
4
4
DocumentName: Python-cve-bin-tool
5
- DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-179884b8-4d95-4ae4-9d55-d569d800b01a
5
+ DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-07124c73-1f18-4124-ac1c-c53724579633
6
6
LicenseListVersion: 3.22
7
7
Creator: Tool: sbom4python-0.10.4
8
- Created: 2024-04-08T00:26:09Z
8
+ Created: 2024-04-15T02:41:52Z
9
9
CreatorComment: <text>This document has been automatically generated.</text>
10
10
#####
11
11
12
12
PackageName: cve-bin-tool
13
13
SPDXID: SPDXRef-Package-1-cve-bin-tool
14
- PackageVersion: 3.3rc2
14
+ PackageVersion: 3.3
15
15
PrimaryPackagePurpose: APPLICATION
16
16
PackageSupplier: Person: Terri Oda (
[email protected] )
17
- PackageDownloadLocation: https://pypi.org/project/cve-bin-tool/3.3rc2
17
+ PackageDownloadLocation: https://pypi.org/project/cve-bin-tool/3.3
18
18
FilesAnalyzed: false
19
- PackageChecksum: SHA1: c491590aeea36235930d1c6b8480d2489a470ece
19
+ PackageChecksum: SHA1: 83e30ee0f640bce7a20d4346c85873d359c05d1f
20
20
PackageLicenseDeclared: GPL-3.0-or-later
21
21
PackageLicenseConcluded: GPL-3.0-or-later
22
22
PackageCopyrightText: NOASSERTION
23
23
PackageSummary: <text>CVE Binary Checker Tool</text>
24
- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/cve-bin-tool@3.3rc2
25
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.3rc2 :*:*:*:*:*:*:*
24
+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/cve-bin-tool@3.3
25
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.3 :*:*:*:*:*:*:*
26
26
#####
27
27
28
28
PackageName: aiohttp
29
29
SPDXID: SPDXRef-Package-2-aiohttp
30
- PackageVersion: 3.9.3
30
+ PackageVersion: 3.9.4
31
31
PrimaryPackagePurpose: LIBRARY
32
32
PackageSupplier: NOASSERTION
33
- PackageDownloadLocation: https://pypi.org/project/aiohttp/3.9.3
33
+ PackageDownloadLocation: https://pypi.org/project/aiohttp/3.9.4
34
34
FilesAnalyzed: false
35
35
PackageLicenseDeclared: NOASSERTION
36
36
PackageLicenseConcluded: Apache-2.0
37
37
PackageLicenseComments: <text>aiohttp declares Apache 2 which is not currently a valid SPDX License identifier or expression.</text>
38
38
PackageCopyrightText: NOASSERTION
39
39
PackageSummary: <text>Async http client/server framework (asyncio)</text>
40
- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/
[email protected] .
3
40
+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/
[email protected] .
4
41
41
#####
42
42
43
43
PackageName: aiosignal
@@ -137,17 +137,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrew_svetlov:yarl:1.9.4:*:*:*:*:*:*:
137
137
138
138
PackageName: idna
139
139
SPDXID: SPDXRef-Package-9-idna
140
- PackageVersion: 3.6
140
+ PackageVersion: 3.7
141
141
PrimaryPackagePurpose: LIBRARY
142
142
PackageSupplier: Person: Kim Davies (
[email protected] )
143
- PackageDownloadLocation: https://pypi.org/project/idna/3.6
143
+ PackageDownloadLocation: https://pypi.org/project/idna/3.7
144
144
FilesAnalyzed: false
145
145
PackageLicenseDeclared: NOASSERTION
146
146
PackageLicenseConcluded: NOASSERTION
147
147
PackageCopyrightText: NOASSERTION
148
148
PackageSummary: <text>Internationalized Domain Names in Applications (IDNA)</text>
149
- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/idna@3.6
150
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:kim_davies:idna:3.6 :*:*:*:*:*:*:*
149
+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/idna@3.7
150
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:kim_davies:idna:3.7 :*:*:*:*:*:*:*
151
151
#####
152
152
153
153
PackageName: beautifulsoup4
@@ -184,19 +184,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:isaac_muse:soupsieve:2.5:*:*:*:*:*:*:*
184
184
185
185
PackageName: cvss
186
186
SPDXID: SPDXRef-Package-12-cvss
187
- PackageVersion: 3.0
187
+ PackageVersion: 3.1
188
188
PrimaryPackagePurpose: LIBRARY
189
189
PackageSupplier: Organization: Stanislav Red Hat Product Security (
[email protected] )
190
- PackageDownloadLocation: https://pypi.org/project/cvss/3.0
190
+ PackageDownloadLocation: https://pypi.org/project/cvss/3.1
191
191
FilesAnalyzed: false
192
- PackageChecksum: SHA1: c637e63a16b7411c6135b5ae8bb5408d06d89b41
193
192
PackageLicenseDeclared: NOASSERTION
194
193
PackageLicenseConcluded: LGPL-3.0-or-later
195
194
PackageLicenseComments: <text>cvss declares LGPLv3+ which is not currently a valid SPDX License identifier or expression.</text>
196
195
PackageCopyrightText: NOASSERTION
197
196
PackageSummary: <text>CVSS2/3/4 library with interactive calculator for Python 2 and Python 3</text>
198
- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/cvss@3.0
199
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:stanislav_red_hat_product_security:cvss:3.0 :*:*:*:*:*:*:*
197
+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/cvss@3.1
198
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:stanislav_red_hat_product_security:cvss:3.1 :*:*:*:*:*:*:*
200
199
#####
201
200
202
201
PackageName: defusedxml
@@ -266,18 +265,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_inc.:gsutil:5.27:*:*:*:*:*:*:*
266
265
267
266
PackageName: argcomplete
268
267
SPDXID: SPDXRef-Package-17-argcomplete
269
- PackageVersion: 3.2.3
268
+ PackageVersion: 3.3.0
270
269
PrimaryPackagePurpose: LIBRARY
271
270
PackageSupplier: Person: Andrey Kislyuk (
[email protected] )
272
- PackageDownloadLocation: https://pypi.org/project/argcomplete/3.2.3
271
+ PackageDownloadLocation: https://pypi.org/project/argcomplete/3.3.0
273
272
FilesAnalyzed: false
274
273
PackageLicenseDeclared: NOASSERTION
275
274
PackageLicenseConcluded: Apache-2.0
276
275
PackageLicenseComments: <text>argcomplete declares Apache Software License which is not currently a valid SPDX License identifier or expression.</text>
277
276
PackageCopyrightText: NOASSERTION
278
277
PackageSummary: <text>Bash tab completion for argparse</text>
279
- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/argcomplete@3.2.3
280
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_kislyuk:argcomplete:3.2.3 :*:*:*:*:*:*:*
278
+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/argcomplete@3.3.0
279
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_kislyuk:argcomplete:3.3.0 :*:*:*:*:*:*:*
281
280
#####
282
281
283
282
PackageName: crcmod
0 commit comments