@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
2
2
DataLicense: CC0-1.0
3
3
SPDXID: SPDXRef-DOCUMENT
4
4
DocumentName: Python-cve-bin-tool
5
- DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-81dc583c-21c5-4aa5-bb6a-0782b82641e9
5
+ DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-955978f6-8abe-4894-a787-b8e0b16a0b30
6
6
LicenseListVersion: 3.22
7
7
Creator: Tool: sbom4python-0.10.4
8
- Created: 2024-05-06T00:26:39Z
8
+ Created: 2024-05-13T00:27:14Z
9
9
CreatorComment: <text>This document has been automatically generated.</text>
10
10
#####
11
11
@@ -172,6 +172,7 @@ PrimaryPackagePurpose: LIBRARY
172
172
PackageSupplier: Organization: Stanislav Red Hat Product Security (
[email protected] )
173
173
PackageDownloadLocation: https://pypi.org/project/cvss/3.1
174
174
FilesAnalyzed: false
175
+ PackageChecksum: SHA1: e4cf69bea6bcfa1cbc38dca13b9ec8bf3363a475
175
176
PackageLicenseDeclared: NOASSERTION
176
177
PackageLicenseConcluded: LGPL-3.0-or-later
177
178
PackageLicenseComments: <text>cvss declares LGPLv3+ which is not currently a valid SPDX License identifier or expression.</text>
@@ -232,18 +233,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:tomas_aparicio:filetype:1.2.0:*:*:*:*:
232
233
233
234
PackageName: gsutil
234
235
SPDXID: SPDXRef-Package-15-gsutil
235
- PackageVersion: 5.28
236
+ PackageVersion: 5.29
236
237
PrimaryPackagePurpose: LIBRARY
237
238
PackageSupplier: Person: Google Inc. (
[email protected] )
238
- PackageDownloadLocation: https://pypi.org/project/gsutil/5.28
239
+ PackageDownloadLocation: https://pypi.org/project/gsutil/5.29
239
240
FilesAnalyzed: false
240
241
PackageLicenseDeclared: NOASSERTION
241
242
PackageLicenseConcluded: Apache-2.0
242
243
PackageLicenseComments: <text>gsutil declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
243
244
PackageCopyrightText: NOASSERTION
244
245
PackageSummary: <text>A command line tool for interacting with cloud storage services.</text>
245
- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/gsutil@5.28
246
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_inc.:gsutil:5.28 :*:*:*:*:*:*:*
246
+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/gsutil@5.29
247
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_inc.:gsutil:5.29 :*:*:*:*:*:*:*
247
248
#####
248
249
249
250
PackageName: argcomplete
@@ -540,17 +541,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_pyopenssl_developers:pyopenssl:24.
540
541
541
542
PackageName: cryptography
542
543
SPDXID: SPDXRef-Package-34-cryptography
543
- PackageVersion: 42.0.6
544
+ PackageVersion: 42.0.7
544
545
PrimaryPackagePurpose: LIBRARY
545
546
PackageSupplier: Organization: The Python Cryptographic Authority and individual contributors (
[email protected] )
546
- PackageDownloadLocation: https://pypi.org/project/cryptography/42.0.6
547
+ PackageDownloadLocation: https://pypi.org/project/cryptography/42.0.7
547
548
FilesAnalyzed: false
548
549
PackageLicenseDeclared: Apache-2.0 OR BSD-3-Clause
549
550
PackageLicenseConcluded: Apache-2.0 OR BSD-3-Clause
550
551
PackageCopyrightText: NOASSERTION
551
552
PackageSummary: <text>cryptography is a package which provides cryptographic recipes and primitives to Python developers.</text>
552
- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/
[email protected] .
6
553
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:42.0.6 :*:*:*:*:*:*:*
553
+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/
[email protected] .
7
554
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:42.0.7 :*:*:*:*:*:*:*
554
555
#####
555
556
556
557
PackageName: cffi
@@ -656,7 +657,6 @@ PrimaryPackagePurpose: LIBRARY
656
657
PackageSupplier: NOASSERTION
657
658
PackageDownloadLocation: https://pypi.org/project/MarkupSafe/2.1.5
658
659
FilesAnalyzed: false
659
- PackageChecksum: SHA1: fbba4acd0312826cec9cfe18371c7df07962cb65
660
660
PackageLicenseDeclared: BSD-3-Clause
661
661
PackageLicenseConcluded: BSD-3-Clause
662
662
PackageCopyrightText: NOASSERTION
@@ -712,17 +712,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:referencing:0.35.1:*:*:*
712
712
713
713
PackageName: rpds-py
714
714
SPDXID: SPDXRef-Package-45-rpds-py
715
- PackageVersion: 0.18.0
715
+ PackageVersion: 0.18.1
716
716
PrimaryPackagePurpose: LIBRARY
717
717
PackageSupplier: Person: Julian Berman
718
- PackageDownloadLocation: https://pypi.org/project/rpds-py/0.18.0
718
+ PackageDownloadLocation: https://pypi.org/project/rpds-py/0.18.1
719
719
FilesAnalyzed: false
720
720
PackageLicenseDeclared: MIT
721
721
PackageLicenseConcluded: MIT
722
722
PackageCopyrightText: NOASSERTION
723
723
PackageSummary: <text>Python bindings to Rust's persistent data structures (rpds)</text>
724
- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/
[email protected] .
0
725
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.18.0 :*:*:*:*:*:*:*
724
+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/
[email protected] .
1
725
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.18.1 :*:*:*:*:*:*:*
726
726
#####
727
727
728
728
PackageName: lib4sbom
@@ -822,19 +822,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:5.22.0:*:*:*:*:*:*:*
822
822
823
823
PackageName: tenacity
824
824
SPDXID: SPDXRef-Package-52-tenacity
825
- PackageVersion: 8.2.3
825
+ PackageVersion: 8.3.0
826
826
PrimaryPackagePurpose: LIBRARY
827
827
PackageSupplier: Person: Julien Danjou (
[email protected] )
828
- PackageDownloadLocation: https://pypi.org/project/tenacity/8.2.3
828
+ PackageDownloadLocation: https://pypi.org/project/tenacity/8.3.0
829
829
FilesAnalyzed: false
830
- PackageChecksum: SHA1: 41ed2420cda8ab7650a39900451099f4730266c3
831
830
PackageLicenseDeclared: NOASSERTION
832
831
PackageLicenseConcluded: Apache-2.0
833
832
PackageLicenseComments: <text>tenacity declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
834
833
PackageCopyrightText: NOASSERTION
835
834
PackageSummary: <text>Retry code until it succeeds</text>
836
- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/tenacity@8.2.3
837
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:julien_danjou:tenacity:8.2.3 :*:*:*:*:*:*:*
835
+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/tenacity@8.3.0
836
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julien_danjou:tenacity:8.3.0 :*:*:*:*:*:*:*
838
837
#####
839
838
840
839
PackageName: python-gnupg
0 commit comments