@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
2
2
DataLicense: CC0-1.0
3
3
SPDXID: SPDXRef-DOCUMENT
4
4
DocumentName: Python-cve-bin-tool
5
- DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-4992f648-3aa3-4c7e-9862-6074ba2c3ba2
5
+ DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-87588567-0852-4721-937b-f64990b706a8
6
6
LicenseListVersion: 3.22
7
7
Creator: Tool: sbom4python-0.10.1
8
- Created: 2023-12-11T00 :26:28Z
8
+ Created: 2023-12-18T00 :26:14Z
9
9
CreatorComment: <text>This document has been automatically generated.</text>
10
10
#####
11
11
@@ -28,7 +28,7 @@ PackageName: aiohttp
28
28
SPDXID: SPDXRef-Package-2-aiohttp
29
29
PackageVersion: 3.9.1
30
30
PrimaryPackagePurpose: LIBRARY
31
- PackageSupplier: Organization: NOASSERTION
31
+ PackageSupplier: NOASSERTION
32
32
PackageDownloadLocation: https://pypi.org/project/aiohttp/3.9.1
33
33
FilesAnalyzed: false
34
34
PackageLicenseDeclared: NOASSERTION
@@ -43,7 +43,7 @@ PackageName: aiosignal
43
43
SPDXID: SPDXRef-Package-3-aiosignal
44
44
PackageVersion: 1.3.1
45
45
PrimaryPackagePurpose: LIBRARY
46
- PackageSupplier: Organization: NOASSERTION
46
+ PackageSupplier: NOASSERTION
47
47
PackageDownloadLocation: https://pypi.org/project/aiosignal/1.3.1
48
48
FilesAnalyzed: false
49
49
PackageLicenseDeclared: NOASSERTION
55
55
56
56
PackageName: frozenlist
57
57
SPDXID: SPDXRef-Package-4-frozenlist
58
- PackageVersion: 1.4.0
58
+ PackageVersion: 1.4.1
59
59
PrimaryPackagePurpose: LIBRARY
60
- PackageSupplier: Organization: NOASSERTION
61
- PackageDownloadLocation: https://pypi.org/project/frozenlist/1.4.0
60
+ PackageSupplier: NOASSERTION
61
+ PackageDownloadLocation: https://pypi.org/project/frozenlist/1.4.1
62
62
FilesAnalyzed: false
63
63
PackageLicenseDeclared: NOASSERTION
64
64
PackageLicenseConcluded: Apache-2.0
65
65
PackageLicenseComments: <text>frozenlist declares Apache 2 which is not currently a valid SPDX License identifier or expression.</text>
66
66
PackageCopyrightText: NOASSERTION
67
67
PackageSummary: <text>A list-like structure which implements collections.abc.MutableSequence</text>
68
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] .
0
68
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] .
1
69
69
#####
70
70
71
71
PackageName: async-timeout
@@ -615,7 +615,7 @@ PackageName: markupsafe
615
615
SPDXID: SPDXRef-Package-40-markupsafe
616
616
PackageVersion: 2.1.3
617
617
PrimaryPackagePurpose: LIBRARY
618
- PackageSupplier: Organization: NOASSERTION
618
+ PackageSupplier: NOASSERTION
619
619
PackageDownloadLocation: https://pypi.org/project/MarkupSafe/2.1.3
620
620
FilesAnalyzed: false
621
621
PackageLicenseDeclared: BSD-3-Clause
@@ -672,32 +672,32 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:referencing:0.32.0:*:*:*
672
672
673
673
PackageName: rpds-py
674
674
SPDXID: SPDXRef-Package-44-rpds-py
675
- PackageVersion: 0.13 .2
675
+ PackageVersion: 0.15 .2
676
676
PrimaryPackagePurpose: LIBRARY
677
677
PackageSupplier: Person: Julian Berman
678
- PackageDownloadLocation: https://pypi.org/project/rpds-py/0.13 .2
678
+ PackageDownloadLocation: https://pypi.org/project/rpds-py/0.15 .2
679
679
FilesAnalyzed: false
680
680
PackageLicenseDeclared: MIT
681
681
PackageLicenseConcluded: MIT
682
682
PackageCopyrightText: NOASSERTION
683
683
PackageSummary: <text>Python bindings to Rust's persistent data structures (rpds)</text>
684
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rpds-py@0.13 .2
685
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.13 .2:*:*:*:*:*:*:*
684
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rpds-py@0.15 .2
685
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.15 .2:*:*:*:*:*:*:*
686
686
#####
687
687
688
688
PackageName: lib4sbom
689
689
SPDXID: SPDXRef-Package-45-lib4sbom
690
- PackageVersion: 0.5.3
690
+ PackageVersion: 0.5.4
691
691
PrimaryPackagePurpose: LIBRARY
692
692
PackageSupplier: Person: Anthony Harrison (
[email protected] )
693
- PackageDownloadLocation: https://pypi.org/project/lib4sbom/0.5.3
693
+ PackageDownloadLocation: https://pypi.org/project/lib4sbom/0.5.4
694
694
FilesAnalyzed: false
695
695
PackageLicenseDeclared: Apache-2.0
696
696
PackageLicenseConcluded: Apache-2.0
697
697
PackageCopyrightText: NOASSERTION
698
698
PackageSummary: <text>Software Bill of Material (SBOM) generator and consumer library</text>
699
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] .
3
700
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:anthony_harrison:lib4sbom:0.5.3 :*:*:*:*:*:*:*
699
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] .
4
700
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:anthony_harrison:lib4sbom:0.5.4 :*:*:*:*:*:*:*
701
701
#####
702
702
703
703
PackageName: pyyaml
@@ -733,17 +733,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:raphael_barrois:semantic-version:2.10.
733
733
734
734
PackageName: packageurl-python
735
735
SPDXID: SPDXRef-Package-48-packageurl-python
736
- PackageVersion: 0.12.0
736
+ PackageVersion: 0.13.1
737
737
PrimaryPackagePurpose: LIBRARY
738
738
PackageSupplier: Person: the purl authors
739
- PackageDownloadLocation: https://pypi.org/project/packageurl-python/0.12.0
739
+ PackageDownloadLocation: https://pypi.org/project/packageurl-python/0.13.1
740
740
FilesAnalyzed: false
741
741
PackageLicenseDeclared: MIT
742
742
PackageLicenseConcluded: MIT
743
743
PackageCopyrightText: NOASSERTION
744
744
PackageSummary: <text>A purl aka. Package URL parser and builder</text>
745
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/packageurl-python@0.12.0
746
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_purl_authors:packageurl-python:0.12.0 :*:*:*:*:*:*:*
745
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/packageurl-python@0.13.1
746
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_purl_authors:packageurl-python:0.13.1 :*:*:*:*:*:*:*
747
747
#####
748
748
749
749
PackageName: packaging
@@ -794,18 +794,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julien_danjou:tenacity:8.2.3:*:*:*:*:*
794
794
795
795
PackageName: python-gnupg
796
796
SPDXID: SPDXRef-Package-52-python-gnupg
797
- PackageVersion: 0.5.1
797
+ PackageVersion: 0.5.2
798
798
PrimaryPackagePurpose: LIBRARY
799
799
PackageSupplier: Person: Vinay Sajip (
[email protected] )
800
- PackageDownloadLocation: https://pypi.org/project/python-gnupg/0.5.1
800
+ PackageDownloadLocation: https://pypi.org/project/python-gnupg/0.5.2
801
801
FilesAnalyzed: false
802
802
PackageLicenseDeclared: NOASSERTION
803
803
PackageLicenseConcluded: BSD-3-Clause
804
804
PackageLicenseComments: <text>python-gnupg declares BSD which is not currently a valid SPDX License identifier or expression.</text>
805
805
PackageCopyrightText: NOASSERTION
806
806
PackageSummary: <text>A wrapper for the Gnu Privacy Guard (GPG or GnuPG)</text>
807
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] .
1
808
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:vinay_sajip:python-gnupg:0.5.1 :*:*:*:*:*:*:*
807
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] .
2
808
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:vinay_sajip:python-gnupg:0.5.2 :*:*:*:*:*:*:*
809
809
#####
810
810
811
811
PackageName: requests
0 commit comments