@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
2
2
DataLicense: CC0-1.0
3
3
SPDXID: SPDXRef-DOCUMENT
4
4
DocumentName: Python-cve-bin-tool
5
- DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-e7911257-23d1-45ec-a66b-4fa017f10eeb
5
+ DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-8539054e-f5f1-454e-9607-6a33c553ab77
6
6
LicenseListVersion: 3.20
7
7
Creator: Tool: sbom4python-0.9.1
8
- Created: 2023-04-24T00:25:21Z
8
+ Created: 2023-05-08T01:27:23Z
9
9
CreatorComment: <text>This document has been automatically generated.</text>
10
10
#####
11
11
@@ -140,18 +140,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrew_svetlov:multidict:6.0.4:*:*:*:*
140
140
141
141
PackageName: yarl
142
142
SPDXID: SPDXRef-Package-9-yarl
143
- PackageVersion: 1.9.1
143
+ PackageVersion: 1.9.2
144
144
PrimaryPackagePurpose: LIBRARY
145
145
PackageSupplier: Person: Andrew Svetlov (
[email protected] )
146
- PackageDownloadLocation: https://pypi.org/project/yarl/1.9.1
146
+ PackageDownloadLocation: https://pypi.org/project/yarl/1.9.2
147
147
FilesAnalyzed: false
148
148
PackageHomePage: https://github.com/aio-libs/yarl/
149
149
PackageLicenseDeclared: Apache-2.0
150
150
PackageLicenseConcluded: Apache-2.0
151
151
PackageCopyrightText: NOASSERTION
152
152
PackageSummary: <text>Yet another URL library</text>
153
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] .
1
154
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrew_svetlov:yarl:1.9.1 :*:*:*:*:*:*:*
153
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] .
2
154
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrew_svetlov:yarl:1.9.2 :*:*:*:*:*:*:*
155
155
#####
156
156
157
157
PackageName: idna
@@ -811,67 +811,66 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julien_danjou:tenacity:8.2.2:*:*:*:*:*
811
811
812
812
PackageName: requests
813
813
SPDXID: SPDXRef-Package-50-requests
814
- PackageVersion: 2.28.2
814
+ PackageVersion: 2.30.0
815
815
PrimaryPackagePurpose: LIBRARY
816
816
PackageSupplier: Person: Kenneth Reitz (
[email protected] )
817
- PackageDownloadLocation: https://pypi.org/project/requests/2.28.2
817
+ PackageDownloadLocation: https://pypi.org/project/requests/2.30.0
818
818
FilesAnalyzed: false
819
819
PackageHomePage: https://requests.readthedocs.io
820
820
PackageLicenseDeclared: NOASSERTION
821
821
PackageLicenseConcluded: Apache-2.0
822
822
PackageLicenseComments: <text>requests declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
823
823
PackageCopyrightText: NOASSERTION
824
824
PackageSummary: <text>Python HTTP for Humans.</text>
825
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/requests@2.28.2
826
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:requests:2.28.2 :*:*:*:*:*:*:*
825
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/requests@2.30.0
826
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:requests:2.30.0 :*:*:*:*:*:*:*
827
827
#####
828
828
829
829
PackageName: certifi
830
830
SPDXID: SPDXRef-Package-51-certifi
831
- PackageVersion: 2022.12 .7
831
+ PackageVersion: 2023.5 .7
832
832
PrimaryPackagePurpose: LIBRARY
833
833
PackageSupplier: Person: Kenneth Reitz (
[email protected] )
834
- PackageDownloadLocation: https://pypi.org/project/certifi/2022.12 .7
834
+ PackageDownloadLocation: https://pypi.org/project/certifi/2023.5 .7
835
835
FilesAnalyzed: false
836
836
PackageHomePage: https://github.com/certifi/python-certifi
837
837
PackageLicenseDeclared: MPL-2.0
838
838
PackageLicenseConcluded: MPL-2.0
839
839
PackageCopyrightText: NOASSERTION
840
840
PackageSummary: <text>Python package for providing Mozilla's CA Bundle.</text>
841
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/certifi@2022.12 .7
842
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:certifi:2022.12 .7:*:*:*:*:*:*:*
841
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/certifi@2023.5 .7
842
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:certifi:2023.5 .7:*:*:*:*:*:*:*
843
843
#####
844
844
845
845
PackageName: urllib3
846
846
SPDXID: SPDXRef-Package-52-urllib3
847
- PackageVersion: 1.26.15
847
+ PackageVersion: 2.0.2
848
848
PrimaryPackagePurpose: LIBRARY
849
849
PackageSupplier: Person: Andrey Petrov (
[email protected] )
850
- PackageDownloadLocation: https://pypi.org/project/urllib3/1.26.15
850
+ PackageDownloadLocation: https://pypi.org/project/urllib3/2.0.2
851
851
FilesAnalyzed: false
852
- PackageHomePage: https://urllib3.readthedocs.io/
853
- PackageLicenseDeclared: MIT
854
- PackageLicenseConcluded: MIT
852
+ PackageLicenseDeclared: NOASSERTION
853
+ PackageLicenseConcluded: NOASSERTION
855
854
PackageCopyrightText: NOASSERTION
856
855
PackageSummary: <text>HTTP library with thread-safe connection pooling, file post, and more.</text>
857
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/urllib3@1.26.15
858
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_petrov:urllib3:1.26.15 :*:*:*:*:*:*:*
856
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/urllib3@2.0.2
857
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_petrov:urllib3:2.0.2 :*:*:*:*:*:*:*
859
858
#####
860
859
861
860
PackageName: rich
862
861
SPDXID: SPDXRef-Package-53-rich
863
- PackageVersion: 13.3.4
862
+ PackageVersion: 13.3.5
864
863
PrimaryPackagePurpose: LIBRARY
865
864
PackageSupplier: Person: Will McGugan (
[email protected] )
866
- PackageDownloadLocation: https://pypi.org/project/rich/13.3.4
865
+ PackageDownloadLocation: https://pypi.org/project/rich/13.3.5
867
866
FilesAnalyzed: false
868
867
PackageHomePage: https://github.com/Textualize/rich
869
868
PackageLicenseDeclared: MIT
870
869
PackageLicenseConcluded: MIT
871
870
PackageCopyrightText: NOASSERTION
872
871
PackageSummary: <text>Render rich text, tables, progress bars, syntax highlighting, markdown and more to the terminal</text>
873
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] .
4
874
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:will_mcgugan:rich:13.3.4 :*:*:*:*:*:*:*
872
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] .
5
873
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:will_mcgugan:rich:13.3.5 :*:*:*:*:*:*:*
875
874
#####
876
875
877
876
PackageName: markdown-it-py
@@ -969,18 +968,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:davide_brunato:xmlschema:2.2.3:*:*:*:*
969
968
970
969
PackageName: elementpath
971
970
SPDXID: SPDXRef-Package-60-elementpath
972
- PackageVersion: 4.1.1
971
+ PackageVersion: 4.1.2
973
972
PrimaryPackagePurpose: LIBRARY
974
973
PackageSupplier: Person: Davide Brunato (
[email protected] )
975
- PackageDownloadLocation: https://pypi.org/project/elementpath/4.1.1
974
+ PackageDownloadLocation: https://pypi.org/project/elementpath/4.1.2
976
975
FilesAnalyzed: false
977
976
PackageHomePage: https://github.com/sissaschool/elementpath
978
977
PackageLicenseDeclared: MIT
979
978
PackageLicenseConcluded: MIT
980
979
PackageCopyrightText: NOASSERTION
981
980
PackageSummary: <text>XPath 1.0/2.0/3.0/3.1 parsers and selectors for ElementTree and lxml</text>
982
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] .
1
983
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:davide_brunato:elementpath:4.1.1 :*:*:*:*:*:*:*
981
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] .
2
982
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:davide_brunato:elementpath:4.1.2 :*:*:*:*:*:*:*
984
983
#####
985
984
986
985
PackageName: zstandard
0 commit comments