@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
2
2
DataLicense: CC0-1.0
3
3
SPDXID: SPDXRef-DOCUMENT
4
4
DocumentName: Python-cve-bin-tool
5
- DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-d75d7ed0-27fe-47a9-b38e-4b006911997d
5
+ DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-994eb14e-2b88-4df0-9829-a6f6ef097526
6
6
LicenseListVersion: 3.26
7
7
Creator: Tool: sbom4python-0.12.4
8
- Created: 2025-07-21T00:54:46Z
8
+ Created: 2025-07-28T00:56:35Z
9
9
CreatorComment: <text>SBOM Type: Build - This document has been automatically generated.</text>
10
10
#####
11
11
414
414
PackageDownloadLocation: https://pypi.org/project/argcomplete/3.6.2/#files
415
415
FilesAnalyzed: false
416
416
PackageHomePage: https://github.com/kislyuk/argcomplete
417
+ PackageChecksum: SHA256: 65b3133a29ad53fb42c48cf5114752c7ab66c1c38544fdf6460f450c09b42591
417
418
PackageLicenseDeclared: NOASSERTION
418
419
PackageLicenseConcluded: Apache-2.0
419
420
PackageLicenseComments: <text>argcomplete declares Apache Software License which is not currently a valid SPDX License identifier or expression.</text>
420
421
PackageCopyrightText: NOASSERTION
421
422
PackageSummary: <text>Bash tab completion for argparse</text>
422
- ReleaseDate: 2025-06-25T08:28:10Z
423
+ ReleaseDate: 2025-04-03T04:57:01Z
423
424
ExternalRef: OTHER documentation https://kislyuk.github.io/argcomplete
424
425
ExternalRef: OTHER vcs https://github.com/kislyuk/argcomplete
425
426
ExternalRef: OTHER issue-tracker https://github.com/kislyuk/argcomplete/issues
842
843
PackageDownloadLocation: https://pypi.org/project/google-apitools/0.5.32/#files
843
844
FilesAnalyzed: false
844
845
PackageHomePage: http://github.com/google/apitools
845
- PackageChecksum: SHA256: b78f74116558e0476e19501b5b4b2ac7c93261a69c5449c861ea95cbc853c688
846
846
PackageLicenseDeclared: NOASSERTION
847
847
PackageLicenseConcluded: Apache-2.0
848
848
PackageLicenseComments: <text>google-apitools declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
849
849
PackageCopyrightText: NOASSERTION
850
850
PackageSummary: <text>client libraries for humans</text>
851
- ReleaseDate: 2021-05-05T22:12:58Z
851
+ ReleaseDate: 2023-12-12T17:40:13Z
852
852
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected]
853
853
ExternalRef: SECURITY cpe23Type cpe:2.3:a:craig_citro:google-apitools:0.5.32:*:*:*:*:*:*:*
854
854
#####
@@ -1161,12 +1161,11 @@ PackageSupplier: Person: Anthony Harrison (
[email protected] )
1161
1161
PackageDownloadLocation: https://pypi.org/project/csaf-tool/0.3.2/#files
1162
1162
FilesAnalyzed: false
1163
1163
PackageHomePage: https://github.com/anthonyharrison/csaf
1164
- PackageChecksum: SHA256: 7e5559cb522eb76e3acad39a7bf9ba1b81e5a6224099d511a4c9c2dcf36caa16
1165
1164
PackageLicenseDeclared: MIT
1166
1165
PackageLicenseConcluded: MIT
1167
1166
PackageCopyrightText: NOASSERTION
1168
1167
PackageSummary: <text>CSAF generator and analyser</text>
1169
- ReleaseDate: 2024-06-12T20:10:06Z
1168
+ ReleaseDate: 2024-08-29T20:36:52Z
1170
1169
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected]
1171
1170
ExternalRef: SECURITY cpe23Type cpe:2.3:a:anthony_harrison:csaf-tool:0.3.2:*:*:*:*:*:*:*
1172
1171
#####
@@ -1191,21 +1190,21 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_purl_authors:packageurl-python:0.1
1191
1190
1192
1191
PackageName: rich
1193
1192
SPDXID: SPDXRef-57-rich
1194
- PackageVersion: 14.0 .0
1193
+ PackageVersion: 14.1 .0
1195
1194
PrimaryPackagePurpose: LIBRARY
1196
1195
PackageSupplier: Person: Will McGugan (
[email protected] )
1197
- PackageDownloadLocation: https://pypi.org/project/rich/14.0 .0/#files
1196
+ PackageDownloadLocation: https://pypi.org/project/rich/14.1 .0/#files
1198
1197
FilesAnalyzed: false
1199
1198
PackageHomePage: https://github.com/Textualize/rich
1200
- PackageChecksum: SHA256: 1c9491e1951aac09caffd42f448ee3d04e58923ffe14993f6e83068dc395d7e0
1199
+ PackageChecksum: SHA256: 536f5f1785986d6dbdea3c75205c473f970777b4a0d6c6dd1b696aa05a3fa04f
1201
1200
PackageLicenseDeclared: MIT
1202
1201
PackageLicenseConcluded: MIT
1203
1202
PackageCopyrightText: NOASSERTION
1204
1203
PackageSummary: <text>Render rich text, tables, progress bars, syntax highlighting, markdown and more to the terminal</text>
1205
- ReleaseDate: 2025-03-30T14:15:12Z
1204
+ ReleaseDate: 2025-07-25T07:32:56Z
1206
1205
ExternalRef: OTHER documentation https://rich.readthedocs.io/en/latest/
1207
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rich@14.0 .0
1208
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:will_mcgugan:rich:14.0 .0:*:*:*:*:*:*:*
1206
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rich@14.1 .0
1207
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:will_mcgugan:rich:14.1 .0:*:*:*:*:*:*:*
1209
1208
#####
1210
1209
1211
1210
PackageName: markdown-it-py
@@ -1334,10 +1333,10 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:6.2.0:*:*:*:*:*:*:*
1334
1333
1335
1334
PackageName: narwhals
1336
1335
SPDXID: SPDXRef-63-narwhals
1337
- PackageVersion: 1.47 .1
1336
+ PackageVersion: 1.48 .1
1338
1337
PrimaryPackagePurpose: LIBRARY
1339
1338
PackageSupplier: Person: Marco Gorelli (
[email protected] )
1340
- PackageDownloadLocation: https://pypi.org/project/narwhals/1.47 .1/#files
1339
+ PackageDownloadLocation: https://pypi.org/project/narwhals/1.48 .1/#files
1341
1340
FilesAnalyzed: false
1342
1341
PackageHomePage: https://github.com/narwhals-dev/narwhals
1343
1342
PackageLicenseDeclared: NOASSERTION
@@ -1349,8 +1348,8 @@ ReleaseDate: 2025-06-26T16:20:40Z
1349
1348
ExternalRef: OTHER documentation https://narwhals-dev.github.io/narwhals/
1350
1349
ExternalRef: OTHER vcs https://github.com/narwhals-dev/narwhals
1351
1350
ExternalRef: OTHER issue-tracker https://github.com/narwhals-dev/narwhals/issues
1352
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@1.47 .1
1353
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:1.47 .1:*:*:*:*:*:*:*
1351
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@1.48 .1
1352
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:1.48 .1:*:*:*:*:*:*:*
1354
1353
#####
1355
1354
1356
1355
PackageName: python-gnupg
1361
1360
PackageDownloadLocation: https://pypi.org/project/python-gnupg/0.5.4/#files
1362
1361
FilesAnalyzed: false
1363
1362
PackageHomePage: https://github.com/vsajip/python-gnupg
1364
- PackageChecksum: SHA256: 40ce25cde9df29af91fe931ce9df3ce544e14a37f62b13ca878c897217b2de6c
1365
1363
PackageLicenseDeclared: NOASSERTION
1366
1364
PackageLicenseConcluded: BSD-3-Clause
1367
1365
PackageLicenseComments: <text>python-gnupg declares BSD which is not currently a valid SPDX License identifier or expression.</text>
1368
1366
PackageCopyrightText: NOASSERTION
1369
1367
PackageSummary: <text>A wrapper for the Gnu Privacy Guard (GPG or GnuPG)</text>
1370
- ReleaseDate: 2025-01-07T11:58:32Z
1368
+ ReleaseDate: 2025-06-26T16:20:40Z
1371
1369
ExternalRef: OTHER documentation https://gnupg.readthedocs.io/
1372
1370
ExternalRef: OTHER vcs https://github.com/vsajip/python-gnupg
1373
1371
ExternalRef: OTHER issue-tracker https://github.com/vsajip/python-gnupg/issues
@@ -1635,7 +1633,6 @@ Relationship: SPDXRef-54-lib4vex DEPENDS_ON SPDXRef-56-packageurl-python
1635
1633
Relationship: SPDXRef-55-csaf-tool DEPENDS_ON SPDXRef-56-packageurl-python
1636
1634
Relationship: SPDXRef-55-csaf-tool DEPENDS_ON SPDXRef-57-rich
1637
1635
Relationship: SPDXRef-57-rich DEPENDS_ON SPDXRef-58-markdown-it-py
1638
- Relationship: SPDXRef-57-rich DEPENDS_ON SPDXRef-6-typing-extensions
1639
1636
Relationship: SPDXRef-57-rich DEPENDS_ON SPDXRef-60-pygments
1640
1637
Relationship: SPDXRef-58-markdown-it-py DEPENDS_ON SPDXRef-59-mdurl
1641
1638
Relationship: SPDXRef-62-plotly DEPENDS_ON SPDXRef-61-packaging
0 commit comments