@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
2
2
DataLicense: CC0-1.0
3
3
SPDXID: SPDXRef-DOCUMENT
4
4
DocumentName: Python-cve-bin-tool
5
- DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-d84b9d8c-409a-42ae-ac76-92c9209bcfcb
5
+ DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-017c6e15-70c3-4e52-8848-f3b20d8272e3
6
6
LicenseListVersion: 3.20
7
7
Creator: Tool: sbom4python-0.9.1
8
- Created: 2023-04-24T00:25:50Z
8
+ Created: 2023-05-08T01:12:05Z
9
9
CreatorComment: <text>This document has been automatically generated.</text>
10
10
#####
11
11
@@ -204,18 +204,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrew_svetlov:multidict:6.0.4:*:*:*:*
204
204
205
205
PackageName: yarl
206
206
SPDXID: SPDXRef-Package-13-yarl
207
- PackageVersion: 1.9.1
207
+ PackageVersion: 1.9.2
208
208
PrimaryPackagePurpose: LIBRARY
209
209
PackageSupplier: Person: Andrew Svetlov (
[email protected] )
210
- PackageDownloadLocation: https://pypi.org/project/yarl/1.9.1
210
+ PackageDownloadLocation: https://pypi.org/project/yarl/1.9.2
211
211
FilesAnalyzed: false
212
212
PackageHomePage: https://github.com/aio-libs/yarl/
213
213
PackageLicenseDeclared: Apache-2.0
214
214
PackageLicenseConcluded: Apache-2.0
215
215
PackageCopyrightText: NOASSERTION
216
216
PackageSummary: <text>Yet another URL library</text>
217
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] .
1
218
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrew_svetlov:yarl:1.9.1 :*:*:*:*:*:*:*
217
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] .
2
218
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrew_svetlov:yarl:1.9.2 :*:*:*:*:*:*:*
219
219
#####
220
220
221
221
PackageName: idna
@@ -907,67 +907,66 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julien_danjou:tenacity:8.2.2:*:*:*:*:*
907
907
908
908
PackageName: requests
909
909
SPDXID: SPDXRef-Package-56-requests
910
- PackageVersion: 2.28.2
910
+ PackageVersion: 2.30.0
911
911
PrimaryPackagePurpose: LIBRARY
912
912
PackageSupplier: Person: Kenneth Reitz (
[email protected] )
913
- PackageDownloadLocation: https://pypi.org/project/requests/2.28.2
913
+ PackageDownloadLocation: https://pypi.org/project/requests/2.30.0
914
914
FilesAnalyzed: false
915
915
PackageHomePage: https://requests.readthedocs.io
916
916
PackageLicenseDeclared: NOASSERTION
917
917
PackageLicenseConcluded: Apache-2.0
918
918
PackageLicenseComments: <text>requests declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
919
919
PackageCopyrightText: NOASSERTION
920
920
PackageSummary: <text>Python HTTP for Humans.</text>
921
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/requests@2.28.2
922
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:requests:2.28.2 :*:*:*:*:*:*:*
921
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/requests@2.30.0
922
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:requests:2.30.0 :*:*:*:*:*:*:*
923
923
#####
924
924
925
925
PackageName: certifi
926
926
SPDXID: SPDXRef-Package-57-certifi
927
- PackageVersion: 2022.12 .7
927
+ PackageVersion: 2023.5 .7
928
928
PrimaryPackagePurpose: LIBRARY
929
929
PackageSupplier: Person: Kenneth Reitz (
[email protected] )
930
- PackageDownloadLocation: https://pypi.org/project/certifi/2022.12 .7
930
+ PackageDownloadLocation: https://pypi.org/project/certifi/2023.5 .7
931
931
FilesAnalyzed: false
932
932
PackageHomePage: https://github.com/certifi/python-certifi
933
933
PackageLicenseDeclared: MPL-2.0
934
934
PackageLicenseConcluded: MPL-2.0
935
935
PackageCopyrightText: NOASSERTION
936
936
PackageSummary: <text>Python package for providing Mozilla's CA Bundle.</text>
937
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/certifi@2022.12 .7
938
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:certifi:2022.12 .7:*:*:*:*:*:*:*
937
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/certifi@2023.5 .7
938
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:certifi:2023.5 .7:*:*:*:*:*:*:*
939
939
#####
940
940
941
941
PackageName: urllib3
942
942
SPDXID: SPDXRef-Package-58-urllib3
943
- PackageVersion: 1.26.15
943
+ PackageVersion: 2.0.2
944
944
PrimaryPackagePurpose: LIBRARY
945
945
PackageSupplier: Person: Andrey Petrov (
[email protected] )
946
- PackageDownloadLocation: https://pypi.org/project/urllib3/1.26.15
946
+ PackageDownloadLocation: https://pypi.org/project/urllib3/2.0.2
947
947
FilesAnalyzed: false
948
- PackageHomePage: https://urllib3.readthedocs.io/
949
- PackageLicenseDeclared: MIT
950
- PackageLicenseConcluded: MIT
948
+ PackageLicenseDeclared: NOASSERTION
949
+ PackageLicenseConcluded: NOASSERTION
951
950
PackageCopyrightText: NOASSERTION
952
951
PackageSummary: <text>HTTP library with thread-safe connection pooling, file post, and more.</text>
953
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/urllib3@1.26.15
954
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_petrov:urllib3:1.26.15 :*:*:*:*:*:*:*
952
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/urllib3@2.0.2
953
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_petrov:urllib3:2.0.2 :*:*:*:*:*:*:*
955
954
#####
956
955
957
956
PackageName: rich
958
957
SPDXID: SPDXRef-Package-59-rich
959
- PackageVersion: 13.3.4
958
+ PackageVersion: 13.3.5
960
959
PrimaryPackagePurpose: LIBRARY
961
960
PackageSupplier: Person: Will McGugan (
[email protected] )
962
- PackageDownloadLocation: https://pypi.org/project/rich/13.3.4
961
+ PackageDownloadLocation: https://pypi.org/project/rich/13.3.5
963
962
FilesAnalyzed: false
964
963
PackageHomePage: https://github.com/Textualize/rich
965
964
PackageLicenseDeclared: MIT
966
965
PackageLicenseConcluded: MIT
967
966
PackageCopyrightText: NOASSERTION
968
967
PackageSummary: <text>Render rich text, tables, progress bars, syntax highlighting, markdown and more to the terminal</text>
969
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] .
4
970
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:will_mcgugan:rich:13.3.4 :*:*:*:*:*:*:*
968
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] .
5
969
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:will_mcgugan:rich:13.3.5 :*:*:*:*:*:*:*
971
970
#####
972
971
973
972
PackageName: markdown-it-py
@@ -1065,18 +1064,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:davide_brunato:xmlschema:2.2.3:*:*:*:*
1065
1064
1066
1065
PackageName: elementpath
1067
1066
SPDXID: SPDXRef-Package-66-elementpath
1068
- PackageVersion: 4.1.1
1067
+ PackageVersion: 4.1.2
1069
1068
PrimaryPackagePurpose: LIBRARY
1070
1069
PackageSupplier: Person: Davide Brunato (
[email protected] )
1071
- PackageDownloadLocation: https://pypi.org/project/elementpath/4.1.1
1070
+ PackageDownloadLocation: https://pypi.org/project/elementpath/4.1.2
1072
1071
FilesAnalyzed: false
1073
1072
PackageHomePage: https://github.com/sissaschool/elementpath
1074
1073
PackageLicenseDeclared: MIT
1075
1074
PackageLicenseConcluded: MIT
1076
1075
PackageCopyrightText: NOASSERTION
1077
1076
PackageSummary: <text>XPath 1.0/2.0/3.0/3.1 parsers and selectors for ElementTree and lxml</text>
1078
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] .
1
1079
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:davide_brunato:elementpath:4.1.1 :*:*:*:*:*:*:*
1077
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] .
2
1078
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:davide_brunato:elementpath:4.1.2 :*:*:*:*:*:*:*
1080
1079
#####
1081
1080
1082
1081
PackageName: zstandard
0 commit comments