@@ -2,26 +2,26 @@ SPDXVersion: SPDX-2.3
2
2
DataLicense: CC0-1.0
3
3
SPDXID: SPDXRef-DOCUMENT
4
4
DocumentName: Python-cve-bin-tool
5
- DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-d43650e7-6fd7-4d7a-a26a-ed4f63fe564e
5
+ DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-ff8dab3a-6076-4661-ade3-e48762928525
6
6
LicenseListVersion: 3.22
7
7
Creator: Tool: sbom4python-0.11.1
8
- Created: 2024-09-02T00:35:18Z
8
+ Created: 2024-09-09T00:36:57Z
9
9
CreatorComment: <text>This document has been automatically generated.</text>
10
10
#####
11
11
12
12
PackageName: cve-bin-tool
13
13
SPDXID: SPDXRef-Package-1-cve-bin-tool
14
- PackageVersion: 3.4rc1
14
+ PackageVersion: 3.4
15
15
PrimaryPackagePurpose: APPLICATION
16
16
PackageSupplier: Person: Terri Oda (
[email protected] )
17
- PackageDownloadLocation: https://pypi.org/project/cve-bin-tool/3.4rc1
17
+ PackageDownloadLocation: https://pypi.org/project/cve-bin-tool/3.4
18
18
FilesAnalyzed: false
19
19
PackageLicenseDeclared: GPL-3.0-or-later
20
20
PackageLicenseConcluded: GPL-3.0-or-later
21
21
PackageCopyrightText: NOASSERTION
22
22
PackageSummary: <text>CVE Binary Checker Tool</text>
23
- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/cve-bin-tool@3.4rc1
24
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.4rc1 :*:*:*:*:*:*:*
23
+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/cve-bin-tool@3.4
24
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.4 :*:*:*:*:*:*:*
25
25
#####
26
26
27
27
PackageName: aiohttp
@@ -136,17 +136,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrew_svetlov:multidict:6.0.5:*:*:*:*
136
136
137
137
PackageName: yarl
138
138
SPDXID: SPDXRef-Package-9-yarl
139
- PackageVersion: 1.9.7
139
+ PackageVersion: 1.11.0
140
140
PrimaryPackagePurpose: LIBRARY
141
141
PackageSupplier: Person: Andrew Svetlov (
[email protected] )
142
- PackageDownloadLocation: https://pypi.org/project/yarl/1.9.7
142
+ PackageDownloadLocation: https://pypi.org/project/yarl/1.11.0
143
143
FilesAnalyzed: false
144
144
PackageLicenseDeclared: Apache-2.0
145
145
PackageLicenseConcluded: Apache-2.0
146
146
PackageCopyrightText: NOASSERTION
147
147
PackageSummary: <text>Yet another URL library</text>
148
- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/yarl@1.9.7
149
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrew_svetlov:yarl:1.9.7 :*:*:*:*:*:*:*
148
+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/yarl@1.11.0
149
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrew_svetlov:yarl:1.11.0 :*:*:*:*:*:*:*
150
150
#####
151
151
152
152
PackageName: idna
@@ -198,19 +198,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:isaac_muse:soupsieve:2.6:*:*:*:*:*:*:*
198
198
199
199
PackageName: cvss
200
200
SPDXID: SPDXRef-Package-13-cvss
201
- PackageVersion: 3.1
201
+ PackageVersion: 3.2
202
202
PrimaryPackagePurpose: LIBRARY
203
203
PackageSupplier: Organization: Stanislav Red Hat Product Security (
[email protected] )
204
- PackageDownloadLocation: https://pypi.org/project/cvss/3.1
204
+ PackageDownloadLocation: https://pypi.org/project/cvss/3.2
205
205
FilesAnalyzed: false
206
- PackageChecksum: SHA1: e4cf69bea6bcfa1cbc38dca13b9ec8bf3363a475
207
206
PackageLicenseDeclared: NOASSERTION
208
207
PackageLicenseConcluded: LGPL-3.0-or-later
209
208
PackageLicenseComments: <text>cvss declares LGPLv3+ which is not currently a valid SPDX License identifier or expression.</text>
210
209
PackageCopyrightText: NOASSERTION
211
210
PackageSummary: <text>CVSS2/3/4 library with interactive calculator for Python 2 and Python 3</text>
212
- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/cvss@3.1
213
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:stanislav_red_hat_product_security:cvss:3.1 :*:*:*:*:*:*:*
211
+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/cvss@3.2
212
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:stanislav_red_hat_product_security:cvss:3.2 :*:*:*:*:*:*:*
214
213
#####
215
214
216
215
PackageName: defusedxml
@@ -570,32 +569,32 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_pyopenssl_developers:pyopenssl:24.
570
569
571
570
PackageName: cryptography
572
571
SPDXID: SPDXRef-Package-36-cryptography
573
- PackageVersion: 43.0.0
572
+ PackageVersion: 43.0.1
574
573
PrimaryPackagePurpose: LIBRARY
575
574
PackageSupplier: Organization: The cryptography developers The Python Cryptographic Authority and individual contributors (
[email protected] )
576
- PackageDownloadLocation: https://pypi.org/project/cryptography/43.0.0
575
+ PackageDownloadLocation: https://pypi.org/project/cryptography/43.0.1
577
576
FilesAnalyzed: false
578
577
PackageLicenseDeclared: Apache-2.0 OR BSD-3-Clause
579
578
PackageLicenseConcluded: Apache-2.0 OR BSD-3-Clause
580
579
PackageCopyrightText: NOASSERTION
581
580
PackageSummary: <text>cryptography is a package which provides cryptographic recipes and primitives to Python developers.</text>
582
- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/
[email protected] .
0
583
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_cryptography_developers_the_python_cryptographic_authority_and_individual_contributors:cryptography:43.0.0 :*:*:*:*:*:*:*
581
+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/
[email protected] .
1
582
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_cryptography_developers_the_python_cryptographic_authority_and_individual_contributors:cryptography:43.0.1 :*:*:*:*:*:*:*
584
583
#####
585
584
586
585
PackageName: cffi
587
586
SPDXID: SPDXRef-Package-37-cffi
588
- PackageVersion: 1.17.0
587
+ PackageVersion: 1.17.1
589
588
PrimaryPackagePurpose: LIBRARY
590
589
PackageSupplier: Organization: Armin Maciej Fijalkowski (
[email protected] )
591
- PackageDownloadLocation: https://pypi.org/project/cffi/1.17.0
590
+ PackageDownloadLocation: https://pypi.org/project/cffi/1.17.1
592
591
FilesAnalyzed: false
593
592
PackageLicenseDeclared: MIT
594
593
PackageLicenseConcluded: MIT
595
594
PackageCopyrightText: NOASSERTION
596
595
PackageSummary: <text>Foreign Function Interface for Python calling C code.</text>
597
- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/
[email protected] .
0
598
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:armin_maciej_fijalkowski:cffi:1.17.0 :*:*:*:*:*:*:*
596
+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/
[email protected] .
1
597
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:armin_maciej_fijalkowski:cffi:1.17.1 :*:*:*:*:*:*:*
599
598
#####
600
599
601
600
PackageName: pycparser
@@ -1086,17 +1085,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:sean_ross:rpmfile:2.1.0:*:*:*:*:*:*:*
1086
1085
1087
1086
PackageName: setuptools
1088
1087
SPDXID: SPDXRef-Package-69-setuptools
1089
- PackageVersion: 74.0.0
1088
+ PackageVersion: 74.1.2
1090
1089
PrimaryPackagePurpose: LIBRARY
1091
1090
PackageSupplier: Organization: Python Packaging Authority (
[email protected] )
1092
- PackageDownloadLocation: https://pypi.org/project/setuptools/74.0.0
1091
+ PackageDownloadLocation: https://pypi.org/project/setuptools/74.1.2
1093
1092
FilesAnalyzed: false
1094
1093
PackageLicenseDeclared: NOASSERTION
1095
1094
PackageLicenseConcluded: NOASSERTION
1096
1095
PackageCopyrightText: NOASSERTION
1097
1096
PackageSummary: <text>Easily download, build, install, upgrade, and uninstall Python packages</text>
1098
- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/setuptools@74.0.0
1099
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:python_packaging_authority:setuptools:74.0.0 :*:*:*:*:*:*:*
1097
+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/setuptools@74.1.2
1098
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:python_packaging_authority:setuptools:74.1.2 :*:*:*:*:*:*:*
1100
1099
#####
1101
1100
1102
1101
PackageName: toml
0 commit comments