@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
2
2
DataLicense: CC0-1.0
3
3
SPDXID: SPDXRef-DOCUMENT
4
4
DocumentName: Python-cve-bin-tool
5
- DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-c36ae76e-814c-4678-86bf-d2ca7200a00e
5
+ DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-c55e7d4f-a926-4b95-9891-671a0ab28523
6
6
LicenseListVersion: 3.26
7
7
Creator: Tool: sbom4python-0.12.4
8
- Created: 2025-07-28T00:56:36Z
8
+ Created: 2025-08-04T00:52:59Z
9
9
CreatorComment: <text>SBOM Type: Build - This document has been automatically generated.</text>
10
10
#####
11
11
@@ -27,18 +27,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.4.1:*:*:*:*:*
27
27
28
28
PackageName: aiohttp
29
29
SPDXID: SPDXRef-2-aiohttp
30
- PackageVersion: 3.12.14
30
+ PackageVersion: 3.12.15
31
31
PrimaryPackagePurpose: LIBRARY
32
32
PackageSupplier: NOASSERTION
33
- PackageDownloadLocation: https://pypi.org/project/aiohttp/3.12.14 /#files
33
+ PackageDownloadLocation: https://pypi.org/project/aiohttp/3.12.15 /#files
34
34
FilesAnalyzed: false
35
35
PackageHomePage: https://github.com/aio-libs/aiohttp
36
- PackageChecksum: SHA256: 906d5075b5ba0dd1c66fcaaf60eb09926a9fef3ca92d912d2a0bbdbecf8b1248
37
- PackageLicenseDeclared: Apache-2.0
38
- PackageLicenseConcluded: Apache-2.0
36
+ PackageChecksum: SHA256: b6fc902bff74d9b1879ad55f5404153e2b33a82e72a95c89cec5eb6cc9e92fbc
37
+ PackageLicenseDeclared: Apache-2.0 AND MIT
38
+ PackageLicenseConcluded: Apache-2.0 AND MIT
39
39
PackageCopyrightText: NOASSERTION
40
40
PackageSummary: <text>Async http client/server framework (asyncio)</text>
41
- ReleaseDate: 2025-07-10T13:02:38Z
41
+ ReleaseDate: 2025-07-29T05:49:43Z
42
42
ExternalRef: OTHER other https://matrix.to/#/#aio-libs:matrix.org
43
43
ExternalRef: OTHER other https://matrix.to/#/#aio-libs-space:matrix.org
44
44
ExternalRef: OTHER build-system https://github.com/aio-libs/aiohttp/actions?query=workflow%3ACI
@@ -47,7 +47,7 @@ ExternalRef: OTHER log https://docs.aiohttp.org/en/stable/changes.html
47
47
ExternalRef: OTHER other https://docs.aiohttp.org
48
48
ExternalRef: OTHER issue-tracker https://github.com/aio-libs/aiohttp/issues
49
49
ExternalRef: OTHER vcs https://github.com/aio-libs/aiohttp
50
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] .
14
50
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] .
15
51
51
#####
52
52
53
53
PackageName: aiohappyeyeballs
867
867
PackageDownloadLocation: https://pypi.org/project/google-apitools/0.5.32/#files
868
868
FilesAnalyzed: false
869
869
PackageHomePage: http://github.com/google/apitools
870
+ PackageChecksum: SHA256: b78f74116558e0476e19501b5b4b2ac7c93261a69c5449c861ea95cbc853c688
870
871
PackageLicenseDeclared: NOASSERTION
871
872
PackageLicenseConcluded: Apache-2.0
872
873
PackageLicenseComments: <text>google-apitools declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
873
874
PackageCopyrightText: NOASSERTION
874
875
PackageSummary: <text>client libraries for humans</text>
875
- ReleaseDate: 2023-12-12T17:40:13Z
876
+ ReleaseDate: 2021-05-05T22:12:58Z
876
877
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected]
877
878
ExternalRef: SECURITY cpe23Type cpe:2.3:a:craig_citro:google-apitools:0.5.32:*:*:*:*:*:*:*
878
879
#####
@@ -1197,20 +1198,20 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:anthony_harrison:csaf-tool:0.3.2:*:*:*
1197
1198
1198
1199
PackageName: packageurl-python
1199
1200
SPDXID: SPDXRef-57-packageurl-python
1200
- PackageVersion: 0.17.1
1201
+ PackageVersion: 0.17.3
1201
1202
PrimaryPackagePurpose: LIBRARY
1202
1203
PackageSupplier: Person: the purl authors
1203
- PackageDownloadLocation: https://pypi.org/project/packageurl-python/0.17.1 /#files
1204
+ PackageDownloadLocation: https://pypi.org/project/packageurl-python/0.17.3 /#files
1204
1205
FilesAnalyzed: false
1205
1206
PackageHomePage: https://github.com/package-url/packageurl-python
1206
- PackageChecksum: SHA256: 59b0862ae0b216994f847e05b4c6e870e0d16e1ddd706feefb19d79810f22cbd
1207
+ PackageChecksum: SHA256: f51b5aab570159f07258c8e998e9972ff3bf060da16b7334a42bd9f9737777d9
1207
1208
PackageLicenseDeclared: MIT
1208
1209
PackageLicenseConcluded: MIT
1209
1210
PackageCopyrightText: NOASSERTION
1210
1211
PackageSummary: <text>A purl aka. Package URL parser and builder</text>
1211
- ReleaseDate: 2025-06-06T13:13:58Z
1212
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] .
1
1213
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_purl_authors:packageurl-python:0.17.1 :*:*:*:*:*:*:*
1212
+ ReleaseDate: 2025-08-01T03:24:33Z
1213
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] .
3
1214
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_purl_authors:packageurl-python:0.17.3 :*:*:*:*:*:*:*
1214
1215
#####
1215
1216
1216
1217
PackageName: rich
@@ -1358,23 +1359,24 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:6.2.0:*:*:*:*:*:*:*
1358
1359
1359
1360
PackageName: narwhals
1360
1361
SPDXID: SPDXRef-64-narwhals
1361
- PackageVersion: 1.48 .1
1362
+ PackageVersion: 2.0 .1
1362
1363
PrimaryPackagePurpose: LIBRARY
1363
1364
PackageSupplier: Person: Marco Gorelli (
[email protected] )
1364
- PackageDownloadLocation: https://pypi.org/project/narwhals/1.48 .1/#files
1365
+ PackageDownloadLocation: https://pypi.org/project/narwhals/2.0 .1/#files
1365
1366
FilesAnalyzed: false
1366
1367
PackageHomePage: https://github.com/narwhals-dev/narwhals
1368
+ PackageChecksum: SHA256: 837457e36a2ba1710c881fb69e1f79ce44fb81728c92ac378f70892a53af8ddb
1367
1369
PackageLicenseDeclared: NOASSERTION
1368
1370
PackageLicenseConcluded: MIT
1369
1371
PackageLicenseComments: <text>narwhals declares MIT License which is not currently a valid SPDX License identifier or expression.</text>
1370
1372
PackageCopyrightText: NOASSERTION
1371
1373
PackageSummary: <text>Extremely lightweight compatibility layer between dataframe libraries</text>
1372
- ReleaseDate: 2025-06-26T16:20:40Z
1374
+ ReleaseDate: 2025-07-29T08:39:03Z
1373
1375
ExternalRef: OTHER documentation https://narwhals-dev.github.io/narwhals/
1374
1376
ExternalRef: OTHER vcs https://github.com/narwhals-dev/narwhals
1375
1377
ExternalRef: OTHER issue-tracker https://github.com/narwhals-dev/narwhals/issues
1376
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@1.48 .1
1377
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:1.48 .1:*:*:*:*:*:*:*
1378
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@2.0 .1
1379
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:2.0 .1:*:*:*:*:*:*:*
1378
1380
#####
1379
1381
1380
1382
PackageName: python-gnupg
@@ -1463,21 +1465,21 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_petrov:urllib3:2.5.0:*:*:*:*:*:
1463
1465
1464
1466
PackageName: certifi
1465
1467
SPDXID: SPDXRef-69-certifi
1466
- PackageVersion: 2025.7.14
1468
+ PackageVersion: 2025.8.3
1467
1469
PrimaryPackagePurpose: LIBRARY
1468
1470
PackageSupplier: Person: Kenneth Reitz (
[email protected] )
1469
- PackageDownloadLocation: https://pypi.org/project/certifi/2025.7.14 /#files
1471
+ PackageDownloadLocation: https://pypi.org/project/certifi/2025.8.3 /#files
1470
1472
FilesAnalyzed: false
1471
1473
PackageHomePage: https://github.com/certifi/python-certifi
1472
- PackageChecksum: SHA256: 6b31f564a415d79ee77df69d757bb49a5bb53bd9f756cbbe24394ffd6fc1f4b2
1474
+ PackageChecksum: SHA256: f6c12493cfb1b06ba2ff328595af9350c65d6644968e5d3a2ffd78699af217a5
1473
1475
PackageLicenseDeclared: MPL-2.0
1474
1476
PackageLicenseConcluded: MPL-2.0
1475
1477
PackageCopyrightText: NOASSERTION
1476
1478
PackageSummary: <text>Python package for providing Mozilla's CA Bundle.</text>
1477
- ReleaseDate: 2025-07-14T03:29:26Z
1479
+ ReleaseDate: 2025-08-03T03:07:45Z
1478
1480
ExternalRef: OTHER vcs https://github.com/certifi/python-certifi
1479
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/certifi@2025.7.14
1480
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:certifi:2025.7.14 :*:*:*:*:*:*:*
1481
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/certifi@2025.8.3
1482
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:certifi:2025.8.3 :*:*:*:*:*:*:*
1481
1483
#####
1482
1484
1483
1485
PackageName: rpmfile
0 commit comments