@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
2
2
DataLicense: CC0-1.0
3
3
SPDXID: SPDXRef-DOCUMENT
4
4
DocumentName: Python-cve-bin-tool
5
- DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-2cdd3fdb-160c-479e-8cbd-8406f9da67a2
5
+ DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-063ee786-799c-43a5-850b-db833b886495
6
6
LicenseListVersion: 3.20
7
7
Creator: Tool: sbom4python-0.9.1
8
- Created: 2023-04-24T00:25:25Z
8
+ Created: 2023-05-08T01:12:48Z
9
9
CreatorComment: <text>This document has been automatically generated.</text>
10
10
#####
11
11
@@ -140,18 +140,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrew_svetlov:multidict:6.0.4:*:*:*:*
140
140
141
141
PackageName: yarl
142
142
SPDXID: SPDXRef-Package-9-yarl
143
- PackageVersion: 1.9.1
143
+ PackageVersion: 1.9.2
144
144
PrimaryPackagePurpose: LIBRARY
145
145
PackageSupplier: Person: Andrew Svetlov (
[email protected] )
146
- PackageDownloadLocation: https://pypi.org/project/yarl/1.9.1
146
+ PackageDownloadLocation: https://pypi.org/project/yarl/1.9.2
147
147
FilesAnalyzed: false
148
148
PackageHomePage: https://github.com/aio-libs/yarl/
149
149
PackageLicenseDeclared: Apache-2.0
150
150
PackageLicenseConcluded: Apache-2.0
151
151
PackageCopyrightText: NOASSERTION
152
152
PackageSummary: <text>Yet another URL library</text>
153
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] .
1
154
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrew_svetlov:yarl:1.9.1 :*:*:*:*:*:*:*
153
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] .
2
154
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrew_svetlov:yarl:1.9.2 :*:*:*:*:*:*:*
155
155
#####
156
156
157
157
PackageName: idna
@@ -843,67 +843,66 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julien_danjou:tenacity:8.2.2:*:*:*:*:*
843
843
844
844
PackageName: requests
845
845
SPDXID: SPDXRef-Package-52-requests
846
- PackageVersion: 2.28.2
846
+ PackageVersion: 2.30.0
847
847
PrimaryPackagePurpose: LIBRARY
848
848
PackageSupplier: Person: Kenneth Reitz (
[email protected] )
849
- PackageDownloadLocation: https://pypi.org/project/requests/2.28.2
849
+ PackageDownloadLocation: https://pypi.org/project/requests/2.30.0
850
850
FilesAnalyzed: false
851
851
PackageHomePage: https://requests.readthedocs.io
852
852
PackageLicenseDeclared: NOASSERTION
853
853
PackageLicenseConcluded: Apache-2.0
854
854
PackageLicenseComments: <text>requests declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
855
855
PackageCopyrightText: NOASSERTION
856
856
PackageSummary: <text>Python HTTP for Humans.</text>
857
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/requests@2.28.2
858
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:requests:2.28.2 :*:*:*:*:*:*:*
857
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/requests@2.30.0
858
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:requests:2.30.0 :*:*:*:*:*:*:*
859
859
#####
860
860
861
861
PackageName: certifi
862
862
SPDXID: SPDXRef-Package-53-certifi
863
- PackageVersion: 2022.12 .7
863
+ PackageVersion: 2023.5 .7
864
864
PrimaryPackagePurpose: LIBRARY
865
865
PackageSupplier: Person: Kenneth Reitz (
[email protected] )
866
- PackageDownloadLocation: https://pypi.org/project/certifi/2022.12 .7
866
+ PackageDownloadLocation: https://pypi.org/project/certifi/2023.5 .7
867
867
FilesAnalyzed: false
868
868
PackageHomePage: https://github.com/certifi/python-certifi
869
869
PackageLicenseDeclared: MPL-2.0
870
870
PackageLicenseConcluded: MPL-2.0
871
871
PackageCopyrightText: NOASSERTION
872
872
PackageSummary: <text>Python package for providing Mozilla's CA Bundle.</text>
873
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/certifi@2022.12 .7
874
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:certifi:2022.12 .7:*:*:*:*:*:*:*
873
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/certifi@2023.5 .7
874
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:certifi:2023.5 .7:*:*:*:*:*:*:*
875
875
#####
876
876
877
877
PackageName: urllib3
878
878
SPDXID: SPDXRef-Package-54-urllib3
879
- PackageVersion: 1.26.15
879
+ PackageVersion: 2.0.2
880
880
PrimaryPackagePurpose: LIBRARY
881
881
PackageSupplier: Person: Andrey Petrov (
[email protected] )
882
- PackageDownloadLocation: https://pypi.org/project/urllib3/1.26.15
882
+ PackageDownloadLocation: https://pypi.org/project/urllib3/2.0.2
883
883
FilesAnalyzed: false
884
- PackageHomePage: https://urllib3.readthedocs.io/
885
- PackageLicenseDeclared: MIT
886
- PackageLicenseConcluded: MIT
884
+ PackageLicenseDeclared: NOASSERTION
885
+ PackageLicenseConcluded: NOASSERTION
887
886
PackageCopyrightText: NOASSERTION
888
887
PackageSummary: <text>HTTP library with thread-safe connection pooling, file post, and more.</text>
889
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/urllib3@1.26.15
890
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_petrov:urllib3:1.26.15 :*:*:*:*:*:*:*
888
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/urllib3@2.0.2
889
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_petrov:urllib3:2.0.2 :*:*:*:*:*:*:*
891
890
#####
892
891
893
892
PackageName: rich
894
893
SPDXID: SPDXRef-Package-55-rich
895
- PackageVersion: 13.3.4
894
+ PackageVersion: 13.3.5
896
895
PrimaryPackagePurpose: LIBRARY
897
896
PackageSupplier: Person: Will McGugan (
[email protected] )
898
- PackageDownloadLocation: https://pypi.org/project/rich/13.3.4
897
+ PackageDownloadLocation: https://pypi.org/project/rich/13.3.5
899
898
FilesAnalyzed: false
900
899
PackageHomePage: https://github.com/Textualize/rich
901
900
PackageLicenseDeclared: MIT
902
901
PackageLicenseConcluded: MIT
903
902
PackageCopyrightText: NOASSERTION
904
903
PackageSummary: <text>Render rich text, tables, progress bars, syntax highlighting, markdown and more to the terminal</text>
905
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] .
4
906
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:will_mcgugan:rich:13.3.4 :*:*:*:*:*:*:*
904
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] .
5
905
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:will_mcgugan:rich:13.3.5 :*:*:*:*:*:*:*
907
906
#####
908
907
909
908
PackageName: markdown-it-py
@@ -1001,18 +1000,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:davide_brunato:xmlschema:2.2.3:*:*:*:*
1001
1000
1002
1001
PackageName: elementpath
1003
1002
SPDXID: SPDXRef-Package-62-elementpath
1004
- PackageVersion: 4.1.1
1003
+ PackageVersion: 4.1.2
1005
1004
PrimaryPackagePurpose: LIBRARY
1006
1005
PackageSupplier: Person: Davide Brunato (
[email protected] )
1007
- PackageDownloadLocation: https://pypi.org/project/elementpath/4.1.1
1006
+ PackageDownloadLocation: https://pypi.org/project/elementpath/4.1.2
1008
1007
FilesAnalyzed: false
1009
1008
PackageHomePage: https://github.com/sissaschool/elementpath
1010
1009
PackageLicenseDeclared: MIT
1011
1010
PackageLicenseConcluded: MIT
1012
1011
PackageCopyrightText: NOASSERTION
1013
1012
PackageSummary: <text>XPath 1.0/2.0/3.0/3.1 parsers and selectors for ElementTree and lxml</text>
1014
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] .
1
1015
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:davide_brunato:elementpath:4.1.1 :*:*:*:*:*:*:*
1013
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] .
2
1014
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:davide_brunato:elementpath:4.1.2 :*:*:*:*:*:*:*
1016
1015
#####
1017
1016
1018
1017
PackageName: zstandard
0 commit comments