@@ -2,26 +2,26 @@ SPDXVersion: SPDX-2.3
22DataLicense: CC0-1.0
33SPDXID: SPDXRef-DOCUMENT
44DocumentName: Python-cve-bin-tool
5- DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-ef020a48-2e0c-4106-8ee5-6ade813bf11c
5+ DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-41bf0b8b-5305-4897-bb42-f8931ff3d31a
66LicenseListVersion: 3.22
77Creator: Tool: sbom4python-0.11.1
8- Created: 2024-09-02T00:34:08Z
8+ Created: 2024-09-09T00:36:02Z
99CreatorComment: <text>This document has been automatically generated.</text>
1010#####
1111
1212PackageName: cve-bin-tool
1313SPDXID: SPDXRef-Package-1-cve-bin-tool
14- PackageVersion: 3.4rc1
14+ PackageVersion: 3.4
1515PrimaryPackagePurpose: APPLICATION
1616PackageSupplier: Person: Terri Oda (
[email protected] )
17- PackageDownloadLocation: https://pypi.org/project/cve-bin-tool/3.4rc1
17+ PackageDownloadLocation: https://pypi.org/project/cve-bin-tool/3.4
1818FilesAnalyzed: false
1919PackageLicenseDeclared: GPL-3.0-or-later
2020PackageLicenseConcluded: GPL-3.0-or-later
2121PackageCopyrightText: NOASSERTION
2222PackageSummary: <text>CVE Binary Checker Tool</text>
23- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/cve-bin-tool@3.4rc1
24- ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.4rc1 :*:*:*:*:*:*:*
23+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/cve-bin-tool@3.4
24+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.4 :*:*:*:*:*:*:*
2525#####
2626
2727PackageName: aiohttp
@@ -119,17 +119,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrew_svetlov:multidict:6.0.5:*:*:*:*
119119
120120PackageName: yarl
121121SPDXID: SPDXRef-Package-8-yarl
122- PackageVersion: 1.9.7
122+ PackageVersion: 1.11.0
123123PrimaryPackagePurpose: LIBRARY
124124PackageSupplier: Person: Andrew Svetlov (
[email protected] )
125- PackageDownloadLocation: https://pypi.org/project/yarl/1.9.7
125+ PackageDownloadLocation: https://pypi.org/project/yarl/1.11.0
126126FilesAnalyzed: false
127127PackageLicenseDeclared: Apache-2.0
128128PackageLicenseConcluded: Apache-2.0
129129PackageCopyrightText: NOASSERTION
130130PackageSummary: <text>Yet another URL library</text>
131- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/yarl@1.9.7
132- ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrew_svetlov:yarl:1.9.7 :*:*:*:*:*:*:*
131+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/yarl@1.11.0
132+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrew_svetlov:yarl:1.11.0 :*:*:*:*:*:*:*
133133#####
134134
135135PackageName: idna
@@ -181,19 +181,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:isaac_muse:soupsieve:2.6:*:*:*:*:*:*:*
181181
182182PackageName: cvss
183183SPDXID: SPDXRef-Package-12-cvss
184- PackageVersion: 3.1
184+ PackageVersion: 3.2
185185PrimaryPackagePurpose: LIBRARY
186186PackageSupplier: Organization: Stanislav Red Hat Product Security (
[email protected] )
187- PackageDownloadLocation: https://pypi.org/project/cvss/3.1
187+ PackageDownloadLocation: https://pypi.org/project/cvss/3.2
188188FilesAnalyzed: false
189- PackageChecksum: SHA1: e4cf69bea6bcfa1cbc38dca13b9ec8bf3363a475
190189PackageLicenseDeclared: NOASSERTION
191190PackageLicenseConcluded: LGPL-3.0-or-later
192191PackageLicenseComments: <text>cvss declares LGPLv3+ which is not currently a valid SPDX License identifier or expression.</text>
193192PackageCopyrightText: NOASSERTION
194193PackageSummary: <text>CVSS2/3/4 library with interactive calculator for Python 2 and Python 3</text>
195- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/cvss@3.1
196- ExternalRef: SECURITY cpe23Type cpe:2.3:a:stanislav_red_hat_product_security:cvss:3.1 :*:*:*:*:*:*:*
194+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/cvss@3.2
195+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:stanislav_red_hat_product_security:cvss:3.2 :*:*:*:*:*:*:*
197196#####
198197
199198PackageName: defusedxml
@@ -553,32 +552,32 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_pyopenssl_developers:pyopenssl:24.
553552
554553PackageName: cryptography
555554SPDXID: SPDXRef-Package-35-cryptography
556- PackageVersion: 43.0.0
555+ PackageVersion: 43.0.1
557556PrimaryPackagePurpose: LIBRARY
558557PackageSupplier: Organization: The cryptography developers The Python Cryptographic Authority and individual contributors (
[email protected] )
559- PackageDownloadLocation: https://pypi.org/project/cryptography/43.0.0
558+ PackageDownloadLocation: https://pypi.org/project/cryptography/43.0.1
560559FilesAnalyzed: false
561560PackageLicenseDeclared: Apache-2.0 OR BSD-3-Clause
562561PackageLicenseConcluded: Apache-2.0 OR BSD-3-Clause
563562PackageCopyrightText: NOASSERTION
564563PackageSummary: <text>cryptography is a package which provides cryptographic recipes and primitives to Python developers.</text>
565- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/
[email protected] .
0 566- ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_cryptography_developers_the_python_cryptographic_authority_and_individual_contributors:cryptography:43.0.0 :*:*:*:*:*:*:*
564+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/
[email protected] .
1 565+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_cryptography_developers_the_python_cryptographic_authority_and_individual_contributors:cryptography:43.0.1 :*:*:*:*:*:*:*
567566#####
568567
569568PackageName: cffi
570569SPDXID: SPDXRef-Package-36-cffi
571- PackageVersion: 1.17.0
570+ PackageVersion: 1.17.1
572571PrimaryPackagePurpose: LIBRARY
573572PackageSupplier: Organization: Armin Maciej Fijalkowski (
[email protected] )
574- PackageDownloadLocation: https://pypi.org/project/cffi/1.17.0
573+ PackageDownloadLocation: https://pypi.org/project/cffi/1.17.1
575574FilesAnalyzed: false
576575PackageLicenseDeclared: MIT
577576PackageLicenseConcluded: MIT
578577PackageCopyrightText: NOASSERTION
579578PackageSummary: <text>Foreign Function Interface for Python calling C code.</text>
580- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/
[email protected] .
0 581- ExternalRef: SECURITY cpe23Type cpe:2.3:a:armin_maciej_fijalkowski:cffi:1.17.0 :*:*:*:*:*:*:*
579+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/
[email protected] .
1 580+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:armin_maciej_fijalkowski:cffi:1.17.1 :*:*:*:*:*:*:*
582581#####
583582
584583PackageName: pycparser
@@ -1039,17 +1038,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:sean_ross:rpmfile:2.1.0:*:*:*:*:*:*:*
10391038
10401039PackageName: setuptools
10411040SPDXID: SPDXRef-Package-66-setuptools
1042- PackageVersion: 74.0.0
1041+ PackageVersion: 74.1.2
10431042PrimaryPackagePurpose: LIBRARY
10441043PackageSupplier: Organization: Python Packaging Authority (
[email protected] )
1045- PackageDownloadLocation: https://pypi.org/project/setuptools/74.0.0
1044+ PackageDownloadLocation: https://pypi.org/project/setuptools/74.1.2
10461045FilesAnalyzed: false
10471046PackageLicenseDeclared: NOASSERTION
10481047PackageLicenseConcluded: NOASSERTION
10491048PackageCopyrightText: NOASSERTION
10501049PackageSummary: <text>Easily download, build, install, upgrade, and uninstall Python packages</text>
1051- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/setuptools@74.0.0
1052- ExternalRef: SECURITY cpe23Type cpe:2.3:a:python_packaging_authority:setuptools:74.0.0 :*:*:*:*:*:*:*
1050+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/setuptools@74.1.2
1051+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:python_packaging_authority:setuptools:74.1.2 :*:*:*:*:*:*:*
10531052#####
10541053
10551054PackageName: xmlschema
0 commit comments