@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
2
2
DataLicense: CC0-1.0
3
3
SPDXID: SPDXRef-DOCUMENT
4
4
DocumentName: Python-cve-bin-tool
5
- DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-e22d6ccd-3b1e-4723-801c-333cec52ae09
5
+ DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-43ca30d9-07f7-4748-a669-8136d177492c
6
6
LicenseListVersion: 3.22
7
7
Creator: Tool: sbom4python-0.10.4
8
- Created: 2024-05-06T00 :27:03Z
8
+ Created: 2024-05-13T00 :27:42Z
9
9
CreatorComment: <text>This document has been automatically generated.</text>
10
10
#####
11
11
@@ -189,6 +189,7 @@ PrimaryPackagePurpose: LIBRARY
189
189
PackageSupplier: Organization: Stanislav Red Hat Product Security (
[email protected] )
190
190
PackageDownloadLocation: https://pypi.org/project/cvss/3.1
191
191
FilesAnalyzed: false
192
+ PackageChecksum: SHA1: e4cf69bea6bcfa1cbc38dca13b9ec8bf3363a475
192
193
PackageLicenseDeclared: NOASSERTION
193
194
PackageLicenseConcluded: LGPL-3.0-or-later
194
195
PackageLicenseComments: <text>cvss declares LGPLv3+ which is not currently a valid SPDX License identifier or expression.</text>
@@ -249,18 +250,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:tomas_aparicio:filetype:1.2.0:*:*:*:*:
249
250
250
251
PackageName: gsutil
251
252
SPDXID: SPDXRef-Package-16-gsutil
252
- PackageVersion: 5.28
253
+ PackageVersion: 5.29
253
254
PrimaryPackagePurpose: LIBRARY
254
255
PackageSupplier: Person: Google Inc. (
[email protected] )
255
- PackageDownloadLocation: https://pypi.org/project/gsutil/5.28
256
+ PackageDownloadLocation: https://pypi.org/project/gsutil/5.29
256
257
FilesAnalyzed: false
257
258
PackageLicenseDeclared: NOASSERTION
258
259
PackageLicenseConcluded: Apache-2.0
259
260
PackageLicenseComments: <text>gsutil declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
260
261
PackageCopyrightText: NOASSERTION
261
262
PackageSummary: <text>A command line tool for interacting with cloud storage services.</text>
262
- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/gsutil@5.28
263
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_inc.:gsutil:5.28 :*:*:*:*:*:*:*
263
+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/gsutil@5.29
264
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_inc.:gsutil:5.29 :*:*:*:*:*:*:*
264
265
#####
265
266
266
267
PackageName: argcomplete
@@ -557,17 +558,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_pyopenssl_developers:pyopenssl:24.
557
558
558
559
PackageName: cryptography
559
560
SPDXID: SPDXRef-Package-35-cryptography
560
- PackageVersion: 42.0.6
561
+ PackageVersion: 42.0.7
561
562
PrimaryPackagePurpose: LIBRARY
562
563
PackageSupplier: Organization: The Python Cryptographic Authority and individual contributors (
[email protected] )
563
- PackageDownloadLocation: https://pypi.org/project/cryptography/42.0.6
564
+ PackageDownloadLocation: https://pypi.org/project/cryptography/42.0.7
564
565
FilesAnalyzed: false
565
566
PackageLicenseDeclared: Apache-2.0 OR BSD-3-Clause
566
567
PackageLicenseConcluded: Apache-2.0 OR BSD-3-Clause
567
568
PackageCopyrightText: NOASSERTION
568
569
PackageSummary: <text>cryptography is a package which provides cryptographic recipes and primitives to Python developers.</text>
569
- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/
[email protected] .
6
570
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:42.0.6 :*:*:*:*:*:*:*
570
+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/
[email protected] .
7
571
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:42.0.7 :*:*:*:*:*:*:*
571
572
#####
572
573
573
574
PackageName: cffi
@@ -721,7 +722,6 @@ PrimaryPackagePurpose: LIBRARY
721
722
PackageSupplier: NOASSERTION
722
723
PackageDownloadLocation: https://pypi.org/project/MarkupSafe/2.1.5
723
724
FilesAnalyzed: false
724
- PackageChecksum: SHA1: fbba4acd0312826cec9cfe18371c7df07962cb65
725
725
PackageLicenseDeclared: BSD-3-Clause
726
726
PackageLicenseConcluded: BSD-3-Clause
727
727
PackageCopyrightText: NOASSERTION
@@ -777,17 +777,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:referencing:0.35.1:*:*:*
777
777
778
778
PackageName: rpds-py
779
779
SPDXID: SPDXRef-Package-49-rpds-py
780
- PackageVersion: 0.18.0
780
+ PackageVersion: 0.18.1
781
781
PrimaryPackagePurpose: LIBRARY
782
782
PackageSupplier: Person: Julian Berman
783
- PackageDownloadLocation: https://pypi.org/project/rpds-py/0.18.0
783
+ PackageDownloadLocation: https://pypi.org/project/rpds-py/0.18.1
784
784
FilesAnalyzed: false
785
785
PackageLicenseDeclared: MIT
786
786
PackageLicenseConcluded: MIT
787
787
PackageCopyrightText: NOASSERTION
788
788
PackageSummary: <text>Python bindings to Rust's persistent data structures (rpds)</text>
789
- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/
[email protected] .
0
790
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.18.0 :*:*:*:*:*:*:*
789
+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/
[email protected] .
1
790
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.18.1 :*:*:*:*:*:*:*
791
791
#####
792
792
793
793
PackageName: pkgutil-resolve-name
@@ -902,19 +902,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:5.22.0:*:*:*:*:*:*:*
902
902
903
903
PackageName: tenacity
904
904
SPDXID: SPDXRef-Package-57-tenacity
905
- PackageVersion: 8.2.3
905
+ PackageVersion: 8.3.0
906
906
PrimaryPackagePurpose: LIBRARY
907
907
PackageSupplier: Person: Julien Danjou (
[email protected] )
908
- PackageDownloadLocation: https://pypi.org/project/tenacity/8.2.3
908
+ PackageDownloadLocation: https://pypi.org/project/tenacity/8.3.0
909
909
FilesAnalyzed: false
910
- PackageChecksum: SHA1: 41ed2420cda8ab7650a39900451099f4730266c3
911
910
PackageLicenseDeclared: NOASSERTION
912
911
PackageLicenseConcluded: Apache-2.0
913
912
PackageLicenseComments: <text>tenacity declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
914
913
PackageCopyrightText: NOASSERTION
915
914
PackageSummary: <text>Retry code until it succeeds</text>
916
- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/tenacity@8.2.3
917
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:julien_danjou:tenacity:8.2.3 :*:*:*:*:*:*:*
915
+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/tenacity@8.3.0
916
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julien_danjou:tenacity:8.3.0 :*:*:*:*:*:*:*
918
917
#####
919
918
920
919
PackageName: python-gnupg
0 commit comments