@@ -2,26 +2,26 @@ SPDXVersion: SPDX-2.3
2
2
DataLicense: CC0-1.0
3
3
SPDXID: SPDXRef-DOCUMENT
4
4
DocumentName: Python-cve-bin-tool
5
- DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-36380a6d-1569-477d-a8b9-2881d984a8f1
5
+ DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-d7cae49c-e580-434a-9e7a-c67ec6bf03a0
6
6
LicenseListVersion: 3.22
7
7
Creator: Tool: sbom4python-0.11.1
8
- Created: 2024-09-02T00:34:50Z
8
+ Created: 2024-09-09T00:36:55Z
9
9
CreatorComment: <text>This document has been automatically generated.</text>
10
10
#####
11
11
12
12
PackageName: cve-bin-tool
13
13
SPDXID: SPDXRef-Package-1-cve-bin-tool
14
- PackageVersion: 3.4rc1
14
+ PackageVersion: 3.4
15
15
PrimaryPackagePurpose: APPLICATION
16
16
PackageSupplier: Person: Terri Oda (
[email protected] )
17
- PackageDownloadLocation: https://pypi.org/project/cve-bin-tool/3.4rc1
17
+ PackageDownloadLocation: https://pypi.org/project/cve-bin-tool/3.4
18
18
FilesAnalyzed: false
19
19
PackageLicenseDeclared: GPL-3.0-or-later
20
20
PackageLicenseConcluded: GPL-3.0-or-later
21
21
PackageCopyrightText: NOASSERTION
22
22
PackageSummary: <text>CVE Binary Checker Tool</text>
23
- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/cve-bin-tool@3.4rc1
24
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.4rc1 :*:*:*:*:*:*:*
23
+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/cve-bin-tool@3.4
24
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.4 :*:*:*:*:*:*:*
25
25
#####
26
26
27
27
PackageName: aiohttp
@@ -136,17 +136,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrew_svetlov:multidict:6.0.5:*:*:*:*
136
136
137
137
PackageName: yarl
138
138
SPDXID: SPDXRef-Package-9-yarl
139
- PackageVersion: 1.9.7
139
+ PackageVersion: 1.11.0
140
140
PrimaryPackagePurpose: LIBRARY
141
141
PackageSupplier: Person: Andrew Svetlov (
[email protected] )
142
- PackageDownloadLocation: https://pypi.org/project/yarl/1.9.7
142
+ PackageDownloadLocation: https://pypi.org/project/yarl/1.11.0
143
143
FilesAnalyzed: false
144
144
PackageLicenseDeclared: Apache-2.0
145
145
PackageLicenseConcluded: Apache-2.0
146
146
PackageCopyrightText: NOASSERTION
147
147
PackageSummary: <text>Yet another URL library</text>
148
- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/yarl@1.9.7
149
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrew_svetlov:yarl:1.9.7 :*:*:*:*:*:*:*
148
+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/yarl@1.11.0
149
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrew_svetlov:yarl:1.11.0 :*:*:*:*:*:*:*
150
150
#####
151
151
152
152
PackageName: idna
@@ -198,19 +198,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:isaac_muse:soupsieve:2.6:*:*:*:*:*:*:*
198
198
199
199
PackageName: cvss
200
200
SPDXID: SPDXRef-Package-13-cvss
201
- PackageVersion: 3.1
201
+ PackageVersion: 3.2
202
202
PrimaryPackagePurpose: LIBRARY
203
203
PackageSupplier: Organization: Stanislav Red Hat Product Security (
[email protected] )
204
- PackageDownloadLocation: https://pypi.org/project/cvss/3.1
204
+ PackageDownloadLocation: https://pypi.org/project/cvss/3.2
205
205
FilesAnalyzed: false
206
- PackageChecksum: SHA1: e4cf69bea6bcfa1cbc38dca13b9ec8bf3363a475
207
206
PackageLicenseDeclared: NOASSERTION
208
207
PackageLicenseConcluded: LGPL-3.0-or-later
209
208
PackageLicenseComments: <text>cvss declares LGPLv3+ which is not currently a valid SPDX License identifier or expression.</text>
210
209
PackageCopyrightText: NOASSERTION
211
210
PackageSummary: <text>CVSS2/3/4 library with interactive calculator for Python 2 and Python 3</text>
212
- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/cvss@3.1
213
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:stanislav_red_hat_product_security:cvss:3.1 :*:*:*:*:*:*:*
211
+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/cvss@3.2
212
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:stanislav_red_hat_product_security:cvss:3.2 :*:*:*:*:*:*:*
214
213
#####
215
214
216
215
PackageName: defusedxml
@@ -570,32 +569,32 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_pyopenssl_developers:pyopenssl:24.
570
569
571
570
PackageName: cryptography
572
571
SPDXID: SPDXRef-Package-36-cryptography
573
- PackageVersion: 43.0.0
572
+ PackageVersion: 43.0.1
574
573
PrimaryPackagePurpose: LIBRARY
575
574
PackageSupplier: Organization: The cryptography developers The Python Cryptographic Authority and individual contributors (
[email protected] )
576
- PackageDownloadLocation: https://pypi.org/project/cryptography/43.0.0
575
+ PackageDownloadLocation: https://pypi.org/project/cryptography/43.0.1
577
576
FilesAnalyzed: false
578
577
PackageLicenseDeclared: Apache-2.0 OR BSD-3-Clause
579
578
PackageLicenseConcluded: Apache-2.0 OR BSD-3-Clause
580
579
PackageCopyrightText: NOASSERTION
581
580
PackageSummary: <text>cryptography is a package which provides cryptographic recipes and primitives to Python developers.</text>
582
- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/
[email protected] .
0
583
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_cryptography_developers_the_python_cryptographic_authority_and_individual_contributors:cryptography:43.0.0 :*:*:*:*:*:*:*
581
+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/
[email protected] .
1
582
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_cryptography_developers_the_python_cryptographic_authority_and_individual_contributors:cryptography:43.0.1 :*:*:*:*:*:*:*
584
583
#####
585
584
586
585
PackageName: cffi
587
586
SPDXID: SPDXRef-Package-37-cffi
588
- PackageVersion: 1.17.0
587
+ PackageVersion: 1.17.1
589
588
PrimaryPackagePurpose: LIBRARY
590
589
PackageSupplier: Organization: Armin Maciej Fijalkowski (
[email protected] )
591
- PackageDownloadLocation: https://pypi.org/project/cffi/1.17.0
590
+ PackageDownloadLocation: https://pypi.org/project/cffi/1.17.1
592
591
FilesAnalyzed: false
593
592
PackageLicenseDeclared: MIT
594
593
PackageLicenseConcluded: MIT
595
594
PackageCopyrightText: NOASSERTION
596
595
PackageSummary: <text>Foreign Function Interface for Python calling C code.</text>
597
- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/
[email protected] .
0
598
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:armin_maciej_fijalkowski:cffi:1.17.0 :*:*:*:*:*:*:*
596
+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/
[email protected] .
1
597
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:armin_maciej_fijalkowski:cffi:1.17.1 :*:*:*:*:*:*:*
599
598
#####
600
599
601
600
PackageName: pycparser
@@ -1131,17 +1130,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:sean_ross:rpmfile:2.1.0:*:*:*:*:*:*:*
1131
1130
1132
1131
PackageName: setuptools
1133
1132
SPDXID: SPDXRef-Package-72-setuptools
1134
- PackageVersion: 74.0.0
1133
+ PackageVersion: 74.1.2
1135
1134
PrimaryPackagePurpose: LIBRARY
1136
1135
PackageSupplier: Organization: Python Packaging Authority (
[email protected] )
1137
- PackageDownloadLocation: https://pypi.org/project/setuptools/74.0.0
1136
+ PackageDownloadLocation: https://pypi.org/project/setuptools/74.1.2
1138
1137
FilesAnalyzed: false
1139
1138
PackageLicenseDeclared: NOASSERTION
1140
1139
PackageLicenseConcluded: NOASSERTION
1141
1140
PackageCopyrightText: NOASSERTION
1142
1141
PackageSummary: <text>Easily download, build, install, upgrade, and uninstall Python packages</text>
1143
- ExternalRef: PACKAGE_MANAGER purl pkg:pypi/setuptools@74.0.0
1144
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:python_packaging_authority:setuptools:74.0.0 :*:*:*:*:*:*:*
1142
+ ExternalRef: PACKAGE_MANAGER purl pkg:pypi/setuptools@74.1.2
1143
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:python_packaging_authority:setuptools:74.1.2 :*:*:*:*:*:*:*
1145
1144
#####
1146
1145
1147
1146
PackageName: toml
0 commit comments