@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22DataLicense: CC0-1.0
33SPDXID: SPDXRef-DOCUMENT
44DocumentName: Python-cve-bin-tool
5- DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-994eb14e-2b88-4df0-9829-a6f6ef097526
5+ DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-7c378e2d-f181-4971-b509-6b6e5d0f3d1a
66LicenseListVersion: 3.26
77Creator: Tool: sbom4python-0.12.4
8- Created: 2025-07-28T00:56:35Z
8+ Created: 2025-08-04T00:52:52Z
99CreatorComment: <text>SBOM Type: Build - This document has been automatically generated.</text>
1010#####
1111
@@ -27,18 +27,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.4.1:*:*:*:*:*
2727
2828PackageName: aiohttp
2929SPDXID: SPDXRef-2-aiohttp
30- PackageVersion: 3.12.14
30+ PackageVersion: 3.12.15
3131PrimaryPackagePurpose: LIBRARY
3232PackageSupplier: NOASSERTION
33- PackageDownloadLocation: https://pypi.org/project/aiohttp/3.12.14 /#files
33+ PackageDownloadLocation: https://pypi.org/project/aiohttp/3.12.15 /#files
3434FilesAnalyzed: false
3535PackageHomePage: https://github.com/aio-libs/aiohttp
36- PackageChecksum: SHA256: 906d5075b5ba0dd1c66fcaaf60eb09926a9fef3ca92d912d2a0bbdbecf8b1248
37- PackageLicenseDeclared: Apache-2.0
38- PackageLicenseConcluded: Apache-2.0
36+ PackageChecksum: SHA256: b6fc902bff74d9b1879ad55f5404153e2b33a82e72a95c89cec5eb6cc9e92fbc
37+ PackageLicenseDeclared: Apache-2.0 AND MIT
38+ PackageLicenseConcluded: Apache-2.0 AND MIT
3939PackageCopyrightText: NOASSERTION
4040PackageSummary: <text>Async http client/server framework (asyncio)</text>
41- ReleaseDate: 2025-07-10T13:02:38Z
41+ ReleaseDate: 2025-07-29T05:49:43Z
4242ExternalRef: OTHER other https://matrix.to/#/#aio-libs:matrix.org
4343ExternalRef: OTHER other https://matrix.to/#/#aio-libs-space:matrix.org
4444ExternalRef: OTHER build-system https://github.com/aio-libs/aiohttp/actions?query=workflow%3ACI
@@ -47,7 +47,7 @@ ExternalRef: OTHER log https://docs.aiohttp.org/en/stable/changes.html
4747ExternalRef: OTHER other https://docs.aiohttp.org
4848ExternalRef: OTHER issue-tracker https://github.com/aio-libs/aiohttp/issues
4949ExternalRef: OTHER vcs https://github.com/aio-libs/aiohttp
50- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] .
14 50+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] .
15 5151#####
5252
5353PackageName: aiohappyeyeballs
843843PackageDownloadLocation: https://pypi.org/project/google-apitools/0.5.32/#files
844844FilesAnalyzed: false
845845PackageHomePage: http://github.com/google/apitools
846+ PackageChecksum: SHA256: b78f74116558e0476e19501b5b4b2ac7c93261a69c5449c861ea95cbc853c688
846847PackageLicenseDeclared: NOASSERTION
847848PackageLicenseConcluded: Apache-2.0
848849PackageLicenseComments: <text>google-apitools declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
849850PackageCopyrightText: NOASSERTION
850851PackageSummary: <text>client libraries for humans</text>
851- ReleaseDate: 2023-12-12T17:40:13Z
852+ ReleaseDate: 2021-05-05T22:12:58Z
852853ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] 853854ExternalRef: SECURITY cpe23Type cpe:2.3:a:craig_citro:google-apitools:0.5.32:*:*:*:*:*:*:*
854855#####
@@ -1161,31 +1162,32 @@ PackageSupplier: Person: Anthony Harrison (
[email protected] )
11611162PackageDownloadLocation: https://pypi.org/project/csaf-tool/0.3.2/#files
11621163FilesAnalyzed: false
11631164PackageHomePage: https://github.com/anthonyharrison/csaf
1165+ PackageChecksum: SHA256: 7e5559cb522eb76e3acad39a7bf9ba1b81e5a6224099d511a4c9c2dcf36caa16
11641166PackageLicenseDeclared: MIT
11651167PackageLicenseConcluded: MIT
11661168PackageCopyrightText: NOASSERTION
11671169PackageSummary: <text>CSAF generator and analyser</text>
1168- ReleaseDate: 2024-08-29T20:36:52Z
1170+ ReleaseDate: 2024-06-12T20:10:06Z
11691171ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] 11701172ExternalRef: SECURITY cpe23Type cpe:2.3:a:anthony_harrison:csaf-tool:0.3.2:*:*:*:*:*:*:*
11711173#####
11721174
11731175PackageName: packageurl-python
11741176SPDXID: SPDXRef-56-packageurl-python
1175- PackageVersion: 0.17.1
1177+ PackageVersion: 0.17.3
11761178PrimaryPackagePurpose: LIBRARY
11771179PackageSupplier: Person: the purl authors
1178- PackageDownloadLocation: https://pypi.org/project/packageurl-python/0.17.1 /#files
1180+ PackageDownloadLocation: https://pypi.org/project/packageurl-python/0.17.3 /#files
11791181FilesAnalyzed: false
11801182PackageHomePage: https://github.com/package-url/packageurl-python
1181- PackageChecksum: SHA256: 59b0862ae0b216994f847e05b4c6e870e0d16e1ddd706feefb19d79810f22cbd
1183+ PackageChecksum: SHA256: f51b5aab570159f07258c8e998e9972ff3bf060da16b7334a42bd9f9737777d9
11821184PackageLicenseDeclared: MIT
11831185PackageLicenseConcluded: MIT
11841186PackageCopyrightText: NOASSERTION
11851187PackageSummary: <text>A purl aka. Package URL parser and builder</text>
1186- ReleaseDate: 2025-06-06T13:13:58Z
1187- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] .
1 1188- ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_purl_authors:packageurl-python:0.17.1 :*:*:*:*:*:*:*
1188+ ReleaseDate: 2025-08-01T03:24:33Z
1189+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] .
3 1190+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_purl_authors:packageurl-python:0.17.3 :*:*:*:*:*:*:*
11891191#####
11901192
11911193PackageName: rich
@@ -1333,23 +1335,24 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:6.2.0:*:*:*:*:*:*:*
13331335
13341336PackageName: narwhals
13351337SPDXID: SPDXRef-63-narwhals
1336- PackageVersion: 1.48 .1
1338+ PackageVersion: 2.0 .1
13371339PrimaryPackagePurpose: LIBRARY
13381340PackageSupplier: Person: Marco Gorelli (
[email protected] )
1339- PackageDownloadLocation: https://pypi.org/project/narwhals/1.48 .1/#files
1341+ PackageDownloadLocation: https://pypi.org/project/narwhals/2.0 .1/#files
13401342FilesAnalyzed: false
13411343PackageHomePage: https://github.com/narwhals-dev/narwhals
1344+ PackageChecksum: SHA256: 837457e36a2ba1710c881fb69e1f79ce44fb81728c92ac378f70892a53af8ddb
13421345PackageLicenseDeclared: NOASSERTION
13431346PackageLicenseConcluded: MIT
13441347PackageLicenseComments: <text>narwhals declares MIT License which is not currently a valid SPDX License identifier or expression.</text>
13451348PackageCopyrightText: NOASSERTION
13461349PackageSummary: <text>Extremely lightweight compatibility layer between dataframe libraries</text>
1347- ReleaseDate: 2025-06-26T16:20:40Z
1350+ ReleaseDate: 2025-07-29T08:39:03Z
13481351ExternalRef: OTHER documentation https://narwhals-dev.github.io/narwhals/
13491352ExternalRef: OTHER vcs https://github.com/narwhals-dev/narwhals
13501353ExternalRef: OTHER issue-tracker https://github.com/narwhals-dev/narwhals/issues
1351- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@1.48 .1
1352- ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:1.48 .1:*:*:*:*:*:*:*
1354+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@2.0 .1
1355+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:2.0 .1:*:*:*:*:*:*:*
13531356#####
13541357
13551358PackageName: python-gnupg
13601363PackageDownloadLocation: https://pypi.org/project/python-gnupg/0.5.4/#files
13611364FilesAnalyzed: false
13621365PackageHomePage: https://github.com/vsajip/python-gnupg
1366+ PackageChecksum: SHA256: 40ce25cde9df29af91fe931ce9df3ce544e14a37f62b13ca878c897217b2de6c
13631367PackageLicenseDeclared: NOASSERTION
13641368PackageLicenseConcluded: BSD-3-Clause
13651369PackageLicenseComments: <text>python-gnupg declares BSD which is not currently a valid SPDX License identifier or expression.</text>
13661370PackageCopyrightText: NOASSERTION
13671371PackageSummary: <text>A wrapper for the Gnu Privacy Guard (GPG or GnuPG)</text>
1368- ReleaseDate: 2025-06-26T16:20:40Z
1372+ ReleaseDate: 2025-01-07T11:58:32Z
13691373ExternalRef: OTHER documentation https://gnupg.readthedocs.io/
13701374ExternalRef: OTHER vcs https://github.com/vsajip/python-gnupg
13711375ExternalRef: OTHER issue-tracker https://github.com/vsajip/python-gnupg/issues
@@ -1437,21 +1441,21 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_petrov:urllib3:2.5.0:*:*:*:*:*:
14371441
14381442PackageName: certifi
14391443SPDXID: SPDXRef-68-certifi
1440- PackageVersion: 2025.7.14
1444+ PackageVersion: 2025.8.3
14411445PrimaryPackagePurpose: LIBRARY
14421446PackageSupplier: Person: Kenneth Reitz (
[email protected] )
1443- PackageDownloadLocation: https://pypi.org/project/certifi/2025.7.14 /#files
1447+ PackageDownloadLocation: https://pypi.org/project/certifi/2025.8.3 /#files
14441448FilesAnalyzed: false
14451449PackageHomePage: https://github.com/certifi/python-certifi
1446- PackageChecksum: SHA256: 6b31f564a415d79ee77df69d757bb49a5bb53bd9f756cbbe24394ffd6fc1f4b2
1450+ PackageChecksum: SHA256: f6c12493cfb1b06ba2ff328595af9350c65d6644968e5d3a2ffd78699af217a5
14471451PackageLicenseDeclared: MPL-2.0
14481452PackageLicenseConcluded: MPL-2.0
14491453PackageCopyrightText: NOASSERTION
14501454PackageSummary: <text>Python package for providing Mozilla's CA Bundle.</text>
1451- ReleaseDate: 2025-07-14T03:29:26Z
1455+ ReleaseDate: 2025-08-03T03:07:45Z
14521456ExternalRef: OTHER vcs https://github.com/certifi/python-certifi
1453- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/certifi@2025.7.14
1454- ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:certifi:2025.7.14 :*:*:*:*:*:*:*
1457+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/certifi@2025.8.3
1458+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:certifi:2025.8.3 :*:*:*:*:*:*:*
14551459#####
14561460
14571461PackageName: rpmfile
0 commit comments