@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22DataLicense: CC0-1.0
33SPDXID: SPDXRef-DOCUMENT
44DocumentName: Python-cve-bin-tool
5- DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-d75d7ed0-27fe-47a9-b38e-4b006911997d
5+ DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-994eb14e-2b88-4df0-9829-a6f6ef097526
66LicenseListVersion: 3.26
77Creator: Tool: sbom4python-0.12.4
8- Created: 2025-07-21T00:54:46Z
8+ Created: 2025-07-28T00:56:35Z
99CreatorComment: <text>SBOM Type: Build - This document has been automatically generated.</text>
1010#####
1111
414414PackageDownloadLocation: https://pypi.org/project/argcomplete/3.6.2/#files
415415FilesAnalyzed: false
416416PackageHomePage: https://github.com/kislyuk/argcomplete
417+ PackageChecksum: SHA256: 65b3133a29ad53fb42c48cf5114752c7ab66c1c38544fdf6460f450c09b42591
417418PackageLicenseDeclared: NOASSERTION
418419PackageLicenseConcluded: Apache-2.0
419420PackageLicenseComments: <text>argcomplete declares Apache Software License which is not currently a valid SPDX License identifier or expression.</text>
420421PackageCopyrightText: NOASSERTION
421422PackageSummary: <text>Bash tab completion for argparse</text>
422- ReleaseDate: 2025-06-25T08:28:10Z
423+ ReleaseDate: 2025-04-03T04:57:01Z
423424ExternalRef: OTHER documentation https://kislyuk.github.io/argcomplete
424425ExternalRef: OTHER vcs https://github.com/kislyuk/argcomplete
425426ExternalRef: OTHER issue-tracker https://github.com/kislyuk/argcomplete/issues
842843PackageDownloadLocation: https://pypi.org/project/google-apitools/0.5.32/#files
843844FilesAnalyzed: false
844845PackageHomePage: http://github.com/google/apitools
845- PackageChecksum: SHA256: b78f74116558e0476e19501b5b4b2ac7c93261a69c5449c861ea95cbc853c688
846846PackageLicenseDeclared: NOASSERTION
847847PackageLicenseConcluded: Apache-2.0
848848PackageLicenseComments: <text>google-apitools declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
849849PackageCopyrightText: NOASSERTION
850850PackageSummary: <text>client libraries for humans</text>
851- ReleaseDate: 2021-05-05T22:12:58Z
851+ ReleaseDate: 2023-12-12T17:40:13Z
852852ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] 853853ExternalRef: SECURITY cpe23Type cpe:2.3:a:craig_citro:google-apitools:0.5.32:*:*:*:*:*:*:*
854854#####
@@ -1161,12 +1161,11 @@ PackageSupplier: Person: Anthony Harrison (
[email protected] )
11611161PackageDownloadLocation: https://pypi.org/project/csaf-tool/0.3.2/#files
11621162FilesAnalyzed: false
11631163PackageHomePage: https://github.com/anthonyharrison/csaf
1164- PackageChecksum: SHA256: 7e5559cb522eb76e3acad39a7bf9ba1b81e5a6224099d511a4c9c2dcf36caa16
11651164PackageLicenseDeclared: MIT
11661165PackageLicenseConcluded: MIT
11671166PackageCopyrightText: NOASSERTION
11681167PackageSummary: <text>CSAF generator and analyser</text>
1169- ReleaseDate: 2024-06-12T20:10:06Z
1168+ ReleaseDate: 2024-08-29T20:36:52Z
11701169ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] 11711170ExternalRef: SECURITY cpe23Type cpe:2.3:a:anthony_harrison:csaf-tool:0.3.2:*:*:*:*:*:*:*
11721171#####
@@ -1191,21 +1190,21 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_purl_authors:packageurl-python:0.1
11911190
11921191PackageName: rich
11931192SPDXID: SPDXRef-57-rich
1194- PackageVersion: 14.0 .0
1193+ PackageVersion: 14.1 .0
11951194PrimaryPackagePurpose: LIBRARY
11961195PackageSupplier: Person: Will McGugan (
[email protected] )
1197- PackageDownloadLocation: https://pypi.org/project/rich/14.0 .0/#files
1196+ PackageDownloadLocation: https://pypi.org/project/rich/14.1 .0/#files
11981197FilesAnalyzed: false
11991198PackageHomePage: https://github.com/Textualize/rich
1200- PackageChecksum: SHA256: 1c9491e1951aac09caffd42f448ee3d04e58923ffe14993f6e83068dc395d7e0
1199+ PackageChecksum: SHA256: 536f5f1785986d6dbdea3c75205c473f970777b4a0d6c6dd1b696aa05a3fa04f
12011200PackageLicenseDeclared: MIT
12021201PackageLicenseConcluded: MIT
12031202PackageCopyrightText: NOASSERTION
12041203PackageSummary: <text>Render rich text, tables, progress bars, syntax highlighting, markdown and more to the terminal</text>
1205- ReleaseDate: 2025-03-30T14:15:12Z
1204+ ReleaseDate: 2025-07-25T07:32:56Z
12061205ExternalRef: OTHER documentation https://rich.readthedocs.io/en/latest/
1207- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rich@14.0 .0
1208- ExternalRef: SECURITY cpe23Type cpe:2.3:a:will_mcgugan:rich:14.0 .0:*:*:*:*:*:*:*
1206+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rich@14.1 .0
1207+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:will_mcgugan:rich:14.1 .0:*:*:*:*:*:*:*
12091208#####
12101209
12111210PackageName: markdown-it-py
@@ -1334,10 +1333,10 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:6.2.0:*:*:*:*:*:*:*
13341333
13351334PackageName: narwhals
13361335SPDXID: SPDXRef-63-narwhals
1337- PackageVersion: 1.47 .1
1336+ PackageVersion: 1.48 .1
13381337PrimaryPackagePurpose: LIBRARY
13391338PackageSupplier: Person: Marco Gorelli (
[email protected] )
1340- PackageDownloadLocation: https://pypi.org/project/narwhals/1.47 .1/#files
1339+ PackageDownloadLocation: https://pypi.org/project/narwhals/1.48 .1/#files
13411340FilesAnalyzed: false
13421341PackageHomePage: https://github.com/narwhals-dev/narwhals
13431342PackageLicenseDeclared: NOASSERTION
@@ -1349,8 +1348,8 @@ ReleaseDate: 2025-06-26T16:20:40Z
13491348ExternalRef: OTHER documentation https://narwhals-dev.github.io/narwhals/
13501349ExternalRef: OTHER vcs https://github.com/narwhals-dev/narwhals
13511350ExternalRef: OTHER issue-tracker https://github.com/narwhals-dev/narwhals/issues
1352- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@1.47 .1
1353- ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:1.47 .1:*:*:*:*:*:*:*
1351+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@1.48 .1
1352+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:1.48 .1:*:*:*:*:*:*:*
13541353#####
13551354
13561355PackageName: python-gnupg
13611360PackageDownloadLocation: https://pypi.org/project/python-gnupg/0.5.4/#files
13621361FilesAnalyzed: false
13631362PackageHomePage: https://github.com/vsajip/python-gnupg
1364- PackageChecksum: SHA256: 40ce25cde9df29af91fe931ce9df3ce544e14a37f62b13ca878c897217b2de6c
13651363PackageLicenseDeclared: NOASSERTION
13661364PackageLicenseConcluded: BSD-3-Clause
13671365PackageLicenseComments: <text>python-gnupg declares BSD which is not currently a valid SPDX License identifier or expression.</text>
13681366PackageCopyrightText: NOASSERTION
13691367PackageSummary: <text>A wrapper for the Gnu Privacy Guard (GPG or GnuPG)</text>
1370- ReleaseDate: 2025-01-07T11:58:32Z
1368+ ReleaseDate: 2025-06-26T16:20:40Z
13711369ExternalRef: OTHER documentation https://gnupg.readthedocs.io/
13721370ExternalRef: OTHER vcs https://github.com/vsajip/python-gnupg
13731371ExternalRef: OTHER issue-tracker https://github.com/vsajip/python-gnupg/issues
@@ -1635,7 +1633,6 @@ Relationship: SPDXRef-54-lib4vex DEPENDS_ON SPDXRef-56-packageurl-python
16351633Relationship: SPDXRef-55-csaf-tool DEPENDS_ON SPDXRef-56-packageurl-python
16361634Relationship: SPDXRef-55-csaf-tool DEPENDS_ON SPDXRef-57-rich
16371635Relationship: SPDXRef-57-rich DEPENDS_ON SPDXRef-58-markdown-it-py
1638- Relationship: SPDXRef-57-rich DEPENDS_ON SPDXRef-6-typing-extensions
16391636Relationship: SPDXRef-57-rich DEPENDS_ON SPDXRef-60-pygments
16401637Relationship: SPDXRef-58-markdown-it-py DEPENDS_ON SPDXRef-59-mdurl
16411638Relationship: SPDXRef-62-plotly DEPENDS_ON SPDXRef-61-packaging
0 commit comments