@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22DataLicense: CC0-1.0
33SPDXID: SPDXRef-DOCUMENT
44DocumentName: Python-cve-bin-tool
5- DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-884e312b-e5de-47e0-b600-1663af54aead
5+ DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-fa29f6d4-6cf8-4604-84f1-ac36679edc65
66LicenseListVersion: 3.26
77Creator: Tool: sbom4python-0.12.4
8- Created: 2025-07-21T00:54:46Z
8+ Created: 2025-07-28T00:56:36Z
99CreatorComment: <text>SBOM Type: Build - This document has been automatically generated.</text>
1010#####
1111
867867PackageDownloadLocation: https://pypi.org/project/google-apitools/0.5.32/#files
868868FilesAnalyzed: false
869869PackageHomePage: http://github.com/google/apitools
870- PackageChecksum: SHA256: b78f74116558e0476e19501b5b4b2ac7c93261a69c5449c861ea95cbc853c688
871870PackageLicenseDeclared: NOASSERTION
872871PackageLicenseConcluded: Apache-2.0
873872PackageLicenseComments: <text>google-apitools declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
874873PackageCopyrightText: NOASSERTION
875874PackageSummary: <text>client libraries for humans</text>
876- ReleaseDate: 2021-05-05T22:12:58Z
875+ ReleaseDate: 2023-12-12T17:40:13Z
877876ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] 878877ExternalRef: SECURITY cpe23Type cpe:2.3:a:craig_citro:google-apitools:0.5.32:*:*:*:*:*:*:*
879878#####
@@ -1223,12 +1222,11 @@ PackageSupplier: Person: Anthony Harrison (
[email protected] )
12231222PackageDownloadLocation: https://pypi.org/project/csaf-tool/0.3.2/#files
12241223FilesAnalyzed: false
12251224PackageHomePage: https://github.com/anthonyharrison/csaf
1226- PackageChecksum: SHA256: 7e5559cb522eb76e3acad39a7bf9ba1b81e5a6224099d511a4c9c2dcf36caa16
12271225PackageLicenseDeclared: MIT
12281226PackageLicenseConcluded: MIT
12291227PackageCopyrightText: NOASSERTION
12301228PackageSummary: <text>CSAF generator and analyser</text>
1231- ReleaseDate: 2024-06-12T20:10:06Z
1229+ ReleaseDate: 2024-08-29T20:36:52Z
12321230ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] 12331231ExternalRef: SECURITY cpe23Type cpe:2.3:a:anthony_harrison:csaf-tool:0.3.2:*:*:*:*:*:*:*
12341232#####
@@ -1253,21 +1251,21 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_purl_authors:packageurl-python:0.1
12531251
12541252PackageName: rich
12551253SPDXID: SPDXRef-60-rich
1256- PackageVersion: 14.0 .0
1254+ PackageVersion: 14.1 .0
12571255PrimaryPackagePurpose: LIBRARY
12581256PackageSupplier: Person: Will McGugan (
[email protected] )
1259- PackageDownloadLocation: https://pypi.org/project/rich/14.0 .0/#files
1257+ PackageDownloadLocation: https://pypi.org/project/rich/14.1 .0/#files
12601258FilesAnalyzed: false
12611259PackageHomePage: https://github.com/Textualize/rich
1262- PackageChecksum: SHA256: 1c9491e1951aac09caffd42f448ee3d04e58923ffe14993f6e83068dc395d7e0
1260+ PackageChecksum: SHA256: 536f5f1785986d6dbdea3c75205c473f970777b4a0d6c6dd1b696aa05a3fa04f
12631261PackageLicenseDeclared: MIT
12641262PackageLicenseConcluded: MIT
12651263PackageCopyrightText: NOASSERTION
12661264PackageSummary: <text>Render rich text, tables, progress bars, syntax highlighting, markdown and more to the terminal</text>
1267- ReleaseDate: 2025-03-30T14:15:12Z
1265+ ReleaseDate: 2025-07-25T07:32:56Z
12681266ExternalRef: OTHER documentation https://rich.readthedocs.io/en/latest/
1269- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rich@14.0 .0
1270- ExternalRef: SECURITY cpe23Type cpe:2.3:a:will_mcgugan:rich:14.0 .0:*:*:*:*:*:*:*
1267+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rich@14.1 .0
1268+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:will_mcgugan:rich:14.1 .0:*:*:*:*:*:*:*
12711269#####
12721270
12731271PackageName: markdown-it-py
@@ -1396,10 +1394,10 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:6.2.0:*:*:*:*:*:*:*
13961394
13971395PackageName: narwhals
13981396SPDXID: SPDXRef-66-narwhals
1399- PackageVersion: 1.47 .1
1397+ PackageVersion: 1.48 .1
14001398PrimaryPackagePurpose: LIBRARY
14011399PackageSupplier: Person: Marco Gorelli (
[email protected] )
1402- PackageDownloadLocation: https://pypi.org/project/narwhals/1.47 .1/#files
1400+ PackageDownloadLocation: https://pypi.org/project/narwhals/1.48 .1/#files
14031401FilesAnalyzed: false
14041402PackageHomePage: https://github.com/narwhals-dev/narwhals
14051403PackageLicenseDeclared: NOASSERTION
@@ -1411,8 +1409,8 @@ ReleaseDate: 2025-06-26T16:20:40Z
14111409ExternalRef: OTHER documentation https://narwhals-dev.github.io/narwhals/
14121410ExternalRef: OTHER vcs https://github.com/narwhals-dev/narwhals
14131411ExternalRef: OTHER issue-tracker https://github.com/narwhals-dev/narwhals/issues
1414- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@1.47 .1
1415- ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:1.47 .1:*:*:*:*:*:*:*
1412+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@1.48 .1
1413+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:1.48 .1:*:*:*:*:*:*:*
14161414#####
14171415
14181416PackageName: python-gnupg
@@ -1699,7 +1697,6 @@ Relationship: SPDXRef-57-lib4vex DEPENDS_ON SPDXRef-58-csaf-tool
16991697Relationship: SPDXRef-57-lib4vex DEPENDS_ON SPDXRef-59-packageurl-python
17001698Relationship: SPDXRef-58-csaf-tool DEPENDS_ON SPDXRef-59-packageurl-python
17011699Relationship: SPDXRef-58-csaf-tool DEPENDS_ON SPDXRef-60-rich
1702- Relationship: SPDXRef-60-rich DEPENDS_ON SPDXRef-6-typing-extensions
17031700Relationship: SPDXRef-60-rich DEPENDS_ON SPDXRef-61-markdown-it-py
17041701Relationship: SPDXRef-60-rich DEPENDS_ON SPDXRef-63-pygments
17051702Relationship: SPDXRef-61-markdown-it-py DEPENDS_ON SPDXRef-62-mdurl
0 commit comments