@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
2
2
DataLicense: CC0-1.0
3
3
SPDXID: SPDXRef-DOCUMENT
4
4
DocumentName: Python-cve-bin-tool
5
- DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-21fe186d-920c-43af-b193-63b9794df5c7
5
+ DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-604c701c-c02e-487c-b4a1-187e77cd27ce
6
6
LicenseListVersion: 3.25
7
7
Creator: Tool: sbom4python-0.12.4
8
- Created: 2025-07-07T00:43:38Z
8
+ Created: 2025-07-14T00:45:32Z
9
9
CreatorComment: <text>SBOM Type: Build - This document has been automatically generated.</text>
10
10
#####
11
11
@@ -27,18 +27,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.4.1:*:*:*:*:*
27
27
28
28
PackageName: aiohttp
29
29
SPDXID: SPDXRef-2-aiohttp
30
- PackageVersion: 3.12.13
30
+ PackageVersion: 3.12.14
31
31
PrimaryPackagePurpose: LIBRARY
32
32
PackageSupplier: NOASSERTION
33
- PackageDownloadLocation: https://pypi.org/project/aiohttp/3.12.13 /#files
33
+ PackageDownloadLocation: https://pypi.org/project/aiohttp/3.12.14 /#files
34
34
FilesAnalyzed: false
35
35
PackageHomePage: https://github.com/aio-libs/aiohttp
36
- PackageChecksum: SHA256: 5421af8f22a98f640261ee48aae3a37f0c41371e99412d55eaf2f8a46d5dad29
36
+ PackageChecksum: SHA256: 906d5075b5ba0dd1c66fcaaf60eb09926a9fef3ca92d912d2a0bbdbecf8b1248
37
37
PackageLicenseDeclared: Apache-2.0
38
38
PackageLicenseConcluded: Apache-2.0
39
39
PackageCopyrightText: NOASSERTION
40
40
PackageSummary: <text>Async http client/server framework (asyncio)</text>
41
- ReleaseDate: 2025-06-14T15:12:58Z
41
+ ReleaseDate: 2025-07-10T13:02:38Z
42
42
ExternalRef: OTHER other https://matrix.to/#/#aio-libs:matrix.org
43
43
ExternalRef: OTHER other https://matrix.to/#/#aio-libs-space:matrix.org
44
44
ExternalRef: OTHER build-system https://github.com/aio-libs/aiohttp/actions?query=workflow%3ACI
@@ -47,7 +47,7 @@ ExternalRef: OTHER log https://docs.aiohttp.org/en/stable/changes.html
47
47
ExternalRef: OTHER other https://docs.aiohttp.org
48
48
ExternalRef: OTHER issue-tracker https://github.com/aio-libs/aiohttp/issues
49
49
ExternalRef: OTHER vcs https://github.com/aio-libs/aiohttp
50
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/aiohttp@3.12.13
50
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/aiohttp@3.12.14
51
51
#####
52
52
53
53
PackageName: aiohappyeyeballs
@@ -79,12 +79,13 @@ PackageSupplier: NOASSERTION
79
79
PackageDownloadLocation: https://pypi.org/project/aiosignal/1.4.0/#files
80
80
FilesAnalyzed: false
81
81
PackageHomePage: https://github.com/aio-libs/aiosignal
82
+ PackageChecksum: SHA256: 053243f8b92b990551949e63930a839ff0cf0b0ebbe0597b0f3fb19e1a0fe82e
82
83
PackageLicenseDeclared: NOASSERTION
83
84
PackageLicenseConcluded: Apache-2.0
84
85
PackageLicenseComments: <text>aiosignal declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
85
86
PackageCopyrightText: NOASSERTION
86
87
PackageSummary: <text>aiosignal: a list of registered asynchronous callbacks</text>
87
- ReleaseDate: 2025-03-12T01:42:47Z
88
+ ReleaseDate: 2025-07-03T22:54:42Z
88
89
ExternalRef: OTHER other https://gitter.im/aio-libs/Lobby
89
90
ExternalRef: OTHER build-system https://github.com/aio-libs/aiosignal/actions
90
91
ExternalRef: OTHER other https://codecov.io/github/aio-libs/aiosignal
@@ -1298,23 +1299,24 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:6.2.0:*:*:*:*:*:*:*
1298
1299
1299
1300
PackageName: narwhals
1300
1301
SPDXID: SPDXRef-61-narwhals
1301
- PackageVersion: 1.45 .0
1302
+ PackageVersion: 1.46 .0
1302
1303
PrimaryPackagePurpose: LIBRARY
1303
1304
PackageSupplier: Person: Marco Gorelli (hello_narwhals@proton.me)
1304
- PackageDownloadLocation: https://pypi.org/project/narwhals/1.45 .0/#files
1305
+ PackageDownloadLocation: https://pypi.org/project/narwhals/1.46 .0/#files
1305
1306
FilesAnalyzed: false
1306
1307
PackageHomePage: https://github.com/narwhals-dev/narwhals
1308
+ PackageChecksum: SHA256: f15d2255695d7e99f624f76aa5b765eb3fff8a509d3215049707af3a3feebc90
1307
1309
PackageLicenseDeclared: NOASSERTION
1308
1310
PackageLicenseConcluded: MIT
1309
1311
PackageLicenseComments: <text>narwhals declares MIT License which is not currently a valid SPDX License identifier or expression.</text>
1310
1312
PackageCopyrightText: NOASSERTION
1311
1313
PackageSummary: <text>Extremely lightweight compatibility layer between dataframe libraries</text>
1312
- ReleaseDate: 2025-06-26T16:20:40Z
1314
+ ReleaseDate: 2025-07-07T11:34:42Z
1313
1315
ExternalRef: OTHER documentation https://narwhals-dev.github.io/narwhals/
1314
1316
ExternalRef: OTHER vcs https://github.com/narwhals-dev/narwhals
1315
1317
ExternalRef: OTHER issue-tracker https://github.com/narwhals-dev/narwhals/issues
1316
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@1.45 .0
1317
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:1.45 .0:*:*:*:*:*:*:*
1318
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@1.46 .0
1319
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:1.46 .0:*:*:*:*:*:*:*
1318
1320
#####
1319
1321
1320
1322
PackageName: python-gnupg
@@ -1403,21 +1405,21 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_petrov:urllib3:2.5.0:*:*:*:*:*:
1403
1405
1404
1406
PackageName: certifi
1405
1407
SPDXID: SPDXRef-66-certifi
1406
- PackageVersion: 2025.6.15
1408
+ PackageVersion: 2025.7.9
1407
1409
PrimaryPackagePurpose: LIBRARY
1408
1410
PackageSupplier: Person: Kenneth Reitz (me@kennethreitz.com)
1409
- PackageDownloadLocation: https://pypi.org/project/certifi/2025.6.15 /#files
1411
+ PackageDownloadLocation: https://pypi.org/project/certifi/2025.7.9 /#files
1410
1412
FilesAnalyzed: false
1411
1413
PackageHomePage: https://github.com/certifi/python-certifi
1412
- PackageChecksum: SHA256: 2e0c7ce7cb5d8f8634ca55d2ba7e6ec2689a2fd6537d8dec1296a477a4910057
1414
+ PackageChecksum: SHA256: d842783a14f8fdd646895ac26f719a061408834473cfc10203f6a575beb15d39
1413
1415
PackageLicenseDeclared: MPL-2.0
1414
1416
PackageLicenseConcluded: MPL-2.0
1415
1417
PackageCopyrightText: NOASSERTION
1416
1418
PackageSummary: <text>Python package for providing Mozilla's CA Bundle.</text>
1417
- ReleaseDate: 2025-06-15T02:45:49Z
1419
+ ReleaseDate: 2025-07-09T02:13:57Z
1418
1420
ExternalRef: OTHER vcs https://github.com/certifi/python-certifi
1419
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/certifi@2025.6.15
1420
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:certifi:2025.6.15 :*:*:*:*:*:*:*
1421
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/certifi@2025.7.9
1422
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:certifi:2025.7.9 :*:*:*:*:*:*:*
1421
1423
#####
1422
1424
1423
1425
PackageName: rpmfile
0 commit comments