@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
2
2
DataLicense: CC0-1.0
3
3
SPDXID: SPDXRef-DOCUMENT
4
4
DocumentName: Python-cve-bin-tool
5
- DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-4fd0947e-d80b-48fb-9b53-f6fc3be425a0
5
+ DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-e9c00b5d-e18a-489d-be4d-9ba1ea8303f1
6
6
LicenseListVersion: 3.25
7
7
Creator: Tool: sbom4python-0.12.4
8
- Created: 2025-07-07T00:43:23Z
8
+ Created: 2025-07-14T00:45:32Z
9
9
CreatorComment: <text>SBOM Type: Build - This document has been automatically generated.</text>
10
10
#####
11
11
@@ -27,18 +27,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.4.1:*:*:*:*:*
27
27
28
28
PackageName: aiohttp
29
29
SPDXID: SPDXRef-2-aiohttp
30
- PackageVersion: 3.12.13
30
+ PackageVersion: 3.12.14
31
31
PrimaryPackagePurpose: LIBRARY
32
32
PackageSupplier: NOASSERTION
33
- PackageDownloadLocation: https://pypi.org/project/aiohttp/3.12.13 /#files
33
+ PackageDownloadLocation: https://pypi.org/project/aiohttp/3.12.14 /#files
34
34
FilesAnalyzed: false
35
35
PackageHomePage: https://github.com/aio-libs/aiohttp
36
- PackageChecksum: SHA256: 5421af8f22a98f640261ee48aae3a37f0c41371e99412d55eaf2f8a46d5dad29
36
+ PackageChecksum: SHA256: 906d5075b5ba0dd1c66fcaaf60eb09926a9fef3ca92d912d2a0bbdbecf8b1248
37
37
PackageLicenseDeclared: Apache-2.0
38
38
PackageLicenseConcluded: Apache-2.0
39
39
PackageCopyrightText: NOASSERTION
40
40
PackageSummary: <text>Async http client/server framework (asyncio)</text>
41
- ReleaseDate: 2025-06-14T15:12:58Z
41
+ ReleaseDate: 2025-07-10T13:02:38Z
42
42
ExternalRef: OTHER other https://matrix.to/#/#aio-libs:matrix.org
43
43
ExternalRef: OTHER other https://matrix.to/#/#aio-libs-space:matrix.org
44
44
ExternalRef: OTHER build-system https://github.com/aio-libs/aiohttp/actions?query=workflow%3ACI
@@ -47,7 +47,7 @@ ExternalRef: OTHER log https://docs.aiohttp.org/en/stable/changes.html
47
47
ExternalRef: OTHER other https://docs.aiohttp.org
48
48
ExternalRef: OTHER issue-tracker https://github.com/aio-libs/aiohttp/issues
49
49
ExternalRef: OTHER vcs https://github.com/aio-libs/aiohttp
50
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/aiohttp@3.12.13
50
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/aiohttp@3.12.14
51
51
#####
52
52
53
53
PackageName: aiohappyeyeballs
@@ -79,12 +79,13 @@ PackageSupplier: NOASSERTION
79
79
PackageDownloadLocation: https://pypi.org/project/aiosignal/1.4.0/#files
80
80
FilesAnalyzed: false
81
81
PackageHomePage: https://github.com/aio-libs/aiosignal
82
+ PackageChecksum: SHA256: 053243f8b92b990551949e63930a839ff0cf0b0ebbe0597b0f3fb19e1a0fe82e
82
83
PackageLicenseDeclared: NOASSERTION
83
84
PackageLicenseConcluded: Apache-2.0
84
85
PackageLicenseComments: <text>aiosignal declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
85
86
PackageCopyrightText: NOASSERTION
86
87
PackageSummary: <text>aiosignal: a list of registered asynchronous callbacks</text>
87
- ReleaseDate: 2025-03-12T01:42:47Z
88
+ ReleaseDate: 2025-07-03T22:54:42Z
88
89
ExternalRef: OTHER other https://gitter.im/aio-libs/Lobby
89
90
ExternalRef: OTHER build-system https://github.com/aio-libs/aiosignal/actions
90
91
ExternalRef: OTHER other https://codecov.io/github/aio-libs/aiosignal
@@ -1322,23 +1323,24 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:6.2.0:*:*:*:*:*:*:*
1322
1323
1323
1324
PackageName: narwhals
1324
1325
SPDXID: SPDXRef-62-narwhals
1325
- PackageVersion: 1.45 .0
1326
+ PackageVersion: 1.46 .0
1326
1327
PrimaryPackagePurpose: LIBRARY
1327
1328
PackageSupplier: Person: Marco Gorelli (hello_narwhals@proton.me)
1328
- PackageDownloadLocation: https://pypi.org/project/narwhals/1.45 .0/#files
1329
+ PackageDownloadLocation: https://pypi.org/project/narwhals/1.46 .0/#files
1329
1330
FilesAnalyzed: false
1330
1331
PackageHomePage: https://github.com/narwhals-dev/narwhals
1332
+ PackageChecksum: SHA256: f15d2255695d7e99f624f76aa5b765eb3fff8a509d3215049707af3a3feebc90
1331
1333
PackageLicenseDeclared: NOASSERTION
1332
1334
PackageLicenseConcluded: MIT
1333
1335
PackageLicenseComments: <text>narwhals declares MIT License which is not currently a valid SPDX License identifier or expression.</text>
1334
1336
PackageCopyrightText: NOASSERTION
1335
1337
PackageSummary: <text>Extremely lightweight compatibility layer between dataframe libraries</text>
1336
- ReleaseDate: 2025-06-26T16:20:40Z
1338
+ ReleaseDate: 2025-07-07T11:34:42Z
1337
1339
ExternalRef: OTHER documentation https://narwhals-dev.github.io/narwhals/
1338
1340
ExternalRef: OTHER vcs https://github.com/narwhals-dev/narwhals
1339
1341
ExternalRef: OTHER issue-tracker https://github.com/narwhals-dev/narwhals/issues
1340
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@1.45 .0
1341
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:1.45 .0:*:*:*:*:*:*:*
1342
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@1.46 .0
1343
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:1.46 .0:*:*:*:*:*:*:*
1342
1344
#####
1343
1345
1344
1346
PackageName: python-gnupg
@@ -1427,21 +1429,21 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_petrov:urllib3:2.5.0:*:*:*:*:*:
1427
1429
1428
1430
PackageName: certifi
1429
1431
SPDXID: SPDXRef-67-certifi
1430
- PackageVersion: 2025.6.15
1432
+ PackageVersion: 2025.7.9
1431
1433
PrimaryPackagePurpose: LIBRARY
1432
1434
PackageSupplier: Person: Kenneth Reitz (me@kennethreitz.com)
1433
- PackageDownloadLocation: https://pypi.org/project/certifi/2025.6.15 /#files
1435
+ PackageDownloadLocation: https://pypi.org/project/certifi/2025.7.9 /#files
1434
1436
FilesAnalyzed: false
1435
1437
PackageHomePage: https://github.com/certifi/python-certifi
1436
- PackageChecksum: SHA256: 2e0c7ce7cb5d8f8634ca55d2ba7e6ec2689a2fd6537d8dec1296a477a4910057
1438
+ PackageChecksum: SHA256: d842783a14f8fdd646895ac26f719a061408834473cfc10203f6a575beb15d39
1437
1439
PackageLicenseDeclared: MPL-2.0
1438
1440
PackageLicenseConcluded: MPL-2.0
1439
1441
PackageCopyrightText: NOASSERTION
1440
1442
PackageSummary: <text>Python package for providing Mozilla's CA Bundle.</text>
1441
- ReleaseDate: 2025-06-15T02:45:49Z
1443
+ ReleaseDate: 2025-07-09T02:13:57Z
1442
1444
ExternalRef: OTHER vcs https://github.com/certifi/python-certifi
1443
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/certifi@2025.6.15
1444
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:certifi:2025.6.15 :*:*:*:*:*:*:*
1445
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/certifi@2025.7.9
1446
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:certifi:2025.7.9 :*:*:*:*:*:*:*
1445
1447
#####
1446
1448
1447
1449
PackageName: rpmfile
0 commit comments