@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
2
2
DataLicense: CC0-1.0
3
3
SPDXID: SPDXRef-DOCUMENT
4
4
DocumentName: Python-cve-bin-tool
5
- DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-b1825513-4478-44f6-93bb-fc741e99e648
5
+ DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-4febd54a-bc7a-4016-83c1-b7304af16ea6
6
6
LicenseListVersion: 3.25
7
7
Creator: Tool: sbom4python-0.12.4
8
- Created: 2025-07-07T00:43:23Z
8
+ Created: 2025-07-14T00:45:32Z
9
9
CreatorComment: <text>SBOM Type: Build - This document has been automatically generated.</text>
10
10
#####
11
11
@@ -27,18 +27,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.4.1:*:*:*:*:*
27
27
28
28
PackageName: aiohttp
29
29
SPDXID: SPDXRef-2-aiohttp
30
- PackageVersion: 3.12.13
30
+ PackageVersion: 3.12.14
31
31
PrimaryPackagePurpose: LIBRARY
32
32
PackageSupplier: NOASSERTION
33
- PackageDownloadLocation: https://pypi.org/project/aiohttp/3.12.13 /#files
33
+ PackageDownloadLocation: https://pypi.org/project/aiohttp/3.12.14 /#files
34
34
FilesAnalyzed: false
35
35
PackageHomePage: https://github.com/aio-libs/aiohttp
36
- PackageChecksum: SHA256: 5421af8f22a98f640261ee48aae3a37f0c41371e99412d55eaf2f8a46d5dad29
36
+ PackageChecksum: SHA256: 906d5075b5ba0dd1c66fcaaf60eb09926a9fef3ca92d912d2a0bbdbecf8b1248
37
37
PackageLicenseDeclared: Apache-2.0
38
38
PackageLicenseConcluded: Apache-2.0
39
39
PackageCopyrightText: NOASSERTION
40
40
PackageSummary: <text>Async http client/server framework (asyncio)</text>
41
- ReleaseDate: 2025-06-14T15:12:58Z
41
+ ReleaseDate: 2025-07-10T13:02:38Z
42
42
ExternalRef: OTHER other https://matrix.to/#/#aio-libs:matrix.org
43
43
ExternalRef: OTHER other https://matrix.to/#/#aio-libs-space:matrix.org
44
44
ExternalRef: OTHER build-system https://github.com/aio-libs/aiohttp/actions?query=workflow%3ACI
@@ -47,7 +47,7 @@ ExternalRef: OTHER log https://docs.aiohttp.org/en/stable/changes.html
47
47
ExternalRef: OTHER other https://docs.aiohttp.org
48
48
ExternalRef: OTHER issue-tracker https://github.com/aio-libs/aiohttp/issues
49
49
ExternalRef: OTHER vcs https://github.com/aio-libs/aiohttp
50
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/aiohttp@3.12.13
50
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/aiohttp@3.12.14
51
51
#####
52
52
53
53
PackageName: aiohappyeyeballs
@@ -79,12 +79,13 @@ PackageSupplier: NOASSERTION
79
79
PackageDownloadLocation: https://pypi.org/project/aiosignal/1.4.0/#files
80
80
FilesAnalyzed: false
81
81
PackageHomePage: https://github.com/aio-libs/aiosignal
82
+ PackageChecksum: SHA256: 053243f8b92b990551949e63930a839ff0cf0b0ebbe0597b0f3fb19e1a0fe82e
82
83
PackageLicenseDeclared: NOASSERTION
83
84
PackageLicenseConcluded: Apache-2.0
84
85
PackageLicenseComments: <text>aiosignal declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
85
86
PackageCopyrightText: NOASSERTION
86
87
PackageSummary: <text>aiosignal: a list of registered asynchronous callbacks</text>
87
- ReleaseDate: 2025-03-12T01:42:47Z
88
+ ReleaseDate: 2025-07-03T22:54:42Z
88
89
ExternalRef: OTHER other https://gitter.im/aio-libs/Lobby
89
90
ExternalRef: OTHER build-system https://github.com/aio-libs/aiosignal/actions
90
91
ExternalRef: OTHER other https://codecov.io/github/aio-libs/aiosignal
@@ -1359,23 +1360,24 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:6.2.0:*:*:*:*:*:*:*
1359
1360
1360
1361
PackageName: narwhals
1361
1362
SPDXID: SPDXRef-64-narwhals
1362
- PackageVersion: 1.45 .0
1363
+ PackageVersion: 1.46 .0
1363
1364
PrimaryPackagePurpose: LIBRARY
1364
1365
PackageSupplier: Person: Marco Gorelli (hello_narwhals@proton.me)
1365
- PackageDownloadLocation: https://pypi.org/project/narwhals/1.45 .0/#files
1366
+ PackageDownloadLocation: https://pypi.org/project/narwhals/1.46 .0/#files
1366
1367
FilesAnalyzed: false
1367
1368
PackageHomePage: https://github.com/narwhals-dev/narwhals
1369
+ PackageChecksum: SHA256: f15d2255695d7e99f624f76aa5b765eb3fff8a509d3215049707af3a3feebc90
1368
1370
PackageLicenseDeclared: NOASSERTION
1369
1371
PackageLicenseConcluded: MIT
1370
1372
PackageLicenseComments: <text>narwhals declares MIT License which is not currently a valid SPDX License identifier or expression.</text>
1371
1373
PackageCopyrightText: NOASSERTION
1372
1374
PackageSummary: <text>Extremely lightweight compatibility layer between dataframe libraries</text>
1373
- ReleaseDate: 2025-06-26T16:20:40Z
1375
+ ReleaseDate: 2025-07-07T11:34:42Z
1374
1376
ExternalRef: OTHER documentation https://narwhals-dev.github.io/narwhals/
1375
1377
ExternalRef: OTHER vcs https://github.com/narwhals-dev/narwhals
1376
1378
ExternalRef: OTHER issue-tracker https://github.com/narwhals-dev/narwhals/issues
1377
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@1.45 .0
1378
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:1.45 .0:*:*:*:*:*:*:*
1379
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@1.46 .0
1380
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:1.46 .0:*:*:*:*:*:*:*
1379
1381
#####
1380
1382
1381
1383
PackageName: python-gnupg
@@ -1464,21 +1466,21 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_petrov:urllib3:2.5.0:*:*:*:*:*:
1464
1466
1465
1467
PackageName: certifi
1466
1468
SPDXID: SPDXRef-69-certifi
1467
- PackageVersion: 2025.6.15
1469
+ PackageVersion: 2025.7.9
1468
1470
PrimaryPackagePurpose: LIBRARY
1469
1471
PackageSupplier: Person: Kenneth Reitz (me@kennethreitz.com)
1470
- PackageDownloadLocation: https://pypi.org/project/certifi/2025.6.15 /#files
1472
+ PackageDownloadLocation: https://pypi.org/project/certifi/2025.7.9 /#files
1471
1473
FilesAnalyzed: false
1472
1474
PackageHomePage: https://github.com/certifi/python-certifi
1473
- PackageChecksum: SHA256: 2e0c7ce7cb5d8f8634ca55d2ba7e6ec2689a2fd6537d8dec1296a477a4910057
1475
+ PackageChecksum: SHA256: d842783a14f8fdd646895ac26f719a061408834473cfc10203f6a575beb15d39
1474
1476
PackageLicenseDeclared: MPL-2.0
1475
1477
PackageLicenseConcluded: MPL-2.0
1476
1478
PackageCopyrightText: NOASSERTION
1477
1479
PackageSummary: <text>Python package for providing Mozilla's CA Bundle.</text>
1478
- ReleaseDate: 2025-06-15T02:45:49Z
1480
+ ReleaseDate: 2025-07-09T02:13:57Z
1479
1481
ExternalRef: OTHER vcs https://github.com/certifi/python-certifi
1480
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/certifi@2025.6.15
1481
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:certifi:2025.6.15 :*:*:*:*:*:*:*
1482
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/certifi@2025.7.9
1483
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:certifi:2025.7.9 :*:*:*:*:*:*:*
1482
1484
#####
1483
1485
1484
1486
PackageName: rpmfile
0 commit comments