@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22DataLicense: CC0-1.0
33SPDXID: SPDXRef-DOCUMENT
44DocumentName: Python-cve-bin-tool
5- DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-44fef178-29ca-49aa-a90e-4e9fa1d6ed6d
5+ DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-156d1333-107b-45f2-9bab-245ab3e876cb
66LicenseListVersion: 3.21
77Creator: Tool: sbom4python-0.10.0
8- Created: 2023-10-23T00:25:18Z
8+ Created: 2023-10-30T00:24:47Z
99CreatorComment: <text>This document has been automatically generated.</text>
1010#####
1111
@@ -240,18 +240,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:nir_cohen:distro:1.8.0:*:*:*:*:*:*:*
240240
241241PackageName: gsutil
242242SPDXID: SPDXRef-Package-16-gsutil
243- PackageVersion: 5.26
243+ PackageVersion: 5.27
244244PrimaryPackagePurpose: LIBRARY
245245PackageSupplier: Person: Google Inc. (buganizer-system+187143@google.com)
246- PackageDownloadLocation: https://pypi.org/project/gsutil/5.26
246+ PackageDownloadLocation: https://pypi.org/project/gsutil/5.27
247247FilesAnalyzed: false
248248PackageLicenseDeclared: NOASSERTION
249249PackageLicenseConcluded: Apache-2.0
250250PackageLicenseComments: <text>gsutil declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
251251PackageCopyrightText: NOASSERTION
252252PackageSummary: <text>A command line tool for interacting with cloud storage services.</text>
253- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/gsutil@5.26
254- ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_inc.:gsutil:5.26 :*:*:*:*:*:*:*
253+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/gsutil@5.27
254+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_inc.:gsutil:5.27 :*:*:*:*:*:*:*
255255#####
256256
257257PackageName: argcomplete
@@ -473,33 +473,33 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:sybren_a._stuvel:rsa:4.7.2:*:*:*:*:*:*
473473
474474PackageName: pyopenssl
475475SPDXID: SPDXRef-Package-31-pyopenssl
476- PackageVersion: 23.2 .0
476+ PackageVersion: 23.3 .0
477477PrimaryPackagePurpose: LIBRARY
478478PackageSupplier: Organization: The pyOpenSSL developers (cryptography-dev@python.org)
479- PackageDownloadLocation: https://pypi.org/project/pyOpenSSL/23.2 .0
479+ PackageDownloadLocation: https://pypi.org/project/pyOpenSSL/23.3 .0
480480FilesAnalyzed: false
481481PackageLicenseDeclared: NOASSERTION
482482PackageLicenseConcluded: Apache-2.0
483483PackageLicenseComments: <text>pyOpenSSL declares Apache License, Version 2.0 which is not currently a valid SPDX License identifier or expression.</text>
484484PackageCopyrightText: NOASSERTION
485485PackageSummary: <text>Python wrapper module around the OpenSSL library</text>
486- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/pyopenssl@23.2 .0
487- ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_pyopenssl_developers:pyopenssl:23.2 .0:*:*:*:*:*:*:*
486+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/pyopenssl@23.3 .0
487+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_pyopenssl_developers:pyopenssl:23.3 .0:*:*:*:*:*:*:*
488488#####
489489
490490PackageName: cryptography
491491SPDXID: SPDXRef-Package-32-cryptography
492- PackageVersion: 41.0.4
492+ PackageVersion: 41.0.5
493493PrimaryPackagePurpose: LIBRARY
494494PackageSupplier: Organization: The Python Cryptographic Authority and individual contributors (cryptography-dev@python.org)
495- PackageDownloadLocation: https://pypi.org/project/cryptography/41.0.4
495+ PackageDownloadLocation: https://pypi.org/project/cryptography/41.0.5
496496FilesAnalyzed: false
497497PackageLicenseDeclared: Apache-2.0 OR BSD-3-Clause
498498PackageLicenseConcluded: Apache-2.0 OR BSD-3-Clause
499499PackageCopyrightText: NOASSERTION
500500PackageSummary: <text>cryptography is a package which provides cryptographic recipes and primitives to Python developers.</text>
501- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/cryptography@41.0.4
502- ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:41.0.4 :*:*:*:*:*:*:*
501+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/cryptography@41.0.5
502+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:the_python_cryptographic_authority_and_individual_contributors:cryptography:41.0.5 :*:*:*:*:*:*:*
503503#####
504504
505505PackageName: cffi
@@ -582,17 +582,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_cloud_platform:google-auth:2.23
582582
583583PackageName: cachetools
584584SPDXID: SPDXRef-Package-38-cachetools
585- PackageVersion: 5.3.1
585+ PackageVersion: 5.3.2
586586PrimaryPackagePurpose: LIBRARY
587587PackageSupplier: Person: Thomas Kemmer (tkemmer@computer.org)
588- PackageDownloadLocation: https://pypi.org/project/cachetools/5.3.1
588+ PackageDownloadLocation: https://pypi.org/project/cachetools/5.3.2
589589FilesAnalyzed: false
590590PackageLicenseDeclared: MIT
591591PackageLicenseConcluded: MIT
592592PackageCopyrightText: NOASSERTION
593593PackageSummary: <text>Extensible memoizing collections and decorators</text>
594- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/cachetools@5.3.1
595- ExternalRef: SECURITY cpe23Type cpe:2.3:a:thomas_kemmer:cachetools:5.3.1 :*:*:*:*:*:*:*
594+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/cachetools@5.3.2
595+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:thomas_kemmer:cachetools:5.3.2 :*:*:*:*:*:*:*
596596#####
597597
598598PackageName: monotonic
@@ -809,17 +809,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:donald_stufft_and_individual_contribut
809809
810810PackageName: plotly
811811SPDXID: SPDXRef-Package-53-plotly
812- PackageVersion: 5.17 .0
812+ PackageVersion: 5.18 .0
813813PrimaryPackagePurpose: LIBRARY
814814PackageSupplier: Person: Chris P (chris@plot.ly)
815- PackageDownloadLocation: https://pypi.org/project/plotly/5.17 .0
815+ PackageDownloadLocation: https://pypi.org/project/plotly/5.18 .0
816816FilesAnalyzed: false
817817PackageLicenseDeclared: MIT
818818PackageLicenseConcluded: MIT
819819PackageCopyrightText: NOASSERTION
820820PackageSummary: <text>An open-source, interactive data visualization library for Python</text>
821- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/plotly@5.17 .0
822- ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:5.17 .0:*:*:*:*:*:*:*
821+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/plotly@5.18 .0
822+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:5.18 .0:*:*:*:*:*:*:*
823823#####
824824
825825PackageName: tenacity
0 commit comments