@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22DataLicense: CC0-1.0
33SPDXID: SPDXRef-DOCUMENT
44DocumentName: Python-cve-bin-tool
5- DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-389e7e0c-72a5-4fd1-81e1-a7100edeee49
5+ DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-6f3240c3-2796-4fa6-b32e-a2ca8c00d5be
66LicenseListVersion: 3.26
77Creator: Tool: sbom4python-0.12.4
8- Created: 2025-10-13T00:40:32Z
8+ Created: 2025-10-20T00:41:59Z
99CreatorComment: <text>SBOM Type: Build - This document has been automatically generated.</text>
1010#####
1111
@@ -27,18 +27,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:terri_oda:cve-bin-tool:3.4.1:*:*:*:*:*
2727
2828PackageName: aiohttp
2929SPDXID: SPDXRef-2-aiohttp
30- PackageVersion: 3.13.0
30+ PackageVersion: 3.13.1
3131PrimaryPackagePurpose: LIBRARY
3232PackageSupplier: NOASSERTION
33- PackageDownloadLocation: https://pypi.org/project/aiohttp/3.13.0 /#files
33+ PackageDownloadLocation: https://pypi.org/project/aiohttp/3.13.1 /#files
3434FilesAnalyzed: false
3535PackageHomePage: https://github.com/aio-libs/aiohttp
36- PackageChecksum: SHA256: ca69ec38adf5cadcc21d0b25e2144f6a25b7db7bea7e730bac25075bc305eff0
36+ PackageChecksum: SHA256: 2349a6b642020bf20116a8a5c83bae8ba071acf1461c7cbe45fc7fafd552e7e2
3737PackageLicenseDeclared: Apache-2.0 AND MIT
3838PackageLicenseConcluded: Apache-2.0 AND MIT
3939PackageCopyrightText: NOASSERTION
4040PackageSummary: <text>Async http client/server framework (asyncio)</text>
41- ReleaseDate: 2025-10-06T19:54:40Z
41+ ReleaseDate: 2025-10-17T13:58:56Z
4242ExternalRef: OTHER other https://matrix.to/#/#aio-libs:matrix.org
4343ExternalRef: OTHER other https://matrix.to/#/#aio-libs-space:matrix.org
4444ExternalRef: OTHER build-system https://github.com/aio-libs/aiohttp/actions?query=workflow%3ACI
@@ -47,7 +47,7 @@ ExternalRef: OTHER log https://docs.aiohttp.org/en/stable/changes.html
4747ExternalRef: OTHER other https://docs.aiohttp.org
4848ExternalRef: OTHER issue-tracker https://github.com/aio-libs/aiohttp/issues
4949ExternalRef: OTHER vcs https://github.com/aio-libs/aiohttp
50- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] .
0 50+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] .
1 5151#####
5252
5353PackageName: aiohappyeyeballs
@@ -278,11 +278,12 @@ PrimaryPackagePurpose: LIBRARY
278278PackageSupplier: Person: Kim Davies (
[email protected] )
279279PackageDownloadLocation: https://pypi.org/project/idna/3.11/#files
280280FilesAnalyzed: false
281+ PackageChecksum: SHA256: 771a87f49d9defaf64091e6e6fe9c18d4833f140bd19464795bc32d966ca37ea
281282PackageLicenseDeclared: NOASSERTION
282283PackageLicenseConcluded: NOASSERTION
283284PackageCopyrightText: NOASSERTION
284285PackageSummary: <text>Internationalized Domain Names in Applications (IDNA)</text>
285- ReleaseDate: 2025-10-06T14:08:42Z
286+ ReleaseDate: 2025-10-12T14:55:18Z
286287ExternalRef: OTHER log https://github.com/kjd/idna/blob/master/HISTORY.rst
287288ExternalRef: OTHER issue-tracker https://github.com/kjd/idna/issues
288289ExternalRef: OTHER vcs https://github.com/kjd/idna
@@ -1148,20 +1149,20 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:michal_horejsek:fastjsonschema:2.21.2:
11481149
11491150PackageName: xmlschema
11501151SPDXID: SPDXRef-56-xmlschema
1151- PackageVersion: 4.1 .0
1152+ PackageVersion: 4.2 .0
11521153PrimaryPackagePurpose: LIBRARY
11531154PackageSupplier: Person: Davide Brunato (
[email protected] )
1154- PackageDownloadLocation: https://pypi.org/project/xmlschema/4.1 .0/#files
1155+ PackageDownloadLocation: https://pypi.org/project/xmlschema/4.2 .0/#files
11551156FilesAnalyzed: false
11561157PackageHomePage: https://github.com/sissaschool/xmlschema
1157- PackageChecksum: SHA256: eabf610f398a58700bc4ac94380ad9ce558297a3f9ca8b7722ed3f7888eb4498
1158+ PackageChecksum: SHA256: 82d24a50eea5e7f2d603312813848cd66fddf8fa2b6730839c6aa3d66312e3b6
11581159PackageLicenseDeclared: NOASSERTION
11591160PackageLicenseConcluded: NOASSERTION
11601161PackageCopyrightText: NOASSERTION
11611162PackageSummary: <text>An XML Schema validator and decoder</text>
1162- ReleaseDate: 2025-06-05T21:17:35Z
1163- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/xmlschema@4.1 .0
1164- ExternalRef: SECURITY cpe23Type cpe:2.3:a:davide_brunato:xmlschema:4.1 .0:*:*:*:*:*:*:*
1163+ ReleaseDate: 2025-10-14T09:19:28Z
1164+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/xmlschema@4.2 .0
1165+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:davide_brunato:xmlschema:4.2 .0:*:*:*:*:*:*:*
11651166#####
11661167
11671168PackageName: elementpath
@@ -1381,23 +1382,24 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:6.3.1:*:*:*:*:*:*:*
13811382
13821383PackageName: narwhals
13831384SPDXID: SPDXRef-67-narwhals
1384- PackageVersion: 2.7 .0
1385+ PackageVersion: 2.8 .0
13851386PrimaryPackagePurpose: LIBRARY
13861387PackageSupplier: Person: Marco Gorelli (
[email protected] )
1387- PackageDownloadLocation: https://pypi.org/project/narwhals/2.7 .0/#files
1388+ PackageDownloadLocation: https://pypi.org/project/narwhals/2.8 .0/#files
13881389FilesAnalyzed: false
13891390PackageHomePage: https://github.com/narwhals-dev/narwhals
1391+ PackageChecksum: SHA256: 6304856676ba4a79fd34148bda63aed8060dd6edb1227edf3659ce5e091de73c
13901392PackageLicenseDeclared: NOASSERTION
13911393PackageLicenseConcluded: MIT
13921394PackageLicenseComments: <text>narwhals declares MIT License which is not currently a valid SPDX License identifier or expression.</text>
13931395PackageCopyrightText: NOASSERTION
13941396PackageSummary: <text>Extremely lightweight compatibility layer between dataframe libraries</text>
1395- ReleaseDate: 2025-10-02T16:10:22Z
1397+ ReleaseDate: 2025-10-13T08:44:25Z
13961398ExternalRef: OTHER documentation https://narwhals-dev.github.io/narwhals/
13971399ExternalRef: OTHER vcs https://github.com/narwhals-dev/narwhals
13981400ExternalRef: OTHER issue-tracker https://github.com/narwhals-dev/narwhals/issues
1399- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@2.7 .0
1400- ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:2.7 .0:*:*:*:*:*:*:*
1401+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@2.8 .0
1402+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:2.8 .0:*:*:*:*:*:*:*
14011403#####
14021404
14031405PackageName: python-gnupg
@@ -1444,23 +1446,23 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:requests:2.32.5:*:*:*:*:
14441446
14451447PackageName: charset-normalizer
14461448SPDXID: SPDXRef-70-charset-normalizer
1447- PackageVersion: 3.4.3
1449+ PackageVersion: 3.4.4
14481450PrimaryPackagePurpose: LIBRARY
14491451PackageSupplier: Organization: Ahmed R. (
[email protected] )
1450- PackageDownloadLocation: https://pypi.org/project/charset-normalizer/3.4.3 /#files
1452+ PackageDownloadLocation: https://pypi.org/project/charset-normalizer/3.4.4 /#files
14511453FilesAnalyzed: false
1452- PackageChecksum: SHA256: fb7f67a1bfa6e40b438170ebdc8158b78dc465a5a67b6dde178a46987b244a72
1454+ PackageChecksum: SHA256: e824f1492727fa856dd6eda4f7cee25f8518a12f3c4a56a74e8095695089cf6d
14531455PackageLicenseDeclared: MIT
14541456PackageLicenseConcluded: MIT
14551457PackageCopyrightText: NOASSERTION
14561458PackageSummary: <text>The Real First Universal Charset Detector. Open, modern and actively maintained alternative to Chardet.</text>
1457- ReleaseDate: 2025-08-09T07:55:36Z
1459+ ReleaseDate: 2025-10-14T04:40:11Z
14581460ExternalRef: OTHER log https://github.com/jawah/charset_normalizer/blob/master/CHANGELOG.md
14591461ExternalRef: OTHER documentation https://charset-normalizer.readthedocs.io/
14601462ExternalRef: OTHER vcs https://github.com/jawah/charset_normalizer
14611463ExternalRef: OTHER issue-tracker https://github.com/jawah/charset_normalizer/issues
1462- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] .
3 1463- ExternalRef: SECURITY cpe23Type cpe:2.3:a:ahmed_r.:charset-normalizer:3.4.3 :*:*:*:*:*:*:*
1464+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/
[email protected] .
4 1465+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:ahmed_r.:charset-normalizer:3.4.4 :*:*:*:*:*:*:*
14641466#####
14651467
14661468PackageName: urllib3
0 commit comments