@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
2
2
DataLicense: CC0-1.0
3
3
SPDXID: SPDXRef-DOCUMENT
4
4
DocumentName: Python-cve-bin-tool
5
- DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-5f495315-237a-40dc-861c-10a1a1ceda44
5
+ DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-b4d96fdd-5043-4abe-aff0-ecab2aa0b7e7
6
6
LicenseListVersion: 3.26
7
7
Creator: Tool: sbom4python-0.12.4
8
- Created: 2025-09-22T00:45:35Z
8
+ Created: 2025-09-29T00:38:26Z
9
9
CreatorComment: <text>SBOM Type: Build - This document has been automatically generated.</text>
10
10
#####
11
11
@@ -295,22 +295,22 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:kim_davies:idna:3.10:*:*:*:*:*:*:*
295
295
296
296
PackageName: beautifulsoup4
297
297
SPDXID: SPDXRef-13-beautifulsoup4
298
- PackageVersion: 4.13.5
298
+ PackageVersion: 4.14.0
299
299
PrimaryPackagePurpose: LIBRARY
300
300
PackageSupplier: Person: Leonard Richardson (leonardr@segfault.org)
301
- PackageDownloadLocation: https://pypi.org/project/beautifulsoup4/4.13.5 /#files
301
+ PackageDownloadLocation: https://pypi.org/project/beautifulsoup4/4.14.0 /#files
302
302
FilesAnalyzed: false
303
303
PackageHomePage: https://www.crummy.com/software/BeautifulSoup/bs4/
304
- PackageChecksum: SHA256: 642085eaa22233aceadff9c69651bc51e8bf3f874fb6d7104ece2beb24b47c4a
304
+ PackageChecksum: SHA256: aee96fbccdf2d2a8d1288b2afa51fc76bb60823b7881a50fb1ed5f711d1a7d73
305
305
PackageLicenseDeclared: NOASSERTION
306
306
PackageLicenseConcluded: MIT
307
307
PackageLicenseComments: <text>beautifulsoup4 declares MIT License which is not currently a valid SPDX License identifier or expression.</text>
308
308
PackageCopyrightText: NOASSERTION
309
309
PackageSummary: <text>Screen-scraping library</text>
310
- ReleaseDate: 2025-08-24T14:06:14Z
310
+ ReleaseDate: 2025-09-27T17:22:16Z
311
311
ExternalRef: OTHER other https://www.crummy.com/software/BeautifulSoup/bs4/download/
312
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/beautifulsoup4@4.13.5
313
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:leonard_richardson:beautifulsoup4:4.13.5 :*:*:*:*:*:*:*
312
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/beautifulsoup4@4.14.0
313
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:leonard_richardson:beautifulsoup4:4.14.0 :*:*:*:*:*:*:*
314
314
#####
315
315
316
316
PackageName: soupsieve
@@ -649,11 +649,12 @@ PackageSupplier: Person: Paul McGuire (ptmcg.gm+pyparsing@gmail.com)
649
649
PackageDownloadLocation: https://pypi.org/project/pyparsing/3.2.5/#files
650
650
FilesAnalyzed: false
651
651
PackageHomePage: https://github.com/pyparsing/pyparsing/
652
+ PackageChecksum: SHA256: e38a4f02064cf41fe6593d328d0512495ad1f3d8a91c4f73fc401b3079a59a5e
652
653
PackageLicenseDeclared: NOASSERTION
653
654
PackageLicenseConcluded: NOASSERTION
654
655
PackageCopyrightText: NOASSERTION
655
656
PackageSummary: <text>pyparsing - Classes and methods to define and execute parsing grammars</text>
656
- ReleaseDate: 2022-02-03T00:00:29Z
657
+ ReleaseDate: 2025-09-21T04:11:04Z
657
658
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/pyparsing@3.2.5
658
659
ExternalRef: SECURITY cpe23Type cpe:2.3:a:paul_mcguire:pyparsing:3.2.5:*:*:*:*:*:*:*
659
660
#####
@@ -858,21 +859,21 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_cloud_platform:google-auth-http
858
859
859
860
PackageName: google-apitools
860
861
SPDXID: SPDXRef-42-google-apitools
861
- PackageVersion: 0.5.32
862
+ PackageVersion: 0.5.35
862
863
PrimaryPackagePurpose: LIBRARY
863
864
PackageSupplier: Person: Craig Citro (craigcitro@google.com)
864
- PackageDownloadLocation: https://pypi.org/project/google-apitools/0.5.32 /#files
865
+ PackageDownloadLocation: https://pypi.org/project/google-apitools/0.5.35 /#files
865
866
FilesAnalyzed: false
866
867
PackageHomePage: http://github.com/google/apitools
867
- PackageChecksum: SHA256: b78f74116558e0476e19501b5b4b2ac7c93261a69c5449c861ea95cbc853c688
868
+ PackageChecksum: SHA256: 0f6f67fbe6f228f4777ae7e9d00e01476f7b8a48dca3a4353a1c32369437bbd0
868
869
PackageLicenseDeclared: NOASSERTION
869
870
PackageLicenseConcluded: Apache-2.0
870
871
PackageLicenseComments: <text>google-apitools declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
871
872
PackageCopyrightText: NOASSERTION
872
873
PackageSummary: <text>client libraries for humans</text>
873
- ReleaseDate: 2021-05-05T22:12:58Z
874
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/google-apitools@0.5.32
875
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:craig_citro:google-apitools:0.5.32 :*:*:*:*:*:*:*
874
+ ReleaseDate: 2025-09-24T20:22:49Z
875
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/google-apitools@0.5.35
876
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:craig_citro:google-apitools:0.5.35 :*:*:*:*:*:*:*
876
877
#####
877
878
878
879
PackageName: monotonic
@@ -918,52 +919,23 @@ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/jinja2@3.1.6
918
919
919
920
PackageName: markupsafe
920
921
SPDXID: SPDXRef-45-markupsafe
921
- PackageVersion: 3.0.2
922
+ PackageVersion: 3.0.3
922
923
PrimaryPackagePurpose: LIBRARY
923
924
PackageSupplier: NOASSERTION
924
- PackageDownloadLocation: https://pypi.org/project/markupsafe/3.0.2 /#files
925
+ PackageDownloadLocation: https://pypi.org/project/markupsafe/3.0.3 /#files
925
926
FilesAnalyzed: false
926
- PackageChecksum: SHA256: 7e94c425039cde14257288fd61dcfb01963e658efbc0ff54f5306b06054700f8
927
+ PackageChecksum: SHA256: 2f981d352f04553a7171b8e44369f2af4055f888dfb147d55e42d29e29e74559
927
928
PackageLicenseDeclared: NOASSERTION
928
929
PackageLicenseConcluded: NOASSERTION
929
- PackageLicenseComments: <text>markupsafe declares Copyright 2010 Pallets
930
-
931
- Redistribution and use in source and binary forms, with or without
932
- modification, are permitted provided that the following conditions are
933
- met:
934
-
935
- 1. Redistributions of source code must retain the above copyright
936
- notice, this list of conditions and the following disclaimer.
937
-
938
- 2. Redistributions in binary form must reproduce the above copyright
939
- notice, this list of conditions and the following disclaimer in the
940
- documentation and/or other materials provided with the distribution.
941
-
942
- 3. Neither the name of the copyright holder nor the names of its
943
- contributors may be used to endorse or promote products derived from
944
- this software without specific prior written permission.
945
-
946
- THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
947
- "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
948
- LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A
949
- PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
950
- HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
951
- SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED
952
- TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR
953
- PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF
954
- LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING
955
- NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
956
- SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
957
- which is not currently a valid SPDX License identifier or expression.</text>
958
930
PackageCopyrightText: NOASSERTION
959
931
PackageSummary: <text>Safely add untrusted strings to HTML/XML markup.</text>
960
- ReleaseDate: 2024-10-18T15:20:51Z
932
+ ReleaseDate: 2025-09-27T18:36:05Z
961
933
ExternalRef: OTHER other https://palletsprojects.com/donate
962
934
ExternalRef: OTHER documentation https://markupsafe.palletsprojects.com/
963
- ExternalRef: OTHER log https://markupsafe.palletsprojects.com/changes/
935
+ ExternalRef: OTHER log https://markupsafe.palletsprojects.com/page/ changes/
964
936
ExternalRef: OTHER vcs https://github.com/pallets/markupsafe/
965
937
ExternalRef: OTHER chat https://discord.gg/pallets
966
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/markupsafe@3.0.2
938
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/markupsafe@3.0.3
967
939
#####
968
940
969
941
PackageName: jsonschema
@@ -1081,25 +1053,25 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:anthony_harrison:lib4sbom:0.8.8:*:*:*:
1081
1053
1082
1054
PackageName: pyyaml
1083
1055
SPDXID: SPDXRef-51-pyyaml
1084
- PackageVersion: 6.0.2
1056
+ PackageVersion: 6.0.3
1085
1057
PrimaryPackagePurpose: LIBRARY
1086
1058
PackageSupplier: Person: Kirill Simonov (xi@resolvent.net)
1087
1059
PackageDownloadLocation: https://pypi.org/project/PyYAML/
1088
1060
FilesAnalyzed: false
1089
1061
PackageHomePage: https://pyyaml.org/
1090
- PackageChecksum: SHA256: 0a9a2848a5b7feac301353437eb7d5957887edbf81d56e903999a75a3d743086
1062
+ PackageChecksum: SHA256: 214ed4befebe12df36bcc8bc2b64b396ca31be9304b8f59e25c11cf94a4c033b
1091
1063
PackageLicenseDeclared: MIT
1092
1064
PackageLicenseConcluded: MIT
1093
1065
PackageCopyrightText: NOASSERTION
1094
1066
PackageSummary: <text>YAML parser and emitter for Python</text>
1095
- ReleaseDate: 2024-08-06T20 :31:40Z
1067
+ ReleaseDate: 2025-09-25T21 :31:46Z
1096
1068
ExternalRef: OTHER issue-tracker https://github.com/yaml/pyyaml/issues
1097
1069
ExternalRef: OTHER build-system https://github.com/yaml/pyyaml/actions
1098
1070
ExternalRef: OTHER documentation https://pyyaml.org/wiki/PyYAMLDocumentation
1099
1071
ExternalRef: OTHER mailing-list http://lists.sourceforge.net/lists/listinfo/yaml-core
1100
1072
ExternalRef: OTHER vcs https://github.com/yaml/pyyaml
1101
- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/pyyaml@6.0.2
1102
- ExternalRef: SECURITY cpe23Type cpe:2.3:a:kirill_simonov:pyyaml:6.0.2 :*:*:*:*:*:*:*
1073
+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/pyyaml@6.0.3
1074
+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:kirill_simonov:pyyaml:6.0.3 :*:*:*:*:*:*:*
1103
1075
#####
1104
1076
1105
1077
PackageName: semantic-version
0 commit comments