@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22DataLicense: CC0-1.0
33SPDXID: SPDXRef-DOCUMENT
44DocumentName: Python-cve-bin-tool
5- DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-887b9b7c-2e29-49c2-b60d-fb137ac69b91
5+ DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-a7a66328-a037-44e0-a536-ef77820d3795
66LicenseListVersion: 3.26
77Creator: Tool: sbom4python-0.12.4
8- Created: 2025-11-10T00:41:40Z
8+ Created: 2025-11-24T00:44:10Z
99CreatorComment: <text>SBOM Type: Build - This document has been automatically generated.</text>
1010#####
1111
@@ -986,44 +986,44 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:referencing:0.37.0:*:*:*
986986
987987PackageName: rpds-py
988988SPDXID: SPDXRef-48-rpds-py
989- PackageVersion: 0.28 .0
989+ PackageVersion: 0.29 .0
990990PrimaryPackagePurpose: LIBRARY
991991PackageSupplier: Person: Julian Berman (Julian+rpds@GrayVines.com)
992- PackageDownloadLocation: https://pypi.org/project/rpds-py/0.28 .0/#files
992+ PackageDownloadLocation: https://pypi.org/project/rpds-py/0.29 .0/#files
993993FilesAnalyzed: false
994994PackageHomePage: https://github.com/crate-py/rpds
995- PackageChecksum: SHA256: 7b6013db815417eeb56b2d9d7324e64fcd4fa289caeee6e7a78b2e11fc9b438a
995+ PackageChecksum: SHA256: 4ae4b88c6617e1b9e5038ab3fccd7bac0842fdda2b703117b2aa99bc85379113
996996PackageLicenseDeclared: NOASSERTION
997997PackageLicenseConcluded: NOASSERTION
998998PackageCopyrightText: NOASSERTION
999999PackageSummary: <text>Python bindings to Rust's persistent data structures (rpds)</text>
1000- ReleaseDate: 2025-10-22T22:21:15Z
1000+ ReleaseDate: 2025-11-16T14:47:36Z
10011001ExternalRef: OTHER documentation https://rpds.readthedocs.io/
10021002ExternalRef: OTHER issue-tracker https://github.com/crate-py/rpds/issues/
10031003ExternalRef: OTHER other https://github.com/sponsors/Julian
10041004ExternalRef: OTHER other https://tidelift.com/subscription/pkg/pypi-rpds-py?utm_source=pypi-rpds-py&utm_medium=referral&utm_campaign=pypi-link
10051005ExternalRef: OTHER vcs https://github.com/crate-py/rpds
10061006ExternalRef: OTHER other https://github.com/orium/rpds
1007- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rpds-py@0.28 .0
1008- ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.28 .0:*:*:*:*:*:*:*
1007+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rpds-py@0.29 .0
1008+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.29 .0:*:*:*:*:*:*:*
10091009#####
10101010
10111011PackageName: lib4sbom
10121012SPDXID: SPDXRef-49-lib4sbom
1013- PackageVersion: 0.9.0
1013+ PackageVersion: 0.9.1
10141014PrimaryPackagePurpose: LIBRARY
10151015PackageSupplier: Person: Anthony Harrison (anthony.p.harrison@gmail.com)
1016- PackageDownloadLocation: https://pypi.org/project/lib4sbom/0.9.0 /#files
1016+ PackageDownloadLocation: https://pypi.org/project/lib4sbom/0.9.1 /#files
10171017FilesAnalyzed: false
10181018PackageHomePage: https://github.com/anthonyharrison/lib4sbom
1019- PackageChecksum: SHA256: 78b8584d10fc7fa28fc3c17c0afcb2967f3c2b96974e4bdbb60b3eb3744d01fd
1019+ PackageChecksum: SHA256: f2423d5e06a82f5462b05d0c5b9273d6e3674753ade9f5a0d4abdcf73f799117
10201020PackageLicenseDeclared: Apache-2.0
10211021PackageLicenseConcluded: Apache-2.0
10221022PackageCopyrightText: NOASSERTION
10231023PackageSummary: <text>Software Bill of Material (SBOM) generator and consumer library</text>
1024- ReleaseDate: 2025-10-28T09:09:40Z
1025- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/lib4sbom@0.9.0
1026- ExternalRef: SECURITY cpe23Type cpe:2.3:a:anthony_harrison:lib4sbom:0.9.0 :*:*:*:*:*:*:*
1024+ ReleaseDate: 2025-11-13T20:07:13Z
1025+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/lib4sbom@0.9.1
1026+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:anthony_harrison:lib4sbom:0.9.1 :*:*:*:*:*:*:*
10271027#####
10281028
10291029PackageName: pyyaml
@@ -1279,13 +1279,13 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:donald_stufft:packaging:25.0:*:*:*:*:*
12791279
12801280PackageName: plotly
12811281SPDXID: SPDXRef-63-plotly
1282- PackageVersion: 6.4 .0
1282+ PackageVersion: 6.5 .0
12831283PrimaryPackagePurpose: LIBRARY
12841284PackageSupplier: Person: Chris P (chris@plot.ly)
1285- PackageDownloadLocation: https://pypi.org/project/plotly/6.4 .0/#files
1285+ PackageDownloadLocation: https://pypi.org/project/plotly/6.5 .0/#files
12861286FilesAnalyzed: false
12871287PackageHomePage: https://plotly.com/python/
1288- PackageChecksum: SHA256: a1062eafbdc657976c2eedd276c90e184ccd6c21282a5e9ee8f20efca9c9a4c5
1288+ PackageChecksum: SHA256: 5ac851e100367735250206788a2b1325412aa4a4917a4fe3e6f0bc5aa6f3d90a
12891289PackageLicenseDeclared: NOASSERTION
12901290PackageLicenseConcluded: NOASSERTION
12911291PackageLicenseComments: <text>plotly declares MIT License
@@ -1312,33 +1312,33 @@ THE SOFTWARE.
13121312 which is not currently a valid SPDX License identifier or expression.</text>
13131313PackageCopyrightText: NOASSERTION
13141314PackageSummary: <text>An open-source interactive data visualization library for Python</text>
1315- ReleaseDate: 2025-11-04T17:59:22Z
1315+ ReleaseDate: 2025-11-17T18:39:20Z
13161316ExternalRef: OTHER documentation https://plotly.com/python/
13171317ExternalRef: OTHER vcs https://github.com/plotly/plotly.py
13181318ExternalRef: OTHER log https://github.com/plotly/plotly.py/blob/main/CHANGELOG.md
1319- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/plotly@6.4 .0
1320- ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:6.4 .0:*:*:*:*:*:*:*
1319+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/plotly@6.5 .0
1320+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:6.5 .0:*:*:*:*:*:*:*
13211321#####
13221322
13231323PackageName: narwhals
13241324SPDXID: SPDXRef-64-narwhals
1325- PackageVersion: 2.10.2
1325+ PackageVersion: 2.12.0
13261326PrimaryPackagePurpose: LIBRARY
13271327PackageSupplier: Person: Marco Gorelli (hello_narwhals@proton.me)
1328- PackageDownloadLocation: https://pypi.org/project/narwhals/2.10.2 /#files
1328+ PackageDownloadLocation: https://pypi.org/project/narwhals/2.12.0 /#files
13291329FilesAnalyzed: false
13301330PackageHomePage: https://github.com/narwhals-dev/narwhals
13311331PackageLicenseDeclared: NOASSERTION
13321332PackageLicenseConcluded: MIT
13331333PackageLicenseComments: <text>narwhals declares MIT License which is not currently a valid SPDX License identifier or expression.</text>
13341334PackageCopyrightText: NOASSERTION
13351335PackageSummary: <text>Extremely lightweight compatibility layer between dataframe libraries</text>
1336- ReleaseDate: 2025-11-04T17:59:22Z
1336+ ReleaseDate: 2025-11-17T18:39:20Z
13371337ExternalRef: OTHER documentation https://narwhals-dev.github.io/narwhals/
13381338ExternalRef: OTHER vcs https://github.com/narwhals-dev/narwhals
13391339ExternalRef: OTHER issue-tracker https://github.com/narwhals-dev/narwhals/issues
1340- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@2.10.2
1341- ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:2.10.2 :*:*:*:*:*:*:*
1340+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/narwhals@2.12.0
1341+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:marco_gorelli:narwhals:2.12.0 :*:*:*:*:*:*:*
13421342#####
13431343
13441344PackageName: python-gnupg
@@ -1427,21 +1427,21 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_petrov:urllib3:2.5.0:*:*:*:*:*:
14271427
14281428PackageName: certifi
14291429SPDXID: SPDXRef-69-certifi
1430- PackageVersion: 2025.10.5
1430+ PackageVersion: 2025.11.12
14311431PrimaryPackagePurpose: LIBRARY
14321432PackageSupplier: Person: Kenneth Reitz (me@kennethreitz.com)
1433- PackageDownloadLocation: https://pypi.org/project/certifi/2025.10.5 /#files
1433+ PackageDownloadLocation: https://pypi.org/project/certifi/2025.11.12 /#files
14341434FilesAnalyzed: false
14351435PackageHomePage: https://github.com/certifi/python-certifi
1436- PackageChecksum: SHA256: 0f212c2744a9bb6de0c56639a6f68afe01ecd92d91f14ae897c4fe7bbeeef0de
1436+ PackageChecksum: SHA256: 97de8790030bbd5c2d96b7ec782fc2f7820ef8dba6db909ccf95449f2d062d4b
14371437PackageLicenseDeclared: MPL-2.0
14381438PackageLicenseConcluded: MPL-2.0
14391439PackageCopyrightText: NOASSERTION
14401440PackageSummary: <text>Python package for providing Mozilla's CA Bundle.</text>
1441- ReleaseDate: 2025-10-05T04:12:14Z
1441+ ReleaseDate: 2025-11-12T02:54:49Z
14421442ExternalRef: OTHER vcs https://github.com/certifi/python-certifi
1443- ExternalRef: PACKAGE-MANAGER purl pkg:pypi/certifi@2025.10.5
1444- ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:certifi:2025.10.5 :*:*:*:*:*:*:*
1443+ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/certifi@2025.11.12
1444+ ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:certifi:2025.11.12 :*:*:*:*:*:*:*
14451445#####
14461446
14471447PackageName: rpmfile
0 commit comments