diff --git a/sbom/cve-bin-tool-py3.8.json b/sbom/cve-bin-tool-py3.8.json index f17e9f14e5..0066379a08 100644 --- a/sbom/cve-bin-tool-py3.8.json +++ b/sbom/cve-bin-tool-py3.8.json @@ -2,10 +2,10 @@ "$schema": "http://cyclonedx.org/schema/bom-1.4.schema.json", "bomFormat": "CycloneDX", "specVersion": "1.4", - "serialNumber": "urn:uuidec348a64-3427-4370-907f-2f5fdee74cf0", + "serialNumber": "urn:uuidd947d692-da16-4b38-abc1-791a7f227d31", "version": 1, "metadata": { - "timestamp": "2023-05-08T01:16:10Z", + "timestamp": "2023-05-22T00:58:12Z", "tools": [ { "name": "sbom4python", @@ -547,7 +547,7 @@ "type": "library", "bom-ref": "16-gsutil", "name": "gsutil", - "version": "5.23", + "version": "5.24", "supplier": { "name": "Google Inc.", "contact": [ @@ -556,7 +556,7 @@ } ] }, - "cpe": "cpe:2.3:a:google_inc.:gsutil:5.23:*:*:*:*:*:*:*", + "cpe": "cpe:2.3:a:google_inc.:gsutil:5.24:*:*:*:*:*:*:*", "description": "A command line tool for interacting with cloud storage services.", "licenses": [ { @@ -573,12 +573,12 @@ "comment": "Home page for project" }, { - "url": "https://pypi.org/project/gsutil/5.23", + "url": "https://pypi.org/project/gsutil/5.24", "type": "distribution", "comment": "Download location for component" } ], - "purl": "pkg:pypi/gsutil@5.23", + "purl": "pkg:pypi/gsutil@5.24", "properties": [ { "name": "License Comments", @@ -1377,7 +1377,7 @@ "type": "library", "bom-ref": "37-google-auth", "name": "google-auth", - "version": "2.17.3", + "version": "2.18.1", "supplier": { "name": "Google Cloud Platform", "contact": [ @@ -1386,7 +1386,7 @@ } ] }, - "cpe": "cpe:2.3:a:google_cloud_platform:google-auth:2.17.3:*:*:*:*:*:*:*", + "cpe": "cpe:2.3:a:google_cloud_platform:google-auth:2.18.1:*:*:*:*:*:*:*", "description": "Google Authentication Library", "licenses": [ { @@ -1403,12 +1403,12 @@ "comment": "Home page for project" }, { - "url": "https://pypi.org/project/google-auth/2.17.3", + "url": "https://pypi.org/project/google-auth/2.18.1", "type": "distribution", "comment": "Download location for component" } ], - "purl": "pkg:pypi/google-auth@2.17.3", + "purl": "pkg:pypi/google-auth@2.18.1", "properties": [ { "name": "License Comments", @@ -1455,7 +1455,44 @@ }, { "type": "library", - "bom-ref": "39-monotonic", + "bom-ref": "39-urllib3", + "name": "urllib3", + "version": "1.26.15", + "supplier": { + "name": "Andrey Petrov", + "contact": [ + { + "email": "andrey.petrov@shazow.net" + } + ] + }, + "cpe": "cpe:2.3:a:andrey_petrov:urllib3:1.26.15:*:*:*:*:*:*:*", + "description": "HTTP library with thread-safe connection pooling, file post, and more.", + "licenses": [ + { + "license": { + "id": "MIT", + "url": "https://opensource.org/licenses/MIT" + } + } + ], + "externalReferences": [ + { + "url": "https://urllib3.readthedocs.io/", + "type": "website", + "comment": "Home page for project" + }, + { + "url": "https://pypi.org/project/urllib3/1.26.15", + "type": "distribution", + "comment": "Download location for component" + } + ], + "purl": "pkg:pypi/urllib3@1.26.15" + }, + { + "type": "library", + "bom-ref": "40-monotonic", "name": "monotonic", "version": "1.6", "supplier": { @@ -1498,7 +1535,7 @@ }, { "type": "library", - "bom-ref": "40-importlib-metadata", + "bom-ref": "41-importlib-metadata", "name": "importlib-metadata", "version": "6.6.0", "supplier": { @@ -1527,7 +1564,7 @@ }, { "type": "library", - "bom-ref": "41-zipp", + "bom-ref": "42-zipp", "name": "zipp", "version": "3.15.0", "supplier": { @@ -1556,7 +1593,7 @@ }, { "type": "library", - "bom-ref": "42-importlib-resources", + "bom-ref": "43-importlib-resources", "name": "importlib-resources", "version": "5.12.0", "supplier": { @@ -1585,7 +1622,7 @@ }, { "type": "library", - "bom-ref": "43-jinja2", + "bom-ref": "44-jinja2", "name": "jinja2", "version": "3.1.2", "supplier": { @@ -1622,7 +1659,7 @@ }, { "type": "library", - "bom-ref": "44-markupsafe", + "bom-ref": "45-markupsafe", "name": "markupsafe", "version": "2.1.2", "supplier": { @@ -1659,7 +1696,7 @@ }, { "type": "library", - "bom-ref": "45-jsonschema", + "bom-ref": "46-jsonschema", "name": "jsonschema", "version": "4.17.3", "supplier": { @@ -1686,7 +1723,7 @@ }, { "type": "library", - "bom-ref": "46-pkgutil-resolve-name", + "bom-ref": "47-pkgutil-resolve-name", "name": "pkgutil-resolve-name", "version": "1.3.10", "supplier": { @@ -1715,7 +1752,7 @@ }, { "type": "library", - "bom-ref": "47-pyrsistent", + "bom-ref": "48-pyrsistent", "name": "pyrsistent", "version": "0.19.3", "supplier": { @@ -1752,7 +1789,7 @@ }, { "type": "library", - "bom-ref": "48-lib4sbom", + "bom-ref": "49-lib4sbom", "name": "lib4sbom", "version": "0.3.1", "supplier": { @@ -1789,7 +1826,7 @@ }, { "type": "library", - "bom-ref": "49-pyyaml", + "bom-ref": "50-pyyaml", "name": "pyyaml", "version": "6.0", "supplier": { @@ -1826,7 +1863,7 @@ }, { "type": "library", - "bom-ref": "50-semantic-version", + "bom-ref": "51-semantic-version", "name": "semantic-version", "version": "2.10.0", "supplier": { @@ -1869,7 +1906,7 @@ }, { "type": "library", - "bom-ref": "51-packaging", + "bom-ref": "52-packaging", "name": "packaging", "version": "21.3", "supplier": { @@ -1911,7 +1948,7 @@ }, { "type": "library", - "bom-ref": "52-plotly", + "bom-ref": "53-plotly", "name": "plotly", "version": "5.14.1", "supplier": { @@ -1948,7 +1985,7 @@ }, { "type": "library", - "bom-ref": "53-tenacity", + "bom-ref": "54-tenacity", "name": "tenacity", "version": "8.2.2", "supplier": { @@ -1991,7 +2028,7 @@ }, { "type": "library", - "bom-ref": "54-requests", + "bom-ref": "55-requests", "name": "requests", "version": "2.30.0", "supplier": { @@ -2034,7 +2071,7 @@ }, { "type": "library", - "bom-ref": "55-certifi", + "bom-ref": "56-certifi", "name": "certifi", "version": "2023.5.7", "supplier": { @@ -2069,30 +2106,6 @@ ], "purl": "pkg:pypi/certifi@2023.5.7" }, - { - "type": "library", - "bom-ref": "56-urllib3", - "name": "urllib3", - "version": "2.0.2", - "supplier": { - "name": "Andrey Petrov", - "contact": [ - { - "email": "andrey.petrov@shazow.net" - } - ] - }, - "cpe": "cpe:2.3:a:andrey_petrov:urllib3:2.0.2:*:*:*:*:*:*:*", - "description": "HTTP library with thread-safe connection pooling, file post, and more.", - "externalReferences": [ - { - "url": "https://pypi.org/project/urllib3/2.0.2", - "type": "distribution", - "comment": "Download location for component" - } - ], - "purl": "pkg:pypi/urllib3@2.0.2" - }, { "type": "library", "bom-ref": "57-rich", @@ -2312,7 +2325,7 @@ "type": "library", "bom-ref": "64-xmlschema", "name": "xmlschema", - "version": "2.2.3", + "version": "2.3.0", "supplier": { "name": "Davide Brunato", "contact": [ @@ -2321,7 +2334,7 @@ } ] }, - "cpe": "cpe:2.3:a:davide_brunato:xmlschema:2.2.3:*:*:*:*:*:*:*", + "cpe": "cpe:2.3:a:davide_brunato:xmlschema:2.3.0:*:*:*:*:*:*:*", "description": "An XML Schema validator and decoder", "licenses": [ { @@ -2338,12 +2351,12 @@ "comment": "Home page for project" }, { - "url": "https://pypi.org/project/xmlschema/2.2.3", + "url": "https://pypi.org/project/xmlschema/2.3.0", "type": "distribution", "comment": "Download location for component" } ], - "purl": "pkg:pypi/xmlschema@2.2.3" + "purl": "pkg:pypi/xmlschema@2.3.0" }, { "type": "library", @@ -2442,19 +2455,19 @@ "14-defusedxml", "15-distro", "16-gsutil", - "40-importlib-metadata", - "42-importlib-resources", - "43-jinja2", - "45-jsonschema", - "48-lib4sbom", - "51-packaging", - "52-plotly", - "49-pyyaml", - "54-requests", + "41-importlib-metadata", + "43-importlib-resources", + "44-jinja2", + "46-jsonschema", + "49-lib4sbom", + "52-packaging", + "53-plotly", + "50-pyyaml", + "55-requests", "57-rich", "62-rpmfile", "63-toml", - "56-urllib3", + "39-urllib3", "64-xmlschema", "66-zstandard" ] @@ -2501,7 +2514,7 @@ "37-google-auth", "22-google-reauth", "25-httplib2", - "39-monotonic", + "40-monotonic", "31-pyopenssl", "35-retry-decorator", "24-six" @@ -2593,63 +2606,64 @@ "38-cachetools", "29-pyasn1-modules", "30-rsa", - "24-six" + "24-six", + "39-urllib3" ] }, { - "ref": "40-importlib-metadata", + "ref": "41-importlib-metadata", "dependsOn": [ - "41-zipp" + "42-zipp" ] }, { - "ref": "42-importlib-resources", + "ref": "43-importlib-resources", "dependsOn": [ - "41-zipp" + "42-zipp" ] }, { - "ref": "43-jinja2", + "ref": "44-jinja2", "dependsOn": [ - "44-markupsafe" + "45-markupsafe" ] }, { - "ref": "45-jsonschema", + "ref": "46-jsonschema", "dependsOn": [ "6-attrs", - "42-importlib-resources", - "46-pkgutil-resolve-name", - "47-pyrsistent" + "43-importlib-resources", + "47-pkgutil-resolve-name", + "48-pyrsistent" ] }, { - "ref": "48-lib4sbom", + "ref": "49-lib4sbom", "dependsOn": [ - "49-pyyaml", - "50-semantic-version" + "50-pyyaml", + "51-semantic-version" ] }, { - "ref": "51-packaging", + "ref": "52-packaging", "dependsOn": [ "26-pyparsing" ] }, { - "ref": "52-plotly", + "ref": "53-plotly", "dependsOn": [ - "51-packaging", - "53-tenacity" + "52-packaging", + "54-tenacity" ] }, { - "ref": "54-requests", + "ref": "55-requests", "dependsOn": [ - "55-certifi", + "56-certifi", "7-charset-normalizer", "10-idna", - "56-urllib3" + "39-urllib3" ] }, { diff --git a/sbom/cve-bin-tool-py3.8.spdx b/sbom/cve-bin-tool-py3.8.spdx index e3bd10d851..a9b33b5d84 100644 --- a/sbom/cve-bin-tool-py3.8.spdx +++ b/sbom/cve-bin-tool-py3.8.spdx @@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3 DataLicense: CC0-1.0 SPDXID: SPDXRef-DOCUMENT DocumentName: Python-cve-bin-tool -DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-d5fda5a2-ef52-4a68-aca0-c95f35aafa5b +DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-6d0a02b5-4730-45c5-8fcd-13a17a988d10 LicenseListVersion: 3.20 Creator: Tool: sbom4python-0.9.1 -Created: 2023-05-08T01:14:50Z +Created: 2023-05-22T00:56:52Z CreatorComment: This document has been automatically generated. ##### @@ -252,10 +252,10 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:nir_cohen:distro:1.8.0:*:*:*:*:*:*:* PackageName: gsutil SPDXID: SPDXRef-Package-16-gsutil -PackageVersion: 5.23 +PackageVersion: 5.24 PrimaryPackagePurpose: LIBRARY PackageSupplier: Person: Google Inc. (buganizer-system+187143@google.com) -PackageDownloadLocation: https://pypi.org/project/gsutil/5.23 +PackageDownloadLocation: https://pypi.org/project/gsutil/5.24 FilesAnalyzed: false PackageHomePage: https://cloud.google.com/storage/docs/gsutil PackageLicenseDeclared: NOASSERTION @@ -263,8 +263,8 @@ PackageLicenseConcluded: Apache-2.0 PackageLicenseComments: gsutil declares Apache 2.0 which is not currently a valid SPDX License identifier or expression. PackageCopyrightText: NOASSERTION PackageSummary: A command line tool for interacting with cloud storage services. -ExternalRef: PACKAGE-MANAGER purl pkg:pypi/gsutil@5.23 -ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_inc.:gsutil:5.23:*:*:*:*:*:*:* +ExternalRef: PACKAGE-MANAGER purl pkg:pypi/gsutil@5.24 +ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_inc.:gsutil:5.24:*:*:*:*:*:*:* ##### PackageName: argcomplete @@ -599,10 +599,10 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:craig_citro:google-apitools:0.5.32:*:* PackageName: google-auth SPDXID: SPDXRef-Package-37-google-auth -PackageVersion: 2.17.3 +PackageVersion: 2.18.1 PrimaryPackagePurpose: LIBRARY PackageSupplier: Organization: Google Cloud Platform (googleapis-packages@google.com) -PackageDownloadLocation: https://pypi.org/project/google-auth/2.17.3 +PackageDownloadLocation: https://pypi.org/project/google-auth/2.18.1 FilesAnalyzed: false PackageHomePage: https://github.com/googleapis/google-auth-library-python PackageLicenseDeclared: NOASSERTION @@ -610,8 +610,8 @@ PackageLicenseConcluded: Apache-2.0 PackageLicenseComments: google-auth declares Apache 2.0 which is not currently a valid SPDX License identifier or expression. PackageCopyrightText: NOASSERTION PackageSummary: Google Authentication Library -ExternalRef: PACKAGE-MANAGER purl pkg:pypi/google-auth@2.17.3 -ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_cloud_platform:google-auth:2.17.3:*:*:*:*:*:*:* +ExternalRef: PACKAGE-MANAGER purl pkg:pypi/google-auth@2.18.1 +ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_cloud_platform:google-auth:2.18.1:*:*:*:*:*:*:* ##### PackageName: cachetools @@ -630,8 +630,24 @@ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/cachetools@5.3.0 ExternalRef: SECURITY cpe23Type cpe:2.3:a:thomas_kemmer:cachetools:5.3.0:*:*:*:*:*:*:* ##### +PackageName: urllib3 +SPDXID: SPDXRef-Package-39-urllib3 +PackageVersion: 1.26.15 +PrimaryPackagePurpose: LIBRARY +PackageSupplier: Person: Andrey Petrov (andrey.petrov@shazow.net) +PackageDownloadLocation: https://pypi.org/project/urllib3/1.26.15 +FilesAnalyzed: false +PackageHomePage: https://urllib3.readthedocs.io/ +PackageLicenseDeclared: MIT +PackageLicenseConcluded: MIT +PackageCopyrightText: NOASSERTION +PackageSummary: HTTP library with thread-safe connection pooling, file post, and more. +ExternalRef: PACKAGE-MANAGER purl pkg:pypi/urllib3@1.26.15 +ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_petrov:urllib3:1.26.15:*:*:*:*:*:*:* +##### + PackageName: monotonic -SPDXID: SPDXRef-Package-39-monotonic +SPDXID: SPDXRef-Package-40-monotonic PackageVersion: 1.6 PrimaryPackagePurpose: LIBRARY PackageSupplier: Person: Ori Livneh (ori@wikimedia.org) @@ -648,7 +664,7 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:ori_livneh:monotonic:1.6:*:*:*:*:*:*:* ##### PackageName: importlib-metadata -SPDXID: SPDXRef-Package-40-importlib-metadata +SPDXID: SPDXRef-Package-41-importlib-metadata PackageVersion: 6.6.0 PrimaryPackagePurpose: LIBRARY PackageSupplier: Organization: Jason R. Coombs (jaraco@jaraco.com) @@ -664,7 +680,7 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:jason_r._coombs:importlib-metadata:6.6 ##### PackageName: zipp -SPDXID: SPDXRef-Package-41-zipp +SPDXID: SPDXRef-Package-42-zipp PackageVersion: 3.15.0 PrimaryPackagePurpose: LIBRARY PackageSupplier: Organization: Jason R. Coombs (jaraco@jaraco.com) @@ -680,7 +696,7 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:jason_r._coombs:zipp:3.15.0:*:*:*:*:*: ##### PackageName: importlib-resources -SPDXID: SPDXRef-Package-42-importlib-resources +SPDXID: SPDXRef-Package-43-importlib-resources PackageVersion: 5.12.0 PrimaryPackagePurpose: LIBRARY PackageSupplier: Person: Barry Warsaw (barry@python.org) @@ -696,7 +712,7 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:barry_warsaw:importlib-resources:5.12. ##### PackageName: jinja2 -SPDXID: SPDXRef-Package-43-jinja2 +SPDXID: SPDXRef-Package-44-jinja2 PackageVersion: 3.1.2 PrimaryPackagePurpose: LIBRARY PackageSupplier: Person: Armin Ronacher (armin.ronacher@active-4.com) @@ -712,7 +728,7 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:armin_ronacher:jinja2:3.1.2:*:*:*:*:*: ##### PackageName: markupsafe -SPDXID: SPDXRef-Package-44-markupsafe +SPDXID: SPDXRef-Package-45-markupsafe PackageVersion: 2.1.2 PrimaryPackagePurpose: LIBRARY PackageSupplier: Person: Armin Ronacher (armin.ronacher@active-4.com) @@ -728,7 +744,7 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:armin_ronacher:markupsafe:2.1.2:*:*:*: ##### PackageName: jsonschema -SPDXID: SPDXRef-Package-45-jsonschema +SPDXID: SPDXRef-Package-46-jsonschema PackageVersion: 4.17.3 PrimaryPackagePurpose: LIBRARY PackageSupplier: Person: Julian Berman @@ -743,7 +759,7 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:jsonschema:4.17.3:*:*:*: ##### PackageName: pkgutil-resolve-name -SPDXID: SPDXRef-Package-46-pkgutil-resolve-name +SPDXID: SPDXRef-Package-47-pkgutil-resolve-name PackageVersion: 1.3.10 PrimaryPackagePurpose: LIBRARY PackageSupplier: Person: Vinay Sajip (vinay_sajip@yahoo.co.uk) @@ -759,7 +775,7 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:vinay_sajip:pkgutil-resolve-name:1.3.1 ##### PackageName: pyrsistent -SPDXID: SPDXRef-Package-47-pyrsistent +SPDXID: SPDXRef-Package-48-pyrsistent PackageVersion: 0.19.3 PrimaryPackagePurpose: LIBRARY PackageSupplier: Person: Tobias Gustafsson (tobias.l.gustafsson@gmail.com) @@ -775,7 +791,7 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:tobias_gustafsson:pyrsistent:0.19.3:*: ##### PackageName: lib4sbom -SPDXID: SPDXRef-Package-48-lib4sbom +SPDXID: SPDXRef-Package-49-lib4sbom PackageVersion: 0.3.1 PrimaryPackagePurpose: LIBRARY PackageSupplier: Person: Anthony Harrison (anthony.p.harrison@gmail.com) @@ -791,7 +807,7 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:anthony_harrison:lib4sbom:0.3.1:*:*:*: ##### PackageName: pyyaml -SPDXID: SPDXRef-Package-49-pyyaml +SPDXID: SPDXRef-Package-50-pyyaml PackageVersion: 6.0 PrimaryPackagePurpose: LIBRARY PackageSupplier: Person: Kirill Simonov (xi@resolvent.net) @@ -807,7 +823,7 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:kirill_simonov:pyyaml:6.0:*:*:*:*:*:*: ##### PackageName: semantic-version -SPDXID: SPDXRef-Package-50-semantic-version +SPDXID: SPDXRef-Package-51-semantic-version PackageVersion: 2.10.0 PrimaryPackagePurpose: LIBRARY PackageSupplier: Person: Raphael Barrois (raphael.barrois+semver@polytechnique.org) @@ -824,7 +840,7 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:raphael_barrois:semantic-version:2.10. ##### PackageName: packaging -SPDXID: SPDXRef-Package-51-packaging +SPDXID: SPDXRef-Package-52-packaging PackageVersion: 21.3 PrimaryPackagePurpose: LIBRARY PackageSupplier: Organization: Donald Stufft and individual contributors (donald@stufft.io) @@ -841,7 +857,7 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:donald_stufft_and_individual_contribut ##### PackageName: plotly -SPDXID: SPDXRef-Package-52-plotly +SPDXID: SPDXRef-Package-53-plotly PackageVersion: 5.14.1 PrimaryPackagePurpose: LIBRARY PackageSupplier: Person: Chris P (chris@plot.ly) @@ -857,7 +873,7 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:chris_p:plotly:5.14.1:*:*:*:*:*:*:* ##### PackageName: tenacity -SPDXID: SPDXRef-Package-53-tenacity +SPDXID: SPDXRef-Package-54-tenacity PackageVersion: 8.2.2 PrimaryPackagePurpose: LIBRARY PackageSupplier: Person: Julien Danjou (julien@danjou.info) @@ -874,7 +890,7 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julien_danjou:tenacity:8.2.2:*:*:*:*:* ##### PackageName: requests -SPDXID: SPDXRef-Package-54-requests +SPDXID: SPDXRef-Package-55-requests PackageVersion: 2.30.0 PrimaryPackagePurpose: LIBRARY PackageSupplier: Person: Kenneth Reitz (me@kennethreitz.org) @@ -891,7 +907,7 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:requests:2.30.0:*:*:*:*: ##### PackageName: certifi -SPDXID: SPDXRef-Package-55-certifi +SPDXID: SPDXRef-Package-56-certifi PackageVersion: 2023.5.7 PrimaryPackagePurpose: LIBRARY PackageSupplier: Person: Kenneth Reitz (me@kennethreitz.com) @@ -906,21 +922,6 @@ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/certifi@2023.5.7 ExternalRef: SECURITY cpe23Type cpe:2.3:a:kenneth_reitz:certifi:2023.5.7:*:*:*:*:*:*:* ##### -PackageName: urllib3 -SPDXID: SPDXRef-Package-56-urllib3 -PackageVersion: 2.0.2 -PrimaryPackagePurpose: LIBRARY -PackageSupplier: Person: Andrey Petrov (andrey.petrov@shazow.net) -PackageDownloadLocation: https://pypi.org/project/urllib3/2.0.2 -FilesAnalyzed: false -PackageLicenseDeclared: NOASSERTION -PackageLicenseConcluded: NOASSERTION -PackageCopyrightText: NOASSERTION -PackageSummary: HTTP library with thread-safe connection pooling, file post, and more. -ExternalRef: PACKAGE-MANAGER purl pkg:pypi/urllib3@2.0.2 -ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_petrov:urllib3:2.0.2:*:*:*:*:*:*:* -##### - PackageName: rich SPDXID: SPDXRef-Package-57-rich PackageVersion: 13.3.5 @@ -1031,18 +1032,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:william_pearson:toml:0.10.2:*:*:*:*:*: PackageName: xmlschema SPDXID: SPDXRef-Package-64-xmlschema -PackageVersion: 2.2.3 +PackageVersion: 2.3.0 PrimaryPackagePurpose: LIBRARY PackageSupplier: Person: Davide Brunato (brunato@sissa.it) -PackageDownloadLocation: https://pypi.org/project/xmlschema/2.2.3 +PackageDownloadLocation: https://pypi.org/project/xmlschema/2.3.0 FilesAnalyzed: false PackageHomePage: https://github.com/sissaschool/xmlschema PackageLicenseDeclared: MIT PackageLicenseConcluded: MIT PackageCopyrightText: NOASSERTION PackageSummary: An XML Schema validator and decoder -ExternalRef: PACKAGE-MANAGER purl pkg:pypi/xmlschema@2.2.3 -ExternalRef: SECURITY cpe23Type cpe:2.3:a:davide_brunato:xmlschema:2.2.3:*:*:*:*:*:*:* +ExternalRef: PACKAGE-MANAGER purl pkg:pypi/xmlschema@2.3.0 +ExternalRef: SECURITY cpe23Type cpe:2.3:a:davide_brunato:xmlschema:2.3.0:*:*:*:*:*:*:* ##### PackageName: elementpath @@ -1085,16 +1086,16 @@ Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-14-defus Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-15-distro Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-16-gsutil Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-2-aiohttp -Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-40-importlib-metadata -Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-42-importlib-resources -Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-43-jinja2 -Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-45-jsonschema -Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-48-lib4sbom -Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-49-pyyaml -Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-51-packaging -Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-52-plotly -Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-54-requests -Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-56-urllib3 +Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-39-urllib3 +Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-41-importlib-metadata +Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-43-importlib-resources +Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-44-jinja2 +Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-46-jsonschema +Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-49-lib4sbom +Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-50-pyyaml +Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-52-packaging +Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-53-plotly +Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-55-requests Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-57-rich Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-62-rpmfile Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-63-toml @@ -1112,7 +1113,7 @@ Relationship: SPDXRef-Package-16-gsutil DEPENDS_ON SPDXRef-Package-31-pyopenssl Relationship: SPDXRef-Package-16-gsutil DEPENDS_ON SPDXRef-Package-35-retry-decorator Relationship: SPDXRef-Package-16-gsutil DEPENDS_ON SPDXRef-Package-36-google-apitools Relationship: SPDXRef-Package-16-gsutil DEPENDS_ON SPDXRef-Package-37-google-auth -Relationship: SPDXRef-Package-16-gsutil DEPENDS_ON SPDXRef-Package-39-monotonic +Relationship: SPDXRef-Package-16-gsutil DEPENDS_ON SPDXRef-Package-40-monotonic Relationship: SPDXRef-Package-2-aiohttp DEPENDS_ON SPDXRef-Package-3-aiosignal Relationship: SPDXRef-Package-2-aiohttp DEPENDS_ON SPDXRef-Package-4-frozenlist Relationship: SPDXRef-Package-2-aiohttp DEPENDS_ON SPDXRef-Package-5-async-timeout @@ -1150,22 +1151,23 @@ Relationship: SPDXRef-Package-37-google-auth DEPENDS_ON SPDXRef-Package-24-six Relationship: SPDXRef-Package-37-google-auth DEPENDS_ON SPDXRef-Package-29-pyasn1-modules Relationship: SPDXRef-Package-37-google-auth DEPENDS_ON SPDXRef-Package-30-rsa Relationship: SPDXRef-Package-37-google-auth DEPENDS_ON SPDXRef-Package-38-cachetools -Relationship: SPDXRef-Package-40-importlib-metadata DEPENDS_ON SPDXRef-Package-41-zipp -Relationship: SPDXRef-Package-42-importlib-resources DEPENDS_ON SPDXRef-Package-41-zipp -Relationship: SPDXRef-Package-43-jinja2 DEPENDS_ON SPDXRef-Package-44-markupsafe -Relationship: SPDXRef-Package-45-jsonschema DEPENDS_ON SPDXRef-Package-42-importlib-resources -Relationship: SPDXRef-Package-45-jsonschema DEPENDS_ON SPDXRef-Package-46-pkgutil-resolve-name -Relationship: SPDXRef-Package-45-jsonschema DEPENDS_ON SPDXRef-Package-47-pyrsistent -Relationship: SPDXRef-Package-45-jsonschema DEPENDS_ON SPDXRef-Package-6-attrs -Relationship: SPDXRef-Package-48-lib4sbom DEPENDS_ON SPDXRef-Package-49-pyyaml -Relationship: SPDXRef-Package-48-lib4sbom DEPENDS_ON SPDXRef-Package-50-semantic-version -Relationship: SPDXRef-Package-51-packaging DEPENDS_ON SPDXRef-Package-26-pyparsing -Relationship: SPDXRef-Package-52-plotly DEPENDS_ON SPDXRef-Package-51-packaging -Relationship: SPDXRef-Package-52-plotly DEPENDS_ON SPDXRef-Package-53-tenacity -Relationship: SPDXRef-Package-54-requests DEPENDS_ON SPDXRef-Package-10-idna -Relationship: SPDXRef-Package-54-requests DEPENDS_ON SPDXRef-Package-55-certifi -Relationship: SPDXRef-Package-54-requests DEPENDS_ON SPDXRef-Package-56-urllib3 -Relationship: SPDXRef-Package-54-requests DEPENDS_ON SPDXRef-Package-7-charset-normalizer +Relationship: SPDXRef-Package-37-google-auth DEPENDS_ON SPDXRef-Package-39-urllib3 +Relationship: SPDXRef-Package-41-importlib-metadata DEPENDS_ON SPDXRef-Package-42-zipp +Relationship: SPDXRef-Package-43-importlib-resources DEPENDS_ON SPDXRef-Package-42-zipp +Relationship: SPDXRef-Package-44-jinja2 DEPENDS_ON SPDXRef-Package-45-markupsafe +Relationship: SPDXRef-Package-46-jsonschema DEPENDS_ON SPDXRef-Package-43-importlib-resources +Relationship: SPDXRef-Package-46-jsonschema DEPENDS_ON SPDXRef-Package-47-pkgutil-resolve-name +Relationship: SPDXRef-Package-46-jsonschema DEPENDS_ON SPDXRef-Package-48-pyrsistent +Relationship: SPDXRef-Package-46-jsonschema DEPENDS_ON SPDXRef-Package-6-attrs +Relationship: SPDXRef-Package-49-lib4sbom DEPENDS_ON SPDXRef-Package-50-pyyaml +Relationship: SPDXRef-Package-49-lib4sbom DEPENDS_ON SPDXRef-Package-51-semantic-version +Relationship: SPDXRef-Package-52-packaging DEPENDS_ON SPDXRef-Package-26-pyparsing +Relationship: SPDXRef-Package-53-plotly DEPENDS_ON SPDXRef-Package-52-packaging +Relationship: SPDXRef-Package-53-plotly DEPENDS_ON SPDXRef-Package-54-tenacity +Relationship: SPDXRef-Package-55-requests DEPENDS_ON SPDXRef-Package-10-idna +Relationship: SPDXRef-Package-55-requests DEPENDS_ON SPDXRef-Package-39-urllib3 +Relationship: SPDXRef-Package-55-requests DEPENDS_ON SPDXRef-Package-56-certifi +Relationship: SPDXRef-Package-55-requests DEPENDS_ON SPDXRef-Package-7-charset-normalizer Relationship: SPDXRef-Package-57-rich DEPENDS_ON SPDXRef-Package-58-markdown-it-py Relationship: SPDXRef-Package-57-rich DEPENDS_ON SPDXRef-Package-60-pygments Relationship: SPDXRef-Package-57-rich DEPENDS_ON SPDXRef-Package-61-typing-extensions