PRODUCT GUIDE
third party notices
Local software · limited supported scope
Third-party notices
| Project | Version / commit | License | URL | Use |
|---|---|---|---|---|
| openpyxl | 3.1.5 | MIT/Expat | project documentation | Local XLSX reader/writer |
| et_xmlfile | 2.0.0 | MIT/Expat | project documentation | XML writer used by openpyxl; pinned transitive runtime dependency |
CryptoProof does not incorporate CBOMkit, Qryx, CycloneDX tooling, NIST text, or scanner source code. Those projects are research inputs only. Python standard library is used for JSON, CSV, ZIP and HTML escaping.
The 0.1.6 local review bundle includes the unmodified public PyPI wheels under wheelhouse/ for offline installation. The openpyxl-3.1.5-py2.py3-none-any.whl SHA-256 is 5282c12b107bffeef825f4617dc029afaf41d0ea60823bbb665ef3079dc79de2; the et_xmlfile-2.0.0-py3-none-any.whl SHA-256 is 7a91720bc756843502c3b7504c77b8fe44217c85c537d85037f0f536151b2caa. Both wheels contain their full MIT/Expat notice in their .dist-info/LICENCE.rst; the et_xmlfile wheel also contains LICENCE.python. The license text and copyright must remain with redistributed wheels. These files and hashes were checked locally on 2026-10-04. Buyer organizations may substitute their own approved package source and must validate dependencies under their policies.