PRODUCT GUIDE

third party notices

Local software · limited supported scope

Third-party notices

ProjectVersion / commitLicenseURLUse
openpyxl3.1.5MIT/Expatproject documentationLocal XLSX reader/writer
et_xmlfile2.0.0MIT/Expatproject documentationXML writer used by openpyxl; pinned transitive runtime dependency

CryptoProof does not incorporate CBOMkit, Qryx, CycloneDX tooling, NIST text, or scanner source code. Those projects are research inputs only. Python standard library is used for JSON, CSV, ZIP and HTML escaping.

The 0.1.6 local review bundle includes the unmodified public PyPI wheels under wheelhouse/ for offline installation. The openpyxl-3.1.5-py2.py3-none-any.whl SHA-256 is 5282c12b107bffeef825f4617dc029afaf41d0ea60823bbb665ef3079dc79de2; the et_xmlfile-2.0.0-py3-none-any.whl SHA-256 is 7a91720bc756843502c3b7504c77b8fe44217c85c537d85037f0f536151b2caa. Both wheels contain their full MIT/Expat notice in their .dist-info/LICENCE.rst; the et_xmlfile wheel also contains LICENCE.python. The license text and copyright must remain with redistributed wheels. These files and hashes were checked locally on 2026-10-04. Buyer organizations may substitute their own approved package source and must validate dependencies under their policies.