> I've looked at nvd database to get vendor name associated for each 
> component:https://nvd.nist.gov/products/cpe/search  
> For bridge-utils, it returns kernel as the vendor name.

Thanks!

> A component only relies on a specific source, which is always associated to a 
> vendor:component pair. Setting the complete name should help to anticipate 
> false-positive CVE reporting before facing that issue.
> It is also interesting in order to supply more precise information for 
> meta-layers like meta-dependencytrack of meta-cyclonedx which rely on 
> CVE_PRODUCT variable to produce SBOM.

I have a bad experience with relying on cpe being exact, especially for first 
CVEs where random names are assigned as there is no former example.
I hope this improves with the new CVE annotations, let's see.
I'd rather change the CVE_PRODUCT on first false positive in fear that someone 
invents new cpe and we have a false negative.

Peter
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#114071): 
https://lists.openembedded.org/g/openembedded-devel/message/114071
Mute This Topic: https://lists.openembedded.org/mt/109700487/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-devel/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to