> I've looked at nvd database to get vendor name associated for each > component:https://nvd.nist.gov/products/cpe/search > For bridge-utils, it returns kernel as the vendor name.
Thanks! > A component only relies on a specific source, which is always associated to a > vendor:component pair. Setting the complete name should help to anticipate > false-positive CVE reporting before facing that issue. > It is also interesting in order to supply more precise information for > meta-layers like meta-dependencytrack of meta-cyclonedx which rely on > CVE_PRODUCT variable to produce SBOM. I have a bad experience with relying on cpe being exact, especially for first CVEs where random names are assigned as there is no former example. I hope this improves with the new CVE annotations, let's see. I'd rather change the CVE_PRODUCT on first false positive in fear that someone invents new cpe and we have a false negative. Peter
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#114071): https://lists.openembedded.org/g/openembedded-devel/message/114071 Mute This Topic: https://lists.openembedded.org/mt/109700487/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-devel/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
