Bug 13621

Summary: Add ability to specify CPE
Product: [Yocto Project Subprojects] Security Response Tool Reporter: Mark Hatle <mark.hatle>
Component: GeneralAssignee: David Reyna <david.reyna>
Status: RESOLVED WONTFIX QA Contact:
Severity: normal    
Priority: Medium CC: randy.macleod
Version: unspecified   
Target Milestone: 5.2 M3   
Hardware: x86   
OS: Multiple   
Whiteboard:
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: Don't know

Description Mark Hatle 2019-11-12 19:58:37 UTC
I would like to be able to define (or edit) the CPE for CVEs.

I would suggest the editing allow you to either directly enter the CPE OR provide a helper that lets you fill out the information per the CPE specification, with unknown fields being '*'.
Comment 1 David Reyna 2019-11-12 20:11:50 UTC
We will have to work out a design since this is a complex tree sturcture. I will assemble so proposals before I implement.
Comment 2 Mark Hatle 2019-11-12 20:15:25 UTC
With the cve-checker part of YP, if it can use this data CPE will be really important.

But ya, we need to figure out a user interface that will work for this.
Comment 3 David Reyna 2025-03-13 04:46:13 UTC
This feature is not being used. Will fix it if renewed.