Bug 16168

Summary: SPDX generation should include patch-fixed-CVE annotations
Product: [Build System, Metadata & Runtime] OE-Core Reporter: Ross Burton <ross.burton>
Component: deploymentAssignee: Joshua Watt <JPEWhacker>
Status: RESOLVED FIXED QA Contact:
Severity: enhancement    
Priority: Medium CC: randy.macleod, yoann.congal
Version: 5.3   
Target Milestone: 6.0   
Hardware: x86   
OS: Multiple   
Whiteboard:
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: No (bug/feature does not impact docs)

Description Ross Burton 2026-02-10 17:39:15 UTC
The SPDXv3 output doesn't include useful metadata like "this CVE was fixed by these patches". This is included in the vex output:

      "issue": [
        {
          "id": "CVE-2022-28391",
          "status": "Patched",
          "link": "https://nvd.nist.gov/vuln/detail/CVE-2022-28391",
          "detail": "fix-file-included",
          "patch-file": [
            "/home/rosbur01/Yocto/openembedded-core/meta/recipes-core/busybox/busybox/0001-libbb-sockaddr2str-ensure-only-printable-characters-.patch",
            "/home/rosbur01/Yocto/openembedded-core/meta/recipes-core/busybox/busybox/0002-nslookup-sanitize-all-printed-strings-with-printable.patch"
          ]
        },

It would be good to not need the vex class, and to have this information in the SPDX.

Concrete use-case being sbom-cve-tool ideally wants both the SPDX and VEX for this data.
Comment 1 Joshua Watt 2026-05-14 14:54:39 UTC
Fixed in 9e85daf516 ("spdx30: Include patch file information in VEX")