| Summary: |
SPDX generation should include patch-fixed-CVE annotations |
| Product: |
[Build System, Metadata & Runtime] OE-Core
|
Reporter: |
Ross Burton <ross.burton> |
| Component: |
deployment | Assignee: |
Joshua Watt <JPEWhacker> |
| Status: |
RESOLVED
FIXED
|
QA Contact: |
|
| Severity: |
enhancement
|
|
|
| Priority: |
Medium
|
CC: |
randy.macleod, yoann.congal
|
| Version: |
5.3 | |
|
| Target Milestone: |
6.0 | |
|
| Hardware: |
x86 | |
|
| OS: |
Multiple | |
|
| Whiteboard: |
|
|
OS type for building Yocto:
|
---
|
Type of Regression:
|
---
|
|
Verified:
|
|
Documentation change:
|
No (bug/feature does not impact docs)
|
The SPDXv3 output doesn't include useful metadata like "this CVE was fixed by these patches". This is included in the vex output: "issue": [ { "id": "CVE-2022-28391", "status": "Patched", "link": "https://nvd.nist.gov/vuln/detail/CVE-2022-28391", "detail": "fix-file-included", "patch-file": [ "/home/rosbur01/Yocto/openembedded-core/meta/recipes-core/busybox/busybox/0001-libbb-sockaddr2str-ensure-only-printable-characters-.patch", "/home/rosbur01/Yocto/openembedded-core/meta/recipes-core/busybox/busybox/0002-nslookup-sanitize-all-printed-strings-with-printable.patch" ] }, It would be good to not need the vex class, and to have this information in the SPDX. Concrete use-case being sbom-cve-tool ideally wants both the SPDX and VEX for this data.