Bug 16168 - SPDX generation should include patch-fixed-CVE annotations
Summary: SPDX generation should include patch-fixed-CVE annotations
Status: RESOLVED FIXED
Alias: None
Product: OE-Core
Classification: Build System, Metadata & Runtime
Component: deployment (show other bugs)
Version: 5.3
Hardware: x86 Multiple
: Medium enhancement
Target Milestone: 6.0
Assignee: Joshua Watt
QA Contact:
URL:
Whiteboard:
Depends on:
Blocks:
 
Reported: 2026-02-10 17:39 UTC by Ross Burton
Modified: 2026-05-14 14:54 UTC (History)
2 users (show)

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: No (bug/feature does not impact docs)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Ross Burton 2026-02-10 17:39:15 UTC
The SPDXv3 output doesn't include useful metadata like "this CVE was fixed by these patches". This is included in the vex output:

      "issue": [
        {
          "id": "CVE-2022-28391",
          "status": "Patched",
          "link": "https://nvd.nist.gov/vuln/detail/CVE-2022-28391",
          "detail": "fix-file-included",
          "patch-file": [
            "/home/rosbur01/Yocto/openembedded-core/meta/recipes-core/busybox/busybox/0001-libbb-sockaddr2str-ensure-only-printable-characters-.patch",
            "/home/rosbur01/Yocto/openembedded-core/meta/recipes-core/busybox/busybox/0002-nslookup-sanitize-all-printed-strings-with-printable.patch"
          ]
        },

It would be good to not need the vex class, and to have this information in the SPDX.

Concrete use-case being sbom-cve-tool ideally wants both the SPDX and VEX for this data.
Comment 1 Joshua Watt 2026-05-14 14:54:39 UTC
Fixed in 9e85daf516 ("spdx30: Include patch file information in VEX")