The SPDXv3 output doesn't include useful metadata like "this CVE was fixed by these patches". This is included in the vex output: "issue": [ { "id": "CVE-2022-28391", "status": "Patched", "link": "https://nvd.nist.gov/vuln/detail/CVE-2022-28391", "detail": "fix-file-included", "patch-file": [ "/home/rosbur01/Yocto/openembedded-core/meta/recipes-core/busybox/busybox/0001-libbb-sockaddr2str-ensure-only-printable-characters-.patch", "/home/rosbur01/Yocto/openembedded-core/meta/recipes-core/busybox/busybox/0002-nslookup-sanitize-all-printed-strings-with-printable.patch" ] }, It would be good to not need the vex class, and to have this information in the SPDX. Concrete use-case being sbom-cve-tool ideally wants both the SPDX and VEX for this data.
Fixed in 9e85daf516 ("spdx30: Include patch file information in VEX")