Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Multi Vuln lookup rule re-evaluate #110

Open
riteshnoronha opened this issue Mar 18, 2023 · 0 comments
Open

Multi Vuln lookup rule re-evaluate #110

riteshnoronha opened this issue Mar 18, 2023 · 0 comments
Assignees

Comments

@riteshnoronha
Copy link
Contributor

In the multi vuln lookup rule, we check to see if a component has both CPE & PURL. Our thinking was the more the merrier for looking up the vuln in NVD. CPE have been known to be error prone and manual. This scoring rule could influence sbom generators to just put in a CPE, even if they dont have the correct data.

We should re-evaluate if this is a legit concern or not.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants