You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
In the multi vuln lookup rule, we check to see if a component has both CPE & PURL. Our thinking was the more the merrier for looking up the vuln in NVD. CPE have been known to be error prone and manual. This scoring rule could influence sbom generators to just put in a CPE, even if they dont have the correct data.
We should re-evaluate if this is a legit concern or not.
The text was updated successfully, but these errors were encountered:
In the multi vuln lookup rule, we check to see if a component has both CPE & PURL. Our thinking was the more the merrier for looking up the vuln in NVD. CPE have been known to be error prone and manual. This scoring rule could influence sbom generators to just put in a CPE, even if they dont have the correct data.
We should re-evaluate if this is a legit concern or not.
The text was updated successfully, but these errors were encountered: