Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add package URL (purl) and CPE to SPDX SBOM files #1482

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Commits on Aug 28, 2024

  1. Add package URL (purl) and CPE to SPDX SBOM files

    Add a package URL and CPE to generated SBOM files so that vulnerability
    databases can start linking CVEs to vcpkg port versions.
    
    Fixes microsoft/vcpkg#39254.
    See also package-url/purl-spec#217 that has
    not been resolved yet but should be resolved before this commit is
    merged.
    
    See also https://nvd.nist.gov/products/cpe/search?namingFormat=2.3 for a
    CPE database.
    aristotelos committed Aug 28, 2024
    Configuration menu
    Copy the full SHA
    483b6c1 View commit details
    Browse the repository at this point in the history