On Thu, Aug 27, 2026 at 07:54 PM, Paul Barker wrote:
Hi Devansh,
The commit messages for these changes make no mention of the SBOM
output. Commit messages need to explain *why* a change is proposed. So
from the patches you sent I could only infer that this was solely about
CVE matching accuracy.
CVE_PRODUCT assignments have so far been used when the default leads to
either CVEs being missed, or unrelated CVEs being matched. We haven't
carried CVE_PRODUCT assignments purely for SBOM accuracy. I don't really
have the context to understand if this is required or not - I think we
need some discussion and input from others here. Could you send an email
to the openembedded-architecture list to discuss the need for additional
CVE_PRODUCT assignments before sending further patches like this?
Best regards,
--
Paul Barker
Hi Paul,
Thank you for the clarification.
We are reviewing the proposed CVE_PRODUCT changes internally at Cisco, particularly
the relationship between CVE matching, CPE identities in SPDX output, and the
sbom-cve-check workflow.
The main question is whether a vendor-qualified mapping is appropriate when it improves
the component identity in the SBOM but does not change the reported CVEs, and how existing
product aliases should be retained where they are necessary for complete CVE coverage.
We will ask our Cisco representative to raise this broader topic to the openembedded community
with more details. In the meantime, we will pause further CVE_PRODUCT submissions
that are intended to improve SBOM identity.
We will continue proposing mappings where the default value demonstrably misses relevant CVEs
or produces unrelated matches, with the specific CVE-reporting impact documented in the commit message.
Best regards,
Devansh