All of lore.kernel.org
 help / color / mirror / Atom feed
From: Thomas Petazzoni via buildroot <buildroot@buildroot.org>
To: Thomas Perale <thomas.perale@mind.be>
Cc: Thomas Perale via buildroot <buildroot@buildroot.org>,
	Christian Stewart <christian@aperture.us>,
	Thomas Perale <thomas.perale@essensium.com>
Subject: Re: [Buildroot] [PATCH 0/7] Add PURL support
Date: Tue, 22 Apr 2025 14:53:24 +0200	[thread overview]
Message-ID: <20250422145324.01ae9635@windsurf> (raw)
In-Reply-To: <bab05300-a70d-4f03-bb15-57bef52edac7@mind.be>

Hello Thomas,

On Mon, 21 Apr 2025 22:19:19 +0200
Thomas Perale <thomas.perale@mind.be> wrote:

> > So I'm still not sure to understand your "DependencyTrack uses NVD
> > annotation unfortunately". Could you clarify?  
> 
> The tool is called DependencyTrack (https://dependencytrack.org/), sorry 
> if the name was misleading.

OK.

> It uses the annotation downloaded from NVD to internally do the
> matching with the CPE ID.

Sorry, but I'm not able to parse that. Could you explain?

> Adding PURL definition the SBOM allows DependencyTrack to rely on 
> https://ossindex.sonatype.org/ to match CVE to packages.

OK.

> My series is more about improving the SBOM contents with information 
> that can be consumed by other software rather than improving
> 'pkg-stats' right now. But, it could be used as a fallback for
> packages without a CPE ID manually assigned.

And so DependencyTrack doesn't use CPEs at all? Or uses either CPEs or
PURLs, depending on the CVE?

Thomas
-- 
Thomas Petazzoni, co-owner and CEO, Bootlin
Embedded Linux and Kernel engineering and training
https://bootlin.com
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot

  reply	other threads:[~2025-04-22 12:53 UTC|newest]

Thread overview: 19+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-04-15 19:55 [Buildroot] [PATCH 0/7] Add PURL support Thomas Perale via buildroot
2025-04-15 19:55 ` [Buildroot] [PATCH 1/7] package/pkg-generic.mk: add PURL package variable Thomas Perale via buildroot
2025-04-15 19:55 ` [Buildroot] [PATCH 2/7] package/pkg-download: add 'owner' macro Thomas Perale via buildroot
2025-04-15 19:55 ` [Buildroot] [PATCH 2/7] package/pkg-download: add repository macro Thomas Perale via buildroot
2025-04-15 19:55 ` [Buildroot] [PATCH 3/7] package/pkg-golang: support PURL generation Thomas Perale via buildroot
2025-04-15 19:55 ` [Buildroot] [PATCH 4/7] package/pkg-cargo: " Thomas Perale via buildroot
2025-04-15 19:55 ` [Buildroot] [PATCH 5/7] package/pkg-perl: " Thomas Perale via buildroot
2025-04-15 19:55 ` [Buildroot] [PATCH 6/7] package/pkg-python: " Thomas Perale via buildroot
2025-04-15 19:55 ` [Buildroot] [PATCH 7/7] package/pkg-utils: add PURL to show-info output Thomas Perale via buildroot
2025-04-16 19:07 ` [Buildroot] [PATCH 0/7] Add PURL support Peter Korsgaard
2025-04-16 19:19   ` Arnout Vandecappelle via buildroot
     [not found]     ` <4b029329-2258-428d-80c9-315dbd6335be@essensium.com>
2025-04-16 19:58       ` Thomas Petazzoni via buildroot
2025-04-16 20:06         ` Thomas Perale via buildroot
2025-04-16 20:40           ` Thomas Petazzoni via buildroot
2025-04-16 20:49             ` Thomas Perale via buildroot
2025-04-18 10:39               ` Thomas Petazzoni via buildroot
2025-04-21 20:19                 ` Thomas Perale via buildroot
2025-04-22 12:53                   ` Thomas Petazzoni via buildroot [this message]
2025-04-22 14:00                     ` Peter Korsgaard

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20250422145324.01ae9635@windsurf \
    --to=buildroot@buildroot.org \
    --cc=christian@aperture.us \
    --cc=thomas.perale@essensium.com \
    --cc=thomas.perale@mind.be \
    --cc=thomas.petazzoni@bootlin.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.