Open wagoodman opened 2 years ago
FYI: The SPDX SBOM team is working on a V2.3 release that includes the ability for a software vendor to provide a link to a vulnerability report that is independently updated from the static SBOM. The SPDX proposal uses existing ExternalRef capabilities and supports any type of vulnerability report format, i.e.
CDX VEX: ExternalRef: SECURITY Disclosure https://raw.githubusercontent.com/rjb4standards/REA-Products/master/CDXVEX/CDX14.xml
SBOM VDR: ExternalRef: SECURITY Disclosure https://raw.githubusercontent.com/rjb4standards/REA-Products/master/SAGVulnDisclosureSAMPLE.xml
As we start to introduce producing VEX documents https://github.com/anchore/grype/issues/591 , there are some input values which are manually curated (e.g. "affected" / "not affected", "justification", "response", etc). There are (at least) two opportunities here: