Re: [Buildroot] [PATCH 0/3] fix CPE for TrustedFirmware projects
Titouan Christophe via buildroot <[email protected]>
| Newsgroups | net.busybox.buildroot |
|---|---|
| Message-ID | <[email protected]> |
On 25/06/26 17:37, Quentin Schulz via buildroot wrote: > OP-TEE OS, TF-A/ATF and mbedTLS had many different CPEs each, from > various vendors and with various different names. It seems[1] > TrustedFirmware finally did the right thing and request all CVEs to be > reported to a single CPE for each project, so this updates the CPE of > those projects to match what's in NVD now. > > This is also great news for Buildroot since it means a single CPE can > now be used for those pieces of software, meaning users can finally stop > working around the CycloneDX SBOM limitation of a single CPE per > component by doing weird stuff (I'm such a user). > > Similar changes were already made in Yocto[2][3] (no change made to > mbedTLS because only the CPE product part is set to mbed_tls unlike in > Buildroot. > > I did not test any of this. > > [1] https://review.trustedfirmware.org/c/TF-A/trusted-firmware-a/+/49486/comment/2fd93ed7_df27998e/ before last comment from Sandrine > [2] https://git.yoctoproject.org/meta-arm/commit/?id=e2e63f20b504c31a4600f95764d3561c32b4b2f7 > [3] https://git.yoctoproject.org/meta-arm/commit/?id=81f5a92193d37027670f2c9b767ccbcd29d1e78c > > Signed-off-by: Quentin Schulz <[email protected]> Series applied to 2025.02.x and 2026.05.x, thanks ! _______________________________________________ buildroot mailing list [email protected] https://lists.buildroot.org/mailman/listinfo/buildroot