Skip to content

Assigning many CPEs per CycloneDX component #2290

Answered by stevespringett
henrirosten asked this question in Q&A
Discussion options

You must be logged in to vote

A component should only ever have a single CPE identity. In reality, the NVD has a ton of data issues. The CycloneDX spec does not try to provide workaround for human problems at the NVD that lead to data inconsistencies between component identity.

One approach that DT could take is to support an alias list where we predefine all the alias CPE vendors and product names and take that list into consideration when performing a vulnerability scan. This would require a ton of research and community feedback, but it is possible.

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@henrirosten
Comment options

@stevespringett
Comment options

Answer selected by henrirosten
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants