sbom-cve-check v1.2.0 has been released, bringing offline usability via a --disable-auto-updates flag, zstd compression support for input/output files, improved export options (summary text reports, stdout output, VEX linking in SPDX 3 exports), better SPDX 3.0 package extraction, and stricter annotation handling to reduce false CVE associations. Progress on Yocto/OpenEmbedded integration is also noted, with a recipe already merged into OpenEmbedded-Core.

2m read timeFrom bootlin.com
Post cover image
Table of contents
Offline usageCompression supportImproved exportsBetter SPDX 3.0 supportSmarter annotation handlingYocto integrationConclusionAuthor: Thomas Petazzoni