---
title: "sbom-cve-check v1.2.0 released – Bootlin"
url: https://daily.dev/posts/sbom-cve-check-v1-2-0-released-bootlin-xjzrwaynl
source_url: https://bootlin.com/blog/sbom-cve-check-v1-2-0-released
type: article
source: "Bootlin"
published: 2026-05-31T07:47:31.048Z
updated: 2026-05-31T08:46:36.565Z
tags: ["security", "sbom"]
reading_time: 2
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# sbom-cve-check v1.2.0 released – Bootlin

**[Bootlin](https://daily.dev/sources/bootlin)** · 2 min read · 0 upvotes · 0 comments

## Summary

sbom-cve-check v1.2.0 has been released, bringing offline usability via a --disable-auto-updates flag, zstd compression support for input/output files, improved export options (summary text reports, stdout output, VEX linking in SPDX 3 exports), better SPDX 3.0 package extraction, and stricter annotation handling to reduce false CVE associations. Progress on Yocto/OpenEmbedded integration is also noted, with a recipe already merged into OpenEmbedded-Core.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://bootlin.com/blog/sbom-cve-check-v1-2-0-released>

## Similar posts on daily.dev

- [sbom-cve-check updates: integrated in Yocto 6.0 Wrynose, Schneider Electric support, new releases, and more – Bootlin](https://daily.dev/posts/sbom-cve-check-updates-integrated-in-yocto-6-0-wrynose-schneider-electric-support-new-releases-a-vdyr1d99s) · Bootlin · 0 upvotes · 0 comments
- [SPDX SBOM Generation Tool Proposed For The Linux Kernel](https://daily.dev/posts/spdx-sbom-generation-tool-proposed-for-the-linux-kernel-behz0husd) · Phoronix · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#sbom](https://daily.dev/tags/sbom)

[View this post on daily.dev](https://daily.dev/posts/sbom-cve-check-v1-2-0-released-bootlin-xjzrwaynl)
