Replies: 1 comment 2 replies
-
A component version is optional. Therefore, you can specify a vulnerability that affects the component (using affects.ref) and specify a range of affected versions using affects.version. |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
See CycloneDX/bom-examples#41.
Why vex specifies affects.version or range if affects.ref is unique bom-ref? Is it intended as a comment or what is the purpose ? Vulnerability is anyway always matched by bom-ref, so as in linked example it is confusing what to do.
Beta Was this translation helpful? Give feedback.
All reactions