Replies: 1 comment 2 replies
-
A component version is optional. Therefore, you can specify a vulnerability that affects the component (using affects.ref) and specify a range of affected versions using affects.version. |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
See CycloneDX/bom-examples#41.
Why vex specifies affects.version or range if affects.ref is unique bom-ref? Is it intended as a comment or what is the purpose ? Vulnerability is anyway always matched by bom-ref, so as in linked example it is confusing what to do.
Beta Was this translation helpful? Give feedback.
All reactions