-
Notifications
You must be signed in to change notification settings - Fork 779
Open
Labels
bugSomething isn't workingSomething isn't workinggood-first-issueGood for newcomersGood for newcomers
Description
What happened:
The project's SBOM was uploaded to DependencyTrack but was not matched with the related CVE. We double checked the CPE, and it was different from the CPE provided by NVD.
The generated CPE by Syft:
cpe:2.3:a:react:react:18.3.1:*:*:*:*:*:*:*
Provided CPE by NVD:
cpe:2.3:a:facebook:react:18.3.1:*:*:*:*:*:*:*
What you expected to happen:
Correct CPEs matching with NVD format.
Steps to reproduce the issue:
Scan a project's package-lock.yaml containing React version 18.3.1 with Syft version 1.42.1.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
bugSomething isn't workingSomething isn't workinggood-first-issueGood for newcomersGood for newcomers
Type
Projects
Status
Ready