Skip to content

OSS vs NVD #1383

Answered by stevespringett
freddiN asked this question in Q&A
Feb 10, 2022 · 1 comments · 2 replies
Discussion options

You must be logged in to vote

The NVD continues to only support CPE for software identifiers, even though the majority of software cannot be described with CPE, nor can CPE be automatically generated or known in advance.

If an SBOM has CPEs for components, then the internal analyzer supporting the NVD will be able to pick it up. However, most SBOMs generated at build-time, will not contain CPEs, they will contain Package URLs (purl).

Refer to https://cyclonedx.org/use-cases/#known-vulnerabilities

Dependency-Check is able to find these vulnerabilities because it uses fuzzy matching and in most cases will generate many false positives.

See also https://docs.dependencytrack.org/odt-odc-comparison/

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@stevespringett
Comment options

@freddiN
Comment options

Answer selected by freddiN
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants