The product-only "tweepy" value emits a wildcard-vendor identity and
hides the distinct NVD identities assigned to the packaged Tweepy source.
Use "josh_roesslein:tweepy" for its NVD dictionary CPE and
"tweepy:tweepy" for the NVD configuration-only identity. With
sbom-cve-check 1.3.3 and the pinned database snapshots, the generated
product identity changes; the current CVE report is unchanged.
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>