mirror of
https://github.com/openembedded/meta-openembedded.git
synced 2026-09-22 11:00:49 +00:00
The default product-only mapping generates a vendor-wildcard CPE. libssh:libssh is the active NVD dictionary CPE and configuration identity for the packaged libssh source. This changes the generated product identity to an exact CPE, but the frozen sbom-cve-check database leaves the 48-entry CVE report unchanged, with no current CVE delta. Signed-off-by: Devansh Patel <devanshp@cisco.com> Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>