Post #4193007
2026-07-28 22:00 UTC
@andrewnez@mastodon.social @gvwilson@mastodon.social @fedora@fosstodon.org is planning to use
https://fedoraproject.org/wiki/Changes/Adopt_PURL_Metadata
which is at the very least SBOM adjacent.
We find that otherwise each packaging ecosyatem has its own way of specifying dependencies, and this makes it harder for security teams to flag issues accurately
Replies (1)
-
@jbm@infosec.exchange 2026-07-29 10:11
@michelin@hachyderm.io @andrewnez@mastodon.social @gvwilson@mastodon.social @fedora@fosstodon.org Red Hat uses a dual CPE/PURL model for its VEX. See: https://www.redhat.com/en/blog/vulnerability-exploitability-exchange-vex-beta-files-now-available https://www.redhat.com/fr/blog/redefining-security-data-red-hats-new-vex-experience-heading-red-hat-summit-2026