]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core.git/commitdiff
lib: sbom30: Add action statement for affected VEX statements
authorJoshua Watt <JPEWhacker@gmail.com>
Wed, 5 Mar 2025 21:00:30 +0000 (14:00 -0700)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Thu, 6 Mar 2025 16:33:18 +0000 (16:33 +0000)
VEX Affected relationships have a mandatory action statement that
indicates the mitigation for a vulnerability. Since we don't track this
add a statement indicating that no mitigation is known.

Signed-off-by: Joshua Watt <JPEWhacker@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/lib/oe/sbom30.py

index 0595ebd41ca1885e7d99a3c26c54b44b29e4e9b9..227ac5187708c8af57a684d34c12a73c0d4d5524 100644 (file)
@@ -685,6 +685,7 @@ class ObjectSet(oe.spdx30.SHACLObjectSet):
             to,
             spdxid_name="vex-affected",
             security_vexVersion=VEX_VERSION,
+            security_actionStatement="Mitigation action unknown",
         )
 
     def new_vex_ignored_relationship(self, from_, to, *, impact_statement):