New version of sbom-cve-check makes more torough version validation
and version strings with distro specific suffix is no longer accepted,
thus leaving some CVEs without version to compare (no-version-ranges).
Per [1] this CVE was fixed in v3.8.0.
[1] https://security-tracker.debian.org/tracker/CVE-2023-0361
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
fi
}
+CVE_STATUS[CVE-2023-0361] = "fixed-version: fixed in version 3.8.0"
CVE_STATUS[CVE-2025-32989] = "fixed-version: fixed in version 3.8.10"
CVE_STATUS[CVE-2025-32990] = "fixed-version: fixed in version 3.8.10"
CVE_STATUS[CVE-2026-1584] = "fixed-version: fixed in version 3.8.12"