feat(sbom): add trustedfirmware CPE for the NVD vendor split

NVD files Mbed TLS CVEs under two vendor CPEs: the legacy `arm` and the
current `trustedfirmware`. Mbed TLS moved from Arm to the
TrustedFirmware.org project in 2020, and NVD created the
`trustedfirmware:mbed_tls` CPE entries on 2026-06-05 and has since been
assigning CVEs to both vendors. A manifest carrying only the `arm` CPE
therefore misses CVEs filed solely under `trustedfirmware`.

Add the `trustedfirmware` CPE alongside the existing `arm` CPE so both
vendors are checked.

Signed-off-by: Frantisek Hrbata <[email protected]>
This commit is contained in:
Frantisek Hrbata
2026-06-26 09:49:22 +02:00
parent c3768eab76
commit 3d49d99001
+3 -1
View File
@@ -1,5 +1,7 @@
version: 3.6.6
cpe: cpe:2.3:a:arm:mbed_tls:{}:*:*:*:*:*:*:*
cpe:
- cpe:2.3:a:arm:mbed_tls:{}:*:*:*:*:*:*:*
- cpe:2.3:a:trustedfirmware:mbed_tls:{}:*:*:*:*:*:*:*
supplier: 'Organization: Espressif Systems (Shanghai) CO LTD'
originator: 'Organization: Trusted Firmware <[email protected]>'
description: An open source, portable, easy to use, readable and flexible SSL library with additional features and patches from Espressif.