From f78df77d4859188d39b6101165977c79e2710a2d Mon Sep 17 00:00:00 2001 From: Frantisek Hrbata Date: Fri, 26 Jun 2026 09:47:19 +0200 Subject: [PATCH] feat(sbom): add trustedfirmware CPE for the NVD vendor split NVD files Mbed TLS and TF-PSA-Crypto CVEs under two vendor CPEs: the legacy `arm` and the current `trustedfirmware`. Mbed TLS moved from Arm to the TrustedFirmware.org project in 2020, and NVD created the `trustedfirmware:*` CPE entries on 2026-06-05 and has since been assigning CVEs to both vendors. A manifest carrying only the `arm` CPE therefore misses CVEs filed solely under `trustedfirmware`. Add the `trustedfirmware` CPE alongside the existing `arm` CPE in both the mbed_tls and tf-psa-crypto manifests so both vendors are checked. Signed-off-by: Frantisek Hrbata --- sbom.yml | 4 +++- tf-psa-crypto/sbom.yml | 4 +++- 2 files changed, 6 insertions(+), 2 deletions(-) diff --git a/sbom.yml b/sbom.yml index b37663c1ca..aab8c131e9 100644 --- a/sbom.yml +++ b/sbom.yml @@ -1,5 +1,7 @@ version: 4.1.0 -cpe: cpe:2.3:a:arm:mbed_tls:{}:*:*:*:*:*:*:* +cpe: + - cpe:2.3:a:arm:mbed_tls:{}:*:*:*:*:*:*:* + - cpe:2.3:a:trustedfirmware:mbed_tls:{}:*:*:*:*:*:*:* supplier: 'Organization: Espressif Systems (Shanghai) CO LTD' originator: 'Organization: Trusted Firmware ' description: An open source, portable, easy to use, readable and flexible SSL library with additional features and patches from Espressif. diff --git a/tf-psa-crypto/sbom.yml b/tf-psa-crypto/sbom.yml index 060715c211..9ba54ca979 100644 --- a/tf-psa-crypto/sbom.yml +++ b/tf-psa-crypto/sbom.yml @@ -1,5 +1,7 @@ version: 1.1.0 -cpe: cpe:2.3:a:arm:tf-psa-crypto:{}:*:*:*:*:*:*:* +cpe: + - cpe:2.3:a:arm:tf-psa-crypto:{}:*:*:*:*:*:*:* + - cpe:2.3:a:trustedfirmware:tf-psa-crypto:{}:*:*:*:*:*:*:* supplier: 'Organization: Espressif Systems (Shanghai) CO LTD' originator: 'Organization: Trusted Firmware ' description: An implementation of the PSA Cryptography API maintained under the Mbed TLS project.