Skip to content

Can a component be added with only a SWID tag? #1440

Answered by stevespringett
mrmoosefish asked this question in Q&A
Discussion options

You must be logged in to vote

The NVD has deprecated CPE, however, they have failed to provide any guidance or solutions for supporting SWID as its replacement. Refer to NISTIR 8060.

From my understanding, the NVD has SWID mappings for many/most CPEs in the NVD, but they have not yet published it. To my knowledge, there are no sources of vulnerability intelligence that support SWID for component identity. This was suppose expected to occur roughly two years ago with the NVD, but it hasn't yet.

There is no way to map SWID (decentralized) to CPE (centralized) currently. The only two identifiers commonly used for vulnerability management purposes are Package URL (purl) and CPE.

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@mrmoosefish
Comment options

Answer selected by mrmoosefish
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants