<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://devzone.nordicsemi.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Sbom cve check RED EN 18031</title><link>https://devzone.nordicsemi.com/f/nordic-q-a/127650/sbom-cve-check-red-en-18031</link><description>Hello, 
 I am currently evaluating and trying to conform to the regulation regarding the RED EN 18031 vulnerabilites checks and I am having some problems due to that the sbom spdx file is incomplete both when I run the &amp;quot; ncs-sbom&amp;quot; and west spdx directly</description><dc:language>en-US</dc:language><generator>Telligent Community 13</generator><lastBuildDate>Mon, 13 Apr 2026 11:12:11 GMT</lastBuildDate><atom:link rel="self" type="application/rss+xml" href="https://devzone.nordicsemi.com/f/nordic-q-a/127650/sbom-cve-check-red-en-18031" /><item><title>RE: Sbom cve check RED EN 18031</title><link>https://devzone.nordicsemi.com/thread/564840?ContentTypeID=1</link><pubDate>Mon, 13 Apr 2026 11:12:11 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:5f86dfc9-f526-4d41-9d32-23318d9f688d</guid><dc:creator>Benjamin</dc:creator><description>&lt;p&gt;Hi,&lt;br /&gt;Yes you are right, this was &lt;a href="https://github.com/nrfconnect/sdk-zephyr/commit/0d05318c96ee38493e6a0411be639ebf04fe2e58"&gt;added&lt;/a&gt; in NCS v2.8.0. I don&amp;#39;t have any quick fixes for making this work better with the cve-bin-tool. However I found &lt;a href="https://theembeddedkit.io/blog/zephyr-sbom-accuracy-vulnerability-management"&gt;this article&lt;/a&gt; online, you may want to have a look at that!&lt;/p&gt;
&lt;p&gt;Benjamin&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sbom cve check RED EN 18031</title><link>https://devzone.nordicsemi.com/thread/564697?ContentTypeID=1</link><pubDate>Thu, 09 Apr 2026 08:22:27 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:ff1bbc33-9913-49c9-a57e-6b97f782e6e4</guid><dc:creator>Hdx</dc:creator><description>&lt;p&gt;Ok same as I do, the only difference is that the&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;span&gt;modules-deps.spdx does not exist for versions below ncs sdk 2.6.0 or 2.7.0 i think, so there is the problem. What is the solution in this case for us that use older version?&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;I only get 3 spdx files, build.spdx, zephyr.spdx, and app.spdx.&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sbom cve check RED EN 18031</title><link>https://devzone.nordicsemi.com/thread/564695?ContentTypeID=1</link><pubDate>Thu, 09 Apr 2026 08:19:39 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:8b929ee5-524e-40f5-bdec-778898f341cd</guid><dc:creator>Benjamin</dc:creator><description>&lt;p&gt;I used the &lt;a href="https://github.com/nrfconnect/sdk-nrf/tree/main/samples/dfu/mcuboot_with_encryption"&gt;mcuboot_with_encryption&lt;/a&gt;&amp;nbsp;sample, it was built using sysbuild and&amp;nbsp;&lt;span&gt;CONFIG_BUILD_OUTPUT_META=&lt;/span&gt;&lt;span&gt;y. The only file I tested&amp;nbsp;was&amp;nbsp;&lt;/span&gt;&lt;span&gt;modules-deps.spdx.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;pre class="ui-code" data-mode="text"&gt;west spdx --init -d build/mcuboot_with_encryption
west build --build-dir /some/path/mcuboot_with_encryption/build /Users/bebo/workspace/mcuboot_with_encryption --board nrf54l15dk/nrf54l15/cpuapp --sysbuild
west spdx -d build/mcuboot_with_encryption
cve-bin-tool \
  --sbom spdx \
  --sbom-file /some/path/mcuboot_with_encryption/build/mcuboot_with_encryption/spdx/modules-deps.spdx&lt;/pre&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sbom cve check RED EN 18031</title><link>https://devzone.nordicsemi.com/thread/564639?ContentTypeID=1</link><pubDate>Wed, 08 Apr 2026 13:28:09 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:1f797f45-9020-4582-b2ed-f7dd91d0f407</guid><dc:creator>Hdx</dc:creator><description>&lt;p&gt;Hello Benjamin,&lt;/p&gt;
&lt;p&gt;Thanks for the reply!&lt;/p&gt;
&lt;p&gt;Ok that is odd, I tried the &amp;acute;&lt;span&gt;west ncs-sbom&amp;acute;&amp;nbsp;&lt;/span&gt;first and that did not work and got no results. Then I tried the west spdx and got the same result. Do you mind providing the steps that you did to verify if I might have exlcuded something in my build?&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sbom cve check RED EN 18031</title><link>https://devzone.nordicsemi.com/thread/564634?ContentTypeID=1</link><pubDate>Wed, 08 Apr 2026 13:22:33 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:6b14f3c1-3d23-441d-831b-3a3f2ef1acf5</guid><dc:creator>Benjamin</dc:creator><description>&lt;p&gt;Hi Hadi,&lt;br /&gt;Thanks for waiting, we have been low staffed because of Easter holidays.&lt;/p&gt;
&lt;p&gt;I don&amp;#39;t know what fields the cve-bin-tool needs to map&amp;nbsp;&lt;span&gt;CVE entries to software components. I tried to run it on a sample and it does find&amp;nbsp;some&amp;nbsp;&lt;/span&gt;components:&lt;br /&gt;&lt;br /&gt;&lt;pre class="ui-code" data-mode="text"&gt;┏━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━┓
┃ Vendor  ┃ Product                 ┃ Version     ┃
┡━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━┩
│ UNKNOWN │ hostap-deps             │ hostap_2_11 │
│ UNKNOWN │ mbedtls-deps            │ v3.6.5      │
│ UNKNOWN │ trusted-firmware-m-deps │ TF-Mv2.2.0  │
└─────────┴─────────────────────────┴─────────────┘&lt;/pre&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;I’m unsure whether the issue is that cve-bin-tool doesn’t recognize all&amp;nbsp;components, or that it isn’t receiving enough information to identify them properly.&amp;nbsp;&lt;/span&gt;&lt;span&gt;I checked the documentation and it seems that&amp;nbsp;there is no support for west spdx to include&amp;nbsp;generating the keywords you are mentioning.&lt;br /&gt;&lt;br /&gt;Best&amp;nbsp;&lt;/span&gt;regards,&lt;br /&gt;Benjamin&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sbom cve check RED EN 18031</title><link>https://devzone.nordicsemi.com/thread/564476?ContentTypeID=1</link><pubDate>Tue, 07 Apr 2026 07:41:14 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:62ad2881-fe03-4f8d-88b2-88a030153c95</guid><dc:creator>Hdx</dc:creator><description>&lt;p&gt;Hi Benjamin, any updates regarding this why the spdx report seem to be incomplete and the file is missing the packageversion and packagesuppliers?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sbom cve check RED EN 18031</title><link>https://devzone.nordicsemi.com/thread/564374?ContentTypeID=1</link><pubDate>Wed, 01 Apr 2026 11:02:25 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:314d5f22-e634-48c9-97b3-1429b7f909a7</guid><dc:creator>Hdx</dc:creator><description>&lt;p&gt;Hello Benjamin!&lt;/p&gt;
&lt;p&gt;Thank you!&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I&amp;#39;ll be waiting for your response then :)&lt;/p&gt;
&lt;p&gt;It is a bit urgent so appreciate if get an answer soon.&lt;/p&gt;
&lt;p&gt;/Hd&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sbom cve check RED EN 18031</title><link>https://devzone.nordicsemi.com/thread/564370?ContentTypeID=1</link><pubDate>Wed, 01 Apr 2026 10:51:37 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:81006515-3c38-4b2d-bca3-c24f16aa1516</guid><dc:creator>Benjamin</dc:creator><description>&lt;p&gt;Hi Hadi,&lt;/p&gt;
&lt;p&gt;Thanks for reporting, I&amp;#39;m on it and will come back to you on this matter.&lt;br /&gt;&lt;br /&gt;Best regards,&lt;br /&gt;Benjamin&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>