which SPDXID to be used for S140 softdevice and nrf5 SDK (name convention)

Hey Nordic team,

which tags or names for identifying nrf5 SDK version and S140 version vulnerabilities inside my SBOM (i take care of creating thiss when using the old sdk, that part is very clear!) shall i use to be able to identify and map public CVE's and EU ENISA SRP database entries  (on nordic hardware and softawre parts) to my products using specific versions of the nrf5 sdk as well as on the S140 softdevice?

Is there any official definition or registered name scheme by nordic as the software supplyer, onwer and maintainer what to use exactly for their sbom software parts?

I am aware the old sdk is in maintenace mode, but a common naming convention helps a lot to fulfill the upcoming CRA requirements on regularly checking for vulnerabilities.

I need to enter those tags to the filter of the cve scanner and enisa srp scanner so i do not need to do this manually.

I found something here: https://stack-canary.com/blog/zephyr-sbom-cra-compliance/ is this an official convention defined by nordic?

i copied spdx content from the blog entry (the relevant content example for S140) here:


PackageName: Nordic SoftDevice S140
SPDXID: SPDXRef-softdevice-s140
PackageVersion: 7.3.0
PackageSupplier: Organization: Nordic Semiconductor
PackageDownloadLocation: NOASSERTION
FilesAnalyzed: false
PackageVerificationCode: NOASSERTION (binary blob — source not available)
PackageLicenseConcluded: LicenseRef-Nordic-Proprietary
PackageLicenseDeclared: LicenseRef-Nordic-Proprietary
PackageCopyrightText: Copyright Nordic Semiconductor ASA
ExternalRef: PACKAGE-MANAGER purl pkg:generic/nordic/[email protected]
PackageComment: Pre-compiled binary blob provided by Nordic Semiconductor.
  Source code not available. Vulnerability assessment depends on vendor advisories

Thanks for clarification & best regards

Jens

AI assistant pointed out that there is no naming convention. can this be confirmed by a human, please.

Parents Reply Children
Related