06/06/2026
This [https://ow.ly/eCPc50Z8n16] discussion focuses on the limitations of SPDX 3.0 SBOMs generated by OE-Core, particularly their lack of details regarding the build layers, versions, and metadata influencing software packages. Marta Rybczynska raises concerns that current SBOMs do not address vulnerabilities related to build metadata, like those affecting BitBake tools and fetchers. She argues for including the list of build layers and their respective versions in SBOMs, citing that this information is crucial for vulnerability management. Richard Purdie expresses concern that updating metadata would necessitate regenerating all SPDX files, complicating the reuse of SBOM state. The discussion highlights the need for better visibility and tracking of layers in vulnerability assessments.