Skip to content

[pull] master from CycloneDX:master#28

Merged
pull[bot] merged 7 commits intoturkdevops:masterfrom
CycloneDX:master
Feb 8, 2026
Merged

[pull] master from CycloneDX:master#28
pull[bot] merged 7 commits intoturkdevops:masterfrom
CycloneDX:master

Conversation

@pull
Copy link

@pull pull bot commented Feb 8, 2026

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

fahedouch and others added 7 commits February 5, 2026 18:23
Signed-off-by: fahed dorgaa <fahed.dorgaa@gmail.com>
… and revert extension changes

Signed-off-by: fahed dorgaa <fahed.dorgaa@gmail.com>
…n VEX usage

Signed-off-by: Fahed Dorgaa <fahed.dorgaa@gmail.com>
Signed-off-by: fahed dorgaa <fahed.dorgaa@gmail.com>
… and revert extension changes

Signed-off-by: fahed dorgaa <fahed.dorgaa@gmail.com>
Signed-off-by: Fahed Dorgaa <fahed.dorgaa@gmail.com>
…722)

<!-- 
Thank you for taking the time to develop and contribute a core
enhancement or fix for a defect!

We kindly request that you create pull requests only for things that
have been discussed in a ticket first; exceptions may be made for
spelling or grammar fixes.
Read more about the process here:
https://cyclonedx.org/participate/standardization-process/#working-model

Please have the related ticket/issue ID ready. 
If there is none, feel free to create a new ticket:
https://github.com/CycloneDX/specification/issues/new/choose

-->

<!-- 

Please provide a brief description of what this pull request intends to
do and which ticket it fixes/closes.
Example: 
> As discussed in ticket #485, this PR adds Streebog to the hash
algorithm enum.
>
> fixes #485 

In case this is for a spelling or grammar improvement, please provide a
brief description.
Example:
> Fixe typo: color(AE) -> colour(BE)

-->

I am translating @stevespringett 's
[feedback](#719 (comment))
on the CycloneDX VEX specification into the code.



> Should ratings be normative inputs for prioritization in VEX
consumers?

_Yes, they should be. It is widely known that the NVD has historically
overrated vulnerabilities (on purpose). So the ratings from the NVD and
those from the manufactures are often different. CycloneDX can convey
this information which can aid in prioritization._


fixes  #719
@pull pull bot locked and limited conversation to collaborators Feb 8, 2026
@pull pull bot added the ⤵️ pull label Feb 8, 2026
@pull pull bot merged commit 251b1cd into turkdevops:master Feb 8, 2026
2 of 3 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants