Since our previous update on sbom-cve-check, the project has continued to evolve with two new releases: version 1.3.2, released in June, and version 1.3.3, released in August.
These releases bring a number of improvements to the handling of SBOM data, CVE version ranges and vulnerability assessments, as well as fixes for some corner cases encountered when analyzing real-world software projects.
For those discovering the project, sbom-cve-check is a lightweight open-source tool developed by Bootlin for performing vulnerability analysis on Software Bill of Materials (SBOMs). It is based on SPDX SBOMs and can be used both as a standalone tool and through its integration in the Yocto Project. Since the Yocto Project’s Wrynose release, sbom-cve-check has been used as the Yocto Project’s official tool for CVE monitoring.


Bootlin has been maintaining 
Bootlin has recently contributed to the