Since our previous update on sbom-cve-check, the project has continued to evolve with two new releases: version 1.3.2, released in June, and version 1.3.3, released in August.
These releases bring a number of improvements to the handling of SBOM data, CVE version ranges and vulnerability assessments, as well as fixes for some corner cases encountered when analyzing real-world software projects.
For those discovering the project, sbom-cve-check is a lightweight open-source tool developed by Bootlin for performing vulnerability analysis on Software Bill of Materials (SBOMs). It is based on SPDX SBOMs and can be used both as a standalone tool and through its integration in the Yocto Project. Since the Yocto Project’s Wrynose release, sbom-cve-check has been used as the Yocto Project’s official tool for CVE monitoring.


Snagboot has just received its
Linux 7.2 has been released 

From the 13th to 16th of July in Rome, Italy, 130 Linux Kernel developers specialized in networking gathered at the
Bootlin has been maintaining
Paul joined Bootlin in February 2026, after graduating from
Diogo joined Bootlin at the beginning of June 2026. Diogo graduated with a Master’s Degree in Engineering Physics from Instituto Superior Técnico (Portugal) in 2022. From 2023 to 2026, he worked at Siemens as an Embedded Linux engineer, working with edge industrial platforms and gaining experience in Yocto integration, platform maintenance and BSP kernel updates. He also contributed to the upstream Linux kernel, namely an Ethernet driver for the Texas Instruments AM654x SR1.0 SoC and a watchdog driver for the Intel Over-Clocking watchdog.