software bill of materials

  1. CVE-2019-10638: Azure Linux Attestation and Open Source Inventory Risks

    Microsoft’s short MSRC entry — that “Azure Linux includes this open‑source library and is therefore potentially affected” — is accurate, but it is a scoped inventory attestation, not a blanket guarantee that no other Microsoft product carries the same vulnerable Linux code. The vulnerability in...