As discussed as part of the PURL spec, we cannot have a generic CPE <-> PURL mapping and need to track CPEs separately for the time being. Which also means to me that we should allow VulnerableCode to be queried by CPE directly, in addition to the supported queries by PURL.
As discussed as part of the PURL spec, we cannot have a generic CPE <-> PURL mapping and need to track CPEs separately for the time being. Which also means to me that we should allow VulnerableCode to be queried by CPE directly, in addition to the supported queries by PURL.