-
Notifications
You must be signed in to change notification settings - Fork 124
Open
Labels
enhancementNew feature or requestNew feature or request
Description
The known vulnerabilities inherited from the use of third-party and open source software and the exploitability of the vulnerabilities can be communicated with CycloneDX. Previously unknown vulnerabilities affecting both components and services may also be disclosed using CycloneDX, making it ideal for both VEX and security advisory use cases.
- VEX information can be represented inside an existing BOM, or in a dedicated VEX BOM
- Supports known and unknown vulnerabilities against components and services
- Communicates the vulnerability details, exploitability, and detailed analysis
More information :
https://cyclonedx.org/capabilities/vex/#vulnerability-exploitability-exchange-vex
https://github.com/CycloneDX/bom-examples/tree/master/VEX
Cc: @stevespringett
stevespringett and nscuro
Metadata
Metadata
Assignees
Labels
enhancementNew feature or requestNew feature or request