Features
- One-command assessment. The assess command runs the full workflow (SBOM generation, CVE scanning, guided triage, and VEX publishing) from a single package PURL or project directory.
- CWE-guided questionnaires. For each CVE, it looks up the CWE type and asks 2 to 4 targeted yes/no questions (for example, deserialization reachability for CWE-502, or XSS rendering for CWE-79). Answers map deterministically to a VEX status and justification code. This questionnaire engine is described as the core IP.
- Automatic CVE discovery. Scans against OSV.dev and GitHub Security Advisories (GHSA), covering PyPI, npm, Maven, Go, crates.io, NuGet, and more. No API keys required.
- SBOM generation and parsing. Builds CycloneDX SBOMs from a Python env, requirements file, or PURL list, and parses both CycloneDX and SPDX JSON. Any language is supported via Syft.
- Auto-suggested upgrade paths. Semver-aware remediation suggestions.
- Auditable output. VEX documents are named after the package (e.g. log4j-core-2.14.1.openvex.json), timestamped, and include a full decision audit trail of questions and answers.
- Resumable triage. Progress saves as you go, so Ctrl+C never loses work. Resume with vex-studio triage.
- VEX Hub-compatible publishing. Outputs to Aqua VEX Hub directory layout, which Trivy consumes automatically to suppress false positives for all downstream users.
- OpenVEX 0.2.0 output in Phase 1, with CSAF 2.0 and CycloneDX VEX planned for Phase 2.
Follow SecPod Vex
Other Useful Business Software
MongoDB Atlas runs apps anywhere
MongoDB Atlas gives you the freedom to build and run modern applications anywhere—across AWS, Azure, and Google Cloud. With global availability in over 115 regions, Atlas lets you deploy close to your users, meet compliance needs, and scale with confidence across any geography.
Rate This Project
Login To Rate This Project
User Reviews
Be the first to post a review of SecPod Vex!