Features
- One-command assessment. The assess command runs the full workflow (SBOM generation, CVE scanning, guided triage, and VEX publishing) from a single package PURL or project directory.
- CWE-guided questionnaires. For each CVE, it looks up the CWE type and asks 2 to 4 targeted yes/no questions (for example, deserialization reachability for CWE-502, or XSS rendering for CWE-79). Answers map deterministically to a VEX status and justification code. This questionnaire engine is described as the core IP.
- Automatic CVE discovery. Scans against OSV.dev and GitHub Security Advisories (GHSA), covering PyPI, npm, Maven, Go, crates.io, NuGet, and more. No API keys required.
- SBOM generation and parsing. Builds CycloneDX SBOMs from a Python env, requirements file, or PURL list, and parses both CycloneDX and SPDX JSON. Any language is supported via Syft.
- Auto-suggested upgrade paths. Semver-aware remediation suggestions.
- Auditable output. VEX documents are named after the package (e.g. log4j-core-2.14.1.openvex.json), timestamped, and include a full decision audit trail of questions and answers.
- Resumable triage. Progress saves as you go, so Ctrl+C never loses work. Resume with vex-studio triage.
- VEX Hub-compatible publishing. Outputs to Aqua VEX Hub directory layout, which Trivy consumes automatically to suppress false positives for all downstream users.
- OpenVEX 0.2.0 output in Phase 1, with CSAF 2.0 and CycloneDX VEX planned for Phase 2.
Follow SecPod Vex
Other Useful Business Software
$300 Free Credits for Your Google Cloud Projects
Launch your next project with $300 in free Google Cloud credits—no strings attached. Test, build, and deploy without risk. Use your credits across the entire Google Cloud platform to find what works best for your needs. After your credits are used, continue with always-free tier services. Only pay when you're ready to scale. Sign up in minutes and start exploring.
Rate This Project
Login To Rate This Project
User Reviews
Be the first to post a review of SecPod Vex!