Features
- One-command assessment. The assess command runs the full workflow (SBOM generation, CVE scanning, guided triage, and VEX publishing) from a single package PURL or project directory.
- CWE-guided questionnaires. For each CVE, it looks up the CWE type and asks 2 to 4 targeted yes/no questions (for example, deserialization reachability for CWE-502, or XSS rendering for CWE-79). Answers map deterministically to a VEX status and justification code. This questionnaire engine is described as the core IP.
- Automatic CVE discovery. Scans against OSV.dev and GitHub Security Advisories (GHSA), covering PyPI, npm, Maven, Go, crates.io, NuGet, and more. No API keys required.
- SBOM generation and parsing. Builds CycloneDX SBOMs from a Python env, requirements file, or PURL list, and parses both CycloneDX and SPDX JSON. Any language is supported via Syft.
- Auto-suggested upgrade paths. Semver-aware remediation suggestions.
- Auditable output. VEX documents are named after the package (e.g. log4j-core-2.14.1.openvex.json), timestamped, and include a full decision audit trail of questions and answers.
- Resumable triage. Progress saves as you go, so Ctrl+C never loses work. Resume with vex-studio triage.
- VEX Hub-compatible publishing. Outputs to Aqua VEX Hub directory layout, which Trivy consumes automatically to suppress false positives for all downstream users.
- OpenVEX 0.2.0 output in Phase 1, with CSAF 2.0 and CycloneDX VEX planned for Phase 2.
Follow SecPod Vex
Other Useful Business Software
Build Agents and Models on One Platform
Gemini Enterprise Agent Platform is Google Cloud's comprehensive platform for developers to build, scale, govern, and optimize agents and models. Choose from Google's most advanced models and third-party models like Anthropic's Claude Model Family.
Rate This Project
Login To Rate This Project
User Reviews
Be the first to post a review of SecPod Vex!