Features
- One-command assessment. The assess command runs the full workflow (SBOM generation, CVE scanning, guided triage, and VEX publishing) from a single package PURL or project directory.
- CWE-guided questionnaires. For each CVE, it looks up the CWE type and asks 2 to 4 targeted yes/no questions (for example, deserialization reachability for CWE-502, or XSS rendering for CWE-79). Answers map deterministically to a VEX status and justification code. This questionnaire engine is described as the core IP.
- Automatic CVE discovery. Scans against OSV.dev and GitHub Security Advisories (GHSA), covering PyPI, npm, Maven, Go, crates.io, NuGet, and more. No API keys required.
- SBOM generation and parsing. Builds CycloneDX SBOMs from a Python env, requirements file, or PURL list, and parses both CycloneDX and SPDX JSON. Any language is supported via Syft.
- Auto-suggested upgrade paths. Semver-aware remediation suggestions.
- Auditable output. VEX documents are named after the package (e.g. log4j-core-2.14.1.openvex.json), timestamped, and include a full decision audit trail of questions and answers.
- Resumable triage. Progress saves as you go, so Ctrl+C never loses work. Resume with vex-studio triage.
- VEX Hub-compatible publishing. Outputs to Aqua VEX Hub directory layout, which Trivy consumes automatically to suppress false positives for all downstream users.
- OpenVEX 0.2.0 output in Phase 1, with CSAF 2.0 and CycloneDX VEX planned for Phase 2.
Follow SecPod Vex
Other Useful Business Software
Build Securely on Azure with Proven Frameworks
Moving to the cloud brings new challenges. How can you manage a larger attack surface while ensuring great network performance? Turn to Fortinet’s Tested Reference Architectures, blueprints for designing and securing cloud environments built by cybersecurity experts. Learn more and explore use cases in this white paper.
Rate This Project
Login To Rate This Project
User Reviews
Be the first to post a review of SecPod Vex!