Skip to content

Conversation

dsseng
Copy link

@dsseng dsseng commented Jul 14, 2025

Populate a single ID, pkg:generic/<lowercase name>@<version>, as long
as we have that data in the source like an SBOM.

This enables VEX files to be used to describe fixed vulnerabilities in
a product described with an SBOM.

Fixes #2471

@dsseng dsseng force-pushed the sbom-openvex-support branch 2 times, most recently from 551fc99 to 9f34a67 Compare July 14, 2025 10:50
@dsseng dsseng changed the title feat: add basic VEX support for SBOM sources feat: add basic VEX support for SBOM and other sources Jul 14, 2025
Populate a single ID, `pkg:generic/<lowercase name>@<version>`, as long
as we have that data in the source like an SBOM.

This enables VEX files to be used to describe fixed vulnerabilities in
a product described with an SBOM.

Signed-off-by: Dmitrii Sharshakov <d3dx12.xx@gmail.com>
Signed-off-by: Alex Goodman <wagoodman@users.noreply.github.com>
@wagoodman wagoodman enabled auto-merge (squash) October 6, 2025 16:17
@dsseng
Copy link
Author

dsseng commented Oct 6, 2025

Thank you for adding a test. Should I rebase this PR to resolve conflicts to facilitate merging?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Support using VEX documents with directory scans and SBOMs
4 participants