Release
Release 2 — VEX and remediation operations
Goal
Give VEX, remediation, support-period, and regulatory evidence an exact product scope instead of treating each image scan as an isolated artifact.
Scope
- Add products, product releases, owners, support start/end dates, and lifecycle state.
- Map releases to image digests, SBOMs, Helm sources, and Git repository revisions.
- Preserve immutable historical mappings when tags move.
- Add product/release views and API endpoints.
- Allow organization policy and reporting to scope by product or release.
Acceptance criteria
- One release can reference multiple platform-specific image digests.
- A digest can be traced to its product release and source revision.
- Moving tags do not rewrite historical product evidence.
- Permissions follow existing organization ownership rules.
- Existing scans remain usable when they have not yet been assigned to a product.
Release
Release 2 — VEX and remediation operations
Goal
Give VEX, remediation, support-period, and regulatory evidence an exact product scope instead of treating each image scan as an isolated artifact.
Scope
Acceptance criteria