Skip to content

Feature: Import, author, approve, and export VEX statements #304

Description

@JustNZ

Release

Release 2 — VEX and remediation operations

Goal

Support interoperable, source-attributed decisions about whether an exact product or component is affected by a vulnerability.

Scope

  • Import and export CycloneDX VEX and CSAF 2.0 VEX.
  • Support affected, not_affected, fixed, and under_investigation.
  • Scope statements to product release, image digest, component/PURL, and CVE.
  • Retain issuer, timestamps, source document, signature/hash, justification, impact statement, and remediation action.
  • Configure trusted suppliers and require a second approver for organization-authored risk reductions.

References:

Acceptance criteria

  • Schema-invalid documents are rejected with actionable errors.
  • Import/export round trips retain semantic content.
  • A statement never applies outside its exact matched scope.
  • Source precedence remains visible and conflicts are not discarded.
  • The author cannot approve their own not_affected or accepted-risk statement.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    Status
    Todo

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions