Release
Release 2 — VEX and remediation operations
Goal
Support interoperable, source-attributed decisions about whether an exact product or component is affected by a vulnerability.
Scope
- Import and export CycloneDX VEX and CSAF 2.0 VEX.
- Support
affected, not_affected, fixed, and under_investigation.
- Scope statements to product release, image digest, component/PURL, and CVE.
- Retain issuer, timestamps, source document, signature/hash, justification, impact statement, and remediation action.
- Configure trusted suppliers and require a second approver for organization-authored risk reductions.
References:
Acceptance criteria
- Schema-invalid documents are rejected with actionable errors.
- Import/export round trips retain semantic content.
- A statement never applies outside its exact matched scope.
- Source precedence remains visible and conflicts are not discarded.
- The author cannot approve their own
not_affected or accepted-risk statement.
Release
Release 2 — VEX and remediation operations
Goal
Support interoperable, source-attributed decisions about whether an exact product or component is affected by a vulnerability.
Scope
affected,not_affected,fixed, andunder_investigation.References:
Acceptance criteria
not_affectedor accepted-risk statement.