VEX

A vulnerability may be exploitable in one product and unreachable in another. Vellaci stores per-product (and per-version) VEX statements with CycloneDX justifications (code_not_reachable, requires_configuration, …), responses and an action statement.

Generate VEX on a version page produces a CycloneDX 1.5 VEX document containing every current statement, signed (HMAC-SHA256 over the content hash, key id recorded) and stored with the version. Download it from the version page or share it with customers.

Last updated . This page describes the current release.