Definition

CycloneDX

An OWASP-originated, ECMA-standardised SBOM and VEX format widely used in application-security tooling.

A lightweight bill-of-materials standard from OWASP, published as ECMA-424, that describes software, hardware, services and their dependencies in JSON or XML. It carries package URLs, hashes, licences, dependency graphs and — natively — VEX exploitability statements, which makes it convenient for the CRA workflow from inventory to vulnerability handling. Vellaci ingests CycloneDX 1.2–1.6 and exports CycloneDX VEX.

Reference: OWASP CycloneDX specification; ECMA-424 · Regulation (EU) 2024/2847 on EUR-Lex

Updated 2026-09-26 · Paraphrase for orientation, not legal advice.

In practice

Related terms

See the term as a workflow.

Vellaci turns each of these definitions into a record with an owner, a timestamp and evidence.