We have hosted the application secpod vex in order to run this application in our online workstations with Wine or directly.
Quick description about secpod vex:
Features:
- One-command assessment. The assess command runs the full workflow (SBOM generation, CVE scanning, guided triage, and VEX publishing) from a single package PURL or project directory.
- CWE-guided questionnaires. For each CVE, it looks up the CWE type and asks 2 to 4 targeted yes/no questions (for example, deserialization reachability for CWE-502, or XSS rendering for CWE-79). Answers map deterministically to a VEX status and justification code. This questionnaire engine is described as the core IP.
- Automatic CVE discovery. Scans against OSV.dev and GitHub Security Advisories (GHSA), covering PyPI, npm, Maven, Go, crates.io, NuGet, and more. No API keys required.
- SBOM generation and parsing. Builds CycloneDX SBOMs from a Python env, requirements file, or PURL list, and parses both CycloneDX and SPDX JSON. Any language is supported via Syft.
- Auto-suggested upgrade paths. Semver-aware remediation suggestions.
- Auditable output. VEX documents are named after the package (e.g. log4j-core-2.14.1.openvex.json), timestamped, and include a full decision audit trail of questions and answers.
- Resumable triage. Progress saves as you go, so Ctrl+C never loses work. Resume with vex-studio triage.
- VEX Hub-compatible publishing. Outputs to Aqua VEX Hub directory layout, which Trivy consumes automatically to suppress false positives for all downstream users.
- OpenVEX 0.2.0 output in Phase 1, with CSAF 2.0 and CycloneDX VEX planned for Phase 2.
.
©2024. Winfy. All Rights Reserved.
By OD Group OU – Registry code: 1609791 -VAT number: EE102345621.