Skip to content

CRAVEX-Integration: import VEX statements #438

@pombredanne

Description

@pombredanne

I would like to import existing VEX documents. This would mean being able to read either at least one of a CSAF or CycloneDX VEX (and later cover all three types with CSAF, CDX and OpenVEX) in the context of a product and apply the exploitability to the Packages of that Product. This could be done through ScanCode.io if need be and appropriate too.

This could instead of doing a DejaCode integration with ERP and business systems which has proven to be harzardous and essentially impossible in the current state of FOSS business tools

As noted in:

In hindsight, these integrations look like either difficult, hard or impossible to achieve in a generic way. We should instead repurpose these towards another useful integration.

Originally posted by @pombredanne in #353

Metadata

Metadata

Assignees

Labels

design neededDesign details needed to complete the issueenhancementNew feature or request

Type

No type

Projects

Status

Needs prep

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions