Skip to content

CRAVEX-Integration: VEX document import - Design and implement CycloneDX VEX import #438

@pombredanne

Description

@pombredanne

I would like to import existing VEX documents. This would mean being able to read either at least one of a CSAF or CycloneDX VEX (and later cover all three types with CSAF, CDX and OpenVEX) in the context of a product and apply the exploitability to the Packages of that Product. This could be done through ScanCode.io if need be and appropriate too.

This could instead of doing a DejaCode integration with ERP and business systems which has proven to be harzardous and essentially impossible in the current state of FOSS business tools

As noted in:

In hindsight, these integrations look like either difficult, hard or impossible to achieve in a generic way. We should instead repurpose these towards another useful integration.

Originally posted by @pombredanne in #353

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Type

No type

Projects

Status

Done

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions