Skip to content

Add support for cyclonedx 1.4 and VEX  #591

@sambhav

Description

@sambhav

What would you like to be added: CycloneDX 1.4 was released with added support for a common vulnerability exchange format.

It would be great if grype could output its vulnerability reports in this format. This could also be helpful down the road as a standardized format to attach vulnerability data as intoto attestations.

Why is this needed: This provides a well defined standard to output and parse vulnerability information. syft already supports Cyclonedx SBOMs and this could be a great counterpart for grype.

Additional context:

More details at

https://cyclonedx.org/capabilities/vex/

https://github.com/CycloneDX/sbom-examples/blob/master/VEX/vex.json

Metadata

Metadata

Assignees

Labels

enhancementNew feature or requestformat:cyclonedxCycloneDX related enhancement or bug

Type

No type

Projects

Status

Done

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions