-
Notifications
You must be signed in to change notification settings - Fork 724
Closed
Labels
enhancementNew feature or requestNew feature or requestformat:cyclonedxCycloneDX related enhancement or bugCycloneDX related enhancement or bug
Description
What would you like to be added: CycloneDX 1.4 was released with added support for a common vulnerability exchange format.
It would be great if grype could output its vulnerability reports in this format. This could also be helpful down the road as a standardized format to attach vulnerability data as intoto attestations.
Why is this needed: This provides a well defined standard to output and parse vulnerability information. syft already supports Cyclonedx SBOMs and this could be a great counterpart for grype.
Additional context:
More details athttps://cyclonedx.org/capabilities/vex/
https://github.com/CycloneDX/sbom-examples/blob/master/VEX/vex.json
VinodAnandan, stevespringett, wagoodman, damiencarol, luhring and 2 more
Metadata
Metadata
Assignees
Labels
enhancementNew feature or requestNew feature or requestformat:cyclonedxCycloneDX related enhancement or bugCycloneDX related enhancement or bug
Type
Projects
Status
Done