<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>VEX on</title><link>https://deploy-preview-3421--ornate-narwhal-088216.netlify.app/tags/vex/</link><description>Recent content in VEX on</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>Copyright (c) 2023 Chainguard</copyright><lastBuildDate>Tue, 31 Jan 2023 15:21:01 +0200</lastBuildDate><atom:link href="https://deploy-preview-3421--ornate-narwhal-088216.netlify.app/tags/vex/index.xml" rel="self" type="application/rss+xml"/><item><title>Getting Started with OpenVEX and vexctl</title><link>https://deploy-preview-3421--ornate-narwhal-088216.netlify.app/open-source/sbom/getting-started-openvex-vexctl/</link><pubDate>Mon, 30 Jan 2023 15:21:01 +0200</pubDate><guid>https://deploy-preview-3421--ornate-narwhal-088216.netlify.app/open-source/sbom/getting-started-openvex-vexctl/</guid><description>&lt;p&gt;The &lt;code&gt;vexctl&lt;/code&gt; CLI is a tool to make VEX work. As part of the open source &lt;a href="https://deploy-preview-3421--ornate-narwhal-088216.netlify.app/open-source/sbom/what-is-openvex/"&gt;OpenVex&lt;/a&gt; project, &lt;code&gt;vexctl&lt;/code&gt; enables you to create, apply, and attest VEX (Vulnerability Exploitability eXchange) data in order to filter out false positive security alerts.&lt;/p&gt;
&lt;p&gt;The &lt;code&gt;vexctl&lt;/code&gt; tool was built to help with the creation and management of VEX documents, communicate transparently to users as time progresses, and enable the &amp;ldquo;turning off&amp;rdquo; of security scanner alerts of vulnerabilities known not to affect a given product. Using VEX, software authors can communicate to their users that an otherwise vulnerable component has no security implications for their product.&lt;/p&gt;</description></item><item><title>What is OpenVex?</title><link>https://deploy-preview-3421--ornate-narwhal-088216.netlify.app/open-source/sbom/what-is-openvex/</link><pubDate>Tue, 31 Jan 2023 15:21:01 +0200</pubDate><guid>https://deploy-preview-3421--ornate-narwhal-088216.netlify.app/open-source/sbom/what-is-openvex/</guid><description>&lt;p&gt;&lt;a href="https://github.com/openvex"&gt;OpenVEX&lt;/a&gt; is an open source specification, library, and suite of tools designed to enable software users to eliminate vulnerability noise and focus their security efforts on vulnerabilities that pose an immediate risk. &lt;a href="https://www.chainguard.dev/unchained/accelerate-vex-adoption-through-openvex"&gt;Released by Chainguard in January 2023&lt;/a&gt;, it’s the first set of open source tools to support the VEX specification championed by the &lt;a href="https://ntia.gov/"&gt;United States National Telecommunications and Information Administration (NTIA)&lt;/a&gt; and the &lt;a href="https://www.cisa.gov/"&gt;Cybersecurity and Infrastructure Security Agency (CISA)&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;With OpenVEX, stakeholders from across the software supply chain can collaborate on identifying and remediating exploitable vulnerabilities and use automation to enable more precise and efficient methods of security management. In this guide, you will learn more about the emerging supply chain security standards that OpenVEX supports, as well as how OpenVEX tooling can help you leverage them in your security management processes.&lt;/p&gt;</description></item></channel></rss>