Results

Why is VEX generation tied to Delivery Reports?

Updated 2025-01-17 SBOM Central

The purpose of VEX reports is to disclose the security status for selected products and maybe also for selected customers.

An SBOM is a general content representation for a product. The security status can vary between different types of use and customers, which means that individual use cases with separate security analyzes may require separate VEX reports, see also What are the use cases for duplicating an SBOM?

To tie the VEX to a Delivery report is a way to organize and track separate security disclosures.