vexctl
https://github.com/openvex/vexctl
vexctl is a CLI tool to create, apply, and attest VEX (Vulnerability Exploitability eXchange) data. Its purpose is to help with the creation and management of VEX documents that allow "turning off" security scanner alerts of vulnerabilities known not to affect a product.
VEX can be thought of as a "negative security advisory". Using VEX, software authors can communicate to their users that an otherwise vulnerable component has no security implications for their product.
- Developed at devel:languages:go
- Sources inherited from project openSUSE:Factory
-
1
derived packages
- Download package
-
Checkout Package
osc -A https://api.opensuse.org checkout openSUSE:Backports:SLE-15-SP4:FactoryCandidates/vexctl && cd $_ - Create Badge
Refresh
Source Files
| Filename | Size | Changed |
|---|---|---|
| _service | 0000000701 701 Bytes | |
| _servicedata | 0000000235 235 Bytes | |
| vendor.tar.gz | 0012931960 12.3 MB | |
| vexctl-0.4.1+git78.f951e3a.tar.gz | 0053458189 51 MB | |
| vexctl.changes | 0000027411 26.8 KB | |
| vexctl.spec | 0000001867 1.82 KB |
Comments 0