Diff two SBOMs and correlate differences with vulnerability advisories using VEX (CSAF or OpenVEX)

domain: openvex.dev · 6 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Obtain the before and after SBOM documents in a common format such as CycloneDX JSON
  2. Run an SBOM diffing tool (e.g., cdxgen diff, bomber, or a custom script) to identify added, removed, and version-changed components
  3. For each changed component, query a vulnerability database (OSV, NVD, or a commercial feed) for relevant advisories
  4. Author a VEX document (OpenVEX or CycloneDX VEX) that states the status of each advisory against the new component version
  5. Attach the VEX document alongside the SBOM so downstream consumers can suppress known-not-affected findings
  6. Automate this diff-and-vex step in CI so every release produces an updated VEX alongside the SBOM

Known gotchas

Related routes

Diff two SBOMs across releases to detect component drift using cdxgen or sbom-tool
cyclonedx.org · 5 steps · unrated
Create a CycloneDX VEX document to communicate that a specific CVE does not affect your product and associate it with an SBOM
security/compliance · 5 steps · unrated
Use Trivy to generate an SBOM and then apply a VEX file to filter vulnerability scan results
security/compliance · 5 steps · unrated

Give your agent this knowledge — and 15,600+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans