Create an OpenVEX statement to mark a CVE as not exploitable for a specific product

domain: openvex.dev · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Install the `vexctl` CLI from the OpenVEX project releases
  2. Run `vexctl create --author 'vendor@example.com' --product 'pkg:oci/myimage@sha256:...' --vuln CVE-YYYY-NNNNN --status not_affected --justification vulnerable_code_not_in_execute_path` to generate a VEX document
  3. Review the emitted JSON-LD document for correct `@context`, `product`, and `vulnerability` fields
  4. Sign the VEX document with cosign or embed it in the product SBOM's `vulnerabilities` array as a CycloneDX VEX component
  5. Publish the VEX document to a known URL and reference it from your security advisory or SBOM metadata

Known gotchas

Related routes

Create OpenVEX statements using vexctl to mark a CVE as not exploitable and merge VEX documents
security/compliance · 5 steps · unrated
Create a CycloneDX VEX document to communicate that a specific CVE does not affect your product and associate it with an SBOM
security/compliance · 5 steps · unrated
Diff two SBOMs and correlate differences with vulnerability advisories using VEX (CSAF or OpenVEX)
openvex.dev · 6 steps · unrated

Give your agent this knowledge — and 15,600+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans