-
-
Notifications
You must be signed in to change notification settings - Fork 18
Description
I would like to import existing VEX documents. This would mean being able to read either at least one of a CSAF or CycloneDX VEX (and later cover all three types with CSAF, CDX and OpenVEX) in the context of a product and apply the exploitability to the Packages of that Product. This could be done through ScanCode.io if need be and appropriate too.
This could instead of doing a DejaCode integration with ERP and business systems which has proven to be harzardous and essentially impossible in the current state of FOSS business tools
As noted in:
In hindsight, these integrations look like either difficult, hard or impossible to achieve in a generic way. We should instead repurpose these towards another useful integration.
Originally posted by @pombredanne in #353
Metadata
Metadata
Assignees
Labels
Type
Projects
Status