buildsafedev / bsf

Developer-centric tool to secure your software supply chain.
https://buildsafe.dev
Apache License 2.0
72 stars 13 forks source link

Generate VEX docs for pkgs #101

Open dr-housemd opened 4 months ago

dr-housemd commented 4 months ago

Certain packages have CVEs whose score is higher than it needs to be or isn't a valid CVE for the package. Industry's effort to fix this is VEX documents. This will help eliminate false positives. Common ways VEX docs can be found are-