nyph-infosec / daggerboard

MIT License
95 stars 19 forks source link

Output VEX documents? #15

Closed nishakm closed 1 year ago

nishakm commented 1 year ago

Could daggerboard generate VEX documents like the CSAF or CycloneDX documents?

namtarb commented 1 year ago

As of now, Daggerboard is on the ingestion side of the SBOM pipeline - meaning that it was only intended to ingest and analyze SBOMs and, in the future, VEX documents. Daggerboard does not currently support VEX ingestion, but this is on the list of features to add in the next phase of the project.

There is a list of tools for generating VEX documents here: https://cyclonedx.org/tool-center/