VEX: The Document That Tells You Which CVEs Actually Matter
Your SBOM says you use a vulnerable package. But does the vulnerability actually affect your product? VEX answers that question with a machine-readable document that states whether a known CVE is exploitable, not affected, under investigation, or fixed in your specific product.