Skip to main content

Lib4VEX

Lib4VEX is a library to parse and generate VEX documents. It supports VEX documents created in the OpenVEX, CycloneDX or CSAF specifications.

It has been developed on the assumption that having a generic abstraction of vulnerability regardless of the underlying format will be useful to developers.

The following facilities are provided:

  • Generate OpenVEX, CycloneDX and CSAF VEX documents in JSON format
  • Parse CycloneDX SBOM in JSON format and extract vulnerability information
  • Parse OpenVEX and CSAF documents to extract vulnerability information
  • Generated VEX document can be output to a file or to the console

Installation

To install use the following command:

pip install lib4vex

Alternatively, just clone the repo and install dependencies using the following command:

pip install -U -r requirements.txt

The tool requires Python 3 (3.8+). It is recommended to use a virtual python environment especially if you are using different versions of python. virtualenv is a tool for setting up virtual python environments which allows you to have all the dependencies for the tool set up in a single environment, or have different environments set up for testing using different versions of Python.

API

Metadata

Product

Vulnerability

Debug

Creating the environment variable LIB4VEX_DEBUG will result in some additional information being reported when a VEX document is being generated.

Examples

A number of example scripts are included in the examples subdirectory. Examples are provided for CSAF, CycloneDX and OpenVEX scenarios.

Tutorial

A tutorial showing a lifecycle of vulnerabilities is available. Whilst the tutorial uses CSAF as the VEX document, equivalent steps can be performed for producing a VEX document using CycloneDX or OpenVEX.

Implementation Notes

The following design decisions have been made in creating and processing VEX files:

  1. VEXes should be produced with reference to an SBOM so that only vulnerabilities for components included in the SBOM are included in the VEX document.

  2. The VEX document contains all reported vulnerabilities and the respective status. The latest VEX is indicated by the latest timestamp. The previous VEX documents are retained for audit purposes.

  3. The VEX document is intended to be used for a single product.

Future Development

  1. Add support for SPDX Security profile when released as part of the SPDX 3.0 release.

License

Licensed under the Apache 2.0 Licence.

Limitations

This library is meant to support software development. The usefulness of the library is dependent on the data which is provided. Unfortunately, the library is unable to determine the validity or completeness of such a VEX file; users of the library and the resulting VEX file are therefore reminded that they should assert the quality of any data which is provided to the library.

Feedback and Contributions

Bugs and feature requests can be made via GitHub Issues.

Metadata

Release files for lib4vex 0.2.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Built distribution (wheel)

Table of built distributions (wheels) for lib4vex 0.2.3
File Interpreter ABI Platform
lib4vex-0.2.3-py3-none-any.whl Python 3 none any Details

Release files / lib4vex-0.2.3-py3-none-any.whl

Download URL lib4vex-0.2.3-py3-none-any.whl
Size 23.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
1943d58c3fb2e2638338572e9b20ec4f801afd506818ea8e6e6aa3f3b27752de
BLAKE2b-256 checksum
How to use checksums
34f64e8c9911536e14250eb82345f166e3e6f8a0f1edad424ad823ba1f060d62
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.10.8

Release history Release notifications | RSS feed

This release

0.2.3 This release

1 release file

0.2.2

1 release file

0.2.1

1 release file

0.2.0

1 release file

0.1.0

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page