<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>VEX on</title><link>https://deploy-preview-3155--ornate-narwhal-088216.netlify.app/tags/vex/</link><description>Recent content in VEX on</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><lastBuildDate>Tue, 31 Jan 2023 15:21:01 +0200</lastBuildDate><atom:link href="https://deploy-preview-3155--ornate-narwhal-088216.netlify.app/tags/vex/index.xml" rel="self" type="application/rss+xml"/><item><title>Getting Started with OpenVEX and vexctl</title><link>https://deploy-preview-3155--ornate-narwhal-088216.netlify.app/open-source/sbom/getting-started-openvex-vexctl/</link><pubDate>Mon, 30 Jan 2023 15:21:01 +0200</pubDate><guid>https://deploy-preview-3155--ornate-narwhal-088216.netlify.app/open-source/sbom/getting-started-openvex-vexctl/</guid><description>The vexctl CLI is a tool to make VEX work. As part of the open source OpenVex project, vexctl enables you to create, apply, and attest VEX (Vulnerability Exploitability eXchange) data in order to filter out false positive security alerts.
The vexctl tool was built to help with the creation and management of VEX documents, communicate transparently to users as time progresses, and enable the &amp;ldquo;turning off&amp;rdquo; of security scanner alerts of vulnerabilities known not to affect a given product.</description></item><item><title>What is OpenVex?</title><link>https://deploy-preview-3155--ornate-narwhal-088216.netlify.app/open-source/sbom/what-is-openvex/</link><pubDate>Tue, 31 Jan 2023 15:21:01 +0200</pubDate><guid>https://deploy-preview-3155--ornate-narwhal-088216.netlify.app/open-source/sbom/what-is-openvex/</guid><description>OpenVEX is an open source specification, library, and suite of tools designed to enable software users to eliminate vulnerability noise and focus their security efforts on vulnerabilities that pose an immediate risk. Released by Chainguard in January 2023, it’s the first set of open source tools to support the VEX specification championed by the United States National Telecommunications and Information Administration (NTIA) and the Cybersecurity and Infrastructure Security Agency (CISA).</description></item></channel></rss>