Skip to content

Create a VEX file for Node.js #1517

Description

@marco-ippolito

Info on vex https://cyclonedx.org/capabilities/vex/
I was thinking that a lot of companies find CVEs in the Node.js distribution that do not actually apply to Node.js:
There is a long list of them in https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues but recently I came across the NPM one on Node v20.
Since we have a list of valid vulns https://github.com/nodejs/security-wg/tree/main/vuln it would be trivial to
generate a vex file, and whenever we get a report of a CVE in the Node.js dependencies that we don't think it is valid we can just include it in the vex file, so we avoid getting requested about it, and companies are happy because they are compliant.
Whenever we do a security release we have to update the vex file, this can be done with an automation.
@nodejs/security-wg wdyt?

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions