<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>VEX on</title><link>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/tags/vex/</link><description>Recent content in VEX on</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><copyright>Copyright (c) 2023 Chainguard</copyright><lastBuildDate>Mon, 30 Jan 2023 15:21:01 +0200</lastBuildDate><atom:link href="https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/tags/vex/index.xml" rel="self" type="application/rss+xml"/><item><title>Getting started with OpenVEX and vexctl</title><link>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/open-source/sbom/getting-started-openvex-vexctl/</link><pubDate>Mon, 30 Jan 2023 15:21:01 +0200</pubDate><guid>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/open-source/sbom/getting-started-openvex-vexctl/</guid><description>&lt;p&gt;The &lt;code&gt;vexctl&lt;/code&gt; CLI is a tool to make VEX work. As part of the open source &lt;a href="https://www.chainguard.dev/supply-chain-security-101/what-is-openvex"&gt;OpenVex&lt;/a&gt; project, &lt;code&gt;vexctl&lt;/code&gt; enables you to create, apply, and attest VEX (Vulnerability Exploitability eXchange) data in order to filter out false positive security alerts.&lt;/p&gt;
&lt;p&gt;The &lt;code&gt;vexctl&lt;/code&gt; tool was built to help with the creation and management of VEX documents, communicate transparently to users as time progresses, and enable the &amp;ldquo;turning off&amp;rdquo; of security scanner alerts of vulnerabilities known not to affect a given product. Using VEX, software authors can communicate to their users that an otherwise vulnerable component has no security implications for their product.&lt;/p&gt;</description></item></channel></rss>