home.social

#openvex — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #openvex, aggregated by home.social.

  1. OpenVEX в CI/CD: как перестать бороться с ложными CVE и научить Trivy понимать контекст

    Представьте: вы пытаетесь объяснить иностранцу, почему красный сигнал светофора не всегда означает «стоять», иногда это — «можно ехать, если ты — скорая помощь». Примерно так до недавнего времени выглядело наше общение с Trivy. Сканер находил уязвимости, DefectDojo их послушно складировал. А мы каждый раз вручную разбирали кучу тикетов, отделяя реальные угрозы от ложных срабатываний. Особенно болезненно это ощущалось во время подготовки релиза, когда каждая минута на счету. Проблема была не в инструментах — они исправно работали и возвращали отчеты о найденных уязвимостях — а в отсутствии «взаимопонимания». Нужно было как-то намекнуть Trivy, что конкретная уязвимость не эксплуатируется в нашем контексте, ее следует пометить как 'not_affected' и больше не отвлекать нас. Таким «мостиком» стал для нас OpenVEX. Меня зовут Роман Корчагин, я занимаюсь процессами безопасной разработки в контейнерной платформе «Штурвал». В статье расскажу, как мы интегрировали генерацию VEX-файлов в пайплайн, и почему разработчики больше не вздрагивают при слове «сканирование».

    habr.com/ru/companies/chislite

    #openvex #open_source #штурвал #kubernetes #trivy #сканирование #vex #уязвимости #безопасность_контейнеров

  2. 🌟 OpenSSF Project Spotlight: #OpenVEX

    Adolfo Veytia walks us through how OpenVEX helps developers clearly communicate which vulnerabilities actually impact their software - and which don’t.

    youtu.be/dGOiWFNKKpM?si=SJIpCx

  3. 🌟 OpenSSF Project Spotlight: #OpenVEX

    Adolfo Veytia walks us through how OpenVEX helps developers clearly communicate which vulnerabilities actually impact their software - and which don’t.

    youtu.be/dGOiWFNKKpM?si=SJIpCx

  4. I'm about to present how to generate #OpenVEX data from #SBOM the hard and the easy way at #OSSummit. There will be fast cars, car crashes and lots of bad stock photos!

    Come and have fun with me and @wolfi at 3:55 pm, room 0C.

  5. I'm about to present how to generate #OpenVEX data from #SBOM the hard and the easy way at #OSSummit. There will be fast cars, car crashes and lots of bad stock photos!

    Come and have fun with me and @wolfi at 3:55 pm, room 0C.

  6. SBOM alone may not encode enough detail to separate non-exploitable vulnerabilities from exploitable ones writes Surendra Pathak in our latest guest blog on #VDR, #VEX, #OpenVEX and #CSAF openssf.org/blog/2023/09/07/vd

  7. SBOM alone may not encode enough detail to separate non-exploitable vulnerabilities from exploitable ones writes Surendra Pathak in our latest guest blog on #VDR, #VEX, #OpenVEX and #CSAF openssf.org/blog/2023/09/07/vd

  8. At the heart of the CVE process and the matching done with the NVD database is the name of the manufacturer and the artefact - the software, system, library or mobile application. It's vital for this to work that the name in the #SBOM is correct to make the match work. The community has developed #PURL - package URL - to improve but so far the CVE/NVD eco system has not adopted PURL.

    This needs to be fixed to make sure that the name in the SBOM matches the right set of vulnerabilities.

    #SBOM #securesupplychain #CycloneDX #OpenVEX #VEX #OpenSource

  9. At the heart of the CVE process and the matching done with the NVD database is the name of the manufacturer and the artefact - the software, system, library or mobile application. It's vital for this to work that the name in the #SBOM is correct to make the match work. The community has developed #PURL - package URL - to improve but so far the CVE/NVD eco system has not adopted PURL.

    This needs to be fixed to make sure that the name in the SBOM matches the right set of vulnerabilities.

    #SBOM #securesupplychain #CycloneDX #OpenVEX #VEX #OpenSource