Skip to content

Commit 6cf34ba

Browse files
authored
Merge pull request #88 from RedHatProductSecurity/vex-beta
Include Bug Fix Information for Beta
2 parents d8cee7d + 61d0584 commit 6cf34ba

1 file changed

Lines changed: 15 additions & 3 deletions

File tree

docs/vex-beta.md

Lines changed: 15 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
# CSAF VEX-Beta Release
22

3-
## VEX-Beta Announcement
3+
## VEX-Beta Announcement
44

55
Red Hat Product Security is pleased to share that the Beta version of our new VEX (Vulnerability Exploit eXchange) files is now available [here](https://security.access.redhat.com/data/csaf/v2/vex-feed/).
66

@@ -17,17 +17,29 @@ This update focuses on data precision and standardizing our CSAF VEX format. Key
1717

1818
More detailed information on the differences between legacy VEX files and Beta VEX files will be found [here](https://redhatproductsecurity.github.io/security-data-guidelines/vex-beta-details/).
1919

20+
### Bugs Fixed in Beta Release
21+
22+
23+
| Area | Priority | Impact |
24+
| ------------------------------------ | -------- | ----------------------------------------------------------------------------------------------------------------------------------- |
25+
| Product Tree Deduplication | Blocker | VEX files now contain cleaner, deduplicated product trees. Scanners see fewer ambiguous or repeated product entries per CVE |
26+
| Identifier Fidelity (CPE, PURL, CWE) | Blocker | More accurate CPEs, PURLs, and CWEs. Fewer edge cases where a scanner cannot match the VEX identifier to an installed component |
27+
| Coverage and Reliability | Critical | More CVEs generating valid VEX files. The current 98.9% success rate is primarily driven by these fixes |
28+
| Data Integrity and Confidentiality | Blocker | Partners can trust that no embargoed or pre-disclosure data leaks into the feed, and container VEX entries are correctly structured |
29+
| Data Quality Investigation | Critical | Enabled resolution of multiple Blocker issues |
30+
31+
2032
### Beta Limitations & Known Issues
2133

2234
As we perform final data cleanup and address some remaining functionality, you may notice daily fluctuations in file content. Please be aware of the following known issues:
2335

24-
- **Binary RPMs**: Currently unavailable for unfixed items. Product Security is working to address this as soon as possible.
36+
- **Binary RPMs**: Only availble for some vulnerabilities. Product Security is working to address this as soon as possible.
2537
- **Legacy Data**: Some older CVEs may display inaccurate CPEs (e.g., RHEL 7 transitioning from mainstream to EUS CPEs).
2638
- **Scope**: Middleware remains out of scope for this project phase. Some middleware products will be included in the GA phase as data becomes available.
2739

2840
### Short Term Adoption Timeline
2941

30-
- **GA VEX (Red Hat Summit)**: Upon GA, legacy VEX files will be deprecated. No further enhancements will be made to legacy files, though they will remain published in the existing location for a transition period based on vendor adoption.
42+
- **GA VEX (Red Hat Summit)**: VEX files will officially be released as GA on May 8th, 2026. Upon GA, legacy VEX files will be deprecated. No further enhancements will be made to legacy files, though they will remain published in the existing location for a transition period based on vendor adoption.
3143

3244
### Future Enhancements
3345

0 commit comments

Comments
 (0)