You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: docs/vex-beta.md
+15-3Lines changed: 15 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,6 +1,6 @@
1
1
# CSAF VEX-Beta Release
2
2
3
-
## VEX-Beta Announcement
3
+
## VEX-Beta Announcement
4
4
5
5
Red Hat Product Security is pleased to share that the Beta version of our new VEX (Vulnerability Exploit eXchange) files is now available [here](https://security.access.redhat.com/data/csaf/v2/vex-feed/).
6
6
@@ -17,17 +17,29 @@ This update focuses on data precision and standardizing our CSAF VEX format. Key
17
17
18
18
More detailed information on the differences between legacy VEX files and Beta VEX files will be found [here](https://redhatproductsecurity.github.io/security-data-guidelines/vex-beta-details/).
| Product Tree Deduplication | Blocker | VEX files now contain cleaner, deduplicated product trees. Scanners see fewer ambiguous or repeated product entries per CVE |
26
+
| Identifier Fidelity (CPE, PURL, CWE) | Blocker | More accurate CPEs, PURLs, and CWEs. Fewer edge cases where a scanner cannot match the VEX identifier to an installed component |
27
+
| Coverage and Reliability | Critical | More CVEs generating valid VEX files. The current 98.9% success rate is primarily driven by these fixes |
28
+
| Data Integrity and Confidentiality | Blocker | Partners can trust that no embargoed or pre-disclosure data leaks into the feed, and container VEX entries are correctly structured |
29
+
| Data Quality Investigation | Critical | Enabled resolution of multiple Blocker issues |
30
+
31
+
20
32
### Beta Limitations & Known Issues
21
33
22
34
As we perform final data cleanup and address some remaining functionality, you may notice daily fluctuations in file content. Please be aware of the following known issues:
23
35
24
-
-**Binary RPMs**: Currently unavailable for unfixed items. Product Security is working to address this as soon as possible.
36
+
-**Binary RPMs**: Only availble for some vulnerabilities. Product Security is working to address this as soon as possible.
25
37
-**Legacy Data**: Some older CVEs may display inaccurate CPEs (e.g., RHEL 7 transitioning from mainstream to EUS CPEs).
26
38
-**Scope**: Middleware remains out of scope for this project phase. Some middleware products will be included in the GA phase as data becomes available.
27
39
28
40
### Short Term Adoption Timeline
29
41
30
-
-**GA VEX (Red Hat Summit)**: Upon GA, legacy VEX files will be deprecated. No further enhancements will be made to legacy files, though they will remain published in the existing location for a transition period based on vendor adoption.
42
+
-**GA VEX (Red Hat Summit)**: VEX files will officially be released as GA on May 8th, 2026. Upon GA, legacy VEX files will be deprecated. No further enhancements will be made to legacy files, though they will remain published in the existing location for a transition period based on vendor adoption.
0 commit comments