Skip to content
#

openvex

Here are 25 public repositories matching this topic...

Deterministic, reachability-aware software composition analysis (SCA) engine — lockfile-first resolution, function- & cross-package reachability, patch-diff symbol mining, EPSS/KEV, SARIF + OpenVEX. Zero runtime dependencies.

  • Updated Jun 11, 2026
  • Python

Vulnerability scanner whose every result is a reproducible, signed claim. Pins the lockfile, the OSV feed, the version comparators, and the exclusions to four digests inside a signed in-toto predicate, so anyone can replay a scan byte for byte, or get a diff naming exactly which input moved.

  • Updated Sep 4, 2026
  • TypeScript

Ultra-fast open-source code security scanner. Finds vulnerabilities across 8 languages (Rust, Go, Python, JS, TS, Java, C, C++) using SAST + taint analysis + LLM verification — fewer false positives, faster audits. Outputs Sigstore-signed SARIF, SBOM, and OpenVEX bundles for supply-chain compliance.

  • Updated Sep 21, 2026
  • C++

The EU Cyber Resilience Act chain, end to end and offline: SBOM, VEX, vulnerability scan, Article 14 reporting, signed updates, and an Annex VII pack that prints its own gaps first. Awareness cannot be backdated once anything is filed, and a dismissal cannot remove a legal deadline.

  • Updated Aug 21, 2026
  • Python

Add this topic to your repo

To associate your repository with the openvex topic, visit your repo's landing page and select "manage topics."

Learn more