Skip to content

Provide VEX Documents for the Kubewarden stack #1241

@flavio

Description

@flavio

We currently don't have a process in place to create and distribute VEX Documents.

We've recently run into a security issue of one of our dependencies that caused our images to look vulnerable. However, we were not making use of the vulnerable bits of the library.

We ended up publishing a patch release of Policy Server and kwctl, plus a helm chart update. Our users then had to go through the "pain" of pulling a brand new image on their cluster.

It would have been great instead to just create a VEX document and mark the Policy Server image as not affected by it.

Acceptance Criteria

  • Define a location where the VEX Documents can be hosted
  • Ensure we are scraped by VEX HUB
  • Define a process a developer has to follow to write and publish a VEX document

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Status

    No status

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions