vex

Referensi spesifikasi OpenVEX v0.2.0 ditambah buku pedoman manajemen VEX - Disajikan oleh microsoft/hve-core.

npx skills add https://github.com/microsoft/hve-core --skill vex

VEX skill

This skill is the entrypoint for VEX operations in hve-core. It combines the OpenVEX v0.2.0 specification reference with reusable management playbooks for implementing, reviewing, and validating VEX documents. The normative reference material below remains the authoritative source for schema, status logic, and public-source guidance.

VEX management playbooks

Detection, drafting, and attestation are workflow-owned automation. This skill supplies the reusable procedures, mutation rules, and review criteria. The CVE Analyzer subagent performs the per-CVE exploitability analysis that feeds those workflows.

Implement VEX in a target project

Use this playbook when standing up VEX in a target project. Scaffold the VEX document under security/vex, wire the vex-detect and vex-draft workflows, reference the PR-body scaffold in assets/pr-body-scaffold.yml, connect the dedicated reusable VEX attestation workflow for provenance and OpenVEX-over-SBOM attestation, and set CODEOWNERS on the VEX document. Use references/vex-status-logic.md and the vex-standards.instructions.md instructions for the detailed rules.

Review and validate VEX

Use this playbook when reviewing drafted VEX statements. Assess the status determination against the evidence and confidence bands, honor the document mutation and forbidden-transition contract, and validate the release attestation output. Attestation generation is owned by the dedicated reusable VEX attestation workflow, not by the reviewer. The forthcoming tested gate module and tests will live in this skill so the workflow and interactive entry points can share the same rules.

VEX statuses

StatusMeaning
not_affectedThe vulnerability is not exploitable in this product. Requires a justification or impact_statement.
affectedThe vulnerability is exploitable. Requires an action_statement describing remediation.
fixedThe vulnerability was present but has been remediated in this product version.
under_investigationThe author is evaluating whether the vulnerability affects this product. Safe default for uncertain cases.

Justification codes for not_affected

When a statement uses not_affected status, it must include a machine-readable justification:

CodeMeaning
component_not_presentThe vulnerable component is not included in the product.
vulnerable_code_not_presentThe component is present but the vulnerable code is not included.
vulnerable_code_not_in_execute_pathThe vulnerable code is present but cannot be reached at runtime.
vulnerable_code_cannot_be_controlled_by_adversaryThe code is reachable but an attacker cannot influence the inputs.
inline_mitigations_already_existExisting controls prevent exploitation of the vulnerability.

Product identifiers

Products use Package URL (PURL) format (for example, pkg:npm/@microsoft/hve-core@3.10.0).

Normative references

  1. OpenVEX JSON Schema Reference: field definitions, required versus optional fields, and example documents.
  2. VEX Status Logic: status determination decision tree, evidence requirements per status, and forbidden transitions.
  3. CVE Data Sources: OSV.dev, NVD, and GitHub Advisory Database API references with licensing posture.

Skill layout

  • SKILL.md: this file (skill entrypoint).
  • references/: normative reference documents.
    • openvex-schema.md: JSON schema reference with field definitions and examples.
    • vex-status-logic.md: status determination decision tree and forbidden transitions.
    • cve-data-sources.md: CVE data source API references and licensing.

Attribution and licensing

The OpenVEX specification reference content in this skill is derived from the OpenVEX Community specification and remains attributed to the OpenVEX Community. The reusable VEX management playbooks and the surrounding guidance in this skill are hve-core-authored content.

Licenses are allocated per file in the table below. The frontmatter expression is the conjunction of every license present in the package, so a redistributor of the whole package complies with all of them; the table states which license actually governs each file.

PathLicenseOrigin
references/openvex-schema.mdApache-2.0Derived from OpenVEX spec
references/vex-status-logic.mdApache-2.0Derived from OpenVEX spec
references/cve-data-sources.mdCC-BY-4.0hve-core-authored
SKILL.md, playbooks, and remaining package contentCC-BY-4.0hve-core-authored

Third-Party Attribution

AttributeValue
SpecificationOpenVEX Specification v0.2.0
Copyright© OpenVEX Contributors
LicenseApache License 2.0
Sourcehttps://github.com/openvex/spec/blob/main/OPENVEX-SPEC.md
ModificationsSpecification restructured into agent-consumable reference documents with added status determination logic, evidence requirements, and CVE data source guidance.

Lebih banyak skill dari microsoft

oss-growth
microsoft
Persona peretas pertumbuhan OSS
agent-framework-azure-ai-py
microsoft
Bangun agen Azure AI Foundry menggunakan Microsoft Agent Framework Python SDK (agent-framework-azure-ai). Gunakan saat membuat agen persisten dengan AzureAIAgentsProvider, menggunakan alat yang dihosting (code interpreter, file search, web search), mengintegrasikan server MCP, mengelola utas percakapan, atau mengimplementasikan respons streaming. Mencakup alat fungsi, keluaran terstruktur, dan agen multi-alat.
development
airunway-aks-setup
microsoft
Siapkan AI Runway di AKS — dari klaster kosong hingga model berjalan. Mencakup verifikasi klaster, instalasi controller, penilaian GPU, penyiapan penyedia, dan deployment pertama. KAPAN: "setup AI Runway", "onboard AKS cluster", "install AI Runway", "airunway setup", "deploy model to AKS", "GPU inference on AKS", "KAITO setup on AKS", "run LLM on AKS", "vLLM on AKS", "set up model serving on AKS", "AI Runway controller".
devops
appinsights-instrumentation
microsoft
Panduan untuk instrumentasi aplikasi web dengan Azure Application Insights. Menyediakan pola telemetri, pengaturan SDK, dan referensi konfigurasi. KAPAN: cara menginstrumentasi aplikasi, SDK App Insights, pola telemetri, apa itu App Insights, panduan Application Insights, contoh instrumentasi, praktik terbaik APM.
devops
applicationinsights-web-ts
microsoft
Instrumentasi aplikasi browser/web dengan Application Insights JavaScript SDK (@microsoft/applicationinsights-web). Digunakan untuk Real User Monitoring (RUM) — tampilan halaman, klik, dependensi AJAX/fetch, pengecualian, peristiwa kustom, dan jejak agen GenAI sisi browser yang dikorelasikan dengan jejak OpenTelemetry backend. Mencakup pengaturan SDK Loader Script dan npm, ekstensi kerangka kerja (React, React Native, Angular), Click Analytics, inisialisasi telemetri, dan konvensi semantik OTel GenAI untuk span agen/alat/model yang dipancarkan dari browser.
devops
azure-ai-anomalydetector-java
microsoft
Bangun aplikasi deteksi anomali dengan Azure AI Anomaly Detector SDK untuk Java. Gunakan saat mengimplementasikan deteksi anomali univariat/multivariat, analisis deret waktu, atau pemantauan bertenaga AI.
development
azure-ai-language-conversations-py
microsoft
Implementasikan Pemahaman Bahasa Percakapan (CLU) menggunakan SDK Python azure-ai-language-conversations. Gunakan saat bekerja dengan ConversationAnalysisClient untuk menganalisis maksud dan entitas percakapan, membangun fitur NLP, atau mengintegrasikan pemahaman bahasa ke dalam aplikasi.
development
azure-ai-ml-py
microsoft
Azure Machine Learning SDK v2 untuk Python. Gunakan untuk ruang kerja ML, pekerjaan, model, kumpulan data, komputasi, dan pipeline. Pemicu: "azure-ai-ml", "MLClient", "ruang kerja", "registri model", "pekerjaan pelatihan", "kumpulan data".
development