Skip to content

SBOM/VEX info update#572

Draft
sboldyreva wants to merge 3 commits into
cloudlinux:masterfrom
sboldyreva:claude/fervent-ritchie-yuTez
Draft

SBOM/VEX info update#572
sboldyreva wants to merge 3 commits into
cloudlinux:masterfrom
sboldyreva:claude/fervent-ritchie-yuTez

Conversation

@sboldyreva

Copy link
Copy Markdown
Collaborator

No description provided.

claude added 2 commits May 28, 2026 15:39
Move VEX detail out of the SBOM bullet into a dedicated section, and
reflect the actual two-state model (exploitable / resolved) TuxCare
publishes — replacing the standard CycloneDX four-state list that was
copy-pasted on these pages but doesn't match what is in our feeds.

- securechain, els-for-libraries: rewrite VEX section with feed
  lifecycle, status values, recommendation to filter to the latest
  -tuxcare.N iteration, and the per-language feed URLs
- els-for-applications, els-for-runtimes: replace the VEX text in the
  Enhanced Metadata bullet with a short VEX-specific bullet pointing
  to the public feed

ELSDOC-167, ELSDOC-288

https://claude.ai/code/session_01JrcTq4ouwM9DoNyZFssyb2
…ullets

Move SBOM/VEX detail off the product overview pages into dedicated
Machine-Readable Security Data pages, and reword the Transparency &
Visibility bullets so they describe the bundle without baking in
specifics that drift out of date.

- New pages under Resources for SecureChain, ELS for Libraries, and
  ELS for Open-Source Applications, each with format/state/feed
  detail and the per-ecosystem links that previously lived only on
  individual product pages.
- Libraries page gathers per-ecosystem VEX/SBOM feeds for Java,
  Python, JavaScript, PHP, and .NET. Applications page covers the
  Java apps (Tomcat, Hadoop, Hive, Gradle, Maven); other application
  ecosystems flagged as expanding. SecureChain points at the general
  VEX feed; SBOM listed as coming soon.
- Sidebar updated to list the new pages under Resources for all
  three sections.
- Runtimes Transparency bullet points to the existing CSAF-based
  machine-readable-security-data page rather than the CycloneDX VEX
  index, since runtimes publish VEX through CSAF.

ELSDOC-167, ELSDOC-288

https://claude.ai/code/session_01JrcTq4ouwM9DoNyZFssyb2
@sboldyreva sboldyreva changed the title Claude/fervent ritchie yu tez SBOM/VEX info update Jun 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants