vdb_vex
Filter a project's vulnerability scan by tracing which advisories are reachable via attacker-controlled data. Provide a source directory and lockfile to generate an OpenVEX document and shareable URL, prioritizing findings for triage.
Instructions
Given a project directory and its lockfile, work out which of its known advisories can actually be reached by attacker-controlled data, and return an OpenVEX document plus a shareable URL. Use this when a scan produced more findings than anyone can triage. Point path at the SOURCE TREE, not one file: a not_affected determination is only as wide as the code behind it, and a single-file run withholds them all. Reachability is decided at package granularity from static summaries — good for triage order, not proof of non-exploitability.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| path | Yes | Project source directory. | |
| manifest_path | Yes | Resolved lockfile for the same project. |