> For the complete documentation index, see [llms.txt](https://breachtrace.gitbook.io/vulnkeeper/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://breachtrace.gitbook.io/vulnkeeper/chapter-e/12-12-sbom-package-identity-vex-and-advisory-exchange-standards.md).

# 12. SBOM, package identity, VEX & advisory exchange standards

## 12.1 SBOM standards

<table><thead><tr><th width="91.59375" align="right">Sl. #</th><th>Source Title</th><th>Notes</th></tr></thead><tbody><tr><td align="right">1</td><td><strong>CycloneDX specification overview</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://cyclonedx.org/specification/overview/">cyclonedx.org/specification/overview</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open standard</td><td><strong><code>Relevance</code>:</strong> SBOM, SaaSBOM, BOM, VEX, vulnerability &#x26; component metadata standard.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Good fit for vulnerability management workflows due to vulnerability &#x26; VEX support.</td></tr><tr><td align="right">2</td><td><strong>CycloneDX GitHub</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/CycloneDX/specification">github.com/CycloneDX/specification</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source public GitHub repo</td><td><strong><code>Relevance</code>:</strong> CycloneDX specification source repository.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Use for versioned spec tracking.</td></tr><tr><td align="right">3</td><td><strong>CycloneDX VEX</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://cyclonedx.org/capabilities/vex/">cyclonedx.org/capabilities/vex</a><br><br><strong><code>Access / Cost</code>:</strong> Free public docs</td><td><strong><code>Relevance</code>:</strong> CycloneDX VEX capability documentation.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for affected/not-affected communication.</td></tr><tr><td align="right">4</td><td><strong>SPDX specifications</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://spdx.dev/specifications/">spdx.dev/specifications</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open standard</td><td><strong><code>Relevance</code>:</strong> SPDX specifications for software bills of materials &#x26; package metadata.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> SPDX is widely used for license/package metadata &#x26; supply-chain exchange.</td></tr><tr><td align="right">5</td><td><strong>SPDX 3.0.1 spec</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://spdx.github.io/spdx-spec/v3.0.1/">spdx.github.io/spdx-spec/v3.0.1</a><br><br><strong><code>Access / Cost</code>:</strong> Free public docs</td><td><strong><code>Relevance</code>:</strong> SPDX 3.0.1 specification.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Track spec version compatibility in parsers.</td></tr><tr><td align="right">6</td><td><strong>SPDX package URL property</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://spdx.github.io/spdx-spec/v3.0.1/model/Software/Properties/packageUrl/">spdx.github.io/spdx-spec/v3.0.1/model/Software/Properties/packageUrl</a><br><br><strong><code>Access / Cost</code>:</strong> Free public docs</td><td><strong><code>Relevance</code>:</strong> SPDX support for package URL property.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Important for PURL-based vulnerability matching.</td></tr><tr><td align="right">7</td><td><strong>SPDX GitHub</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/spdx/spdx-spec">github.com/spdx/spdx-spec</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source public GitHub repo</td><td><strong><code>Relevance</code>:</strong> SPDX specification repository.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Use for release tracking &#x26; schema/source inspection.</td></tr><tr><td align="right">8</td><td><strong>NTIA SBOM resources</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.ntia.gov/page/software-bill-materials">www.ntia.gov/page/software-bill-materials</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> SBOM policy &#x26; foundational resources.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for governance &#x26; compliance context.</td></tr><tr><td align="right">9</td><td><strong>CISA SBOM</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.cisa.gov/sbom">www.cisa.gov/sbom</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> CISA SBOM guidance &#x26; resources.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for U.S. public-sector &#x26; enterprise SBOM program alignment.</td></tr></tbody></table>

## 12.2 Package & software identity

<table><thead><tr><th width="91.30078125" align="right">Sl. #</th><th>Source Title</th><th>Notes</th></tr></thead><tbody><tr><td align="right">1</td><td><strong>Package URL - PURL spec</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/package-url/purl-spec">github.com/package-url/purl-spec</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source public GitHub repo</td><td><strong><code>Relevance</code>:</strong> Standard package identifier used in SBOMs &#x26; vulnerability DBs.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Crucial for OSV &#x26; package ecosystem matching.</td></tr><tr><td align="right">2</td><td><strong>PURL types</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/package-url/purl-spec/blob/master/PURL-TYPES.rst">github.com/package-url/purl-spec/blob/master/PURL-TYPES.rst</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Defines PURL types per ecosystem.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Helps normalize ecosystem-specific package coordinates.</td></tr><tr><td align="right">3</td><td><strong>CPE specification / dictionary</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://nvd.nist.gov/products/cpe">nvd.nist.gov/products/cpe</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Product naming &#x26; CPE dictionary.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for product/platform matching, but can be imprecise for packages.</td></tr><tr><td align="right">4</td><td><strong>NVD CPE API</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://nvd.nist.gov/developers/products">nvd.nist.gov/developers/products</a><br><br><strong><code>Access / Cost</code>:</strong> Free public; optional free API key for higher rate limits</td><td><strong><code>Relevance</code>:</strong> Programmatic CPE dictionary access.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Required for automated CPE matching workflows.</td></tr><tr><td align="right">5</td><td><strong>SWID tags - NIST</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://csrc.nist.gov/projects/software-identification-swid">csrc.nist.gov/projects/software-identification-swid</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Software Identification Tags for installed software identity.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful in enterprise asset inventory &#x26; compliance.</td></tr><tr><td align="right">6</td><td><strong>GS1 Digital Link / identifiers</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.gs1.org/standards/gs1-digital-link">www.gs1.org/standards/gs1-digital-link</a><br><br><strong><code>Access / Cost</code>:</strong> Free public standard docs; GS1 membership may apply for assigned identifiers</td><td><strong><code>Relevance</code>:</strong> Optional identity standard for physical/embedded supply chains.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Not a vulnerability standard, but can matter in hardware/product traceability.</td></tr><tr><td align="right">7</td><td><strong>Software Heritage IDs</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.swhid.org/">www.swhid.org</a><br><br><strong><code>Access / Cost</code>:</strong> Free public / open</td><td><strong><code>Relevance</code>:</strong> Persistent source- code artifact identity.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for source provenance &#x26; precise code artifact references.</td></tr></tbody></table>

## 12.3 Advisory exchange, CSAF & VEX

<table><thead><tr><th width="93.8203125" align="right">Sl. #</th><th>Source Title</th><th>Notes</th></tr></thead><tbody><tr><td align="right">1</td><td><strong>OASIS CSAF 2.0 specification</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://docs.oasis-open.org/csaf/csaf/v2.0/os/csaf-v2.0-os.html">docs.oasis-open.org/csaf/csaf/v2.0/os/csaf-v2.0-os.html</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open standard</td><td><strong><code>Relevance</code>:</strong> Common Security Advisory Framework for structured advisories.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> CSAF can express product status, remediation, impact, &#x26; VEX-like affectedness.</td></tr><tr><td align="right">2</td><td><strong>CSAF home</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.csaf.io/">www.csaf.io</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> CSAF ecosystem &#x26; tooling hub.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Good starting point for CSAF adoption.</td></tr><tr><td align="right">3</td><td><strong>OpenVEX specification</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/openvex/spec">github.com/openvex/spec</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source public GitHub repo</td><td><strong><code>Relevance</code>:</strong> Minimal JSON-LD VEX format based on CISA VEX requirements.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for communicating not- affected/fixed/affected status.</td></tr><tr><td align="right">4</td><td><strong>OpenVEX project page</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://openssf.org/projects/openvex/">openssf.org/projects/openvex</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> OpenSSF project page for OpenVEX.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Project-level overview.</td></tr><tr><td align="right">5</td><td><strong>CISA Minimum Requirements for VEX</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.cisa.gov/sites/default/files/2023-04/minimum-requirements-for-vex-508c.pdf">www.cisa.gov/sites/default/files/2023-04/minimum-requirements-for- vex-508c.pdf</a><br><br><strong><code>Access / Cost</code>:</strong> Free public PDF</td><td><strong><code>Relevance</code>:</strong> Baseline VEX requirements.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for evaluating VEX completeness.</td></tr><tr><td align="right">6</td><td><strong>OpenSSF VDR, VEX, OpenVEX &#x26; CSAF explainer</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://openssf.org/blog/2023/09/07/vdr-vex-openvex-and-csaf/">openssf.org/blog/2023/09/07/vdr-vex-openvex-and-csaf</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Explains VDR, VEX, OpenVEX, &#x26; CSAF.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for conceptual alignment &#x26; terminology.</td></tr><tr><td align="right">7</td><td><strong>Red Hat CSAF/VEX guidance</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://redhatproductsecurity.github.io/security-data-guidelines/csaf-vex/">redhatproductsecurity.github.io/security-data-guidelines/csaf-vex</a><br><br><strong><code>Access / Cost</code>:</strong> Free public docs</td><td><strong><code>Relevance</code>:</strong> Red Hat CSAF/VEX semantics &#x26; usage guidance.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Important for vendor-specific interpretation.</td></tr><tr><td align="right">8</td><td><strong>Ubuntu VEX</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://ubuntu.com/security/vex">ubuntu.com/security/vex</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Ubuntu VEX data entry point.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for Ubuntu affectedness &#x26; false-positive reduction.</td></tr><tr><td align="right">9</td><td><strong>Canonical Ubuntu Security Notices repo - OSV &#x26; OpenVEX</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/canonical/ubuntu-security-notices">github.com/canonical/ubuntu-security-notices</a><br><br><strong><code>Access / Cost</code>:</strong> Free public GitHub repo</td><td><strong><code>Relevance</code>:</strong> Canonical USN/LSN, OSV, &#x26; OpenVEX JSON data.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Strong machine-readable source for Ubuntu security status.</td></tr></tbody></table>

## Discussion

This chapter section keeps the latest table structure, source titles, access/cost fields, relevance notes, & operational notes from the source inventory. Review the table entries as ingestion candidates, then validate source freshness, licensing, authentication requirements, & link-check behavior before production use.

***

#### [Back to Index](/vulnkeeper/index.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://breachtrace.gitbook.io/vulnkeeper/chapter-e/12-12-sbom-package-identity-vex-and-advisory-exchange-standards.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
