We currently don't have a process in place to create and distribute VEX Documents.
We've recently run into a security issue of one of our dependencies that caused our images to look vulnerable. However, we were not making use of the vulnerable bits of the library.
We ended up publishing a patch release of Policy Server and kwctl, plus a helm chart update. Our users then had to go through the "pain" of pulling a brand new image on their cluster.
It would have been great instead to just create a VEX document and mark the Policy Server image as not affected by it.
Acceptance Criteria
We currently don't have a process in place to create and distribute VEX Documents.
We've recently run into a security issue of one of our dependencies that caused our images to look vulnerable. However, we were not making use of the vulnerable bits of the library.
We ended up publishing a patch release of Policy Server and kwctl, plus a helm chart update. Our users then had to go through the "pain" of pulling a brand new image on their cluster.
It would have been great instead to just create a VEX document and mark the Policy Server image as not affected by it.
Acceptance Criteria