Skip to content

docs(vex): how the Asset page builds VEX statements when findings disagree - #16246

Open
blakeaowens wants to merge 1 commit into
devfrom
docs/vex-export-disagreeing-states
Open

blakeaowens wants to merge 1 commit into
devfrom
docs/vex-export-disagreeing-states

Conversation

@blakeaowens

Copy link
Copy Markdown
Contributor

Description

Documents how DefectDojo Pro's Asset page builds VEX statements, and corrects a claim that the Asset page and API exports are interchangeable.

  • Exporting SBOMs and VEX (asset_modelling/locations/PRO__exporting_sboms_and_vex.md): the Asset page and the /api/v2/ endpoints emit the same specification version, but their VEX statements come from different data. The API reads each Finding's per-dependency status; the Asset page reads each Finding's own VEX analysis.
  • A new How the Asset page builds VEX statements subsection:
    • the state a Finding gets when it has no VEX analysis;
    • the least-resolved rule when the Findings for one vulnerability disagree: per component, the asset-wide case for Findings with no component, and separate entries per state;
    • so two hosts with different states for one vulnerability in the same component never export as one not_affected.

English pages only: the translated copies are regenerated by the docs translation pipeline.

Test results

Documentation only. The one new link is an in-page anchor to an existing heading.

Checklist

  • Documentation only.

🤖 Generated with Claude Code

…agree

The Asset page's VEX reads each Finding's own analysis rather than the
per-location statuses the API export reads, so the two are not
interchangeable. Document the derived states and the least-resolved
rule that keeps one host's not_affected from speaking for another.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@blakeaowens
blakeaowens requested a review from Maffooch as a code owner October 7, 2026 06:55
@blakeaowens blakeaowens added this to the 3.4.100 milestone Oct 7, 2026
@github-actions github-actions Bot added the docs label Oct 7, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant