{"repo":"PrismorSec/product-sbom-vex","free":true,"listed":false,"github":"https://github.com/PrismorSec/product-sbom-vex","clone":"git clone https://github.com/PrismorSec/product-sbom-vex.git","description":"Last Mile EU CRA Compliance Tooling. Bring your own build SBOMs to generate product level SBOM and VEX based on CSAF 2.0","language":"Python","stars":22,"topics":["automation","compliance","cybersecurity-tools","security","cyber-resilience-act","sbom","vex"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"CRA-CLI — EU Cyber Resilience Act Compliance Tooling A Python CLI tool that helps organizations comply with the EU Cyber Resilience Act (CRA) by automating the creation of Product-level SBOMs and VEX (Vulnerability Exploitability eXchange) documents. Why Compliance Matters For Auditors and Market Surveillance Authorities , this tool produces the legally required artifacts: - SBOM ( product.spdx.json ) — The Required Artifact . A complete inventory of your software components. - VEX ( vex.csaf.json ) — The Required Operational Evidence . Proof that you have assessed vulnerabilities and determined their impact. Crucial Compliance Requirements: 1. Continuous Updates : Both documents must be kept up-to-date with every release or vulnerability disclosure. 2. Authority Requests : Both must be provided to authorities upon request to prove conformity. 3. Process Linkage : These artifacts serve as evidence that your secure update processes and vulnerability reporting timelines are functioning (e.g., addressing critical risks promptly). More info on CRA Hub Features - cra aggregate — Merge multiple component SBOMs (SPDX JSON from Syft) into a single Product SBOM with automatic namespace isolation and deduplication. - cra vex — Generate a CSAF 2.0 VEX document by scanning the Product SBOM with Trivy (or any scanner) and applying manual triage rules from a Markdown file. Workflow Overview File Classification � Component SBOMs (Input) - frontend.spdx.json , firmware.spdx.json , etc. - Gen","default_branch":null,"files":null,"tree":[],"storefront":"/r/PrismorSec","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/PrismorSec/product-sbom-vex/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}