遇见数据集

Lifecycle-Based VEX Risk Dataset for Software Supply Chain Governance

收藏
Zenodo2026-04-07 更新2026-05-26 收录
官方服务:

资源简介:

This dataset provides structured risk metadata derived from lifecycle-based analysis of Vulnerability Exploitability eXchange (VEX) statements. It is designed to support governance, auditing, and research use cases where exploitability assertions must be evaluated over time rather than treated as static status indicators. The dataset includes attributes such as lifecycle phase, scope, validity context, exploitability conditions, and risk interpretation categories intended to reflect real-world VEX usage challenges observed in enterprise and open-source software supply chains. It can be used by software producers, consumers, auditors, and tool vendors to study VEX staleness, context drift, governance controls, and integration patterns with SBOM and compliance workflows.

提供机构:
Zenodo
创建时间:
2026-04-07
二维码
社区交流群
二维码
科研交流群
商业服务