Skip to content

SBOMs and VEX Attestations

Every QHx release publishes two types of Cosign attestations attached directly to each OCI image:

  • A CycloneDX Software Bill of Materials (SBOM) — a machine-readable inventory of every component and dependency present in the image.
  • A VEX (Vulnerability Exploitability eXchange) document — statements from the Messier-42 security team on the applicability of known CVEs to each image, including mitigations and version-specific clarifications.

Both are produced and signed as part of the standard release pipeline and can be verified offline.

Verifying and retrieving the CycloneDX SBOM
$ cosign verify-attestation \
--type cyclonedx \
--certificate-identity-regexp 'https://github.com/messier-42/qhx-core/.*' \
--certificate-oidc-issuer=https://token.actions.githubusercontent.com \
"oci.messier42.com/qhx/${x}:v${VERSION}" \
| jq -r '.payload' | base64 -d | jq '.predicate'

The --type cyclonedx flag selects the SBOM attestation. The decoded predicate is a standard CycloneDX 1.6 BOM JSON document listing all components with their names, versions, and package URLs (purls).

Verifying and retrieving the VEX document
$ cosign verify-attestation \
--type "https://openvex.dev/ns/v0.2.0" \
--certificate-identity-regexp 'https://github.com/messier-42/qhx-core/.*' \
--certificate-oidc-issuer=https://token.actions.githubusercontent.com \
"oci.messier42.com/qhx/${x}:v${VERSION}" \
| jq -r '.payload' | base64 -d | jq '.predicate'

The decoded predicate is an OpenVEX document containing statements authored by the Messier-42 security team. Each statement covers a specific CVE and records one of the following statuses:

StatusMeaning
not_affectedThe vulnerable code path is not reachable in this image. An impact_statement explains why.
affectedThe image is impacted. A remediation statement describes mitigations or compensating controls.
fixedThe vulnerability has been patched in this version.
under_investigationAssessment is in progress.

The VEX document is also available as a standalone file attached to each GitHub release under the name qhx-core-v${VERSION}.openvex.json.