SBOMs and VEX Attestations
Every QHx release publishes two types of Cosign attestations attached directly to each OCI image:
- A CycloneDX Software Bill of Materials (SBOM) — a machine-readable inventory of every component and dependency present in the image.
- A VEX (Vulnerability Exploitability eXchange) document — statements from the Messier-42 security team on the applicability of known CVEs to each image, including mitigations and version-specific clarifications.
Both are produced and signed as part of the standard release pipeline and can be verified offline.
Verifying the SBOM attestation
Section titled “Verifying the SBOM attestation”$ cosign verify-attestation \ --type cyclonedx \ --certificate-identity-regexp 'https://github.com/messier-42/qhx-core/.*' \ --certificate-oidc-issuer=https://token.actions.githubusercontent.com \ "oci.messier42.com/qhx/${x}:v${VERSION}" \ | jq -r '.payload' | base64 -d | jq '.predicate'The --type cyclonedx flag selects the SBOM attestation. The decoded
predicate is a standard CycloneDX 1.6 BOM
JSON document listing all components with their names, versions, and
package URLs (purls).
Verifying the VEX attestation
Section titled “Verifying the VEX attestation”$ cosign verify-attestation \ --type "https://openvex.dev/ns/v0.2.0" \ --certificate-identity-regexp 'https://github.com/messier-42/qhx-core/.*' \ --certificate-oidc-issuer=https://token.actions.githubusercontent.com \ "oci.messier42.com/qhx/${x}:v${VERSION}" \ | jq -r '.payload' | base64 -d | jq '.predicate'The decoded predicate is an OpenVEX document containing statements authored by the Messier-42 security team. Each statement covers a specific CVE and records one of the following statuses:
| Status | Meaning |
|---|---|
not_affected | The vulnerable code path is not reachable in this image. An impact_statement explains why. |
affected | The image is impacted. A remediation statement describes mitigations or compensating controls. |
fixed | The vulnerability has been patched in this version. |
under_investigation | Assessment is in progress. |
The VEX document is also available as a standalone file attached to each
GitHub release under the
name qhx-core-v${VERSION}.openvex.json.