JustHandled Labs
// Security & Compliance

SBOM & VEX Release Evidence Gate

Gate a release on consistent SBOM, VEX, identifier, relationship, and artifact-digest evidence.

What problem does SBOM & VEX Release Evidence Gate solve?

CycloneDX or SPDX SBOMs, VEX statements, release manifests, component identifiers, and artifact hashes are reviewed across separate tools before shipping.

Use it to

What it returns

A representative input and result

fixture-backed sample
input `as_of` is timezone-aware; `artifacts[]` uses `artifact_id`, `expected_digest`, and `sbom_digest`; `components[]` uses `component_id`, `purl`, `version`, and relationship; `vex_statements[]` uses `statement_id`, `component_id`, and `updated_at`.
result A deterministic READY, REVIEW, or BLOCK result with stable finding codes, a complete review manifest, a human-readable report, and a SHA-256 receipt.

Access and approval boundaries

Known limitations

// choose with context

Is SBOM & VEX Release Evidence Gate the right skill?

Best fit

CycloneDX or SPDX SBOMs, VEX statements, release manifests, component identifiers, and artifact hashes are reviewed across separate tools before shipping.

It returns

findings.csv with stable codes and evidence sources. review-manifest.csv with every reviewed record.

Do not use it as

The package does not scan for vulnerabilities or decide whether a VEX status is substantively correct.

Compatibility, access, version, and licence

Reads or accesses
Declared local scope: one owner-selected local JSON input, one owner-selected local output directory.
Compatibility
SKILL.md-compatible agents that can run a local Python helper. Python 3.10 or newer on Windows, macOS, or Linux using only the standard library. One documented UTF-8 JSON evidence packet; no API key or provider account.
Version
1.0.0
Licence
Review the package licence and seller terms at the linked destination.

What happens next

The Agensi listing opens at the current offer. Complete purchase there, inspect SKILL.md and its bundled files, then add the complete folder to your agent.

Questions

Does it connect to a live account or provider?

No. It reads one normalized local JSON packet and makes no network request.

Does it make the final decision or external change?

No. It produces evidence findings; the responsible owner makes every decision and action outside the package.

Is the result deterministic?

Yes. Stable finding codes, sorted records, and a SHA-256 receipt make repeated review inspectable.

What happens with malformed input?

Unreadable JSON, missing arrays, duplicate core identifiers, invalid timestamps, and invalid core numbers fail closed.

Does READY prove the underlying evidence is true?

No. READY means no automated finding appeared in the supplied normalized packet; source truth still requires human review.

SBOM & VEX Release Evidence Gate keeps proof and approval boundaries visible.

The listing includes the tested package, realistic samples, declared permissions, and known limitations.

Get SBOM & VEX Release Evidence Gate on Agensi