Best fit
CycloneDX or SPDX SBOMs, VEX statements, release manifests, component identifiers, and artifact hashes are reviewed across separate tools before shipping.
Gate a release on consistent SBOM, VEX, identifier, relationship, and artifact-digest evidence.
CycloneDX or SPDX SBOMs, VEX statements, release manifests, component identifiers, and artifact hashes are reviewed across separate tools before shipping.
CycloneDX or SPDX SBOMs, VEX statements, release manifests, component identifiers, and artifact hashes are reviewed across separate tools before shipping.
findings.csv with stable codes and evidence sources. review-manifest.csv with every reviewed record.
The package does not scan for vulnerabilities or decide whether a VEX status is substantively correct.
No. It reads one normalized local JSON packet and makes no network request.
No. It produces evidence findings; the responsible owner makes every decision and action outside the package.
Yes. Stable finding codes, sorted records, and a SHA-256 receipt make repeated review inspectable.
Unreadable JSON, missing arrays, duplicate core identifiers, invalid timestamps, and invalid core numbers fail closed.
No. READY means no automated finding appeared in the supplied normalized packet; source truth still requires human review.
The listing includes the tested package, realistic samples, declared permissions, and known limitations.
Get SBOM & VEX Release Evidence Gate on Agensi