Skip to main content

Software Bill of Materials (SBOM) and VEX

Overview​

Clea OS provides machine-readable software composition and vulnerability information to support software traceability and vulnerability management.

Two complementary types of artifacts are generated as part of the Clea OS build process:

  • Software Bill of Materials (SBOM), which describes the software components included in the build.
  • Vulnerability Exploitability eXchange (VEX), which provides available information about known vulnerabilities associated with those components and their applicability or resolution status.

For official Clea OS releases, these artifacts are automatically generated during the release build and provided with the release artifacts.

Software Bill of Materials (SBOM)​

A Software Bill of Materials (SBOM) is a machine-readable inventory of the software components included in a software product or build.

An SBOM can provide information such as:

  • component and package names;
  • component versions;
  • software identifiers;
  • dependency relationships;
  • license information;
  • additional component metadata.

Clea OS generates SBOM information in the following standard formats:

FormatDescription
SPDXStandard format for representing software components, dependencies, licenses, and related metadata.
CycloneDXSoftware Bill of Materials format designed for software supply-chain and security use cases.

Vulnerability Exploitability eXchange (VEX)​

A component listed in an SBOM may be associated with one or more publicly known vulnerabilities.

However, the presence of a component associated with a CVE does not by itself mean that the vulnerability is applicable or exploitable in a specific Clea OS build.

Vulnerability applicability can depend on several factors, including:

  • the version of the component;
  • the presence of the vulnerable code;
  • build options and configuration;
  • enabled functionality;
  • code reachability;
  • runtime configuration;
  • available mitigations;
  • the target platform.

VEX provides machine-readable information about the available vulnerability analysis for components included in the build.

Clea OS generates vulnerability information in CycloneDX VEX format. This information may include assessments provided by the underlying Yocto layers and software component maintainers, including information about vulnerabilities that have already been analyzed or fixed.

Vulnerability analysis information​

A VEX entry can include an analysis state describing the available assessment of a vulnerability in the context of the build.

For example:

  • not_affected indicates that the vulnerability is reported as not applicable to the evaluated build or configuration;
  • resolved indicates that the vulnerability has already been addressed in the software included in the build.

Additional information explaining the assessment may also be included in the VEX entry.

note

The VEX document represents the vulnerability information available when the build is generated. It should not be interpreted as a guarantee that every vulnerability associated with every component has been individually assessed.

The absence of a vulnerability from the VEX document does not imply that the product is not affected by that vulnerability.

SBOM and VEX in Clea OS releases​

For each supported board, the Clea OS release page provides an SBOM & CVEs package.

To access it:

  1. Open the Clea OS Releases page.
  2. Select the required Clea OS release.
  3. Locate the required board and image configuration.
  4. Select SBOM & CVEs.

The package is provided in tar.gz format and contains the Software Bill of Materials and associated vulnerability information generated during the release build.

A typical package contains:

cyclonedx-export/
├── bom.json
└── vex.json

*.spdx.tar.zst

Where:

  • bom.json contains the CycloneDX SBOM;
  • vex.json contains the CycloneDX VEX information;
  • *.spdx.tar.zst contains the SPDX SBOM artifacts.

These artifacts are generated automatically as part of the Clea OS release build.

SBOM and VEX in local builds​

The same software composition information is generated when building Clea OS from source.

SPDX​

SPDX artifacts generated during the build are available under:

<BUILDDIR>/tmp/deploy/images/

The directory contains the SPDX documents generated for the components and images produced by the build.

CycloneDX and VEX​

CycloneDX SBOM and VEX artifacts generated during the build are available under:

<BUILDDIR>/tmp/deploy/cyclonedx-export/

The generated artifacts include:

bom.json
vex.json

Interpreting SBOM and VEX information​

An SBOM describes the software composition of a build. It is not, by itself, a vulnerability assessment.

important

The presence of a CVE associated with a component listed in the SBOM does not automatically mean that the vulnerability is exploitable in Clea OS.

Vulnerability applicability may depend on the exact component version, compilation options, enabled features, runtime configuration, code reachability, mitigations, platform, and deployment environment.

The VEX information provides additional context where vulnerability analysis information is available.

Applications, packages, configuration changes, and other software added by the system integrator are outside the scope of the SBOM and VEX generated for the original Clea OS build and can change the vulnerability exposure of the final product.

For additional information about Clea OS security capabilities and the shared responsibilities between Clea OS, the hardware platform, and the system integrator, see the Clea OS Security Overview.