The Lab · 2026-03-27 14:27:29 · GitHub Issues
Microsoft's hve-core project is proposing a new AI-powered security agent designed to automate vulnerability triage for any codebase. The proposed 'VEX Generation Agent' would be a custom Copilot agent within the project's security collection, enabling users to scan for dependency vulnerabilities, perform AI-assisted e...
The Lab · 2026-04-04 15:27:02 · GitHub Issues
A proposed change to a GitHub CI/CD policy workflow seeks to automate the management of permanently unfixable, high-severity vulnerabilities, eliminating the need for manual script edits with each new scan. The current process lacks a formal Vulnerability Exploitability eXchange (VEX) register, forcing developers to ma...
The Lab · 2026-04-04 15:27:03 · GitHub Issues
A proposed change to a GitHub repository's CI/CD pipeline reveals a strategic move to automate the handling of unfixable, high-severity vulnerabilities. The current policy lacks a formal Vulnerability Exploitability eXchange (VEX) register, forcing developers to manually edit workflow scripts each time a permanently un...
The Lab · 2026-04-04 21:26:58 · GitHub Issues
A new automated GitHub workflow establishes a rigorous vulnerability management pipeline for container images, moving beyond simple scanning to enforce structured remediation and compliance. The system performs a weekly rescan of all released images every Monday using the latest Grype vulnerability database, uploading ...
The Lab · 2026-04-17 12:22:51 · GitHub Issues
A critical discrepancy in a GitHub repository's security automation undermines the integrity of its software supply chain. The project's SECURITY.md file claims it generates OpenVEX artifacts—machine-readable security advisories—during its release workflow. However, the actual artifact shipped is a static template cont...
The Lab · 2026-05-08 09:54:40 · GitHub Issues
A security review of the SUSE Observability Kafka broker container image has produced formal OpenVEX statements addressing six HIGH-severity findings, marking a significant documentation effort for enterprise container vulnerability disclosure. The work combines independent security assessment with VEX (Vulnerability E...