{"categories":[{"label":"Security","url":"https://skillfed.io/packages/category/security/3"}],"enrichment":{"capability":"Lib4VEX parses and generates VEX (Vulnerability Exploitability eXchange) documents in OpenVEX, CycloneDX, and CSAF formats, providing a unified abstraction layer for vulnerability information across these specifications.","skillfed_tags":["sbom-vulnerability","devsecops","format-conversion"],"use_cases":["Convert vulnerability data between OpenVEX, CycloneDX, and CSAF formats in automated security pipelines.","Extract vulnerability information from a CycloneDX SBOM and generate a corresponding VEX document.","Parse existing OpenVEX or CSAF VEX documents to audit vulnerability status across your software inventory.","Generate audit trails of vulnerability assessments by retaining timestamped VEX documents for compliance.","Integrate vulnerability exploitability data into CI/CD workflows that use multiple security tools."],"what_it_does":"Lib4VEX is a library that bridges three major vulnerability document formats\u2014OpenVEX, CycloneDX, and CSAF\u2014by providing a common abstraction for parsing and generating VEX (Vulnerability Exploitability eXchange) documents. It lets you work with vulnerability information without being locked into a single specification, making it easier to integrate vulnerability data into DevSecOps workflows that may use different tools or standards.\n\nThe library is designed to work alongside SBOMs (Software Bill of Materials), extracting and organizing vulnerability status information so you can track which vulnerabilities affect your software components and their current remediation state. It supports JSON output, file writing, and console output, and includes a debug mode via the LIB4VEX_DEBUG environment variable. Three runtime dependencies (lib4sbom, csaf-tool, packageurl-python) handle SBOM parsing and package URL normalization.","worth_installing":"Yes, if you work with multiple VEX or SBOM formats in security tooling. The library solves a real interoperability problem and is actively maintained with no known vulnerabilities. Alpha status and limited documentation mean you should expect to read examples and the tutorial; the three runtime dependencies add modest install friction but are well-established packages. Worth trying in a development environment first to validate the API fits your workflow."},"id":"lib4vex","links":{"html":"https://skillfed.io/packages/lib4vex","md":"https://skillfed.io/packages/lib4vex.md","pypi":"https://pypi.org/project/lib4vex/"},"maintenance":{"status":"active"},"meta":{"latest_release":"2026-03-09","license_spdx":null,"license_treatment":"permissive","name":"lib4vex","python_support":"supports_current","summary":"VEX generator and consumer library"},"popularity":{"monthly_downloads":83121,"position":14099,"tier":"top_15000"},"security":{"n_vulnerabilities":0},"version":"0.2.3"}
