Skip to content

Update vulnetix_cli.json - #121

Open
0x73746F66 wants to merge 2 commits into
CycloneDX:mainfrom
Vulnetix:main
Open

Update vulnetix_cli.json#121
0x73746F66 wants to merge 2 commits into
CycloneDX:mainfrom
Vulnetix:main

Conversation

@0x73746F66

Copy link
Copy Markdown
Contributor

We've extended features to cover gitlab, PQC, and AI inventory

AI-BOM
CBOM
Gitlab
CycloneDX VEX creation during SCA Autofix
CycloneDX VEX creation during SCA reachability

We've extended features to cover gitlab, PQC, and AI inventory

Signed-off-by: Stof <93355168+0x73746F66@users.noreply.github.com>
@0x73746F66
0x73746F66 requested a review from a team as a code owner July 10, 2026 10:46

@jkowalleck jkowalleck left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you for the update.
I have some remarks.

Comment thread tools/vulnetix_cli.json
"ANALYSIS",
"TRANSFORM"
"TRANSFORM",
"AUTHOR"

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AUTOR seams not right for an automated tool.

https://cyclonedx.github.io/tool-center/tool.html#tool_functions

AUTHOR - Tools that human authors can use to create CycloneDX BOMs.

Suggested change
"AUTHOR"

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

it has go module architecture where the authoring primitive are used by any go.mod project

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

a programmable interface does not mean author capabilities. please remove that property.

@0x73746F66 0x73746F66 Aug 1, 2026

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

you mean cli, sure, that was always there https://docs.cli.vulnetix.com/docs/cli-reference/cdx/
I thought you were asking that the cli authoring was not some low level variation like sdk/lib but you can see the cli bom auhoing is there for sbom, cbom, ai-bom specs.
Maybe instead of saying "remove" on repeat, ask some clarifying questions next time? I was the contirbutor of the pubisher spec for TEA, I kind of am pretty meticulous about this stuff. Cheers

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants