OpenSSF publication
OSV Schema & OpenVEX
Standard, machine-readable formats for describing vulnerabilities (OSV) and their exploitability status (OpenVEX) across the software supply chain.
How each persona uses OSV Schema & OpenVEX
Software Developer / Maintainer Developer
Generates OpenVEX documents to explicitly inform users that their project is not affected by a specific vulnerability found in a dependency.
Open Source Professional (OSPO) OSPO
Adopts the OSV schema to standardize how vulnerability information is ingested and tracked across all enterprise open source usage.
Security Engineer / Architect Security
Adopts the OSV Schema and OpenVEX to standardize vulnerability reporting and coordinate incident response and analysis.
CI/CD DevOps & Tooling Integrator DevOps
Automates the ingestion of OSV data and OpenVEX statements in the pipeline to prevent false positive vulnerability alerts from breaking builds.
Package & Repository Manager Package Manager
Serves OSV-formatted advisories directly from the registry to ensure package consumers receive actionable, machine-readable vulnerability updates.
Executive / End-User Consumer Executive
Reviews standardized vulnerability data formats to clearly understand post-release risk during procurement and auditing.
Problems OSV Schema & OpenVEX helps with
Vulnerability Management Vulnerabilities
Standardises how vulnerabilities and their exploitability status are described so tools can exchange them and suppress false positives.
Relationships
Incoming
-
extended byOSV Record (vulnerability record format)publication
The artifact (the record format itself) is the concrete instance of what the OSV Schema project specifies.