OpenSSF publication

OSV Schema & OpenVEX

Standard, machine-readable formats for describing vulnerabilities (OSV) and their exploitability status (OpenVEX) across the software supply chain.

How each persona uses OSV Schema & OpenVEX

Software Developer / Maintainer Developer

Generates OpenVEX documents to explicitly inform users that their project is not affected by a specific vulnerability found in a dependency.

See everything for Developer →

Open Source Professional (OSPO) OSPO

Adopts the OSV schema to standardize how vulnerability information is ingested and tracked across all enterprise open source usage.

See everything for OSPO →

Security Engineer / Architect Security

Adopts the OSV Schema and OpenVEX to standardize vulnerability reporting and coordinate incident response and analysis.

See everything for Security →

CI/CD DevOps & Tooling Integrator DevOps

Automates the ingestion of OSV data and OpenVEX statements in the pipeline to prevent false positive vulnerability alerts from breaking builds.

See everything for DevOps →

Package & Repository Manager Package Manager

Serves OSV-formatted advisories directly from the registry to ensure package consumers receive actionable, machine-readable vulnerability updates.

See everything for Package Manager →

Executive / End-User Consumer Executive

Reviews standardized vulnerability data formats to clearly understand post-release risk during procurement and auditing.

See everything for Executive →

Problems OSV Schema & OpenVEX helps with

Vulnerability Management Vulnerabilities

Standardises how vulnerabilities and their exploitability status are described so tools can exchange them and suppress false positives.

See everything for Vulnerabilities →

Relationships

Incoming