Scan, Vulnerability & VEX | ESL SBOMator
Scan, Vulnerability & VEX โ€” the Core Engine

From Build Inventory to a Defensible Vulnerability Decision

SBOMator’s core workflow turns a repository, container, or firmware image into a standards-compliant SBOM, correlates it against multiple vulnerability sources, and preserves every engineering decision as machine- and human-readable evidence.

SBOMโ†’Vulnerabilityโ†’VEXโ†’Dashboardโ†’Evidence
Step 1 ยท Inventory

Accurate, Standards-Compliant SBOMs

CycloneDX 1.6 JSON and SPDX with direct and transitive dependencies, PURLs, versions, suppliers, licenses, hashes, and dependency relationships โ€” with automatic project detection.

CycloneDX 1.6 & SPDX

Industry-standard output with NTIA minimum-element support that imports cleanly into Dependency-Track and other consumers.

Direct & Transitive

Complete dependency trees with relationships, scoped to runtime, development, or complete as your evidence requires.

Fail-Closed Quality Gate

Unresolved versions or licenses are flagged with auditable exceptions โ€” an incomplete BOM never passes silently.

Comprehensive Mode

Merges Syft, CDXgen, and ecosystem-specific parsers into one deduplicated, reconciled inventory.

Suppliers & Licenses

Supplier/manufacturer enrichment, SPDX license normalization, and compound/dual-license expression preservation.

Scope & Exclusions

Inventory-only mode without CVE analysis, plus exclusions for test, CI, build, or vendored manifests.

15+ Languages & Ecosystems

From modern JavaScript monorepos to C/C++ build systems, containers, and Linux distributions.

npm, Yarn, pnpm, Bun
pip, Pipenv, Poetry
Maven & Gradle
NuGet (.NET)
Cargo (Rust)
Go modules
PHP Composer
Ruby Bundler
CMake, Make, Meson
WordPress
Linux packages
Containers
Git submodules
Vendored components
Autotools (C/C++)
Perforce & local Git
Step 2 ยท Intelligence

Vulnerability Intelligence That Supports a Decision

Multiple sources combined with exploitation, reachability, lifecycle, and supplier evidence โ€” then preserved in machine- and human-readable form.

NVD OSV Grype CISA KEV FIRST EPSS CVSS v4.0

Version-aware matching

Ecosystem-aware CPE/CVE matching reduces cross-ecosystem false positives; backport, fixed-version, and affected-range filtering.

Exploitation context

CISA KEV known-exploited status and FIRST EPSS probability order remediation; weaponized and ransomware-linked CVEs identified.

CVSS v4.0 & v3.x

Parses, scores, and maps severity from both standards, with mixed v3/v4 CycloneDX ratings.

Coverage classification

Every component is marked matched, scanned clean, or not analyzed โ€” with disputed-CVE annotations.

Offline / air-gapped options. Local NVD, OSV, KEV, HalluSquat, and fingerprint data reduce dependency on external services. Cached EPSS and local supplier/license knowledge remain available with source-specific coverage limits.
Step 3 ยท Decision

VEX: Document Every Vulnerability State

CycloneDX VEX turns raw findings into defensible engineering dispositions with justifications and reachability.

Affected

Confirmed exposure with remediation detail and mitigation timeline.

Not Affected

Justification plus reachability and component-scope rationale.

Under Investigation

In-triage state carried forward across future scans.

Resolved

Fixed and preserved as part of the audit history.

Persistent, cross-scan suppressions. Dashboard VEX decisions reapply by PURL coordinates with version- and scope-aware policies, and reconcile consistently between the SBOM, VEX, and HTML reports.
Step 4 ยท Triage

Dashboard & Droid-as-Judge

The PyQt6 desktop dashboard loads CycloneDX JSON or HTML reports, turning component and CVE evidence into an interactive triage workspace โ€” with AI-assisted judging in an embedded terminal.

1

Select CVEs

Filter by severity, license, secrets, VEX state, and Ransomware / Weaponized / Standard threat class.

2

Send to Droid

Analyze checked CVEs with the Droid CLI running inside the dashboard’s real embedded terminal.

3

Judge & Justify

False positive, not affected, reachability, and the smallest safe fix โ€” explained with evidence.

4

VEX Evidence

Preserve the engineering decision and justification; diff two reports to track fix progress.

Restricted autonomy โ€” the engineer stays in control. Droid runs with --auto medium and --disabled-tools Edit: it can read and create files but cannot modify existing files. It judges false positives and not-affected cases, explains reachability, and proposes the smallest safe fix or VEX justification. Factory and Droid are marks of Factory AI; no partnership or endorsement is implied.

Run the Full Scan-to-Decision Flow

Point SBOMator at a repository, container, or firmware image and get a standards-compliant SBOM, correlated vulnerabilities, and defensible VEX evidence โ€” entirely on-premises.