Davide Fucci
Davide Fucci
> Looks two of them are already resolved since your script ran, but two of them point to places we could maybe recommend higher minimums, so thank you for that!...
@terriko, thank you so much for the effort you put into this PR and the words of encouragement 🙏
Thank you for your answer and for following up on this. Feel free to use the [script](https://gist.github.com/dfucci/055db60081cf188791ea593a149e1073) to generate the VEX. Notice that it depends on `osv-scanner`, so if you...
Thanks for your feedback, @sseide. You’re right that VEX and SBOM should stay aligned. A VEX can easily be added to the deployment pipeline—see our [script](https://gist.github.com/dfucci/055db60081cf188791ea593a149e1073) for reference. On the...