Export
findings:read. One statement per vulnerability finding on the asset,
in every state. A container image is named by a pkg:oci Package URL, and
each finding’s package is a subcomponent.
A suppression without a justification is exported as
affected, never
not_affected. Accepting a risk is a decision not to fix it, not a finding
that the product is unaffected, and a VEX document is read by tools that act
on the difference.
Import
Every change goes through the same lifecycle a person uses, as the caller:
findings:write, and findings:suppress for any suppression — checked before
anything is applied, so a credential without it is refused the whole document.
Each change is on the finding’s timeline, by the caller, with a reason naming
the document’s @id, its author and its SHA-256. The response lists what was
applied and, for every statement that changed nothing, why.
Importing a document you exported changes nothing.
A justification belongs to one suppression: unsuppressing, the expiry sweep,
or re-suppressing by hand clears it.
