Vulnerability Scan
Last updated
Last updated
The platform periodically runs vulnerability scans on imported SBOM for a version and supports disabling vulnerability scans if necessary.
With the SBOM in Interlynk, each vulnerability's exploitability status (e.g., Not Applicable or Fixed) can be recorded in place and exported as VEX.
However, in a build/release pipeline, the newer versions might have the same vulnerability and exploitability status.
Interlynk supports retaining exploitability status across newer SBOMs if the underlying data—the vulnerable component name and version—does not change.