Skip to content

dhi: add vex status and refresh#24838

Open
craig-osterhout wants to merge 3 commits intodocker:mainfrom
craig-osterhout:dhi-vex-updates
Open

dhi: add vex status and refresh#24838
craig-osterhout wants to merge 3 commits intodocker:mainfrom
craig-osterhout:dhi-vex-updates

Conversation

@craig-osterhout
Copy link
Copy Markdown
Contributor

@craig-osterhout craig-osterhout commented Apr 20, 2026

Description

  • Adds VEX status reference and not_affected justification codes based on OpenVEX and usage in the advisory repo.
  • Adds "Why DHI does not use fixed"
  • Removes "Why is VEX important?" and "How DHI integrates VEX" sections. This content is covered more concretely in scanner-integrations.md. Will follow up to figure out how to cover the content better between these two topics, but removing redundant content for now.

https://deploy-preview-24838--docsdocker.netlify.app/dhi/core-concepts/vex/

Related issues or tickets

ENGDOCS-3238

Reviews

  • Technical review
  • Editorial review

Signed-off-by: Craig Osterhout <craig.osterhout@docker.com>
@netlify
Copy link
Copy Markdown

netlify bot commented Apr 20, 2026

Deploy Preview for docsdocker ready!

Name Link
🔨 Latest commit 616c812
🔍 Latest deploy log https://app.netlify.com/projects/docsdocker/deploys/69e6975b5b8660000840713f
😎 Deploy Preview https://deploy-preview-24838--docsdocker.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@craig-osterhout
Copy link
Copy Markdown
Contributor Author

/review

@craig-osterhout craig-osterhout added status/review Pull requests that are ready for review area/dhi labels Apr 20, 2026
Signed-off-by: Craig Osterhout <craig.osterhout@docker.com>
Copy link
Copy Markdown
Contributor

@docker-agent docker-agent bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Assessment: 🟡 NEEDS ATTENTION

Comment thread content/manuals/dhi/core-concepts/vex.md
@craig-osterhout craig-osterhout requested review from a team and brianru April 20, 2026 19:55
Copy link
Copy Markdown

@brianru brianru left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me! By the way - we do have an integration guide for software scanner vendors. It may be a very different audience than these docs, but I thought I should mention it as they do not seem to link to each other. https://github.com/docker-hardened-images/advisories/tree/main/integration

Signed-off-by: Craig Osterhout <craig.osterhout@docker.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/dhi status/review Pull requests that are ready for review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants