SBOM and VEX Exploitability Triage
Correlate CycloneDX components with VEX statements, prioritize exploitable findings, and open evidence-rich remediation work.
The full canvas, before you import it
Click any node to see its config.
Click a node to select it — same as the Heym editor; the panel shows its settings.
10 nodes · Free & source-available
SBOM and VEX Exploitability Triage
Reduce noisy software supply chain alerts by comparing an SBOM with Vulnerability Exploitability eXchange statements. The workflow normalizes package identifiers, highlights unresolved components, and routes exploitable, not-affected, and needs-analysis findings differently.
What this workflow does
- SupplyChainEvidence receives CycloneDX SBOM and VEX JSON
- CorrelateSbomAndVex joins components and statements by package URL
- AssessExploitability creates a structured triage decision
- RouteVexDisposition splits exploitable, not-affected, and unresolved results
- Exploitable findings become a GitHub remediation issue
- Not-affected evidence is archived in DataTable
- Unresolved findings go to the application security Slack channel
Use cases
- SBOM vulnerability triage
- CycloneDX and VEX correlation
- Software supply chain risk reduction
- Evidence-backed CVE remediation routing
Setup
Paste representative CycloneDX and VEX JSON in the input fields, then connect an LLM credential, GitHub, DataTable, and Slack. Verify package URLs and VEX status claims against the signed source before closing a vulnerability.
How to import this template
- 1Click Import → Copy JSON on this page.
- 2Open your Heym and navigate to a workflow canvas.
- 3PressCmd+V/Ctrl+V— nodes appear instantly.
- 4Add your API keys in the node config panels and click Run.
Discover more automations
- Dev & IT OpsHTML Status PageCheck an upstream service and answer a browser GET with a rendered status page instead of JSON.
- Dev & IT OpsWorkflow Change Audit LogCapture every workflow create, update, and delete on your Heym instance and post a batched summary to Slack.
- Dev & IT OpsCodex PR Fix AgentSend a coding task to Codex, open a draft PR when it succeeds, and notify Slack when Codex needs follow-up input.
- Dev & IT OpsOpenCode Go PR Fix AgentSend a coding task to OpenCode Go, open a review-ready pull request, and return the implementation result.
- Dev & IT OpsAgent-Guided Codex PR DispatcherLet an Agent inspect a GitHub request, prepare a confirmed Codex task, open a ready PR, and notify Slack when Codex needs input.
- Dev & IT OpsCursor Post NotifierMonitor the Cursor blog on a schedule and Slack-notify your team when a new post goes live.
- Dev & IT OpsClaude Blog MonitorMonitor the Anthropic blog on a schedule and Slack-notify your team on new Claude posts.
- Dev & IT OpsGitHub Release RadarCompare the latest GitHub release tag against Redis and notify Slack when a project ships a new version.
- Dev & IT Opsweb.dev Article MonitorCron + crawler + Redis dedupe + Slack: get notified when Google's web.dev blog publishes a new article.
- Dev & IT OpsCloudback MCP Backup Coverage ReviewReview Cloudback backup coverage with a Docker-based MCP server, gate configuration changes with HITL, and notify ops in Slack.
- Dev & IT OpsResilient HTTP + Error HandlerAttach an Error Handler node to an HTTP call and Slack-notify your team the moment a request fails.
- Dev & IT OpsPlaywright Visual AI MonitorTake a full-page screenshot on a schedule, analyse it with an LLM for anomalies, and Slack-alert when something looks off.