FeaturedDev & IT Ops#SBOM#VEX#CycloneDX#Software Supply Chain#CVE Triage#AppSec

SBOM and VEX Exploitability Triage

Correlate CycloneDX components with VEX statements, prioritize exploitable findings, and open evidence-rich remediation work.

Workflow at a glance

The full canvas, before you import it

Click any node to see its config.

#SBOM#VEX#CycloneDX#Software Supply Chain#CVE Triage#AppSec

Click a node to select it — same as the Heym editor; the panel shows its settings.

10 nodes · Free & source-available

SBOM and VEX Exploitability Triage

Reduce noisy software supply chain alerts by comparing an SBOM with Vulnerability Exploitability eXchange statements. The workflow normalizes package identifiers, highlights unresolved components, and routes exploitable, not-affected, and needs-analysis findings differently.

What this workflow does

  1. SupplyChainEvidence receives CycloneDX SBOM and VEX JSON
  2. CorrelateSbomAndVex joins components and statements by package URL
  3. AssessExploitability creates a structured triage decision
  4. RouteVexDisposition splits exploitable, not-affected, and unresolved results
  5. Exploitable findings become a GitHub remediation issue
  6. Not-affected evidence is archived in DataTable
  7. Unresolved findings go to the application security Slack channel

Use cases

  • SBOM vulnerability triage
  • CycloneDX and VEX correlation
  • Software supply chain risk reduction
  • Evidence-backed CVE remediation routing

Setup

Paste representative CycloneDX and VEX JSON in the input fields, then connect an LLM credential, GitHub, DataTable, and Slack. Verify package URLs and VEX status claims against the signed source before closing a vulnerability.

How to import this template

  1. 1Click Import → Copy JSON on this page.
  2. 2Open your Heym and navigate to a workflow canvas.
  3. 3PressCmd+V/Ctrl+V— nodes appear instantly.
  4. 4Add your API keys in the node config panels and click Run.
More workflow templates
View all templates
Heym
incident analysis · production AI
Observed across 100s of AI rollouts

AI workflows don't fail because of prompts.
They fail because of orchestration.

symptom · glue code01
5 tools
Scripts, vector DB, approval bot, tracing, browser runner — none of them talk.
symptom · visibility02
~0%
Observable behavior across the stack. Debugging is guesswork.
with heym · one runtime
1 canvas
Agents, RAG, HITL, MCP, traces & evals. Self-hosted. Observable.
AI-Native RuntimeProduction-Grade
github.com/heymrun/heym