{
 "use_case": "vex-triage",
 "title": "VEX triage: three findings on the public nginx:1.20.0 image",
 "about": "The official nginx:1.20.0 image (May 2021) scanned with Grype, and the collector's evidence bundle for three of its findings. libwebp's CVE-2023-4863 is known exploited, but only the image filter module loads libwebp and the shipped nginx.conf does not load it: it must come back not_affected with vulnerable_code_not_in_execute_path. OpenSSL's CVE-2022-0778 is in a library nginx itself links: affected. CVE-2009-4487, where NVD lists a single exact nginx version, must never be not_affected on that weak evidence. The signed OpenVEX must verify, and fail once a status is changed; the evidence record must verify.",
 "licence": "Public image (Docker Official Image nginx:1.20.0). Scanner report: Grype 0.119 (Apache-2.0); evidence bundle from decosa-api's collector (Apache-2.0). Advisory text comes from the API's own store (OSV.dev and NVD, public). Part of decosa-api, AGPL-3.0-or-later.",
 "inputs": [
  {
   "file": "inputs/grype.json",
   "what": "Grype's JSON report for nginx:1.20.0, cut to the three findings (four package matches)."
  },
  {
   "file": "inputs/evidence.json",
   "what": "The collector's evidence bundle for those findings: file index size, loader chains, config excerpts."
  }
 ],
 "steps": [
  {
   "id": "triage",
   "method": "POST",
   "path": "/vex/triage",
   "timeout": 300,
   "body": {
    "findings": {
     "$file": "inputs/grype.json"
    },
    "evidence": {
     "$file": "inputs/evidence.json"
    },
    "author": "Rehearsal PSIRT",
    "title": "Rehearsal: nginx:1.20.0"
   }
  },
  {
   "id": "verify",
   "method": "POST",
   "path": "/vex/verify",
   "auth": false,
   "body": {
    "envelope": {
     "$ref": "triage.envelopes.openvex"
    }
   }
  },
  {
   "id": "tampered",
   "method": "POST",
   "path": "/vex/verify",
   "auth": false,
   "body": {
    "envelope": {
     "$ref": "triage.envelopes.openvex"
    }
   },
   "tamper": {
    "at": "envelope.payload",
    "set": "eyJzdGF0ZW1lbnRzIjogW119"
   }
  },
  {
   "id": "record",
   "method": "POST",
   "path": "/record/verify",
   "auth": false,
   "body": {
    "record": {
     "$ref": "triage.record"
    }
   }
  }
 ],
 "checks": [
  {
   "says": "libwebp's known-exploited CVE-2023-4863 is not in the execute path (only an unloaded module loads it)",
   "path": "triage.statements[id=CVE-2023-4863][0].justification",
   "equals": "vulnerable_code_not_in_execute_path"
  },
  {
   "says": "and its status is not_affected",
   "path": "triage.statements[id=CVE-2023-4863][0].status",
   "equals": "not_affected"
  },
  {
   "says": "OpenSSL's CVE-2022-0778 stays affected for both packages",
   "path": "triage.statements[id=CVE-2022-0778].status",
   "all_in": [
    "affected"
   ]
  },
  {
   "says": "CVE-2009-4487 is never not_affected on an exact-version NVD entry",
   "path": "triage.statements[id=CVE-2009-4487][0].status",
   "in": [
    "affected",
    "under_investigation"
   ]
  },
  {
   "says": "the OpenVEX document names the author",
   "path": "triage.openvex.author",
   "equals": "Rehearsal PSIRT"
  },
  {
   "says": "every statement is marked pending review",
   "path": "triage.openvex.statements[0].status_notes",
   "contains": "pending review"
  },
  {
   "says": "the signed OpenVEX verifies",
   "path": "verify.valid_signature",
   "equals": true
  },
  {
   "says": "a changed OpenVEX payload does not",
   "path": "tampered.valid_signature",
   "equals": false
  },
  {
   "says": "the evidence record verifies",
   "path": "record.ok",
   "equals": true
  },
  {
   "says": "every model call has a signed receipt",
   "receipts": "signed",
   "min": 3
  }
 ]
}