Product Logo
A
Admission Control

(Kubernetes) policy mechanism to enforce conditions (e.g., vulnerability scan) before deployment.

Attestation

Meta-Data Documents ( usually signed ) to OCI-Container Images.

Attested

Adding Meta-Data Documents ( usually signed ) to OCI-Container Images.

B
BOV

The Bill of Vulnerabilities (BOV) is a standardized way to exchange vulnerability information between systems, enabling organizations to share complex vulnerability data effectively. By focusing on a machine-readable format, BOV simplifies the communication of vulnerability metadata such as severities, risk ratings, and remediation details.

C
CI

Continuous Integration (CI) in GitLab ist ein automatisierter Prozess, der Codeänderungen fortlaufend zusammenführt, baut, testet und validiert, um frühzeitig Fehler zu erkennen und die Softwarequalität sicherzustellen

CI/CD

CI/CD ist ein kontinuierlicher, standardisierter Mechanismus, der über Versionierung getriggert wird und Qualität und Lieferung automatisiert

Cosign

Tool from Sigstore to sign and verify container images and attach attestations.

CRA

Cyber Resilience Act – EU regulation on cybersecurity of IT products.

CSAF

Common Security Advisory Framework – standard format for structured security advisories.

CVE

Common Vulnerabilities and Exposures – unique identifier for known security vulnerabilities.

CVSS

Common Vulnerability Scoring System – rating scale for vulnerabilities from 0 to 10.

Cyber Resilience Act

CRA – EU regulation on cybersecurity of IT products.

CycloneDX

SBOM standard focused on application security use cases.

D
DevGuard

Open-Source Security platform for CVE matching and VEX workflows. More on https://devguard.org .

Digest

Immutable cryptographic hash (SHA256) that uniquely identifies a container image.

F
False Positive

Reported but non-relevant vulnerability.

G
GitLab-CI/CD

CI/CD ist ein kontinuierlicher, standardisierter Mechanismus, der über Versionierung getriggert wird und Qualität und Lieferung automatisiert

Guide

Guide bezeichnet in der Softwareentwicklung eine strukturierte Anleitung oder Dokumentation, die Entwicklerinnen und Entwicklern hilft, bestimmte Aufgaben korrekt und effizient zu erledigen.

I
Image

Refers to OCI-Container Images.

ISO/IEC 18974

Standard for processes in handling vulnerabilities.

Issue

Ein Issue in GitLab ist ein zentrales Element zur Nachverfolgung von Aufgaben, Fehlern, Feature-Wünschen und sonstigen Arbeitspaketen innerhalb eines Projekts

IT

Informationstechnik

K
Kyverno

Kubernetes policy engine used for admission control, validation, and security enforcement.

M
Mitigation

Measure to reduce the risk of a vulnerability.

N
Notary

CNCF project for signing and verifying container images.

NVD

National Vulnerability Database – official CVE database with ratings.

O
OCI

Open Container Initiative – industry standard for container images and their distribution.

OCI Attestation

Metadata attached to a container image digest to provide supply chain security information.

openVEX

Minimal VEX implementation that uses JSON for efficient CVE status communication.

P
PDF

Portable Document Format ist ein plattformunabhängiges Dateiformat für elektronische Dokumente. Diese unabhängig vom ursprünglichen Anwendungsprogramm originalgetreu wiedergegeben werden kann.

Primary Package Predicate

Minimal JSON file declaring the shipped component in an image.

Provenance

Metadata describing how and from what source an artifact was built (e.g., SLSA provenance).

PURL

Package URL – a standardized way to identify software packages across ecosystems.

R
Reverse SBOM

SBOM generated automatically from a built container image (not from source).

S
SBOM

Software Bill of Materials – inventory of all software components and versions.

SCA

Software Composition Analysis – analysis of dependencies and known vulnerabilities.

SCCON

Smart Country Convention - The leading event for the digital state and public services. Three Days of Congress, Expo, Workshops & Networking.

SLSA

Supply-chain Levels for Software Artifacts – framework for supply chain integrity.

SPDX

Software Package Data Exchange – SBOM standard used across industry.

T
Tools

Bezeichnet digitale Werkzeuge die ein Prozess standardisieren und vereinfachen.

True Positive

Confirmed, relevant vulnerability.

U
UA

(Universal Accessibility; englisch für „Universeller Zugang“) ist ein Substandard des PDF-Standards (ISO 32000-1) für barrierefreie PDF-Dokumente.

V
VEX

Vulnerability Exploitability eXchange – format for specifying whether a CVE affects a software product.