
VEX Repository Specification
The keywords "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in RFC 2119.
When comparing versions:
Example comparisons:
The manifest file provides metadata about a VEX data repository. This file MUST contain information necessary for retrieving and updating VEX data.
https://<domain>/.well-known/vex-repository.jsonvex-repository.json MUST be placed in the root directory of the main branch.The JSON schema for the manifest file is defined here.
{
"name": "Example Org VEX Repository",
"description": "VEX repository for Example Organization",
"versions": [
{
"spec_version": "0.1",
"locations": [
{
"url": "https://example.com/vex-hub/v0/vex-data-v0.tar.gz"
}
],
"update_interval": "24h",
"repository_specific": {
"location": {
"repository_type": "db",
"db_type": "bbolt",
"url": "oci://ghcr.io/example.com/vex-db:0"
}
}
},
{
"spec_version": "1.0",
"locations": [
{
"url": "https://example.com/vex-hub/v1/vex-data-v1.tar.gz//subdirectory"
},
{
"url": "https://example.com/vex-api/v1"
}
],
"update_interval": "1h"
}
]
}
| Field | Required | Description and Usage Notes |
|---|---|---|
| name | ✓ | The name of the repository. |
| description | ✓ | A brief description of the repository. |
| versions | ✓ | An array containing details of available versions. Each object in the array represents a version implementing a VEX Repository Specification version. Versions MUST be sorted in ascending order, from oldest to newest. See separate table for subfields. |
| Field | Required | Description and Usage Notes |
|---|---|---|
| spec_version | ✓ | The version of the VEX Repository Specification implemented (e.g., "0.1"). Format MUST be "X.Y" as defined in section 1. |
| locations | ✓ | An array of objects describing VEX data locations. MUST contain at least one location object. See separate table for subfields. |
| update_interval | ✓ | The recommended update check interval for this version's VEX data. Uses Go duration format (e.g., "1h", "30m", "24h"). |
| repository_specific | - | Additional repository-specific information. |
| Field | Required | Description and Usage Notes |
|---|---|---|
| url | ✓ | A URL for the VEX data location, starting with "https://". The content adheres to the repository structure specifications in section 3 and 4. The URL may include a subdirectory specification by appending '//' followed by the subdirectory path. |
The repository MUST have the following structure:
vex-repository.<archive_extension>
[optional_subdirectory/]
├── index.json
└── pkg/
├── <type>/
│ ├── <namespace>/
│ │ ├── <name>/
│ │ │ └── vex.json
│ │ └── ...
│ └── ...
└── ...
Where <archive_extension> is one of supported archive formats.