VEXine: Automating SBOM and VEX Generation Using Transformer LLM Models with LangGraph
摘要
As software systems grow more complex and supply chain attacks become more advanced, ensuring security and transparency is a global priority. This paper introduces VEXine, an AI-powered framework that automates the generation of Software Bill of Materials (SBOM) and Vulnerability Exploitability Exchange (VEX) reports using transformer-based large language models. By combining advanced AI with automated security assessment tools, VEXine enhances the accuracy, efficiency, and scalability of supply chain vulnerability management. Evaluations against traditional software composition analysis (SCA) tools show that VEXine delivers superior performance, providing actionable insights and addressing critical security challenges in modern software ecosystems.