First-Class SBOMSoftware Bill of Materials - a complete list of all packages and dependencies in your software & VEXVulnerability Exploitability eXchange - machine-readable statements about whether vulnerabilities are actually exploitable in your context

Know What’s in Your Containers

Generate industry-standard SBOMs and apply VEXVulnerability Exploitability eXchange - machine-readable statements about whether vulnerabilities are actually exploitable in your context statements from multiple sources — with intelligent conflict resolution and offline verification built in.

What this means for your business

Know exactly what's in every release and which advisories apply. Stella generates signed SBOMs and resolves conflicting VEXVulnerability Exploitability eXchange - machine-readable statements about whether vulnerabilities are actually exploitable in your context statements so compliance teams get one clear picture. VEXVulnerability Exploitability eXchange - machine-readable statements about whether vulnerabilities are actually exploitable in your context

Industry-Standard Formats

Stella generates SBOMs in the formats your auditors and compliance teams expect, with full component metadata and provenance.

SPDX 3.0.1

The latest ISO/IEC 5962 standard with full supplier metadata and SPDXSoftware Package Data Exchange - another open standard format for SBOMs, widely used in open source license expressions.

CycloneDX 1.7

OWASP CycloneDXAn open standard format for software bill of materials (SBOM) used across the industry with integrated VEXVulnerability Exploitability eXchange - machine-readable statements about whether vulnerabilities are actually exploitable in your context support and dependency graph extensions.

Generate, verify, and publish SBOMs from the CLI

Terminal
$ stella sbom generate --image myapp:v2.1.0 --format Spdx --output sbom.spdx.json
$ stella sbom verify --archive sbom.tar.gz --offline
$ stella sbom attach --image myapp:v2.1.0 --digest sha256:8c1a4f…

Why It Matters

SBOMs are becoming mandatory. Stella makes them practical.

Reproducible Results

Same image, same SBOMSoftware Bill of Materials - a complete list of all packages and dependencies in your software — every time. Auditors can verify your results independently.

Works Offline

Generate and verify SBOMs in air-gapped environments. No external calls required.

Compliance Ready

Supports EO 14028, EU CRA, and other supply chain security requirements with signed, verifiable SBOMs.

Cryptographically Signed

Every SBOMSoftware Bill of Materials - a complete list of all packages and dependencies in your software is signed and tamper-evident. Evidence you can trust.

VEX: Context for Vulnerabilities

Not every CVECommon Vulnerabilities and Exposures - a unique identifier for a publicly known security vulnerability affects you. VEXVulnerability Exploitability eXchange - machine-readable statements about whether vulnerabilities are actually exploitable in your context (Vulnerability Exploitability eXchange) statements let vendors and your own analysis say which vulnerabilities actually matter for your specific deployment.

Affected

Not Affected

Fixed

Under Investigation

VEXVulnerability Exploitability eXchange - machine-readable statements about whether vulnerabilities are actually exploitable in your context cuts through the noise: a CVECommon Vulnerabilities and Exposures - a unique identifier for a publicly known security vulnerability in a library you don’t use isn’t your problem. Stella applies VEX statements automatically to focus your attention on what matters.

What this means for your business

When scanners disagree, see all evidence instead of a silent override. Stella surfaces conflicts so your team makes informed decisions — fewer missed vulnerabilities, less wasted remediation.

How conflict states are computed (advanced)

When multiple VEXVulnerability Exploitability eXchange - machine-readable statements about whether vulnerabilities are actually exploitable in your context sources disagree, Stella uses Belnap’s four-valued logic to compute the definitive state. Conflicts become visible, not hidden. ⊥ Unknown No information yet. Default state before any VEXVulnerability Exploitability eXchange - machine-readable statements about whether vulnerabilities are actually exploitable in your context statement applies. T Affected At least one issuer says this vulnerability affects you. F Not Affected At least one issuer says you’re not affected. ⊤ Conflict Multiple issuers disagree. Requires review or higher-authority override. Vendor says “not affected” but your runtime probe saw the function called? Result: Conflict (⊤) — the disagreement is visible, not silently suppressed. No silent suppression. No hidden assumptions. Uncertainty is tracked and surfaced.
Read more

When multiple VEXVulnerability Exploitability eXchange - machine-readable statements about whether vulnerabilities are actually exploitable in your context sources disagree, Stella uses Belnap’s four-valued logic to compute the definitive state. Conflicts become visible, not hidden.

Unknown

No information yet. Default state before any VEXVulnerability Exploitability eXchange - machine-readable statements about whether vulnerabilities are actually exploitable in your context statement applies.

T

Affected

At least one issuer says this vulnerability affects you.

F

Not Affected

At least one issuer says you’re not affected.

Conflict

Multiple issuers disagree. Requires review or higher-authority override.

Vendor says “not affected” but your runtime probe saw the function called? Result: Conflict (⊤) — the disagreement is visible, not silently suppressed.

No silent suppression. No hidden assumptions. Uncertainty is tracked and surfaced.

Multi-source VEX aggregation (advanced)

Vendors, distributors, and your own security team may all publish VEXVulnerability Exploitability eXchange - machine-readable statements about whether vulnerabilities are actually exploitable in your context statements. Stella aggregates them with weighted consensus. Ingest VEXVulnerability Exploitability eXchange - machine-readable statements about whether vulnerabilities are actually exploitable in your context from software vendors, Linux distributors, and internal sources Sources are weighted by authority — your internal assessments can override external ones Conflicts trigger review workflows rather than being silently resolved One View of Truth Instead of juggling spreadsheets and emails, get a single authoritative view of which vulnerabilities actually affect your release.
Read more

Vendors, distributors, and your own security team may all publish VEXVulnerability Exploitability eXchange - machine-readable statements about whether vulnerabilities are actually exploitable in your context statements. Stella aggregates them with weighted consensus.

  • Ingest VEXVulnerability Exploitability eXchange - machine-readable statements about whether vulnerabilities are actually exploitable in your context from software vendors, Linux distributors, and internal sources
  • Sources are weighted by authority — your internal assessments can override external ones
  • Conflicts trigger review workflows rather than being silently resolved

One View of Truth

Instead of juggling spreadsheets and emails, get a single authoritative view of which vulnerabilities actually affect your release.

Ready for practical SBOM compliance?

Install Stella Ops and start generating auditor-ready SBOMs with multi-source VEXVulnerability Exploitability eXchange - machine-readable statements about whether vulnerabilities are actually exploitable in your context support.