DevGuard VEX Rules API

The DevGuard VEX Rules API lets you define and manage Vulnerability Exploitability eXchange (VEX) rules. A rule pairs a CEL expression with a decision — accept risk or false positive with a mechanical justification — and DevGuard applies it to every matching dependency vulnerability in the asset.

Rules are identified by the combination of asset, CEL expression and source, so there is no update operation: change an expression by deleting the rule and creating a new one. The test endpoint evaluates expressions against the asset's open vulnerabilities without creating anything.

For the concepts and the equivalent web UI flows, see Create & Manage VEX Rules.


Have feedback? We want to hear from you!

Fields marked with * are required