OpenVEX Documents for Maintained OTP Releases

The otp-<REL>.openvex.json documents describe vulnerabilities in Erlang/OTP and in third party products (3pps) that have been embedded into the Erlang/OTP source code and how they affect Erlang/OTP. The otp-<REL>.openvex.json.sigstore documents can be used to verify the authenticity of the corresponding otp-<REL>.openvex.json file.

You may link against the same 3pps when building Erlang/OTP (for example, OpenSSL when building the crypto application). Note that the evaluations of 3pps in these documents do not cover such usage of the 3pps.