The otp-<REL>.openvex.json documents
describe vulnerabilities in Erlang/OTP and in third party
products (3pps) that have been embedded into the Erlang/OTP
source code, and how they affect Erlang/OTP. The
otp-<REL>.openvex.json.sigstore documents
can be used to verify the authenticity of the corresponding
otp-<REL>.openvex.json file.
Note: that the evaluations of 3pps in these
VEX files only apply to the usage of the
embedded code in OTP and does not apply to
usage of the same 3pps when linked via a NIF or a driver. As
an example, parts of OpenSSL is embedded in some versions of
OTP and you typically link against OpenSSL when you build
the crypto NIF. The crypto NIF may very well be
affected by vulnerabilities in OpenSSL even when OTP is not
affected by those vulnerabilities from the usage of the
embedded code of OpenSSL.
Verifying the OpenVEX signature
Each otp-<REL>.openvex.json.sigstore
file is a sigstore bundle produced by the
Erlang/OTP release automation on GitHub. It is a single
SLSA provenance attestation that covers the OpenVEX
documents for all maintained releases; the same bundle is
published alongside each document. The signature covers
the document content, so the files can be renamed without
affecting verification.
Verify a downloaded OpenVEX document with the
sigstore
CLI. Install it with pip install sigstore,
then run:
$ sigstore verify identity \
--bundle otp-29.openvex.json.sigstore \
--cert-identity "https://github.com/erlang/otp/.github/workflows/reusable-vex-attest.yml@refs/heads/master" \
--cert-oidc-issuer "https://token.actions.githubusercontent.com" \
otp-29.openvex.json
OK: otp-29.openvex.json
Note: Verification requires network access to fetch the sigstore trust root.
Downloads
| OTP Release | OpenVEX Document | Signature |
|---|---|---|
| OTP 29 | otp-29.openvex.json |
otp-29.openvex.json.sigstore |
| OTP 28 | otp-28.openvex.json |
otp-28.openvex.json.sigstore |
| OTP 27 | otp-27.openvex.json |
otp-27.openvex.json.sigstore |