The otp-<REL>.openvex.json documents describe vulnerabilities in Erlang/OTP and in third party products (3pps) that have been embedded into the Erlang/OTP source code, and how they affect Erlang/OTP. The otp-<REL>.openvex.json.sigstore documents can be used to verify the authenticity of the corresponding otp-<REL>.openvex.json file.

Note: that the evaluations of 3pps in these VEX files only apply to the usage of the embedded code in OTP and does not apply to usage of the same 3pps when linked via a NIF or a driver. As an example, parts of OpenSSL is embedded in some versions of OTP and you typically link against OpenSSL when you build the crypto NIF. The crypto NIF may very well be affected by vulnerabilities in OpenSSL even when OTP is not affected by those vulnerabilities from the usage of the embedded code of OpenSSL.

Verifying the OpenVEX signature

Each otp-<REL>.openvex.json.sigstore file is a sigstore bundle produced by the Erlang/OTP release automation on GitHub. It is a single SLSA provenance attestation that covers the OpenVEX documents for all maintained releases; the same bundle is published alongside each document. The signature covers the document content, so the files can be renamed without affecting verification.

Verify a downloaded OpenVEX document with the sigstore CLI. Install it with pip install sigstore, then run:

$ sigstore verify identity \
            --bundle otp-29.openvex.json.sigstore \
            --cert-identity "https://github.com/erlang/otp/.github/workflows/reusable-vex-attest.yml@refs/heads/master" \
            --cert-oidc-issuer "https://token.actions.githubusercontent.com" \
            otp-29.openvex.json
      OK: otp-29.openvex.json

Note: Verification requires network access to fetch the sigstore trust root.

Downloads

Maintained OTP releases
OTP Release OpenVEX Document Signature
OTP 29 otp-29.openvex.json otp-29.openvex.json.sigstore
OTP 28 otp-28.openvex.json otp-28.openvex.json.sigstore
OTP 27 otp-27.openvex.json otp-27.openvex.json.sigstore