We are using Docker Hardened Images (DHI), specifically dhi.io/debian-base, and scanning them with JFrog Xray.
Some CVEs reported by Xray appear to have been marked as not exploitable according to a VEX statement. However, we are unable to determine how to retrieve this VEX information from the image or from Docker.
What is the recommended way to access the VEX data associated with a DHI image?
Additionally, is there a supported method to export or consume this VEX information so that it can be integrated into JFrog Xray reports and vulnerability management workflows?
Any documentation or examples would be appreciated.