In this article
Security/Vex Standards
| Field | Value |
|---|---|
| Kind | instruction |
| Source | .github/instructions/security/vex-standards.instructions.md |
| Invocation | Applied automatically to **/security/vex/**, **/.copilot-tracking/security/vex/** |
| Interactive | No |
What it does
VEX document standards: canonical rule reference, licensing posture, author-of-record contract, and document mutation contract for OpenVEX management - Brought to you by microsoft/hve-core
When to use it
Apply these standards whenever files under security/vex/ or its tracking root
create, change, or review OpenVEX statements. Follow the canonical vex skill
logic, source licensing, and human author-of-record contract; statement changes
must also refresh rolling-document metadata and provenance.
Example usage
Provide a concrete example that shows the asset in action, including representative input and the resulting output.