Skip to main content

In this article

vex-implement

vex-implement
FieldValue
Kindprompt
Source.github/prompts/security/vex-implement.prompt.md
InvocationSlash command /vex-implement
InteractiveYes

What it does

Plan the work to stand up VEX in a target project as a backlog for Task-* implementors - Brought to you by microsoft/hve-core

When to use it

Use this prompt to plan the backlog needed to establish VEX generation and management in a target project. Use vex-scan for an existing project that is ready to scan and draft a VEX document now.

How to use it

Optionally provide the project scope and product package URL. The prompt plans and delegates implementation work; it does not publish VEX statements or replace the product's qualified author of record.

Example usage

/vex-implement scope=packages/api product=pkg:npm/@example/sample-api

The prompt creates a reviewable backlog for adding VEX capabilities to the fictional package.