-
Notifications
You must be signed in to change notification settings - Fork 12
Open
Description
From today's SPWG meeting, the current CVE JSON format (unsurprisingly) almost implements VEX, as defined here:
https://www.cisa.gov/sites/default/files/2023-04/minimum-requirements-for-vex-508c.pdf
Should CVE JSON be compatible with VEX?
At a glance, changes would need to be made to status, and some additional VEX-specific fields would need to be added, such as:
- not_affected/justification
- action_statement
- impact_statement
- some timestamps (maybe, may be able to reuse existing timestamps)
Status justification would need a definition.
See also #8 which also includes CSAF integration, which I do not think is appropriate for CVE JSON.
Metadata
Metadata
Assignees
Labels
No labels