Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Editor revision for TC meeting 2025-02-26 #885

Open
wants to merge 78 commits into
base: master
Choose a base branch
from
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
78 commits
Select commit Hold shift + click to select a range
68e5ca0
SSVC
tschmidtb51 Jan 16, 2025
4eecfc2
SSVC
tschmidtb51 Jan 16, 2025
a38b394
SSVC
tschmidtb51 Jan 16, 2025
789785c
SSVC
tschmidtb51 Jan 16, 2025
599b150
SSVC
tschmidtb51 Jan 16, 2025
7ac9c47
SSVC
tschmidtb51 Jan 16, 2025
23556f3
Seed Editor revision 2025-02-26
tschmidtb51 Feb 19, 2025
a239382
DNS Domain
tschmidtb51 Feb 19, 2025
18a30ee
Merge pull request #867 from tschmidtb51/editorial-2025-02-26
tschmidtb51 Feb 20, 2025
7a9fae0
DNS Domain
tschmidtb51 Feb 20, 2025
c6889a5
Merge remote-tracking branch 'upstream/editor-revision-2025-02-26' in…
tschmidtb51 Feb 20, 2025
4d23886
SSVC
tschmidtb51 Feb 20, 2025
4946309
SSVC
tschmidtb51 Feb 20, 2025
9762db1
SSVC
tschmidtb51 Feb 20, 2025
1ec5b95
SSVC
tschmidtb51 Feb 20, 2025
e53d883
Merge pull request #868 from tschmidtb51/dns-domain
tschmidtb51 Feb 20, 2025
07cfab1
SSVC
tschmidtb51 Feb 20, 2025
cd9aabf
SSVC
tschmidtb51 Feb 20, 2025
52f5d9b
SSVC
tschmidtb51 Feb 20, 2025
5029755
Fixed CWE link with multiple targets #870
sthagen Feb 20, 2025
1136122
SSVC
tschmidtb51 Feb 20, 2025
95cc120
SSVC
tschmidtb51 Feb 20, 2025
946d25e
SSVC
tschmidtb51 Feb 20, 2025
7291d49
SSVC
tschmidtb51 Feb 20, 2025
e7f49c8
SSVC
tschmidtb51 Feb 20, 2025
12e3f58
Model and Serial Number
tschmidtb51 Feb 21, 2025
51b3efb
Model and Serial Number
tschmidtb51 Feb 21, 2025
1421c2f
Model and Serial Number
tschmidtb51 Feb 21, 2025
674e64d
SSVC
tschmidtb51 Feb 21, 2025
4c11d5e
Model and Serial Number
tschmidtb51 Feb 21, 2025
23518a7
Nit: Distribution of a sentence across two lines.
sthagen Feb 21, 2025
87be620
Model and Serial Number
tschmidtb51 Feb 21, 2025
c581d40
Model and Serial Number
tschmidtb51 Feb 21, 2025
f29dd52
Model and Serial Number
tschmidtb51 Feb 21, 2025
e7f3ddd
Initial release date
tschmidtb51 Feb 21, 2025
34b150f
Initial release date
tschmidtb51 Feb 21, 2025
1c9b84b
Initial release date
tschmidtb51 Feb 21, 2025
1dcd329
simplify language
sthagen Feb 24, 2025
f443bdb
Simplify and match plurality
sthagen Feb 24, 2025
0a7a9c7
Adapt plurality
sthagen Feb 24, 2025
8772a18
Review feedback on matchin rules
sthagen Feb 24, 2025
39a992a
Initial release date
tschmidtb51 Feb 24, 2025
f3f2cde
Initial release date
tschmidtb51 Feb 24, 2025
fca42fe
Model and Serial Number
tschmidtb51 Feb 24, 2025
4b694e3
Disclosure Date
tschmidtb51 Feb 26, 2025
6a0df71
Disclosure Date
tschmidtb51 Feb 26, 2025
5d9002b
Disclosure Date
tschmidtb51 Feb 26, 2025
bc9a183
Disclosure Date
tschmidtb51 Feb 26, 2025
b006461
Disclosure Date
tschmidtb51 Feb 26, 2025
dcc987a
Disclosure Date
tschmidtb51 Feb 26, 2025
f66606e
Disclosure Date
tschmidtb51 Feb 26, 2025
22613fd
Merge pull request #872 from tschmidtb51/pih-numbers
tschmidtb51 Feb 26, 2025
97f8f01
Merge pull request #873 from tschmidtb51/clarify-initial_release_date
tschmidtb51 Feb 27, 2025
a77be1e
Merge remote-tracking branch 'upstream/editor-revision-2025-02-26' in…
tschmidtb51 Feb 27, 2025
7d9d451
Disclosure Date
tschmidtb51 Feb 28, 2025
b13b272
Disclosure Date
tschmidtb51 Feb 28, 2025
07a6877
Disclosure Date
tschmidtb51 Feb 28, 2025
62154b7
Disclosure Date
tschmidtb51 Feb 28, 2025
69eb92d
Disclosure Date
tschmidtb51 Feb 28, 2025
24109fd
Disclosure Date
tschmidtb51 Feb 28, 2025
c41d8f6
Daten and Time
tschmidtb51 Feb 28, 2025
db0cfa5
Nit: More direct, closer to the format terms
sthagen Feb 28, 2025
c4a03ae
Nits: typo and varied speech
sthagen Feb 28, 2025
c7a22c4
Nit: Replaced not newer with earlier or equal to
sthagen Feb 28, 2025
7e90404
Nit: Replaced not newer with earlier or equal to
sthagen Feb 28, 2025
ab891f7
Merge pull request #879 from tschmidtb51/disclosure_date
tschmidtb51 Feb 28, 2025
85aefd8
SSVC
tschmidtb51 Mar 1, 2025
f7fbb1f
Merge remote-tracking branch 'upstream/editor-revision-2025-02-26' in…
tschmidtb51 Mar 1, 2025
4a421c3
SSVC
tschmidtb51 Mar 1, 2025
3d3ad6e
SSVC
tschmidtb51 Mar 1, 2025
789e037
SSVC
tschmidtb51 Mar 1, 2025
8e19dc4
SSVC
tschmidtb51 Mar 1, 2025
ac5052f
Merge pull request #871 from tschmidtb51/ssvc
tschmidtb51 Mar 4, 2025
11333d6
Suggested from review feedback / dsicussions
sthagen Mar 4, 2025
5858221
Fixed entry in the binder
sthagen Mar 4, 2025
39939b9
Completed section and example mappings
sthagen Mar 4, 2025
f1d5bf3
Further review discussion results
sthagen Mar 4, 2025
4d909c6
Updated user facing delivery items
sthagen Mar 4, 2025
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions csaf_2.1/examples/csaf/rhsa-2021_5186.json
Original file line number Diff line number Diff line change
Expand Up @@ -173,6 +173,7 @@
"version": "4.6"
}
],
"disclosure_date": "2021-12-10T00:00:00Z",
"discovery_date": "2021-12-13T00:00:00Z",
"ids": [
{
Expand Down Expand Up @@ -228,7 +229,6 @@
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2031667"
}
],
"release_date": "2021-12-10T00:00:00Z",
"remediations": [
{
"category": "vendor_fix",
Expand All @@ -252,6 +252,7 @@
},
{
"cve": "CVE-2021-4125",
"disclosure_date": "2021-12-16T00:00:00Z",
"discovery_date": "2021-12-16T00:00:00Z",
"ids": [
{
Expand Down Expand Up @@ -297,7 +298,6 @@
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2033121"
}
],
"release_date": "2021-12-16T00:00:00Z",
"remediations": [
{
"category": "vendor_fix",
Expand All @@ -320,4 +320,4 @@
"title": "CVE-2021-4125 kube-reporting/hive: Incomplete fix for log4j CVE-2021-44228 and CVE-2021-45046"
}
]
}
}
4 changes: 2 additions & 2 deletions csaf_2.1/examples/csaf/rhsa-2021_5217.json
Original file line number Diff line number Diff line change
Expand Up @@ -124,6 +124,7 @@
"version": "4.6"
}
],
"disclosure_date": "2021-12-16T17:05:00Z",
"discovery_date": "2021-12-17T00:00:00Z",
"ids": [
{
Expand Down Expand Up @@ -165,7 +166,6 @@
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2033602"
}
],
"release_date": "2021-12-16T17:05:00Z",
"remediations": [
{
"category": "vendor_fix",
Expand All @@ -186,4 +186,4 @@
"title": "CVE-2021-4133 Keycloak: Incorrect authorization allows unpriviledged users to create other users"
}
]
}
}
4 changes: 2 additions & 2 deletions csaf_2.1/examples/csaf/rhsa-2022_0011.json
Original file line number Diff line number Diff line change
Expand Up @@ -348,6 +348,7 @@
"version": "4.6"
}
],
"disclosure_date": "2020-02-28T00:00:00Z",
"discovery_date": "2020-03-06T00:00:00Z",
"ids": [
{
Expand Down Expand Up @@ -393,7 +394,6 @@
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1811673"
}
],
"release_date": "2020-02-28T00:00:00Z",
"remediations": [
{
"category": "vendor_fix",
Expand Down Expand Up @@ -428,4 +428,4 @@
"title": "CVE-2020-10188 telnet-server: no bounds checks in nextitem() function allows to remotely execute arbitrary code"
}
]
}
}
17 changes: 10 additions & 7 deletions csaf_2.1/json_schema/csaf_json_schema.json
Original file line number Diff line number Diff line change
Expand Up @@ -855,7 +855,7 @@
},
"initial_release_date": {
"title": "Initial release date",
"description": "The date when this document was first published.",
"description": "The date when this document was first released to the specified target group.",
"type": "string",
"format": "date-time"
},
Expand Down Expand Up @@ -1099,6 +1099,12 @@
}
}
},
"disclosure_date": {
"title": "Disclosure date",
"description": "Holds the date and time the vulnerability was originally disclosed to the public.",
"type": "string",
"format": "date-time"
},
"discovery_date": {
"title": "Discovery date",
"description": "Holds the date and time the vulnerability was originally discovered.",
Expand Down Expand Up @@ -1275,6 +1281,9 @@
},
"cvss_v4": {
"$ref": "https://www.first.org/cvss/cvss-v4.0.json"
},
"ssvc_v1": {
"$ref": "https://certcc.github.io/SSVC/data/schema/v1/Decision_Point_Value_Selection-1-0-1.schema.json"
}
}
},
Expand Down Expand Up @@ -1348,12 +1357,6 @@
"description": "Holds a list of references associated with this vulnerability item.",
"$ref": "#/$defs/references_t"
},
"release_date": {
"title": "Release date",
"description": "Holds the date and time the vulnerability was originally released into the wild.",
"type": "string",
"format": "date-time"
},
"remediations": {
"title": "List of remediations",
"description": "Contains a list of remediations.",
Expand Down
7 changes: 7 additions & 0 deletions csaf_2.1/prose/edit/etc/bind.txt
Original file line number Diff line number Diff line change
Expand Up @@ -73,6 +73,13 @@ tests-01-mndtr-39-public-sharing-group-with-no-max-uuid.md
tests-01-mndtr-40-invalid-sharing-group-name.md
tests-01-mndtr-41-missing-sharing-group-name.md
tests-01-mndtr-42-purl-qualifiers.md
tests-01-mndtr-43-use-of-multiple-stars-in-model-number.md
tests-01-mndtr-44-use-of-multiple-stars-in-serial-number.md
tests-01-mndtr-45-inconsistent-disclosure-date.md
tests-01-mndtr-46-invalid-ssvc.md
tests-01-mndtr-47-inconsistent-ssvc-id.md
tests-01-mndtr-48-ssvc-decision-points.md
tests-01-mndtr-49-inconsistent-ssvc-timestamp.md
tests-02-optional.md
tests-03-informative.md
distributing.md
Expand Down
Loading