Skip to content

Make CVE JSON compatible with VEX #11

@zmanion

Description

@zmanion

From today's SPWG meeting, the current CVE JSON format (unsurprisingly) almost implements VEX, as defined here:

https://www.cisa.gov/sites/default/files/2023-04/minimum-requirements-for-vex-508c.pdf

Should CVE JSON be compatible with VEX?

At a glance, changes would need to be made to status, and some additional VEX-specific fields would need to be added, such as:

  • not_affected/justification
  • action_statement
  • impact_statement
  • some timestamps (maybe, may be able to reuse existing timestamps)

Status justification would need a definition.

See also #8 which also includes CSAF integration, which I do not think is appropriate for CVE JSON.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions