Skip to content

exclusively-hosted-service and unsupported-when-assigned tags should apply to affected element not CNA contaner #13

@zmanion

Description

@zmanion

The exclusively-hosted-service and unsupported-when-assigned tags (glossary, schema) apply to the entire CNA container. Should they instead apply to an affected element?

Real world example: Given a CVE ID that affects Adminer (unsupported, will not be fixed) and AdminerEvo (fork of Adminer, supported, fixed), there is currently not a machine-readable way to specifify that Adminer is EOL.

Example: A CVE ID affects software that exists both as a service and an "on-prem" product. It is not possible to indicate that one affected element is a cloud service while another element is not.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions