Skip to content

Can non-CNA Suppliers provide SADP information? How? Through CNA-LRs? #10

@zmanion

Description

@zmanion

Can non-CNA Suppliers provide SADP information? How? Through CNA-LRs? Can CNA-LRs provide such information proactively without a request from the non-CNA Supplier, or only when requested?

There may be CRA implications, as manufacturers are required to convey information about vulnerabilities.

Example: https://cveawg-test.mitre.org/api/cve/CVE-2026-20538

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions