CERTCC / SSVC

Stakeholder-Specific Vulnerability Categorization
https://certcc.github.io/SSVC/
Other
127 stars 31 forks source link

ssvc-calc: Add coordinator and vendor trees #169

Closed zmanion closed 2 years ago

zmanion commented 2 years ago

Low priority, add trees/selection options for

sei-vsarvepalli commented 2 years ago

This is for the demo site? Supplier 2.0 already exists in the demo and also in Github https://github.com/CERTCC/SSVC/blob/main/ssvc-calc/Supplier-v2.0.0.json

The following trees are pending for the demo site

zmanion commented 2 years ago

Sorry yes, the request is basically for the demo (and eventually "production") public calculator to support all of the trees: coordinator triage, coordinator publish, CISA coordinator, supplier, deployer.

sei-vsarvepalli commented 2 years ago

The Deployer tree has been added the demo site. Pending some validation it will get added in the next Pull Request.

https://democert.org/ssvc/Deployer-v2.0.0.json

sei-vsarvepalli commented 2 years ago

More trees added to demo site as requested by @zmanion

https://democert.org/ssvc/Coordinator-Triage-v2.0.0.json for Coordination centers like CERT/CC trying to decide whether to Triage a vulnerability report that has been submitted to them.

https://democert.org/ssvc/Coordinator-Publish-v2.0.0.json for Coordination centers like CERT/CC to pursue public notification or a public announcement of a vulnerability that is coordinated.

Note: These Coordination decisions may not be relevant to all types of CERT coordination centers. Some CSIRT's may find this useful https://www.first.org/standards/frameworks/csirts/csirt_services_framework_v2.1

sei-vsarvepalli commented 2 years ago

Closed by #174