CERTCC / SSVC

Stakeholder-Specific Vulnerability Categorization
https://certcc.github.io/SSVC/
Other
125 stars 31 forks source link

Create ADR for SSVC JSON schema versioning #601

Open ahouseholder opened 1 month ago

ahouseholder commented 1 month ago

Yeh - I think we can move that way later without a problem. The idea would be to provide "breaking" vs "non-breaking" Schema changes to be version controlled. Mostly from Snowplow's musings .

The challenge with some of these issues seems to show that much of the schema versioning itself is so experimental and we are trying to imagine an operational viability which is sort of impossible to know till we have enough usage.

_Originally posted by @sei-vsarvepalli in https://github.com/CERTCC/SSVC/pull/599#discussion_r1674439644_

This issue can be resolved by a PR that includes a new ADR addressing JSON schema versioning and pointing to the snowplow.io link in the above comment.

sei-vsarvepalli commented 1 month ago

Also related #596