csaf-tools / CVRF-CSAF-Converter

A CVRF CSAF Converter, taking care about OASIS specification.
https://www.telekom.com/security
MIT License
10 stars 4 forks source link

Encode HTML in JSON output #5

Open cgi1 opened 2 years ago

cgi1 commented 2 years ago
  • CSAF producers SHOULD NOT emit messages that contain HTML, even though all variants of Markdown permit it. To include HTML, source code, or any other content that may be interpreted or executed by a CSAF consumer, e.g. to provide a proof-of-concept, the issuing party SHALL use Markdown's fenced code blocks or inline code option.

Source: Safety, Security, and Data Protection Considerations

A/C:

cgi1 commented 2 years ago

valid encoding from TC is markdown, so please just add a markdown codeblock around it.

cgi1 commented 2 years ago

lower prio.