csaf-tools / CVRF-CSAF-Converter

A CVRF CSAF Converter, taking care about OASIS specification.
https://www.telekom.com/security
MIT License
10 stars 4 forks source link

Background check: Validate changes between CVRF 1.2 and CSAF #6

Closed cgi1 closed 2 years ago

cgi1 commented 3 years ago

Researching for a complete changelog between CVRF 1.2 and CSAF 2.0, we could not find a complete list.

Therefore, we asked in Oasis TCS CSAF project for it and sthagen reported back, that currently there is no such complete change log. However, there is a prelimary mapping which will slightly change over time (CS01), but looks to be the best changelog publicy available.

As this is a moving target, we will check back later if we covered all changes during the converter implementation.

cgi1 commented 3 years ago

Insert link to Comment Resolution Log

cgi1 commented 2 years ago

To be discussed with @tschmidtb51 during the KickOff tomorrow, which conversion schema we will apply during implementation phase.

The code will be open to changes later on, but we need some fixed set of relations.

cgi1 commented 2 years ago

Can we assume CVRF 1.1 as the input or CVRF 1.2? If CVRF 1.1, how is this mind map as an oriantiation?

image

CVRF-mindmap-1.1.pdf

cgi1 commented 2 years ago

Due to @tschmidtb51, there will be a complete mapping list here. Most likely, this will be there by EOY.

At all, we agreed on taking CVRF 1.2.

cgi1 commented 2 years ago

All changes have now been documented by @tschmidtb51 right here

Documented in xpath notation

cgi1 commented 2 years ago

Changes between CVRF 1.2 and CSAF 2.0 have been outlined from different angles.