ocsf / ocsf-schema

OCSF Schema
Apache License 2.0
582 stars 118 forks source link

Package extension (affected packages) by vendor name and type #1091

Open PavelJurka opened 1 month ago

PavelJurka commented 1 month ago

As security analytic I would like to Vendor name and type of package of found vulnerability.

Vulnerability finding contains affected packages -> there is missing Vendor_name and Type of OS/Application

We suggest to extend it by:

optional string vendor_name optional type + type_id -> OS, Application, Other, Unknown