openjs-foundation / pkg-vuln-collab-space

Project for work on improved Package Vulnerability Management & Reporting
Apache License 2.0
79 stars 6 forks source link

add draft Audit File RFC and schema #11

Open naugtur opened 3 years ago

naugtur commented 3 years ago

It's an early draft to serve as a background for discussion. Based on what worked for npm-audit-resolver, with improvements allowing for it to become not only storage, but also an exchange format.

I intend to test the schema, but it's 2AM and I'm trying to keep up with how the conversation is progressing, so I'll see if I get to it on the weekend.

If we want RFCs (plural) in this collab space, the folder structure I made makes no sense.

Please get me in touch with people capable of the paperwork necessary for me to donate the copyright to OpenJSF when we merge.