Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Store a canonical CWE database for CSAF in the TC repo #821

Open
oxisto opened this issue Nov 1, 2024 · 1 comment
Open

Store a canonical CWE database for CSAF in the TC repo #821

oxisto opened this issue Nov 1, 2024 · 1 comment
Labels

Comments

@oxisto
Copy link

oxisto commented Nov 1, 2024

While currently trying to implement Test 6.1.11 for kotlin-csaf (csaf-sbom/kotlin-csaf#81) I was wondering, whether it would make sense to store a canonical version of the CWE database here in this repo. Most (if not all) CSAF implementations make use of this repository already for the test files and currently each library has to update the CWE list on its own, with possibly different mechanisms. Furthermore, if I read #660 correctly, we also need to even consider different versions of the CWE database (which quite frankly is quite a burden on library developers) for CSAF 2.1 (although it seems optional).

At least having these files here in this repo with a clear versioning scheme would make the life of library developers MUCH easier and ease further adoption of the CSAF standard in more ecosystems.

A better option would be to have these files somewhere pulled from https://github.com/CWE-CAPEC, but unfortunately, they are not available there in a good format.

@tschmidtb51
Copy link
Contributor

I think that, if we are allowed to compile such a database (that needs to be checked with Mitre), it should be in a different repository.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants