You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Describe the bug
Currently the CWE number is associated to a rule via the tags property on the rule. However, according to spec, the taxa property should be used instead.
Tags SHOULD NOT be used to label a result or a rule as belonging to a category in a classification system such as the Common Weakness Enumeration [CWE™] (for example, by adding a tag "CWE/622"). Instead, taxonomies (§3.19.3) SHOULD be used for this purpose.
To Reproduce
Steps to reproduce the behavior:
n/a
Expected behavior
Will this still work in GitHub UI? If not, might have to do both.
Describe the bug
Currently the CWE number is associated to a rule via the tags property on the rule. However, according to spec, the taxa property should be used instead.
Tags SHOULD NOT be used to label a result or a rule as belonging to a category in a classification system such as the Common Weakness Enumeration [CWE™] (for example, by adding a tag "CWE/622"). Instead, taxonomies (§3.19.3) SHOULD be used for this purpose.
To Reproduce
Steps to reproduce the behavior:
n/a
Expected behavior
Will this still work in GitHub UI? If not, might have to do both.
Version
Additional context
See 3.19.25 taxa property in
https://docs.oasis-open.org/sarif/sarif/v2.1.0/csprd01/sarif-v2.1.0-csprd01.html
The text was updated successfully, but these errors were encountered: