Skip to content

Commit

Permalink
SSVC
Browse files Browse the repository at this point in the history
- addresses parts of oasis-tcs#803
- add SSVC to guidance on size
  • Loading branch information
tschmidtb51 committed Jan 16, 2025
1 parent 599b150 commit 7ac9c47
Showing 1 changed file with 10 additions and 0 deletions.
10 changes: 10 additions & 0 deletions csaf_2.1/prose/edit/src/guidance-on-size.md
Original file line number Diff line number Diff line change
Expand Up @@ -76,6 +76,8 @@ An array SHOULD NOT have more than:
* `/vulnerabilities[]/acknowledgments[]/urls`
* `/vulnerabilities[]/cwes`
* `/vulnerabilities[]/ids`
* `/vulnerabilities[]/metrics[]/content/ssvc_v1/selections`
* `/vulnerabilities[]/metrics[]/content/ssvc_v1/selections[]/values`
* `/vulnerabilities[]/remediations[]/entitlements`

* 40 000 items for
Expand Down Expand Up @@ -201,6 +203,12 @@ A string SHOULD NOT have a length greater than:
* `/vulnerabilities[]/flags[]/product_ids[]`
* `/vulnerabilities[]/ids[]/system_name`
* `/vulnerabilities[]/ids[]/text`
* `/vulnerabilities[]/metrics[]/content/ssvc_v1/id`
* `/vulnerabilities[]/metrics[]/content/ssvc_v1/role`
* `/vulnerabilities[]/metrics[]/content/ssvc_v1/selections[]/name`
* `/vulnerabilities[]/metrics[]/content/ssvc_v1/selections[]/namespace`
* `/vulnerabilities[]/metrics[]/content/ssvc_v1/selections[]/values[]`
* `/vulnerabilities[]/metrics[]/content/ssvc_v1/selections[]/version`
* `/vulnerabilities[]/notes[]/audience`
* `/vulnerabilities[]/notes[]/title`
* `/vulnerabilities[]/product_status/first_affected[]`
Expand Down Expand Up @@ -263,6 +271,7 @@ The maximum length of strings representing a temporal value is given by the form
* `/vulnerabilities[]/flags[]/date`
* `/vulnerabilities[]/release_date`
* `/vulnerabilities[]/involvements[]/date`
* `/vulnerabilities[]/metrics[]/content/ssvc_v1/timestamp`
* `/vulnerabilities[]/remediations[]/date`
* `/vulnerabilities[]/threats[]/date`

Expand Down Expand Up @@ -374,6 +383,7 @@ This applies to:
* `/vulnerabilities[]/metrics[]/content/cvss_v4/baseSeverity` (8)
* `/vulnerabilities[]/metrics[]/content/cvss_v4/threatSeverity` (8)
* `/vulnerabilities[]/metrics[]/content/cvss_v4/environmentalSeverity` (8)
* `/vulnerabilities[]/metrics[]/content/ssvc_v1/schemaVersion` (5)
* `/vulnerabilities[]/threats[]/category` (14)

## URI Length
Expand Down

0 comments on commit 7ac9c47

Please sign in to comment.