Skip to content

Unified evidence model addressing #278, #333 and other concerns.#980

Open
stevespringett wants to merge 2 commits into
2.0-devfrom
2.0-dev-vuln-evidence
Open

Unified evidence model addressing #278, #333 and other concerns.#980
stevespringett wants to merge 2 commits into
2.0-devfrom
2.0-dev-vuln-evidence

Conversation

@stevespringett

Copy link
Copy Markdown
Member

Closes #979
Closes #278
Closes #333

Signed-off-by: Steve Springett <steve@springett.us>
@stevespringett stevespringett added this to the 2.0 milestone Jul 20, 2026
@stevespringett stevespringett self-assigned this Jul 20, 2026
@stevespringett
stevespringett requested a review from a team as a code owner July 20, 2026 00:14
@stevespringett stevespringett linked an issue Jul 20, 2026 that may be closed by this pull request
@stevespringett stevespringett linked an issue Jul 20, 2026 that may be closed by this pull request
9 tasks
@stevespringett stevespringett added request for comment RFC notice sent A public RFC notice was distributed to the CycloneDX mailing list for consideration labels Jul 20, 2026
@jkowalleck

Copy link
Copy Markdown
Member

RFC notice sent on July 20, 2026

Public RFC period ends August 17, 2026

Signed-off-by: Steve Springett <steve@springett.us>
@planetlevel

planetlevel commented Jul 25, 2026

Copy link
Copy Markdown

@stevespringett - in reviewing all this, it occurs to me that we do a good job of capturing evidence. But to really understand a risk, it's important to understand any compensating controls. It's almost like evidence againt vulnerability. I'm wondering if we should add something in the standard to model these controls so that you can take them into account. Is this already handled somehow? Or is this somewhere else in the standard that I missed?

If we dd this, we could distinguish inherent and residual ratings and allow the residual rating to reference the mitigation assertion.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

breaking-changes proposed core enhancement request for comment RFC notice sent A public RFC notice was distributed to the CycloneDX mailing list for consideration

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Unified evidence model Request: Evidence for Vulnerabilities

3 participants