Skip to content

Require reporting of which reserved CVE IDs have and have not been assigned to a vulnerability #37

Description

@EvansJonathan

GOAL: Increase transparency?
CHANGE: Helps differentiate between what are actually assigned vs. those that are reserved and (maybe) unused.
The Primary CNA should be publishing these summaries.
The Root CNAs must provide the Primary CNA these data.
"Allocated" vs. "Reserved"?

Primary CNA will send periodic reports to the Root/Sub CNAs indicating what CVE IDs we have observed/had reported to us that have not been published.
One other option is a query on demand vs an email notification

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions