Skip to content

Add OPEV 0016#24

Open
macedogm wants to merge 1 commit intoopenvex:mainfrom
macedogm:opev-0016
Open

Add OPEV 0016#24
macedogm wants to merge 1 commit intoopenvex:mainfrom
macedogm:opev-0016

Conversation

@macedogm
Copy link
Copy Markdown

As discussed in openvex/spec#31 and in the OpenVEX SIG meeting on April 13th, this OPEV proposes to extend the OpenVEX spec to allow re-scoring vulnerabilities. The extension is minimal, doesn't break backwards compatibility and follows the original NTIA VEX spec.

Signed-off-by: Guilherme Macedo <guilherme@gmacedo.com>
@macedogm
Copy link
Copy Markdown
Author

@puerco PTAL and thanks for the support of the OpenVEX SIG.

@fahedouch
Copy link
Copy Markdown

Great news! I couldn't make it to the meeting yesterday. So, am I right in understanding that OpenVEX has agreed to support ratings in its spec?

@macedogm
Copy link
Copy Markdown
Author

macedogm commented Apr 14, 2026

@fahedouch those that were in the OpenVEX SIG meeting sympathize with this proposal, because they face the same issue (overall need to provide better scoring at product level instead of the generic scoring from the upstream source). They agreed to get it reviewed, improved and them be submitted for official voting from the maintainers of the spec.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants