Skip to content

Require reporting of which reserved CVE IDs have and have not been assigned to a vulnerability #37

Open
@EvansJonathan

Description

@EvansJonathan

GOAL: Increase transparency?
CHANGE: Helps differentiate between what are actually assigned vs. those that are reserved and (maybe) unused.
The Primary CNA should be publishing these summaries.
The Root CNAs must provide the Primary CNA these data.
"Allocated" vs. "Reserved"?

Primary CNA will send periodic reports to the Root/Sub CNAs indicating what CVE IDs we have observed/had reported to us that have not been published.
One other option is a query on demand vs an email notification

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions