Poll: Software ID RFD Direction #416
Replies: 2 comments
-
Just noting that I don't really feel a strong preference - I kind of lean toward the affected array if only because parsers already have to deal with many different versioning schemes when parsing that, while cpeApplicability is an easy switch for parsers written to handle NVD data. If we start introducing other schemes for cpeApplicability it complicates the parsing of that block as you have to first determine what is actually being represented. So I guess I'll vote for affected, but it isn't a hill I'd die on. |
Beta Was this translation helpful? Give feedback.
-
Closing, as we appear to have settled on pursuing the |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
In RFD #407, we outline two options for expanding support for software identifiers in the CVE Record Format:
cpeApplicability
object.affected
array.This poll is to determine which of the two options the QWG prefers.
To vote, please react to this post with the emoji matching your choice:
cpeApplicability
object.affected
array.This vote is not a vote to accept or reject the RFD, only to gauge the preference between the two options within the RFD.
Note
Why not make a "real" poll?
GitHub Discussion's poll feature doesn't show who voted for what option, which would permit non-QWG participants to vote without us being able to know. Voting-via-emoji does show who clicked each emoji, which lets us validate voters.
Warning
This poll will close at the start of the QWG meeting on May 29th.
Beta Was this translation helpful? Give feedback.
All reactions