On  2022-11-10 03:27, John Helmert III wrote:
The first GLSA in glsa.git is GLSA-200310-03, the third GLSA of
October 2003. It used roughly the same format of the GLSAs we release
today, in 2022, making that format almost as old as me.

Somewhere along the way, it started to become necessary to target
multiple version ranges within the same package. The GLSA format
isn't capable of expressing this. Thus, I propose a new format (an
example of which I've attached inline below), with the following
changes from the old format:

  - Rework affected to use XML-ified logical operators to specify the
    affected versions, and *don't* use different fields to specify
    vulnerable and unaffected versions. Instead, only list vulnerable
    versions, unaffected versions are implicit.

  - Drop synopsis and description fields. These fields contain the same
    information and will be superceded by the existing impact field.

  - Drop background field. This is usually just the package's
    description, or some similar text. No reason to reproduce it in
    GLSAs.

What does everyone think?

I still like the idea to provide CSAF because it is good to use the same format and share powerful tools. Several projects and companies (Not just distributions) have already implemented CSAF.

In the meantime we have now a wiki page to collect all knowledge on this topic
https://wiki.gentoo.org/wiki/CSAF_for_Gentoo

If you want to have a look into CSAF, there is a webinar on 2025-10-06
You can register for free: https://www.safe-machines-at-work.org/digital-manufacturing/webinars-on-digital-manufacturing


--
Best,
Jonas

Reply via email to