On 2022-11-10 03:27, John Helmert III wrote:
The first GLSA in glsa.git is GLSA-200310-03, the third GLSA of
October 2003. It used roughly the same format of the GLSAs we release
today, in 2022, making that format almost as old as me.
Somewhere along the way, it started to become necessary to target
multiple version ranges within the same package. The GLSA format
isn't capable of expressing this. Thus, I propose a new format (an
example of which I've attached inline below), with the following
changes from the old format:
- Rework affected to use XML-ified logical operators to specify the
affected versions, and *don't* use different fields to specify
vulnerable and unaffected versions. Instead, only list vulnerable
versions, unaffected versions are implicit.
- Drop synopsis and description fields. These fields contain the same
information and will be superceded by the existing impact field.
- Drop background field. This is usually just the package's
description, or some similar text. No reason to reproduce it in
GLSAs.
What does everyone think?
I still like the idea to provide CSAF because it is good to use the same
format and share powerful tools. Several projects and companies (Not
just distributions) have already implemented CSAF.
In the meantime we have now a wiki page to collect all knowledge on this
topic
https://wiki.gentoo.org/wiki/CSAF_for_Gentoo
If you want to have a look into CSAF, there is a webinar on 2025-10-06
You can register for free:
https://www.safe-machines-at-work.org/digital-manufacturing/webinars-on-digital-manufacturing
--
Best,
Jonas