Skip to content

Commit 713496e

Browse files
ahouseholderdependabot[bot]sei-vsarvepallipatrickmgarrity
authored
Merge main --> publish (#587)
* Bump pandas from 2.2.1 to 2.2.2 (#557) Bumps [pandas](https://github.com/pandas-dev/pandas) from 2.2.1 to 2.2.2. - [Release notes](https://github.com/pandas-dev/pandas/releases) - [Commits](pandas-dev/pandas@v2.2.1...v2.2.2) --- updated-dependencies: - dependency-name: pandas dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Bump scikit-learn from 1.4.1.post1 to 1.4.2 (#556) Bumps [scikit-learn](https://github.com/scikit-learn/scikit-learn) from 1.4.1.post1 to 1.4.2. - [Release notes](https://github.com/scikit-learn/scikit-learn/releases) - [Commits](scikit-learn/scikit-learn@1.4.1.post1...1.4.2) --- updated-dependencies: - dependency-name: scikit-learn dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Allen D. Householder <[email protected]> * Bump mkdocs-print-site-plugin from 2.3.6 to 2.4.0 in the mkdocs group (#555) Bumps the mkdocs group with 1 update: [mkdocs-print-site-plugin](https://github.com/timvink/mkdocs-print-site-plugin). Updates `mkdocs-print-site-plugin` from 2.3.6 to 2.4.0 - [Release notes](https://github.com/timvink/mkdocs-print-site-plugin/releases) - [Commits](timvink/mkdocs-print-site-plugin@v2.3.6...v2.4.0) --- updated-dependencies: - dependency-name: mkdocs-print-site-plugin dependency-type: direct:production update-type: version-update:semver-minor dependency-group: mkdocs ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Updated Mission-Impact in Deployer.json and in csvs/child_trees to match latest (#559) * i18n improvement to Deployer.json (#560) * Updated Mission-Impact in Deployer.json and in csvs/child_trees to match latest * Add keys to Deployer.json example Issue-123-1 * Update in CSS to fix default darkmode/blackbody * Bump the mkdocs group with 2 updates (#563) * Bump the mkdocs group with 2 updates Bumps the mkdocs group with 3 updates: [mkdocs](https://github.com/mkdocs/mkdocs), [mkdocs-material](https://github.com/squidfunk/mkdocs-material) and [mkdocstrings-python](https://github.com/mkdocstrings/python). (mkdocs 1.6.0 ignored because incompatible with mkdocs-material 9.5.18 Updates `mkdocs-material` from 9.5.17 to 9.5.18 - [Release notes](https://github.com/squidfunk/mkdocs-material/releases) - [Changelog](https://github.com/squidfunk/mkdocs-material/blob/master/CHANGELOG) - [Commits](squidfunk/mkdocs-material@9.5.17...9.5.18) Updates `mkdocstrings-python` from 1.9.2 to 1.10.0 - [Release notes](https://github.com/mkdocstrings/python/releases) - [Changelog](https://github.com/mkdocstrings/python/blob/main/CHANGELOG.md) - [Commits](mkdocstrings/python@1.9.2...1.10.0) --- updated-dependencies: - dependency-name: mkdocs dependency-type: direct:production update-type: version-update:semver-minor dependency-group: mkdocs - dependency-name: mkdocs-material dependency-type: direct:production update-type: version-update:semver-patch dependency-group: mkdocs - dependency-name: mkdocstrings-python dependency-type: direct:production update-type: version-update:semver-minor dependency-group: mkdocs ... Signed-off-by: dependabot[bot] <[email protected]> * Update requirements.txt --------- Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Allen D. Householder <[email protected]> * replace vuls.cert.org CVD guide links with certcc.github.io links (#562) * Add requirements.txt trigger to link_checker.yml Linkchecker also confirms that the site builds successfully, so any changes to the pip requirements should trigger it to run as well. * Bump dataclasses-json from 0.6.4 to 0.6.5 (#566) Bumps [dataclasses-json](https://github.com/lidatong/dataclasses-json) from 0.6.4 to 0.6.5. - [Release notes](https://github.com/lidatong/dataclasses-json/releases) - [Commits](lidatong/dataclasses-json@v0.6.4...v0.6.5) --- updated-dependencies: - dependency-name: dataclasses-json dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Bump the mkdocs group across 1 directory with 5 updates (#567) Bumps the mkdocs group with 5 updates in the / directory: | Package | From | To | | --- | --- | --- | | [mkdocs](https://github.com/mkdocs/mkdocs) | `1.5.3` | `1.6.0` | | [mkdocs-include-markdown-plugin](https://github.com/mondeja/mkdocs-include-markdown-plugin) | `6.0.5` | `6.0.6` | | [mkdocs-table-reader-plugin](https://github.com/timvink/mkdocs-table-reader-plugin) | `2.1.0` | `2.2.0` | | [mkdocs-material](https://github.com/squidfunk/mkdocs-material) | `9.5.18` | `9.5.21` | | [mkdocstrings](https://github.com/mkdocstrings/mkdocstrings) | `0.24.3` | `0.25.1` | Updates `mkdocs` from 1.5.3 to 1.6.0 - [Release notes](https://github.com/mkdocs/mkdocs/releases) - [Commits](mkdocs/mkdocs@1.5.3...1.6.0) Updates `mkdocs-include-markdown-plugin` from 6.0.5 to 6.0.6 - [Release notes](https://github.com/mondeja/mkdocs-include-markdown-plugin/releases) - [Commits](mondeja/mkdocs-include-markdown-plugin@v6.0.5...v6.0.6) Updates `mkdocs-table-reader-plugin` from 2.1.0 to 2.2.0 - [Release notes](https://github.com/timvink/mkdocs-table-reader-plugin/releases) - [Commits](timvink/mkdocs-table-reader-plugin@v2.1.0...v2.2.0) Updates `mkdocs-material` from 9.5.18 to 9.5.21 - [Release notes](https://github.com/squidfunk/mkdocs-material/releases) - [Changelog](https://github.com/squidfunk/mkdocs-material/blob/master/CHANGELOG) - [Commits](squidfunk/mkdocs-material@9.5.18...9.5.21) Updates `mkdocstrings` from 0.24.3 to 0.25.1 - [Release notes](https://github.com/mkdocstrings/mkdocstrings/releases) - [Changelog](https://github.com/mkdocstrings/mkdocstrings/blob/main/CHANGELOG.md) - [Commits](mkdocstrings/mkdocstrings@0.24.3...0.25.1) --- updated-dependencies: - dependency-name: mkdocs dependency-type: direct:production update-type: version-update:semver-minor dependency-group: mkdocs - dependency-name: mkdocs-include-markdown-plugin dependency-type: direct:production update-type: version-update:semver-patch dependency-group: mkdocs - dependency-name: mkdocs-table-reader-plugin dependency-type: direct:production update-type: version-update:semver-minor dependency-group: mkdocs - dependency-name: mkdocs-material dependency-type: direct:production update-type: version-update:semver-patch dependency-group: mkdocs - dependency-name: mkdocstrings dependency-type: direct:production update-type: version-update:semver-minor dependency-group: mkdocs ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Bump jsonschema from 4.21.1 to 4.22.0 (#568) Bumps [jsonschema](https://github.com/python-jsonschema/jsonschema) from 4.21.1 to 4.22.0. - [Release notes](https://github.com/python-jsonschema/jsonschema/releases) - [Changelog](https://github.com/python-jsonschema/jsonschema/blob/main/CHANGELOG.rst) - [Commits](python-jsonschema/jsonschema@v4.21.1...v4.22.0) --- updated-dependencies: - dependency-name: jsonschema dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Bump dataclasses-json from 0.6.5 to 0.6.6 (#572) * Bump the mkdocs group with 3 updates (#571) Bumps the mkdocs group with 3 updates: [mkdocs-table-reader-plugin](https://github.com/timvink/mkdocs-table-reader-plugin), [mkdocs-material](https://github.com/squidfunk/mkdocs-material) and [mkdocs-print-site-plugin](https://github.com/timvink/mkdocs-print-site-plugin). Updates `mkdocs-table-reader-plugin` from 2.2.0 to 2.2.1 - [Release notes](https://github.com/timvink/mkdocs-table-reader-plugin/releases) - [Commits](timvink/mkdocs-table-reader-plugin@v2.2.0...v2.2.1) Updates `mkdocs-material` from 9.5.21 to 9.5.22 - [Release notes](https://github.com/squidfunk/mkdocs-material/releases) - [Changelog](https://github.com/squidfunk/mkdocs-material/blob/master/CHANGELOG) - [Commits](squidfunk/mkdocs-material@9.5.21...9.5.22) Updates `mkdocs-print-site-plugin` from 2.4.0 to 2.4.1 - [Release notes](https://github.com/timvink/mkdocs-print-site-plugin/releases) - [Commits](timvink/mkdocs-print-site-plugin@v2.4.0...v2.4.1) --- updated-dependencies: - dependency-name: mkdocs-table-reader-plugin dependency-type: direct:production update-type: version-update:semver-patch dependency-group: mkdocs - dependency-name: mkdocs-material dependency-type: direct:production update-type: version-update:semver-patch dependency-group: mkdocs - dependency-name: mkdocs-print-site-plugin dependency-type: direct:production update-type: version-update:semver-patch dependency-group: mkdocs ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Bump the mkdocs group with 3 updates (#573) Bumps the mkdocs group with 3 updates: [mkdocs-table-reader-plugin](https://github.com/timvink/mkdocs-table-reader-plugin), [mkdocs-material](https://github.com/squidfunk/mkdocs-material) and [mkdocstrings-python](https://github.com/mkdocstrings/python). Updates `mkdocs-table-reader-plugin` from 2.2.1 to 2.2.2 - [Release notes](https://github.com/timvink/mkdocs-table-reader-plugin/releases) - [Commits](timvink/mkdocs-table-reader-plugin@v2.2.1...v2.2.2) Updates `mkdocs-material` from 9.5.22 to 9.5.24 - [Release notes](https://github.com/squidfunk/mkdocs-material/releases) - [Changelog](https://github.com/squidfunk/mkdocs-material/blob/master/CHANGELOG) - [Commits](squidfunk/mkdocs-material@9.5.22...9.5.24) Updates `mkdocstrings-python` from 1.10.0 to 1.10.2 - [Release notes](https://github.com/mkdocstrings/python/releases) - [Changelog](https://github.com/mkdocstrings/python/blob/main/CHANGELOG.md) - [Commits](mkdocstrings/python@1.10.0...1.10.2) --- updated-dependencies: - dependency-name: mkdocs-table-reader-plugin dependency-type: direct:production update-type: version-update:semver-patch dependency-group: mkdocs - dependency-name: mkdocs-material dependency-type: direct:production update-type: version-update:semver-patch dependency-group: mkdocs - dependency-name: mkdocstrings-python dependency-type: direct:production update-type: version-update:semver-patch dependency-group: mkdocs ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Bump scikit-learn from 1.4.2 to 1.5.0 (#575) Bumps [scikit-learn](https://github.com/scikit-learn/scikit-learn) from 1.4.2 to 1.5.0. - [Release notes](https://github.com/scikit-learn/scikit-learn/releases) - [Commits](scikit-learn/scikit-learn@1.4.2...1.5.0) --- updated-dependencies: - dependency-name: scikit-learn dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Bump the mkdocs group with 2 updates (#574) Bumps the mkdocs group with 2 updates: [mkdocs-material](https://github.com/squidfunk/mkdocs-material) and [mkdocstrings-python](https://github.com/mkdocstrings/python). Updates `mkdocs-material` from 9.5.24 to 9.5.25 - [Release notes](https://github.com/squidfunk/mkdocs-material/releases) - [Changelog](https://github.com/squidfunk/mkdocs-material/blob/master/CHANGELOG) - [Commits](squidfunk/mkdocs-material@9.5.24...9.5.25) Updates `mkdocstrings-python` from 1.10.2 to 1.10.3 - [Release notes](https://github.com/mkdocstrings/python/releases) - [Changelog](https://github.com/mkdocstrings/python/blob/main/CHANGELOG.md) - [Commits](mkdocstrings/python@1.10.2...1.10.3) --- updated-dependencies: - dependency-name: mkdocs-material dependency-type: direct:production update-type: version-update:semver-patch dependency-group: mkdocs - dependency-name: mkdocstrings-python dependency-type: direct:production update-type: version-update:semver-patch dependency-group: mkdocs ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Bump the mkdocs group with 3 updates (#577) * Fixed URL Typo in README.md (#578) * Bump dataclasses-json from 0.6.6 to 0.6.7 (#580) Bumps [dataclasses-json](https://github.com/lidatong/dataclasses-json) from 0.6.6 to 0.6.7. - [Release notes](https://github.com/lidatong/dataclasses-json/releases) - [Commits](lidatong/dataclasses-json@v0.6.6...v0.6.7) --- updated-dependencies: - dependency-name: dataclasses-json dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Bump the mkdocs group with 2 updates (#579) Bumps the mkdocs group with 2 updates: [mkdocs-include-markdown-plugin](https://github.com/mondeja/mkdocs-include-markdown-plugin) and [mkdocs-material](https://github.com/squidfunk/mkdocs-material). Updates `mkdocs-include-markdown-plugin` from 6.1.1 to 6.2.0 - [Release notes](https://github.com/mondeja/mkdocs-include-markdown-plugin/releases) - [Commits](mondeja/mkdocs-include-markdown-plugin@v6.1.1...v6.2.0) Updates `mkdocs-material` from 9.5.25 to 9.5.26 - [Release notes](https://github.com/squidfunk/mkdocs-material/releases) - [Changelog](https://github.com/squidfunk/mkdocs-material/blob/master/CHANGELOG) - [Commits](squidfunk/mkdocs-material@9.5.25...9.5.26) --- updated-dependencies: - dependency-name: mkdocs-include-markdown-plugin dependency-type: direct:production update-type: version-update:semver-minor dependency-group: mkdocs - dependency-name: mkdocs-material dependency-type: direct:production update-type: version-update:semver-patch dependency-group: mkdocs ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * empty dockerfile * Dockerfile to run pytest * Mention docker in README.md * use 3.12 slim bookworm as base container * Bump mkdocs-material from 9.5.26 to 9.5.27 in the mkdocs group (#583) * Bump the mkdocs group with 2 updates (#585) * Make schema available via data/ folder for certcc.github.io (#586) --------- Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Vijay Sarvepalli <[email protected]> Co-authored-by: Patrick Garrity <[email protected]>
1 parent 37f28bc commit 713496e

File tree

13 files changed

+76
-38
lines changed

13 files changed

+76
-38
lines changed

.github/workflows/link_checker.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,8 @@ on:
1010
- '**/*.md'
1111
# run on any PR that changes this workflow
1212
- .github/workflows/linkchecker.yml
13+
# run on any PR that changes the pip requirements
14+
- requirements.txt
1315
# let us trigger it manually
1416
workflow_dispatch:
1517

Dockerfile

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
1+
FROM python:3.12-slim-bookworm
2+
3+
WORKDIR /app
4+
5+
# install requirements
6+
COPY requirements.txt .
7+
RUN pip install -r requirements.txt
8+
9+
# Copy the files we need
10+
COPY src/ .
11+
COPY data ./data
12+
13+
# install pytest
14+
RUN pip install pytest
15+
16+
# run the unit tests \
17+
ENTRYPOINT ["pytest"]
18+
CMD ["test"]

README.md

Lines changed: 24 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -69,7 +69,7 @@ This directory holds helper scripts that can make managing or using SSVC easier.
6969
### `/src/ssvc/*`
7070

7171
The `ssvc` python module provides tools to work with decision points, decision point groups, and outcomes.
72-
These modules are used to generate documentation for various [Decision Points](https://certcc.github.io/SSVC/reference/decsion_points/)
72+
These modules are used to generate documentation for various [Decision Points](https://certcc.github.io/SSVC/reference/decision_points/)
7373

7474
Documentation for the `ssvc` module can be found at [https://certcc.github.io/SSVC/reference/code/](https://certcc.github.io/SSVC/reference/code/)
7575

@@ -101,6 +101,29 @@ Navigate to http://localhost:8001/ to see the site.
101101

102102
(Hint: You can use the `--dev-addr` argument with mkdocs to change the port, e.g. `mkdocs serve --dev-addr localhost:8000`)
103103

104+
## Run tests
105+
106+
We include a few tests for the `ssvc` module.
107+
108+
### With Docker
109+
110+
```bash
111+
112+
docker build -t ssvc_test .
113+
docker run -it --rm ssvc_test
114+
```
115+
116+
### Without Docker
117+
118+
```bash
119+
pip install pytest # if you haven't already
120+
121+
pytest # should find tests in src/test/*
122+
```
123+
124+
125+
126+
104127
## Contributing
105128

106129
- [SSVC Community Engagement](https://certcc.github.io/SSVC/about/contributing/) has more detail on how to contribute to the project.

data/csvs/child_trees/human-impact.csv

Lines changed: 0 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,25 +1,20 @@
11
Situated Safety Impact , Mission Impact , Human Impact
2-
None , None , Low
32
None , Degraded , Low
43
None , Crippled , Low
54
None , MEF Failure , Medium
65
None , Mission Failure , Very High
7-
Minor , None , Low
86
Minor , Degraded , Low
97
Minor , Crippled , Low
108
Minor , MEF Failure , Medium
119
Minor , Mission Failure , Very High
12-
Major , None , Medium
1310
Major , Degraded , Medium
1411
Major , Crippled , Medium
1512
Major , MEF Failure , High
1613
Major , Mission Failure , Very High
17-
Hazardous , None , High
1814
Hazardous , Degraded , High
1915
Hazardous , Crippled , High
2016
Hazardous , MEF Failure , High
2117
Hazardous , Mission Failure , Very High
22-
Catastrophic , None , Very High
2318
Catastrophic , Degraded , Very High
2419
Catastrophic , Crippled , Very High
2520
Catastrophic , MEF Failure , Very High

data/schema_examples/CISA-Coordinator.json

Lines changed: 0 additions & 1 deletion
This file was deleted.

docs/data

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
../data

docs/howto/coordination_intro.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ A coordinator may want to gather and publish information about SSVC decision poi
1111
Furthermore, a coordinator may only publish some of the information it uses to make decisions.
1212
Consistent with other stakeholder perspectives (supplier and deployer), SSVC provides the priority with which a coordinator should take some defined action, but not how to do that action.
1313
For more information about types of coordinators and their facilitation actions within vulnerability management, see
14-
[The CERT Guide to Coordinated Vulnerability Disclosure](https://vuls.cert.org/confluence/display/CVD/3.5.+Coordinator)
14+
[The CERT Guide to Coordinated Vulnerability Disclosure](https://certcc.github.io/CERT-Guide-to-CVD/topics/roles/coordinator/)
1515

1616
The two decisions that CERT/CC makes as a coordinator that we will discuss in terms of SSVC are
1717

@@ -27,7 +27,7 @@ These two decisions are not the entirety of vulnerability coordination, but we l
2727

2828

2929
Different coordinators have different scopes and constituencies.
30-
See [The CERT Guide to Coordinated Vulnerability Disclosure](https://vuls.cert.org/confluence/display/CVD/3.5.+Coordinator) for a listing of different coordinator types.
30+
See [The CERT Guide to Coordinated Vulnerability Disclosure](https://certcc.github.io/CERT-Guide-to-CVD/topics/roles/coordinator/) for a listing of different coordinator types.
3131
If a coordinator receives a report that is outside its own work scope or constituency, it should make an effort to route the report to a more suitable coordinator.
3232
The decisions in this section assume the report or vulnerability in question is within the work scope or constituency for the coordinator.
3333

docs/howto/coordination_triage_decision.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,7 @@ SSVC can be applied to either the initial report or to the results of such refin
2727

2828
## Coordinator Triage Decision Outcomes
2929

30-
We take three priority levels in our decision about whether and how to [coordinate](https://vuls.cert.org/confluence/display/CVD/1.1.+Coordinated+Vulnerability+Disclosure+is+a+Process%2C+Not+an+Event)
30+
We take three priority levels in our decision about whether and how to [coordinate](https://certcc.github.io/CERT-Guide-to-CVD/tutorials/cvd_is_a_process/)
3131
a vulnerability based on an incoming report:
3232

3333
!!! info "Coordinator Triage Priority"
@@ -57,7 +57,7 @@ a vulnerability based on an incoming report:
5757
(VRDA) provides a starting point for a decision model for this situation.
5858
VRDA is likely [adequate](https://insights.sei.cmu.edu/library/effectiveness-of-the-vulnerability-response-decision-assistance-vrda-framework/)
5959
for national-level CSIRTs that do general CVD, but other CSIRT types may have different needs.
60-
The [*CERT Guide to Coordinated Vulnerability Disclosure*](https://vuls.cert.org/confluence/display/CVD/6.10+Troubleshooting+Coordinated+Vulnerability+Disclosure+Table)
60+
The [*CERT Guide to Coordinated Vulnerability Disclosure*](https://certcc.github.io/CERT-Guide-to-CVD/howto/coordination/cvd_recipes/)
6161
provides something similar for those who are deciding how to report and disclose vulnerabilities they have discovered.
6262

6363
The coordination and publication decisions for CERT/CC are about the social and collaborative state of vulnerability management.

docs/howto/publication_decision.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@ Two points where CERT/CC policy clearly influences the publication decision are
3131
As a matter of policy, CERT/CC will support an embargo from the public of information about a vulnerability through its
3232
choice not to publish that information while a number of conditions hold:
3333

34-
- A negotiated embargo timer has not expired. The CERT/CC default embargo period is [45 days](https://vuls.cert.org/confluence/display/Wiki/Vulnerability+Disclosure+Policy).
34+
- A negotiated embargo timer has not expired. The CERT/CC default embargo period is [45 days](https://certcc.github.io/CERT-Guide-to-CVD/reference/certcc_disclosure_policy/).
3535
- Other exceptions have not been met, including active exploitation of the vulnerability in the wild or other public
3636
discussion of the vulnerability details.
3737

docs/ssvc-calc/Deployer.json

Lines changed: 4 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -99,11 +99,6 @@
9999
"label": "Mission Impact",
100100
"key": "M",
101101
"options": [
102-
{
103-
"label": "none",
104-
"key": "N",
105-
"description": "Little to no impact up to degradation of non-essential functions; chronic degradation would eventually harm essential functions. (aka Non-Essential Degraded)"
106-
},
107102
{
108103
"label": "degraded",
109104
"key": "D",
@@ -132,6 +127,7 @@
132127
{
133128
"label": "Human Impact",
134129
"decision_type": "complex",
130+
"key": "H",
135131
"children": [
136132
{
137133
"label": "Situated Safety Impact"
@@ -158,7 +154,6 @@
158154
"child_label": "Mission Impact",
159155
"child_key": "M",
160156
"child_option_labels":[
161-
"none",
162157
"degraded",
163158
"crippled"
164159
]
@@ -201,7 +196,6 @@
201196
"child_label": "Mission Impact",
202197
"child_key": "M",
203198
"child_option_labels":[
204-
"none",
205199
"degraded",
206200
"crippled"
207201
]
@@ -243,7 +237,6 @@
243237
"child_label": "Mission Impact",
244238
"child_key": "M",
245239
"child_option_labels":[
246-
"none",
247240
"degraded",
248241
"crippled",
249242
"mef failure"
@@ -292,7 +285,6 @@
292285
"child_label": "Mission Impact",
293286
"child_key": "M",
294287
"child_option_labels":[
295-
"none",
296288
"degraded",
297289
"crippled",
298290
"mef failure",
@@ -335,7 +327,8 @@
335327
"color": "#EA3423"
336328
}
337329
],
338-
"label": "Priority"
330+
"label": "Priority",
331+
"key": "P"
339332
} ],
340333
"decisions_table": [
341334
{
@@ -844,6 +837,6 @@
844837
}
845838
],
846839
"lang": "en",
847-
"version": "2.0",
840+
"version": "2.0.0",
848841
"title": "Deployer v2.1.0"
849842
}

0 commit comments

Comments
 (0)