SSVC v2024.3 #536
ahouseholder
started this conversation in
General
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
In the 2024.3 release of the Stakeholder-Specific Vulnerability Classification (SSVC) system, we've made a number of significant changes:
New Web Site
This release debuts the certcc.github.io/SSVC web site to serve as the front-door for all things SSVC.
New and Revised Content
Versioned Objects
Experimental & Emerging Features
There are a few improvements we've begun but have not yet fully finished, and that are largely undocumented. Most of these in the current release are python-centric. Here's a brief overview for those who want to poke around at code.
ssvc
python module to allow us to more easily work with Decision Points, Decision Point Groups, Outcomes, and Policies that map from Decision Points to Outcomes. We expect to have more to say about this module in the future, but for now it's geared towards helping us produce the site documentation.ssvc.decision_points.cvss
andssvc.dp_groups.cvss
modules contain python implementations of CVSS vector elements from CVSS v1, v2, v3, v3.1, and v4. We anticipate some of these coming in handy in the future as we look toward modeling other decisions potentially based on CVSS vector elements as well as other decision points from SSVC and elsewhere. We also included decision points and groups from CISA's customized SSVC implementation.Other project infrastructure improvements
What's Changed
howto/index.md
by @ahouseholder in Revisehowto/index.md
#469link_checker.yml
run automatically on push tomain
by @ahouseholder in Makelink_checker.yml
run automatically on push tomain
#471Learning SSVC
by @ahouseholder in Add Calculator blurb toLearning SSVC
#515New Contributors
Full Changelog: v2023.9...v2024.3
This discussion was created from the release SSVC v2024.3.
Beta Was this translation helpful? Give feedback.
All reactions