-
Notifications
You must be signed in to change notification settings - Fork 12
Description
Unless I'm missing something fundamental, the CVE corpus does not inherently have revision history.
The git/GitHub bulk download feature may address this, at least partially, e.g., CVEProject/cvelistV5@a93cad3.
The services/corpus may have "internal" revision history but this doesn't help with external uses cases.
At least one recent use case: A CNA wants to take ownership of and update all of their records. The CNA wants to make substantial changes, possibly verging on "rewriting history." We've discussed and decided some policy limits on this use case, however revision history would make it clear to anyone who made what change when. So if a CNA makes substantial changes, everyone would know, and be able to access previous versions of changed records.