Skip to content

exclusively-hosted-service and unsupported-when-assigned tags should apply to affected element not CNA contaner #13

@zmanion

Description

@zmanion

The exclusively-hosted-service and unsupported-when-assigned tags (glossary, schema) apply to the entire CNA container. Should they instead apply to an affected element?

Real world example: Given a CVE ID that affects Adminer (unsupported, will not be fixed) and AdminerEvo (fork of Adminer, supported, fixed), there is currently not a machine-readable way to specifify that Adminer is EOL.

Example: A CVE ID affects software that exists both as a service and an "on-prem" product. It is not possible to indicate that one affected element is a cloud service while another element is not.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions