-
Notifications
You must be signed in to change notification settings - Fork 1
Description
To a significant extent, and historically, the CVE Program follows a model of not deleting Records or content (with an exception for at least REJECTED records, but see CVEProject/strategic-planning-working-group#6). Do we want to be able to fully delete ADP or SADP containers? If so, we should propose a new CVE Services API call (probably HTTP DELETE) and policy about when deletion is allowed and how it is done. For instance, can any (S)ADP delete their own containers? Or can only the Secretariat delete ADP containers? I'll propose that only the Secretariat has the technical capability, but is only permitted to delete containers at the behest of the (S)ADP or the CVE Board, and when all parties involved (Secretariat and the ADP or Board) all agree. This balances the "CVE Historical Preservation Society" against "this ADP container is a complete mistake."
For the SADP pilot, participants can "zero out" a container, that is, remove all the content, and maybe leaving a brief explanatory note in .description.