Skip to content

Conversation

@taladrane
Copy link
Contributor

This document provides an update on the activities and discussions of the Vulnerability Disclosures Working Group for Q4 2025, including proposals for standardizing vulnerability reporting and addressing challenges in the CVE program.

This document provides an update on the activities and discussions of the Vulnerability Disclosures Working Group for Q4 2025, including proposals for standardizing vulnerability reporting and addressing challenges in the CVE program.

Signed-off-by: Madison Oliver <[email protected]>
@taladrane taladrane requested a review from a team as a code owner October 28, 2025 14:39
@marcelamelara marcelamelara added the TI Update Quarterly TI update. Needs 5 approvals, 7d review. label Nov 11, 2025
Comment on lines +22 to +34
- Extensive discussions have taken place regarding the necessity and alignment of a VDR standard with existing frameworks like FedRAMP.
- The working group has validated the belief that users struggle with CPE identifiers and need a product-centric view of vulnerabilities.
- Key requirements for a successful VDR standard have been established, including machine-readable format, API accessibility, familiar product naming, and compliance with various standards (NIST SP 800-161r1 RA-5, FedRAMP).
- Existing VDR solutions from vendors like Cisco have been reviewed, highlighting the need for a standardized, easily parsable format.
- Motivation for adoption has been discussed, with potential drivers identified in the energy industry and cyber insurance sector.
- The distinction between VEX (vulnerability-centric) and VDR (product-centric) has been clarified.

**Up Next (Next 4–8 Weeks):**

1. TAC vote for this initiative is open: https://github.com/ossf/tac/issues/530
2. Further exploration of aligning VDR efforts with SBOM standards.
3. Continued discussion on how OSV.dev could support exporting data in a newly defined VDR format.
4. Investigate how CycloneDX can support "clean" VDRs (reports with zero known vulnerabilities).
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This section is now unfortunately out of date given that issue #530 was discussed by the TAC and the request for funding was turned down based on the existence of the CycloneDX VDR format and the desire to engage with that community rather than creating a competing format.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

TI Update Quarterly TI update. Needs 5 approvals, 7d review.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants