Security Report JSON format improvements to consider
Problem to solve
The current JSON report format we use for security reports needs improvements to broader usage.
Intended users
Further details
Proposal
To be discussed further, maybe open separate issues for each of them.
-
deprecate the cveproperty, replace it with aremediation_idto be used in theremediation.fixesas a reference for which vulnerabilities get fixed by that remediation. (TDB further sinceremediation_idlooks like inverse relationship at first) -
deprecate categoryproperty, replace it withreport_type -
disambiguate namevsmessage, possible deprecatenameif we can't rely on it for all scanners
Permissions and Security
Documentation
Testing
What does success look like, and how can we measure that?
What is the type of buyer?
Links / references
Edited by Olivier Gonzalez