Comments (4)
Currently cvss4 has a draft state (release 2023-10-31). There are some major changes and therefore some effort for this project. Maybe we should implement that code (create merge request) request based on the current draft, to ensure the final changes can be implemented faster?
from go-cvss.
There are some major changes
Partially true thus partially false: the vector is composed in the same way as for CVSS v3 so the code already exists.
The only thing I changed in Section 7 of the release is the examples of valid and invalid vectors.
Nevertheless, the maths changed and I suggest you wait for the release to implement it (could take a bit of time to implement), as we are still finishing it.
EDIT(06th oct. 2023): I choosed to go with with strict ordering as for CVSS v2.0 to be able to build a linear regex. Else it would have been of O(n!) complexity thus not possible to build a regex (it is a current problem of CVSS v3). As you already support it, the code exists. One more point goes to the "wait for the release" 😉
from go-cvss.
v4 has been published om the 1st of November, revision 1.1 of their document on 2023-11-09. https://www.first.org/cvss/v4-0/ So work could start on it. ;)
from go-cvss.
thank you.
I'm too busy with my day job to work on this package at the moment.
I hope to work on CVSSv4 after the official release.
from go-cvss.
Related Issues (12)
- CVSSv3 Temporal score HOT 3
- Improper Input Validation in CVSS v3 parsing HOT 1
- Another Improper Input Validation in CVSS v3 parsing HOT 1
- One more Improper Input Validation in CVSS v3 parsing HOT 1
- Invalid CVSS v3 environmental score computation HOT 1
- Improper Input Validation in CVSS v2 parsing HOT 1
- Invalid CVSS v2 vector HOT 1
- Improper Input Validation in CVSS v2 parsing HOT 1
- Another Improper Input Validation in CVSS v2 parsing HOT 7
- One more Improper Input Validation in CVSS v2 parsing HOT 3
- Invalid CVSS v2 environmental score computation HOT 12
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from go-cvss.