Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

explanation of test 6.3.10 (product_version_range) #845

Open
jaccoNCSCNL opened this issue Dec 16, 2024 · 2 comments
Open

explanation of test 6.3.10 (product_version_range) #845

jaccoNCSCNL opened this issue Dec 16, 2024 · 2 comments
Assignees

Comments

@jaccoNCSCNL
Copy link

We fail to understand test 6.3.10:
https://docs.oasis-open.org/csaf/csaf/v2.0/os/csaf-v2.0-os.html#6310-usage-of-product-version-range

What we read here, is that there is a category product_version_range but if you try to use it, your test will fail.

Jacco

@jaccoNCSCNL jaccoNCSCNL changed the title explanation of test 6.3.10 explanation of test 6.3.10 (product_version_range) Dec 16, 2024
@tschmidtb51 tschmidtb51 self-assigned this Dec 16, 2024
@tschmidtb51
Copy link
Contributor

Hi Jacco,
it is an informative test - that means that the test can fail without having an effect on the validity of the CSAF document. From the standard:

Informative tests provide insights in common mistakes and bad practices. They MAY fail at a valid CSAF document. It is up to the issuing party to decide whether this was an intended behavior and can be ignore or should be treated. These tests MAY include information about recommended usage. A program MUST handle a test failure as a information.

The use of product_version_range is allowed. However, it is considered a "bad practice" as it may result in difficulties in matching against assets or SBOMs. Nevertheless, it is recommended if otherwise the affected versions wouldn't be listed.

Does that answer your question?

@tschmidtb51
Copy link
Contributor

Is there anything in particular that would need rephrasing?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants