Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

#2178 Update CNA Rules page to add View as PDF #2183

Merged
merged 4 commits into from
Sep 5, 2023
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
113 changes: 113 additions & 0 deletions src/assets/data/CNAsList.json
Original file line number Diff line number Diff line change
Expand Up @@ -18064,5 +18064,118 @@
]
},
"country": "USA"
},
{
"shortName": "PureStorage",
"cnaID": "CNA-2023-0052",
"organizationName": "Pure Storage, Inc.",
"scope": "Pure Storage products only",
"contact": [
{
"email": [
{
"label": "Email",
"emailAddr": "psirt@purestorage.com"
}
],
"contact": [],
"form": []
}
],
"disclosurePolicy": [
{
"label": "Policy",
"language": "",
"url": "https://support.purestorage.com/Pure_Security/Product_Security_Policy"
}
],
"securityAdvisories": {
"alerts": [],
"advisories": [
{
"label": "Advisories",
"url": "https://support.purestorage.com/Pure_Security/Security_Bulletins"
}
]
},
"resources": [],
"CNA": {
"isRoot": false,
"root": {
"shortName": "n/a",
"organizationName": "n/a"
},
"roles": [
{
"helpText": "",
"role": "CNA"
}
],
"TLR": {
"shortName": "mitre",
"organizationName": "MITRE Corporation"
},
"type": [
"Vendor"
]
},
"country": "USA"
},
{
"shortName": "PSF",
"cnaID": "CNA-2023-0053",
"organizationName": "Python Software Foundation",
"scope": "Only supported and end-of-life Python versions available at <a href='https://python.org/downloads' target='_blank'>https://python.org/downloads</a> and pip versions available at <a href='https://pypi.org/project/pip'>https://pypi.org/project/pip</a>, and excluding distributions of Python and pip maintained by third-party redistributors",
"contact": [
{
"email": [
{
"label": "Email",
"emailAddr": "cna@python.org"
}
],
"contact": [],
"form": []
}
],
"disclosurePolicy": [
{
"label": "Policy",
"language": "",
"url": "https://www.python.org/dev/security"
}
],
"securityAdvisories": {
"alerts": [],
"advisories": [
{
"label": "Advisories",
"url": "https://mail.python.org/archives/list/security-announce@python.org/latest"
}
]
},
"resources": [],
"CNA": {
"isRoot": false,
"root": {
"shortName": "n/a",
"organizationName": "n/a"
},
"roles": [
{
"helpText": "",
"role": "CNA"
}
],
"TLR": {
"shortName": "mitre",
"organizationName": "MITRE Corporation"
},
"type": [
"Vendor",
"Open Source"
]
},
"country": "USA"
}
]
59 changes: 59 additions & 0 deletions src/assets/data/news.json
Original file line number Diff line number Diff line change
@@ -1,5 +1,47 @@
{
"currentNews": [
{
"id": 242,
"newsType": "news",
"title": "Python Software Foundation Added as CVE Numbering Authority (CNA)",
"urlKeywords": "Python Software Foundation Added as CNA",
"date": "2023-08-29",
"description": [
{
"contentnewsType": "paragraph",
"content": "<a href='/PartnerInformation/ListofPartners/partner/PSF'>Python Software Foundation</a> is now a <a href='/ResourcesSupport/Glossary?activeTerm=glossaryCNA'>CVE Numbering Authority (CNA)</a> for only supported and end-of-life Python versions available at <a href='https://python.org/downloads' target='_blank'>https://python.org/downloads</a> and pip versions available at <a href='https://pypi.org/project/pip'>https://pypi.org/project/pip</a>, and excluding distributions of Python and pip maintained by third-party redistributors."
},
{
"contentnewsType": "paragraph",
"content": "To date, <a href='/PartnerInformation/ListofPartners'>314 organizations</a> from <a href='/ProgramOrganization/CNAs'>37 countries</a> have partnered with the CVE Program. CNAs are organizations from around the world that are authorized to assign <a href='/ResourcesSupport/Glossary?activeTerm=glossaryCVEID'>CVE Identifiers (CVE IDs)</a> and publish <a href='/ResourcesSupport/Glossary?activeTerm=glossaryRecord'>CVE Records</a> for vulnerabilities affecting products within their distinct, agreed-upon scope, for inclusion in first-time public announcements of new vulnerabilities."
},
{
"contentnewsType": "paragraph",
"content": "Python Software Foundation’s Root is the <a href='/PartnerInformation/ListofPartners/partner/mitre'>MITRE Top-Level Root</a>."
}
]
},
{
"id": 241,
"newsType": "news",
"title": "Pure Storage Added as CVE Numbering Authority (CNA)",
"urlKeywords": "Pure Storage Added as CNA",
"date": "2023-08-29",
"description": [
{
"contentnewsType": "paragraph",
"content": "<a href='/PartnerInformation/ListofPartners/partner/PureStorage'>Pure Storage, Inc.</a> is now a <a href='/ResourcesSupport/Glossary?activeTerm=glossaryCNA'>CVE Numbering Authority (CNA)</a> for Pure Storage products only."
},
{
"contentnewsType": "paragraph",
"content": "To date, <a href='/PartnerInformation/ListofPartners'>313 organizations</a> from <a href='/ProgramOrganization/CNAs'>37 countries</a> have partnered with the CVE Program. CNAs are organizations from around the world that are authorized to assign <a href='/ResourcesSupport/Glossary?activeTerm=glossaryCVEID'>CVE Identifiers (CVE IDs)</a> and publish <a href='/ResourcesSupport/Glossary?activeTerm=glossaryRecord'>CVE Records</a> for vulnerabilities affecting products within their distinct, agreed-upon scope, for inclusion in first-time public announcements of new vulnerabilities."
},
{
"contentnewsType": "paragraph",
"content": "Pure Storage’s Root is the <a href='/PartnerInformation/ListofPartners/partner/mitre'>MITRE Top-Level Root</a>."
}
]
},
{
"id": 240,
"newsType": "news",
Expand Down Expand Up @@ -56,6 +98,23 @@
}
]
},
{
"id": 239,
"newsType": "news",
"title": "Minutes from CVE Board Teleconference Meeting on August 16 Now Available",
"urlKeywords": "CVE Board Minutes from August 16",
"date": "2023-08-29",
"description": [
{
"contentnewsType": "paragraph",
"content": "The <a href='/ProgramOrganization/Board'>CVE Board</a> held teleconference meeting on August 16, 2023. Read the <a href='https://cve.mitre.org/community/board/meeting_summaries/16_August_2023.pdf' target='_blank'>meeting minutes</a>."
},
{
"contentnewsType": "paragraph",
"content": "The CVE Board is the organization responsible for the strategic direction, governance, operational structure, policies, and rules of the CVE Program. The Board includes members from numerous cybersecurity-related organizations including commercial security tool vendors, academia, research institutions, government departments and agencies, and other prominent security experts, as well as end-users of vulnerability information."
}
]
},
{
"id": 238,
"newsType": "blog",
Expand Down
10 changes: 4 additions & 6 deletions src/views/ResourcesSupport/AllResources/CNARules.vue
Original file line number Diff line number Diff line change
Expand Up @@ -8,12 +8,10 @@
<main id="cve-main-page-content" role="main">
<h1 class="title">CVE Numbering Authority (CNA) Rules</h1>
<div id="cve-versionInformation">
<span class="has-text-weight-bold">Document Version: </span>
<span>{{versionNum}}</span><br>
<span class="has-text-weight-bold">CVE Board Approval: </span>
<span>{{versionApprovalDate}}</span><br>
<span class="has-text-weight-bold">Effective Date: </span>
<span>{{versionDate}}</span><br>
<p class="has-text-weight-bold">Document Version: <span>{{versionNum}}</span></p>
<p class="has-text-weight-bold">CVE Board Approval: <span>{{versionApprovalDate}}</span></p>
<p class="has-text-weight-bold">Effective Date: <span>{{versionDate}}</span></p>
<p><router-link to="/Resources/Roles/Cnas/CNA_Rules_v3.0.pdf" target="_blank">View as PDF (0.5MB)</router-link></p>
</div>
<hr>
<!-- Top level section -->
Expand Down