Reading this:

https://github.com/oasis-tcs/csaf/issues/1482#issuecomment-4805639860

"Adoption of CSAF for vulnerability reports submission pre-embargo using TLP markings and phased release to public CSAF report"

But I think it's actually we do with BCP-05 (using a standard CVE-record format), you can pre-edit the vulnerability before it's actually disclosed.

What you think of this? @cedric any PoV?



Discuss this on our forum.