Reading this:
https://github.com/oasis-tcs/csaf/issues/1482#issuecomment-4805639860
"Adoption of CSAF for vulnerability reports submission pre-embargo using TLP markings and phased release to public CSAF report"
But I think it's actually we do with BCP-05 (using a standard CVE-record format), you can pre-edit the vulnerability before it's actually disclosed.
What you think of this? @cedric any PoV?
Discuss this on our forum.