|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Re: VuXML and pkgsrc
From: Daniel Carosone (dan
geek.com.au)
Date: Tue May 04 2004 - 06:17:25 CDT
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
On Tue, May 04, 2004 at 10:25:48AM +0100, Adrian Portelli wrote:
> Some other *BSD's have started using VuXML (http://www.vuxml.org/) for
> their ports/packages related security issues.
>
> "VuXML is the Vulnerability and eXposure Markup Language, an XML
> application for documenting security issues in a software package
> collection such as the FreeBSD Ports Collection or OpenBSD Ports &
> Packages Collection"
>
> Is it worth looking at this for NetBSD pkgsrc issues ?
I like XML, as a general rule, but for what use would VuXML be valuable:
- does it add anything important to the current format for the
pkg-vulnerabilities list? I guess possibly not, without checking
the references.
- is it something we should write a separate tool, to import other
project's XML files and look for vulnerabilities? (and perhaps
likewise publish in turn)
The best benefit for XML in the general case is "i don't have to write
a parser", which is fine as far as it goes, but the present format is
parsed by existing tools easily anyway.
If it offers us, as pkgsrc developers, easier maintenance and faster
notification of problems with 3rd party code, that's of value and
interest, certainly.
I'll take a look at VuXML separately as s-o, because I've been wanting
something more structured as a source format for project Security
Advisories.
--
Dan.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (NetBSD)
iD8DBQFAl3vFEAVxvV4N66cRAjeHAJ9n6EwYG+6a90iKugy+pZ00qUF32gCgikk5
/HKu9aG7pNXhJZen0uNO/kQ=
=4siJ
-----END PGP SIGNATURE-----
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]