I will give an update from the MITRE CPE side of things. NIST, please =
correct where I am mistaken.
Version 1.0 of the CPE Specification was released on March 13th. At that =
time, the official dictionary was a bit under-developed and in need of =
work. We posted that version of the dictionary as draft since we knew =
changes would have to be made.
NVD offered to convert their product dictionary over to the CPE format and =
submit those names for inclusion in the dictionary. This work has been =
ongoing and is what TK noted in his original post. Most of the work has =
been done, but there are some formatting errors and quality assurance that =
still has to take place. Our goal is to get that information solidified =
and release the first official version of the CPE Dictionary.
While that work at NVD has been going on, the CPE Community has begun work =
on an updated version of the CPE Specification. We had a call on June 7th =
to discuss a few of the proposed enhancements and since that call I have =
been working to create a draft version of the new spec. This draft is =
currently being reviewed by some internal personnel and I hope to post it =
shortly to the list.
When this draft (version 2.0) becomes official, we will convert the =
dictionary over to the 2.0 format. The changes being proposed will only =
require a find and replace to names being submitted by NVD.
I hope this helps clear things up.
Thanks
Drew
>-----Original Message-----
>From: Tim Keanini Sr. [mailto:
[hidden email]]=20
>Sent: Monday, June 25, 2007 12:46 PM
>To: cpe-discussion-list CPE Community Forum
>Subject: [CPE-DISCUSSION-LIST] update please
>
>Hello all,
>could we get an update on where we are with CPE?
>
>I'm trying to reconcile the progress being made on NVD with=20
>CPE and the discussion threads of CPE on the mailing list.
>When I look at something like the cpe-dictionary.xml which is=20
>as current as June 25th, I see a URI that is unique (and=20
>useful) but does not follow the HW/OS/App facet-based=20
>categorization as previously discussed. My guess is that the=20
>discussion threads need to be updated and that is the reason=20
>for my posting.
>
>--tk
>
>--
>Timothy 'TK' Keanini. CTO
>
>101 Second Street, Suite 400
>San Francisco, CA 94105
>Office: +1 415 625 5939
>Mobile: +1 415 328 2722
>Fax: +1 415 625 5984
>
http://www.ncircle.com/>
>Check out our Blog:
http://blog.ncircle.com/patterns>
>
>