Re: update please

1 message Options
Embed this post
Permalink
Andrew Buttner

Re: update please

Reply Threaded More More options
Print post
Permalink
I will give an update from the MITRE CPE side of things.  NIST, please =
correct where I am mistaken.

Version 1.0 of the CPE Specification was released on March 13th.  At that =
time, the official dictionary was a bit under-developed and in need of =
work.  We posted that version of the dictionary as draft since we knew =
changes would have to be made.

NVD offered to convert their product dictionary over to the CPE format and =
submit those names for inclusion in the dictionary.  This work has been =
ongoing and is what TK noted in his original post.  Most of the work has =
been done, but there are some formatting errors and quality assurance that =
still has to take place.  Our goal is to get that information solidified =
and release the first official version of the CPE Dictionary.

While that work at NVD has been going on, the CPE Community has begun work =
on an updated version of the CPE Specification.  We had a call on June 7th =
to discuss a few of the proposed enhancements and since that call I have =
been working to create a draft version of the new spec.  This draft is =
currently being reviewed by some internal personnel and I hope to post it =
shortly to the list.

When this draft (version 2.0) becomes official, we will convert the =
dictionary over to the 2.0 format.  The changes being proposed will only =
require a find and replace to names being submitted by NVD.

I hope this helps clear things up.

Thanks
Drew

>-----Original Message-----
>From: Tim Keanini Sr. [mailto:[hidden email]]=20
>Sent: Monday, June 25, 2007 12:46 PM
>To: cpe-discussion-list CPE Community Forum
>Subject: [CPE-DISCUSSION-LIST] update please
>
>Hello all,
>could we get an update on where we are with CPE?
>
>I'm trying to reconcile the progress being made on NVD with=20
>CPE and the discussion threads of CPE on the mailing list.
>When I look at something like the cpe-dictionary.xml which is=20
>as current as June 25th, I see a URI that is unique (and=20
>useful) but does not follow the HW/OS/App facet-based=20
>categorization as previously discussed.  My guess is that the=20
>discussion threads need to be updated and that is the reason=20
>for my posting.
>
>--tk
>
>--
>Timothy 'TK' Keanini. CTO
>
>101 Second Street, Suite 400
>San Francisco, CA  94105
>Office: +1 415 625 5939
>Mobile: +1 415 328 2722
>Fax: +1 415 625 5984
>http://www.ncircle.com/
>
>Check out our Blog: http://blog.ncircle.com/patterns
>
>
>

attachment0 (3K) Download Attachment