Skip to content

Section for changelog based on closed issues#139

Merged
j--- merged 2 commits into
CERTCC:mainfrom
j---:changelog
Mar 31, 2021
Merged

Section for changelog based on closed issues#139
j--- merged 2 commits into
CERTCC:mainfrom
j---:changelog

Conversation

@j---

@j--- j--- commented Mar 29, 2021

Copy link
Copy Markdown
Collaborator

fixes #122

@j--- j--- added this to the SSVC v2 milestone Mar 29, 2021
@j--- j--- self-assigned this Mar 29, 2021

@ahouseholder ahouseholder left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

proposed changes look fine to me

Comment thread doc/md_src_files/065_changelog.md
Comment thread doc/md_src_files/065_changelog.md Outdated

@laurie-tyz laurie-tyz left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It seems like more sections/ideas have been added to version 2 vs version 1. Should this section itemize the changes? no, but should one or two more be highlighted? maybe.

Comment thread doc/md_src_files/065_changelog.md Outdated
Comment thread doc/md_src_files/065_changelog.md Outdated
These terms in v2 better reflect the stakeholder's relationship to the vulnerable component and also help keep clear that SSVC is about prioritization of work items in vulnerability management, not just patches.
We have also generally removed the word patch and instead use the more general "remediation" for a complete fix and "mitigation" for actions that reduce risk but do not remove a vulnerability from a system.
"Virulence" was renamed [*Automatable*](#automatable) in a effort to be more direct and clear, rather than relying on an epidemiology metaphor.
Based on feedback from Sounil Yu, we changed "out-of-band" to [**out-of-cycle**](#enumerating-vulnerability-management-actions).

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No problem giving direct credit, but are we somewhat consistent about this?

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good point. It looks like the acknowledgements didn't get converted, I'll reintroduce those and make sure they're updated.

@zmanion

zmanion commented Mar 30, 2021

Copy link
Copy Markdown
Contributor

See a few minor comments in my review, they do not block.

@zmanion zmanion closed this Mar 30, 2021
@zmanion zmanion reopened this Mar 30, 2021
@j---
j--- merged commit 88fe255 into CERTCC:main Mar 31, 2021
@j---
j--- deleted the changelog branch March 5, 2024 16:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Summarize changes from v1 in v2 doc

4 participants