From e8b9bf0163615d36fda977d59adbe1c7106d511a Mon Sep 17 00:00:00 2001 From: tschmidtb51 <65305130+tschmidtb51@users.noreply.github.com> Date: Fri, 31 Jan 2025 16:03:42 +0100 Subject: [PATCH] CWEs - addresses parts of oasis-tcs/csaf#530, oasis-tcs/csaf#841 - rephrase test 6.1.11 and 6.3.4 to clarify the test according to the change to multiple CWEs --- csaf_2.1/prose/edit/src/tests-01-mndtr-11-cwe.md | 2 +- csaf_2.1/prose/edit/src/tests-03-informative.md | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/csaf_2.1/prose/edit/src/tests-01-mndtr-11-cwe.md b/csaf_2.1/prose/edit/src/tests-01-mndtr-11-cwe.md index 1d680687c..05d8fa167 100644 --- a/csaf_2.1/prose/edit/src/tests-01-mndtr-11-cwe.md +++ b/csaf_2.1/prose/edit/src/tests-01-mndtr-11-cwe.md @@ -1,6 +1,6 @@ ### CWE -It MUST be tested that given CWE exists and is valid in the version provided. +For each CWE it MUST be tested that the given CWE exists and is valid in the version provided. Any `id` that refers to a CWE Category or View MUST fail the test. The relevant path for this test is: diff --git a/csaf_2.1/prose/edit/src/tests-03-informative.md b/csaf_2.1/prose/edit/src/tests-03-informative.md index 21ae1b7a5..64a8f94f5 100644 --- a/csaf_2.1/prose/edit/src/tests-03-informative.md +++ b/csaf_2.1/prose/edit/src/tests-03-informative.md @@ -120,7 +120,7 @@ If no CVE exists for that vulnerability, it is recommended to get one assigned. ### Missing CWE -It MUST be tested that the CWE is given. +It MUST be tested that at least one CWE is given. The relevant path for this test is: @@ -139,7 +139,7 @@ The relevant path for this test is: ] ``` -> The CWE number is not given. +> No CWE number is given. ### Use of Short Hash