On 5/9/17 3:02 PM, Kurt Seifried wrote:
> So I assumed we'd have a publishing model where CNA's just publish to
> their parent until it hits MITRE.
I'd suggest a model where every CNA publishes, in at least the CVE MVP
format (but more is OK, such as DWF requirements). I guess this is pull
not push? Parent CNAs would be required to pull/aggregate from their
children.
This way, anybody can pull from any CNA, MITRE or NVD can pull from
all/lots of CNAs. This allows a lot more flexibility in aggregation,
possibly at the cost of more effort for a central aggregator (MITRE).
I think Atom/PubSub is more than this, but I haven't read up on it.
- Art