OASIS Static Analysis Results Interchange Format (SARIF) TC

 View Only
  • 1.  RE: [EXTERNAL] Re: [sarif] Draft IANA registration for media type application/sarif+json

    Posted 04-03-2020 23:52
    Oh! That is a very interesting point. Maybe I was answering the wrong question. I was answering the question "What applications use SARIF files?". I was not answering the question "What applications currently use application/sarif+json" to designate SARIF files?" Because the answer to _that_ question is "None" ð David, what should I be doing here?


  • 2.  Re: [sarif] RE: [EXTERNAL] Re: [sarif] Draft IANA registration for media type application/sarif+json

    Posted 04-03-2020 23:59
    Larry, Maybe we are being too specific. For example, if you look at the description for application/sql, it just says "Databases and related tools" instead of listing product names. https://tools.ietf.org/html/rfc6922 What if we went through the conformance clauses and picked out generic descriptions for tools, such as "static analyzers," "static analysis results visualization tools," etc. (still keeping the list labeled as not exhaustive)? Does that sound reasonable to you? David On 4/3/20 4:51 PM, Larry Golding (Myriad Consulting Inc) wrote: Oh! That is a very interesting point. Maybe I was answering the wrong question. I was answering the question "What applications use SARIF files?". I was not answering the question "What applications currently use application/sarif+json" to designate SARIF files?" Because the answer to _that_ question is "None" ð David, what should I be doing here?


  • 3.  RE: [sarif] RE: [EXTERNAL] Re: [sarif] Draft IANA registration for media type application/sarif+json

    Posted 04-04-2020 00:01
    That sounds like a great idea, thanks! (And the sql example does answer my question: the intent of the question is "what kinds of software would use this type", not "what kinds of software are using it now".)