Hello CSAF community,
we completed an analysis of PURL conformance gaps in csaf-rs and wanted to share the current outcome. Some inconsistencies were first identified in https://github.com/csaf-rs/csaf/pull/712#issue-4918968557
Initially, we had two general findings:
- Implementation-level mismatches where the Rust validation pipeline accepted or rejected cases differently from the purl tests
- Policy-level differences between CSAF's stricter canonical expectations and purl-spec's normalization-oriented testing
When upgrading to packageurl 0.7.0, the implementation-level mismatches disappear. Thus, the policy-level alignment question remains around canonical-only validation. At the moment, this does not indicate a change needed in CSAF itself. We will keep up the discussion about requiring normalized inputs in the purl community.
Related CSAF issue discussion: Purl misjudgment claims · Issue #1490 · oasis-tcs/csaf
Best regards
------------------------------
Immanuel Kunz
Fraunhofer-Gesellschaft e.V. - Fraunhofer AISEC
------------------------------