OASIS Common Security Advisory Framework (CSAF) TC

 View Only
  • 1.  TC meeting 2026-01-26

    Posted 01-27-2026 19:29

    Dear colleagues,

    this is a short reminder and request for this week's TC meeting: Please familiarize yourself with currrent open issues (https://github.com/oasis-tcs/csaf/issues) and pull requests (https://github.com/oasis-tcs/csaf/pulls).

    Many thanks in advance.

    Best wishes,

    Thomas



    ------------------------------
    Thomas Schmidt
    Subject Matter Expert
    Federal Office for Information Security (BSI) Germany
    ------------------------------


  • 2.  RE: TC meeting 2026-01-26

    Posted 01-28-2026 10:50

    Dear colleagues,

    here is a rough agenda for the items that we should discuss in today's meeting. Please familiarize yourself with the topics so that we can have a productive discussion. DO NOT hesitate to state your opinion in the issue / pull request beforehand - even though not everyone might have a chance to read all comments (and you might have to restate your opinion in the meeting), this will help to get to resolutions faster as it.

    Agenda:
    - Super-Motion for all pending motions (except for https://groups.oasis-open.org/discussion/motion-for-1221 - this is discussed separately):
      - https://groups.oasis-open.org/discussion/motion-for-1274
      - https://groups.oasis-open.org/discussion/motion-for-1278
      - https://groups.oasis-open.org/discussion/motion-for-1281
      - https://groups.oasis-open.org/discussion/motion-for-1282
    - other pending PRs shortly introduced to provide opportunity for questions
    - suggestion of standing rule "Known issues": The editors can add any item fixed in the a version of the standard to the list of known issue for all previous versions if applicable without an extra motion. Also, items that are acknowledged as known issue in one version can be added to other versions of the standard, if applicable. The process of having at least one approval and no rejection from an member with write access remains in place.
    - discussion and decision regarding way forward at
      - https://github.com/oasis-tcs/csaf/issues/1280: Please take a thorough look as this is an important issue regarding the retrieval.
      - https://github.com/oasis-tcs/csaf/issues/1177: A quite significant change
      - https://github.com/oasis-tcs/csaf/issues/1220 / https://github.com/oasis-tcs/csaf/pull/1221: Christian pointed out in https://groups.oasis-open.org/discussion/motion-for-1221#bm780f0b77-6ca4-4184-adfa-4b45066f21d1 that he is missing the feedback from other TC members that wanted to ask their technical writers about their opinion.
      - https://github.com/oasis-tcs/csaf/issues/1044
    - General Path Forward (potentially with motion):
      - https://github.com/oasis-tcs/csaf/issues/1283
      - https://github.com/oasis-tcs/csaf/issues/1264: add to known issue list
    - Labeled for TC discussion:
      - https://github.com/oasis-tcs/csaf/issues/675
      - https://github.com/oasis-tcs/csaf/issues/1239 (maybe more of a committee note / FAQ entry so that we adapt faster?)
      - https://github.com/oasis-tcs/csaf/issues/883 
      - https://github.com/oasis-tcs/csaf/issues/1163 (based on the discussion on 2025-12-17, I suggest to close as "no intention to do anything (aka won't fix)"
      - https://github.com/oasis-tcs/csaf/issues/850 (suggestion to clearly state: not mentioned - no assumption)
      - https://github.com/oasis-tcs/csaf/issues/692

    - Probably other stuff that I forgot to mention

    As we have a full agenda, I appreciate your commitment to make this a productive meeting.

    Best wishes,
    Thomas



    ------------------------------
    Thomas Schmidt
    Subject Matter Expert
    Federal Office for Information Security (BSI) Germany
    ------------------------------



  • 3.  RE: TC meeting 2026-01-26

    Posted 01-28-2026 10:57

    I just realized that the date in the heading is wrong (but there is no way to change that). Obviously, our TC meeting is today: 2026-01-28



    ------------------------------
    Thomas Schmidt
    Subject Matter Expert
    Federal Office for Information Security (BSI) Germany
    ------------------------------