csaf-tools/CSAF Advisory Provider

Creates the CSAF documents to create a CSAF trusted provider

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
csaf_versionThe version of the gocsaf/csaf tool suite. Either only a major version number or the exact version number.no3
secvisogram_versionVersion of the secvisogram validator service. Either only a major version number or the exact version number.no2
publisher_categoryThe category of the CSAF Publishernovendor
publisher_nameName of the CSAF Publisheryes
publisher_namespaceURL of the CSAF Publisheryes
publisher_issuing_authorityDescription of the Issuing Authority of the CSAF Publisheryes
publisher_contact_detailsContact details of the CSAF Publisheryes
source_csaf_documentsPath to the CSAF source documentsno
openpgp_use_signaturesUse the signtures files placed along the advisory files with `.asc` file endingnotrue
openpgp_key_email_addressIf the OpenPGP is to be generated on the fly, this is the associated e-mail addressnocsaf@example.invalid
openpgp_key_real_nameIf the OpenPGP is to be generated on the fly, this is the associated real namenoExample CSAF Publisher
openpgp_key_typeIf the OpenPGP is to be generated on the fly, this is the key typenoRSA
openpgp_key_lengthIf the OpenPGP is to be generated on the fly, this is the key length in bitsno4096
openpgp_secret_keyThe armored OpenPGP secret key, provided as GitHub secretno
openpgp_public_keyThe armored OpenPGP public key, provided as GitHub secretno
openpgp_passphraseThe passphrase to unlock the OpenPGP secret key, provided as GitHub secretno
generate_index_filesGenerate index.html files in .well-known/csaf/ for easier navigation in the browser. Otherwise GitHub will give 404s when accessing the directories directly.nofalse
target_branchThe target branch to push the resulting data tonogh-pages
tlpsSet the TLP levels allowed to be send with the upload request. Possible levels: "csaf", "white", "amber", "green", "red". The "csaf" entry lets the provider take the value from the CSAF document.nocsaf,white
write_securityWrite a `CSAF:` entry into `security.txt`. Creates the file if it does not exist.nofalse
html_titleThe title of the HTML pages, if generate_index_files is active.noCSAF Advisories

no outputs