World Models · Published

Vulnerability Record

Represent an authority-qualified security vulnerability record, its affected product assertions, evidence, assessments and disclosure lifecycle independent of storage and interface format.

AI YAMLAGENTS.mdResearch evidence
Published. Research assurance: reviewable-draft. The Codex-only synthesis is published under an explicit repository-owner provider waiver. It passed structural validation and a separate no-tools adversarial audit, but remains a reviewable draft until independent second-provider review and the holds below are closed.
Catalogue IDWM-SFT-006
Version0.3.0-research.1
Previous version-
Typeaggregate
ValidationPassed
Synthesis digestsha256:81ef7bacb326c523…
12Sources
6Bundles
12Layers
24Findings
72Questions
24Artifacts
Format-independent logical structure

Bundles → Layers → Findings → Questions + Artifacts

vulnerability-identity-record-authority-and-classVulnerability identity, record authority and class2 layers

Identifies one vulnerability record and preserves source authority, aliases and assertion containers.

record-identity-aliases-and-boundaryRecord identity, aliases and boundary2 findings

Stable identifiers and relations among same, upstream and related vulnerability records.

authoritative-identifier-namespace-alias-resolver-and-collision

Authoritative identifier, namespace, alias, resolver and collision

Master identifier, assigning namespace, aliases, resolver, reservation status, predecessor, duplicate and collision evidence.

Questions
  1. What identifiers, source containers, classes, scope and values define authoritative identifier, namespace, alias, resolver and collision?identity
    Expected answer
    • identifiers and aliases
    • source and class
    • scope and values
    • explicit unknowns
  2. Which authority, evidence, method, event time and knowledge time support authoritative identifier, namespace, alias, resolver and collision?evidence
    Expected answer
    • authority
    • evidence and method
    • event and knowledge time
    • confidence
  3. How may authoritative identifier, namespace, alias, resolver and collision be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?validation
    Expected answer
    • validation
    • challenge and correction
    • successor history
    • retention and access
    • unsafe-detail boundary
Artifacts
  • Authoritative identifier, namespace, alias, resolver and collision recordVersioned evidence-bearing vulnerability record for authoritative identifier, namespace, alias, resolver and collision with source, method, event and knowledge time, confidence and access marking.
record-container-authorship-and-versionRecord container, authorship and version2 findings

Separates authoritative source containers and immutable versions.

cna-adp-nvd-vendor-ecosystem-and-database-assertion-container

CNA, ADP, NVD, vendor, ecosystem and database assertion container

Container kind, source organization, role, authority, schema version, covered claims, original locator and signature or digest.

Questions
  1. What identifiers, source containers, classes, scope and values define cna, adp, nvd, vendor, ecosystem and database assertion container?ownership
    Expected answer
    • identifiers and aliases
    • source and class
    • scope and values
    • explicit unknowns
  2. Which authority, evidence, method, event time and knowledge time support cna, adp, nvd, vendor, ecosystem and database assertion container?provenance
    Expected answer
    • authority
    • evidence and method
    • event and knowledge time
    • confidence
  3. How may cna, adp, nvd, vendor, ecosystem and database assertion container be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?access
    Expected answer
    • validation
    • challenge and correction
    • successor history
    • retention and access
    • unsafe-detail boundary
Artifacts
  • CNA, ADP, NVD, vendor, ecosystem and database assertion container recordVersioned evidence-bearing vulnerability record for cna, adp, nvd, vendor, ecosystem and database assertion container with source, method, event and knowledge time, confidence and access marking.
record-version-state-published-modified-rejected-and-withdrawn

Record version, state, published, modified, rejected and withdrawn

Version identifier, lifecycle state, state reason, predecessor, publication and modification times, withdrawal or rejection and retained history.

Questions
  1. What identifiers, source containers, classes, scope and values define record version, state, published, modified, rejected and withdrawn?lifecycle
    Expected answer
    • identifiers and aliases
    • source and class
    • scope and values
    • explicit unknowns
  2. Which authority, evidence, method, event time and knowledge time support record version, state, published, modified, rejected and withdrawn?temporal
    Expected answer
    • authority
    • evidence and method
    • event and knowledge time
    • confidence
  3. How may record version, state, published, modified, rejected and withdrawn be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?retention
    Expected answer
    • validation
    • challenge and correction
    • successor history
    • retention and access
    • unsafe-detail boundary
Artifacts
  • Record version, state, published, modified, rejected and withdrawn recordVersioned evidence-bearing vulnerability record for record version, state, published, modified, rejected and withdrawn with source, method, event and knowledge time, confidence and access marking.
description-weakness-and-affected-productDescription, weakness and affected product2 layers

Describes the flaw and source-qualified affected product and version assertions.

descriptions-problem-types-and-root-causeDescriptions, problem types and root cause2 findings

Captures multilingual statements and classifier mappings without turning inference into fact.

summary-description-language-supporting-media-and-redaction

Summary, description, language, supporting media and redaction

Plain-language and technical descriptions, language, media type, value, redaction markers, source, audience and version.

Questions
  1. What identifiers, source containers, classes, scope and values define summary, description, language, supporting media and redaction?definition
    Expected answer
    • identifiers and aliases
    • source and class
    • scope and values
    • explicit unknowns
  2. Which authority, evidence, method, event time and knowledge time support summary, description, language, supporting media and redaction?quality
    Expected answer
    • authority
    • evidence and method
    • event and knowledge time
    • confidence
  3. How may summary, description, language, supporting media and redaction be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?security
    Expected answer
    • validation
    • challenge and correction
    • successor history
    • retention and access
    • unsafe-detail boundary
Artifacts
  • Summary, description, language, supporting media and redaction recordVersioned evidence-bearing vulnerability record for summary, description, language, supporting media and redaction with source, method, event and knowledge time, confidence and access marking.
cwe-problem-type-root-cause-mechanism-and-prerequisite

CWE problem type, root cause, mechanism and prerequisite

Versioned CWE or other classifier reference, mapping method, weakness mechanism, prerequisites, confidence and disputed mappings.

Questions
  1. What identifiers, source containers, classes, scope and values define cwe problem type, root cause, mechanism and prerequisite?classification
    Expected answer
    • identifiers and aliases
    • source and class
    • scope and values
    • explicit unknowns
  2. Which authority, evidence, method, event time and knowledge time support cwe problem type, root cause, mechanism and prerequisite?process
    Expected answer
    • authority
    • evidence and method
    • event and knowledge time
    • confidence
  3. How may cwe problem type, root cause, mechanism and prerequisite be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?interoperability
    Expected answer
    • validation
    • challenge and correction
    • successor history
    • retention and access
    • unsafe-detail boundary
Artifacts
  • CWE problem type, root cause, mechanism and prerequisite recordVersioned evidence-bearing vulnerability record for cwe problem type, root cause, mechanism and prerequisite with source, method, event and knowledge time, confidence and access marking.
products-platforms-versions-and-statusProducts, platforms, versions and status2 findings

Expresses affectedness independently of inventory exposure.

vendor-product-package-module-platform-cpe-purl-and-identity-reference

Vendor, product, package, module, platform, CPE, purl and identity reference

External product or package identity, vendor, module, platform, CPE or purl, ecosystem and source namespace.

Questions
  1. What identifiers, source containers, classes, scope and values define vendor, product, package, module, platform, cpe, purl and identity reference?composition
    Expected answer
    • identifiers and aliases
    • source and class
    • scope and values
    • explicit unknowns
  2. Which authority, evidence, method, event time and knowledge time support vendor, product, package, module, platform, cpe, purl and identity reference?measurement
    Expected answer
    • authority
    • evidence and method
    • event and knowledge time
    • confidence
  3. How may vendor, product, package, module, platform, cpe, purl and identity reference be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?validation
    Expected answer
    • validation
    • challenge and correction
    • successor history
    • retention and access
    • unsafe-detail boundary
Artifacts
  • Vendor, product, package, module, platform, CPE, purl and identity reference recordVersioned evidence-bearing vulnerability record for vendor, product, package, module, platform, cpe, purl and identity reference with source, method, event and knowledge time, confidence and access marking.
affected-unaffected-unknown-version-range-configuration-and-justification

Affected, unaffected, unknown version range, configuration and justification

Product-status assertion, range scheme, introduced, fixed, last affected or limit events, configuration constraints, justification and source confidence.

Questions
  1. What identifiers, source containers, classes, scope and values define affected, unaffected, unknown version range, configuration and justification?state
    Expected answer
    • identifiers and aliases
    • source and class
    • scope and values
    • explicit unknowns
  2. Which authority, evidence, method, event time and knowledge time support affected, unaffected, unknown version range, configuration and justification?decision
    Expected answer
    • authority
    • evidence and method
    • event and knowledge time
    • confidence
  3. How may affected, unaffected, unknown version range, configuration and justification be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?temporal
    Expected answer
    • validation
    • challenge and correction
    • successor history
    • retention and access
    • unsafe-detail boundary
Artifacts
  • Affected, unaffected, unknown version range, configuration and justification recordVersioned evidence-bearing vulnerability record for affected, unaffected, unknown version range, configuration and justification with source, method, event and knowledge time, confidence and access marking.
discovery-disclosure-evidence-and-coordinationDiscovery, disclosure, evidence and coordination2 layers

Records accountable discovery and disclosure evidence without publishing restricted exploit detail.

discovery-reporting-evidence-and-confidenceDiscovery, reporting, evidence and confidence2 findings

Separates reports and observations from validated vulnerability claims.

discoverer-reporter-contact-role-credit-and-attribution

Discoverer, reporter, contact role, credit and attribution

External actor reference, contribution role, requested credit, contact protection, organization, consent and attribution status.

Questions
  1. What identifiers, source containers, classes, scope and values define discoverer, reporter, contact role, credit and attribution?identity
    Expected answer
    • identifiers and aliases
    • source and class
    • scope and values
    • explicit unknowns
  2. Which authority, evidence, method, event time and knowledge time support discoverer, reporter, contact role, credit and attribution?evidence
    Expected answer
    • authority
    • evidence and method
    • event and knowledge time
    • confidence
  3. How may discoverer, reporter, contact role, credit and attribution be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?validation
    Expected answer
    • validation
    • challenge and correction
    • successor history
    • retention and access
    • unsafe-detail boundary
Artifacts
  • Discoverer, reporter, contact role, credit and attribution recordVersioned evidence-bearing vulnerability record for discoverer, reporter, contact role, credit and attribution with source, method, event and knowledge time, confidence and access marking.
discovery-method-report-evidence-reproducer-validation-and-confidence

Discovery method, report, evidence, reproducer, validation and confidence

Method, report reference, restricted evidence locator, affected environment, validation outcome, validator, confidence and disclosure class.

Questions
  1. What identifiers, source containers, classes, scope and values define discovery method, report, evidence, reproducer, validation and confidence?relationship
    Expected answer
    • identifiers and aliases
    • source and class
    • scope and values
    • explicit unknowns
  2. Which authority, evidence, method, event time and knowledge time support discovery method, report, evidence, reproducer, validation and confidence?authority
    Expected answer
    • authority
    • evidence and method
    • event and knowledge time
    • confidence
  3. How may discovery method, report, evidence, reproducer, validation and confidence be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?exception
    Expected answer
    • validation
    • challenge and correction
    • successor history
    • retention and access
    • unsafe-detail boundary
Artifacts
  • Discovery method, report, evidence, reproducer, validation and confidence recordVersioned evidence-bearing vulnerability record for discovery method, report, evidence, reproducer, validation and confidence with source, method, event and knowledge time, confidence and access marking.
coordination-timeline-references-and-disclosureCoordination, timeline, references and disclosure2 findings

Maintains event and publication history and typed evidence links.

reservation-vendor-notification-embargo-publication-update-and-knowledge-time

Reservation, vendor notification, embargo, publication, update and knowledge time

Event kind, actor, event time, observation and knowledge time, embargo authority, planned disclosure, actual publication and sequence.

Questions
  1. What identifiers, source containers, classes, scope and values define reservation, vendor notification, embargo, publication, update and knowledge time?ownership
    Expected answer
    • identifiers and aliases
    • source and class
    • scope and values
    • explicit unknowns
  2. Which authority, evidence, method, event time and knowledge time support reservation, vendor notification, embargo, publication, update and knowledge time?provenance
    Expected answer
    • authority
    • evidence and method
    • event and knowledge time
    • confidence
  3. How may reservation, vendor notification, embargo, publication, update and knowledge time be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?access
    Expected answer
    • validation
    • challenge and correction
    • successor history
    • retention and access
    • unsafe-detail boundary
Artifacts
  • Reservation, vendor notification, embargo, publication, update and knowledge time recordVersioned evidence-bearing vulnerability record for reservation, vendor notification, embargo, publication, update and knowledge time with source, method, event and knowledge time, confidence and access marking.
advisory-report-fix-evidence-reference-tag-and-integrity

Advisory, report, fix, evidence reference, tag and integrity

Typed URL or document reference, source, role, tags, access class, retrieved version, digest, publication state and trust caveat.

Questions
  1. What identifiers, source containers, classes, scope and values define advisory, report, fix, evidence reference, tag and integrity?lifecycle
    Expected answer
    • identifiers and aliases
    • source and class
    • scope and values
    • explicit unknowns
  2. Which authority, evidence, method, event time and knowledge time support advisory, report, fix, evidence reference, tag and integrity?temporal
    Expected answer
    • authority
    • evidence and method
    • event and knowledge time
    • confidence
  3. How may advisory, report, fix, evidence reference, tag and integrity be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?retention
    Expected answer
    • validation
    • challenge and correction
    • successor history
    • retention and access
    • unsafe-detail boundary
Artifacts
  • Advisory, report, fix, evidence reference, tag and integrity recordVersioned evidence-bearing vulnerability record for advisory, report, fix, evidence reference, tag and integrity with source, method, event and knowledge time, confidence and access marking.
severity-exploitability-and-prioritization-signalsSeverity, exploitability and prioritization signals2 layers

Stores versioned assessments while preventing severity, exploitation probability, known exploitation and organizational risk from being conflated.

cvss-severity-and-impact-assertionsCVSS severity and impact assertions2 findings

Preserves vector, metric group, scope and assessor.

cvss-version-vector-base-threat-environmental-and-supplemental-metrics

CVSS version, vector, Base, Threat, Environmental and Supplemental metrics

CVSS version, full vector, metric groups, score, qualitative rating, calculator version and calculation evidence.

Questions
  1. What identifiers, source containers, classes, scope and values define cvss version, vector, base, threat, environmental and supplemental metrics?definition
    Expected answer
    • identifiers and aliases
    • source and class
    • scope and values
    • explicit unknowns
  2. Which authority, evidence, method, event time and knowledge time support cvss version, vector, base, threat, environmental and supplemental metrics?quality
    Expected answer
    • authority
    • evidence and method
    • event and knowledge time
    • confidence
  3. How may cvss version, vector, base, threat, environmental and supplemental metrics be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?security
    Expected answer
    • validation
    • challenge and correction
    • successor history
    • retention and access
    • unsafe-detail boundary
Artifacts
  • CVSS version, vector, Base, Threat, Environmental and Supplemental metrics recordVersioned evidence-bearing vulnerability record for cvss version, vector, base, threat, environmental and supplemental metrics with source, method, event and knowledge time, confidence and access marking.
severity-assessor-scope-product-context-time-and-disagreement

Severity assessor, scope, product context, time and disagreement

Assessor identity and role, affected product scope, environment, assertion time, source container, confidence and relation to competing scores.

Questions
  1. What identifiers, source containers, classes, scope and values define severity assessor, scope, product context, time and disagreement?classification
    Expected answer
    • identifiers and aliases
    • source and class
    • scope and values
    • explicit unknowns
  2. Which authority, evidence, method, event time and knowledge time support severity assessor, scope, product context, time and disagreement?process
    Expected answer
    • authority
    • evidence and method
    • event and knowledge time
    • confidence
  3. How may severity assessor, scope, product context, time and disagreement be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?interoperability
    Expected answer
    • validation
    • challenge and correction
    • successor history
    • retention and access
    • unsafe-detail boundary
Artifacts
  • Severity assessor, scope, product context, time and disagreement recordVersioned evidence-bearing vulnerability record for severity assessor, scope, product context, time and disagreement with source, method, event and knowledge time, confidence and access marking.
exploitation-priority-and-risk-contextExploitation, priority and risk context2 findings

Links time-varying signals and local decisions without inventing one universal priority.

epss-probability-percentile-model-date-window-and-source

EPSS probability, percentile, model date, window and source

Estimated probability, percentile, scoring date, prediction window, model version, source and later-observed outcome reference.

Questions
  1. What identifiers, source containers, classes, scope and values define epss probability, percentile, model date, window and source?composition
    Expected answer
    • identifiers and aliases
    • source and class
    • scope and values
    • explicit unknowns
  2. Which authority, evidence, method, event time and knowledge time support epss probability, percentile, model date, window and source?measurement
    Expected answer
    • authority
    • evidence and method
    • event and knowledge time
    • confidence
  3. How may epss probability, percentile, model date, window and source be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?validation
    Expected answer
    • validation
    • challenge and correction
    • successor history
    • retention and access
    • unsafe-detail boundary
Artifacts
  • EPSS probability, percentile, model date, window and source recordVersioned evidence-bearing vulnerability record for epss probability, percentile, model date, window and source with source, method, event and knowledge time, confidence and access marking.
kev-known-exploitation-ssvc-decision-priority-and-local-risk-reference

KEV known exploitation, SSVC decision, priority and local risk reference

Catalog or decision source, inclusion evidence, known-ransomware status, decision points, required action, due date and external local-risk decision.

Questions
  1. What identifiers, source containers, classes, scope and values define kev known exploitation, ssvc decision, priority and local risk reference?state
    Expected answer
    • identifiers and aliases
    • source and class
    • scope and values
    • explicit unknowns
  2. Which authority, evidence, method, event time and knowledge time support kev known exploitation, ssvc decision, priority and local risk reference?decision
    Expected answer
    • authority
    • evidence and method
    • event and knowledge time
    • confidence
  3. How may kev known exploitation, ssvc decision, priority and local risk reference be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?temporal
    Expected answer
    • validation
    • challenge and correction
    • successor history
    • retention and access
    • unsafe-detail boundary
Artifacts
  • KEV known exploitation, SSVC decision, priority and local risk reference recordVersioned evidence-bearing vulnerability record for kev known exploitation, ssvc decision, priority and local risk reference with source, method, event and knowledge time, confidence and access marking.
remediation-exposure-and-change-lifecycleRemediation, exposure and change lifecycle2 layers

Links remediation and concrete exposure processes while preserving vulnerability record history.

remediation-advisory-fix-and-exposure-linksRemediation, advisory, fix and exposure links2 findings

Connects external products, advisories, fixes and deployments.

fix-version-patch-commit-workaround-mitigation-and-remediation-reference

Fix version, patch, commit, workaround, mitigation and remediation reference

External remediation identifier, kind, vendor, product scope, fixed version or commit, availability, restart, caveat and supersession.

Questions
  1. What identifiers, source containers, classes, scope and values define fix version, patch, commit, workaround, mitigation and remediation reference?identity
    Expected answer
    • identifiers and aliases
    • source and class
    • scope and values
    • explicit unknowns
  2. Which authority, evidence, method, event time and knowledge time support fix version, patch, commit, workaround, mitigation and remediation reference?evidence
    Expected answer
    • authority
    • evidence and method
    • event and knowledge time
    • confidence
  3. How may fix version, patch, commit, workaround, mitigation and remediation reference be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?validation
    Expected answer
    • validation
    • challenge and correction
    • successor history
    • retention and access
    • unsafe-detail boundary
Artifacts
  • Fix version, patch, commit, workaround, mitigation and remediation reference recordVersioned evidence-bearing vulnerability record for fix version, patch, commit, workaround, mitigation and remediation reference with source, method, event and knowledge time, confidence and access marking.
deployed-asset-exposure-detection-vex-status-and-verification-reference

Deployed asset exposure, detection, VEX status and verification reference

External asset and exposure identifiers, matched product evidence, VEX product status, detection time, verification method and current remediation-state reference.

Questions
  1. What identifiers, source containers, classes, scope and values define deployed asset exposure, detection, vex status and verification reference?relationship
    Expected answer
    • identifiers and aliases
    • source and class
    • scope and values
    • explicit unknowns
  2. Which authority, evidence, method, event time and knowledge time support deployed asset exposure, detection, vex status and verification reference?authority
    Expected answer
    • authority
    • evidence and method
    • event and knowledge time
    • confidence
  3. How may deployed asset exposure, detection, vex status and verification reference be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?exception
    Expected answer
    • validation
    • challenge and correction
    • successor history
    • retention and access
    • unsafe-detail boundary
Artifacts
  • Deployed asset exposure, detection, VEX status and verification reference recordVersioned evidence-bearing vulnerability record for deployed asset exposure, detection, vex status and verification reference with source, method, event and knowledge time, confidence and access marking.
record-change-dispute-correction-and-retirementRecord change, dispute, correction and retirement2 findings

Keeps append-only changes and justified terminal states.

change-item-field-diff-reason-source-actor-and-predecessor

Change item, field diff, reason, source, actor and predecessor

Changed path, old and new assertion references, reason, responsible actor, authority, predecessor digest, validation and effective time.

Questions
  1. What identifiers, source containers, classes, scope and values define change item, field diff, reason, source, actor and predecessor?ownership
    Expected answer
    • identifiers and aliases
    • source and class
    • scope and values
    • explicit unknowns
  2. Which authority, evidence, method, event time and knowledge time support change item, field diff, reason, source, actor and predecessor?provenance
    Expected answer
    • authority
    • evidence and method
    • event and knowledge time
    • confidence
  3. How may change item, field diff, reason, source, actor and predecessor be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?access
    Expected answer
    • validation
    • challenge and correction
    • successor history
    • retention and access
    • unsafe-detail boundary
Artifacts
  • Change item, field diff, reason, source, actor and predecessor recordVersioned evidence-bearing vulnerability record for change item, field diff, reason, source, actor and predecessor with source, method, event and knowledge time, confidence and access marking.
dispute-correction-rejection-withdrawal-supersession-and-tombstone

Dispute, correction, rejection, withdrawal, supersession and tombstone

Challenge and evidence, resolution authority, corrected successor, rejection or withdrawal reason, tombstone status and retained aliases.

Questions
  1. What identifiers, source containers, classes, scope and values define dispute, correction, rejection, withdrawal, supersession and tombstone?lifecycle
    Expected answer
    • identifiers and aliases
    • source and class
    • scope and values
    • explicit unknowns
  2. Which authority, evidence, method, event time and knowledge time support dispute, correction, rejection, withdrawal, supersession and tombstone?temporal
    Expected answer
    • authority
    • evidence and method
    • event and knowledge time
    • confidence
  3. How may dispute, correction, rejection, withdrawal, supersession and tombstone be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?retention
    Expected answer
    • validation
    • challenge and correction
    • successor history
    • retention and access
    • unsafe-detail boundary
Artifacts
  • Dispute, correction, rejection, withdrawal, supersession and tombstone recordVersioned evidence-bearing vulnerability record for dispute, correction, rejection, withdrawal, supersession and tombstone with source, method, event and knowledge time, confidence and access marking.
interoperability-access-quality-and-agent-governanceInteroperability, access, quality and agent governance2 layers

Provides versioned projections, quality controls, restricted views and safe automated maintenance.

crosswalk-projection-deduplication-and-qualityCrosswalk, projection, deduplication and quality2 findings

Maps overlapping formats and measures claim-level quality.

cve-nvd-osv-csaf-vex-stix-cwe-cvss-crosswalk-and-loss

CVE, NVD, OSV, CSAF, VEX, STIX, CWE and CVSS crosswalk and loss

Source and target versions, field mappings, code translations, omissions, assertion-authority changes and round-trip limits.

Questions
  1. What identifiers, source containers, classes, scope and values define cve, nvd, osv, csaf, vex, stix, cwe and cvss crosswalk and loss?definition
    Expected answer
    • identifiers and aliases
    • source and class
    • scope and values
    • explicit unknowns
  2. Which authority, evidence, method, event time and knowledge time support cve, nvd, osv, csaf, vex, stix, cwe and cvss crosswalk and loss?quality
    Expected answer
    • authority
    • evidence and method
    • event and knowledge time
    • confidence
  3. How may cve, nvd, osv, csaf, vex, stix, cwe and cvss crosswalk and loss be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?security
    Expected answer
    • validation
    • challenge and correction
    • successor history
    • retention and access
    • unsafe-detail boundary
Artifacts
  • CVE, NVD, OSV, CSAF, VEX, STIX, CWE and CVSS crosswalk and loss recordVersioned evidence-bearing vulnerability record for cve, nvd, osv, csaf, vex, stix, cwe and cvss crosswalk and loss with source, method, event and knowledge time, confidence and access marking.
completeness-consistency-timeliness-source-trust-and-conflict-quality

Completeness, consistency, timeliness, source trust and conflict quality

Quality rule version, evaluated claims, missing fields, stale sources, contradictions, validation evidence, score and prohibited inference.

Questions
  1. What identifiers, source containers, classes, scope and values define completeness, consistency, timeliness, source trust and conflict quality?classification
    Expected answer
    • identifiers and aliases
    • source and class
    • scope and values
    • explicit unknowns
  2. Which authority, evidence, method, event time and knowledge time support completeness, consistency, timeliness, source trust and conflict quality?process
    Expected answer
    • authority
    • evidence and method
    • event and knowledge time
    • confidence
  3. How may completeness, consistency, timeliness, source trust and conflict quality be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?interoperability
    Expected answer
    • validation
    • challenge and correction
    • successor history
    • retention and access
    • unsafe-detail boundary
Artifacts
  • Completeness, consistency, timeliness, source trust and conflict quality recordVersioned evidence-bearing vulnerability record for completeness, consistency, timeliness, source trust and conflict quality with source, method, event and knowledge time, confidence and access marking.
access-retention-and-safe-agent-operationsAccess, retention and safe agent operations2 findings

Controls disclosure and autonomous use.

public-coordinator-vendor-researcher-operator-and-analytical-view

Public, coordinator, vendor, researcher, operator and analytical view

Audience, purpose, authority, allowed fields, embargo, contact masking, exploit-detail restriction, expiry, freshness and disclosure event.

Questions
  1. What identifiers, source containers, classes, scope and values define public, coordinator, vendor, researcher, operator and analytical view?composition
    Expected answer
    • identifiers and aliases
    • source and class
    • scope and values
    • explicit unknowns
  2. Which authority, evidence, method, event time and knowledge time support public, coordinator, vendor, researcher, operator and analytical view?measurement
    Expected answer
    • authority
    • evidence and method
    • event and knowledge time
    • confidence
  3. How may public, coordinator, vendor, researcher, operator and analytical view be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?validation
    Expected answer
    • validation
    • challenge and correction
    • successor history
    • retention and access
    • unsafe-detail boundary
Artifacts
  • Public, coordinator, vendor, researcher, operator and analytical view recordVersioned evidence-bearing vulnerability record for public, coordinator, vendor, researcher, operator and analytical view with source, method, event and knowledge time, confidence and access marking.
agent-authority-operation-prewrite-postwrite-concurrency-recovery-and-retention

Agent authority, operation, pre-write, post-write, concurrency, recovery and retention

Actor and agent, delegated authority, operation, expected head, validation, idempotency, approval class, outcome, rollback, retention and audit event.

Questions
  1. What identifiers, source containers, classes, scope and values define agent authority, operation, pre-write, post-write, concurrency, recovery and retention?state
    Expected answer
    • identifiers and aliases
    • source and class
    • scope and values
    • explicit unknowns
  2. Which authority, evidence, method, event time and knowledge time support agent authority, operation, pre-write, post-write, concurrency, recovery and retention?decision
    Expected answer
    • authority
    • evidence and method
    • event and knowledge time
    • confidence
  3. How may agent authority, operation, pre-write, post-write, concurrency, recovery and retention be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?temporal
    Expected answer
    • validation
    • challenge and correction
    • successor history
    • retention and access
    • unsafe-detail boundary
Artifacts
  • Agent authority, operation, pre-write, post-write, concurrency, recovery and retention recordVersioned evidence-bearing vulnerability record for agent authority, operation, pre-write, post-write, concurrency, recovery and retention with source, method, event and knowledge time, confidence and access marking.

Publication holds

  • Claude and Grok timed out during their bounded attempts, so independent external review is absent and explicitly waived for this published reviewable draft.
  • No approved outgoing model relations were supplied; product, weakness, advisory, exposure, remediation, exploit, threat and incident contracts require governance review.
  • Vendor, ecosystem, embedded, cloud, hardware, configuration and end-of-life profiles require specialist review.
  • Certified CVE, NVD, OSV, CSAF, VEX, STIX, CWE and CVSS crosswalks and conformance fixtures remain unverified.
  • Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft.

Deferred research

  • Approve relation cardinalities and ownership contracts for products, weaknesses, advisories, exposures, remediation, exploits, threats and incidents.
  • Develop ecosystem and product profiles for affected-version ordering, forks, backports, configurations and end-of-life branches.
  • Create fixtures for duplicate, split, merge, rejection, withdrawal, conflicting ranges, multiple CVSS sources, KEV addition and VEX status changes.
  • Validate certified cross-schema projections with authority, time, conflict, access, information-loss and round-trip tests.