Skip to content

hdf2ckl: empty Check_Content and Fix_Text for CVE-based sources; document intended ASSET population path #8614

Description

@wdower

Checklists generated from CVE-oriented OHDF (e.g. twistlock2hdf output) have empty Check_Content and Fix_Text in every stanza. hdf2ckl populates those fields from control.tags.check / control.tags.fix (libs/hdf-converters/src/ckl-mapper/checklist-jsonix-converter.ts), and vulnerability-scan mappers don't set those tags. Vuln_Discuss does carry the CVE description, so the stanza isn't empty — but Check_Content and Fix_Text are what an assessor works from.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions