Skip to content

Commit 67bec5e

Browse files
add CSAF publication workflow and first document
1 parent 0af90a3 commit 67bec5e

File tree

3 files changed

+216
-0
lines changed

3 files changed

+216
-0
lines changed

.github/workflows/publish.yml

Lines changed: 73 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,73 @@
1+
name: Validate & publish CSAF advisories
2+
on:
3+
push:
4+
branches:
5+
- main
6+
paths:
7+
- 'csaf_documents/**.json'
8+
workflow_dispatch:
9+
10+
permissions:
11+
contents: write
12+
13+
jobs:
14+
csaf:
15+
runs-on: ubuntu-24.04
16+
name: Update CSAF provider
17+
strategy:
18+
fail-fast: false
19+
20+
steps:
21+
- name: Publish CSAF advisories
22+
uses: csaf-tools/csaf-action@v0
23+
with:
24+
publisher_category: vendor
25+
publisher_name: Isduba Development Community
26+
publisher_namespace: https://github.com/ISDuBA
27+
publisher_issuing_authority: Developers of the Free Software ISDuBA
28+
publisher_contact_details: Open public issues at https://github.com/ISDuBA or contact one of the recently active developers in confidence.
29+
source_csaf_documents: csaf_documents
30+
generate_index_files: true
31+
openpgp_key: |
32+
-----BEGIN PGP PUBLIC KEY BLOCK-----
33+
34+
mQGNBGj7dkwBDADffbLnN3FX1g2xRLI7UngOY/ecoTGgIrWjwZ/NX13SwpzNPrvC
35+
XMYdiZXKYRP2Nol7NBRvOAKQDRfUv/SHCqSG99uQyPRaC1skJPa6CCYpNTYhG7CU
36+
hb4V/bCC1yQNfzEmyQw7dMuEqlsCZam/njOyr0Hw7UAwVNIk/q55PlSZ79i1PhTO
37+
32sADFZ3B739qZA0HqDN4PlMdNzxJBbHekCQcDS/LYljKlqqEJZviK81LL/RGm1y
38+
CE8Wqx/IFwpv841ydz95nJjPXp4NqUCsWg9ZsjOnBexlWXNgHOm1YagAdIBX/eRy
39+
NhVxQAMcOeWR2IsA18RYytlnR+FH+IHLnHUJbsR2DuhoSQjql0Z6MCQcR2dWzOXJ
40+
avoWYOGCqvV/uuTLkhVin7XJnb1t7l4u+vT14I5jZ1bxOfrBx/UqEVVOhA13TlUC
41+
n72loDL32Jv28q+gWequuhvQYR4OTxzFh+IjJqXClOvJMfh0XBdgTbV04fye46u4
42+
b7bT9eiGL1aaaKkAEQEAAbQ4SXNkdWJhIERldmVsb3BtZW50IENvbW11bml0eSAo
43+
aHR0cHM6Ly9naXRodWIuY29tL0lTRHVCQSmJAdQEEwEKAD4WIQSiX+DxdYlr+mNv
44+
GgUd5kWxkmg13QUCaPt2TAIbAwUJC0c1AAULCQgHAgYVCgkICwIEFgIDAQIeAQIX
45+
gAAKCRAd5kWxkmg13QtPC/wJlcTcMpKKZPzDXwgIMEn06PqBCjmpvqyS7bHaYWod
46+
jN+FgOLLYbNbAwwMdWlS1D5tKDXTm35LTvPaGgRLuCPN8Mf3Hpd0cAP1qGKXtLP8
47+
MUOshprsW0ntoVFHXw5Vsf2uycsQPqwx6KFnT+9833BVzIKGfNBgfnUTKJaWbWLS
48+
naNdNwnm1RTkbJezKMPYwRI/M9XH4JTm7QEOhO0cCJqbsdVs98038UBj0h1DEOL1
49+
e2n980a7l9RRrYJjmXosqrybhknOl3PGVUtWqWDH9O8tkfYGLyYQOy0Ae1Bvd4gg
50+
QpycI0cBoth5vqrkhC6RAbpJA8ExQxP15K0VdieNKx2qC+RDGrKGrLGdIPJ1TQqB
51+
ZLy6NMU3KsGp5VaIllKMZ2kIlEKQkGz0/24iGAdTWpOyHgZhd9i710zoyxfSr6bh
52+
rqM7KHQssbABeJvsplMed4R2iJsBg8vrp1dj3Pqb3cQFCH2SlUN43FICHG5rsKop
53+
REbpnyfDJ9fIaAKHpoDLugi5AY0EaPt2TAEMAOWwwh4xzz519By+Z7RFb8WjL71+
54+
IoQ8h3buemh+hjd9+dCYOu6wmTlGPBazQ6fVOIX0O5sIu4SOtyyjc2SwjleXh449
55+
jBwrfmlSxBrdlGWQJh2zfdommRdO0F9jplbyT8aU5yvTL5XgmRCxUKBjGMYrcCB1
56+
QbwArp3/0mRean3IxPYVgBNjsqHqJjj+pWelOyhEYxaFiLvWH3iBKNQpHRtiRLnW
57+
xFtvJvfXL67eNjhRHqbWE5KuVUqfbI+rDMU5GOagWudUyIOWIO5qdALg4fJWwGSe
58+
4FrrfMQLMe8P1nwhmHC1npbToZlb027NMJL1XMgeP+7MdlI/jWTvNjNk3KwE/9GW
59+
y++ARE5wTHTC7SZkQI2lpHPTFGuoKvAWknf2PBzVZUmBKkXIZBwjjAqUg6X1CmfQ
60+
QKlZxixhUZv5huG0D8V8eAmyWlvHDpKOWrCgReXysiMO0ZxgaPJMYvrpbK0QM6GG
61+
Hbxp6l9cbTUzEmcIOMnd30hqomNx/gTWnp+2QwARAQABiQG8BBgBCgAmFiEEol/g
62+
8XWJa/pjbxoFHeZFsZJoNd0FAmj7dkwCGwwFCQtHNQAACgkQHeZFsZJoNd0jogv/
63+
XGZRP3+vQvxjH12/7P4mmDvQ/cONiiEEi5vHivdGYQZ3suuvgD8A7FX/uYL7PBhH
64+
zDbuSk1vF1XgAmPk2e2zSALMP0UdUaL4qjs1dd2+cjjnCBtxwCftKb/hPuy22H6o
65+
QgrQwwNMzgpiyUE3vZl8W8oRvoujflaZpGtpoZXB9PNmAlhL79CeQXsFCBGhzOWT
66+
gSVi69GFXG+3nkmbA2y0EBzYbjllVLH/g91YayCwe80DChbpD/Dj9vA6nMq+dKXY
67+
RnK5NaoCVLah7Ts3JlOzf3aPB6zD6Ped/CgAYOEpffPdDcQliaGG1+XHb9SVpuLK
68+
z/8PZSkeAr2Wflj82UJsrUf0Krzy8h8N/Qz9J7AvlYSkFqrc9oLnyRyu5wLCCpFE
69+
jcKaW2YeGFnhtemjyr1CX5kH3X4dpxjvA4zpu/hqzE63YzoFIRFYrC+eChLMkHR5
70+
yYPU3BBj4wvyV4NoZ3nnTtrJ2st3ILa6ks7WpGUxDjfSGzdmU/rXu3qy6fJgo84F
71+
=ZY3x
72+
-----END PGP PUBLIC KEY BLOCK-----
73+

csaf_documents/isduba-2025-01.json

Lines changed: 129 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,129 @@
1+
{
2+
"document": {
3+
"category": "csaf_vex",
4+
"csaf_version": "2.0",
5+
"distribution": {
6+
"tlp": {
7+
"label": "WHITE",
8+
"url": "https://www.first.org/tlp/v1/"
9+
}
10+
},
11+
"lang": "en",
12+
"publisher": {
13+
"category": "vendor",
14+
"contact_details": "See contact points at https://github.com/ISDuBA",
15+
"name": "Isduba Development Community",
16+
"namespace": "https://github.com/ISDuBA"
17+
},
18+
"title": "does not integrate Cisco Secure Firewall Adaptive Security Appliance Software",
19+
"tracking": {
20+
"current_release_date": "2025-10-02T17:35:00.000Z",
21+
"id": "isduba-2025-01",
22+
"initial_release_date": "2025-10-02T17:35:00.000Z",
23+
"revision_history": [
24+
{
25+
"date": "2025-10-02T17:35:00.000Z",
26+
"number": "1.0.0",
27+
"summary": "Initial revision"
28+
}
29+
],
30+
"status": "final",
31+
"version": "1.0.0"
32+
}
33+
},
34+
"product_tree": {
35+
"branches": [
36+
{
37+
"branches": [
38+
{
39+
"branches": [
40+
{
41+
"category": "product_version_range",
42+
"name": "vers:all/*",
43+
"product": {
44+
"name": "ISDuBA all versions",
45+
"product_id": "isduba-all-versions"
46+
}
47+
}
48+
],
49+
"category": "product_name",
50+
"name": "ISDuBA"
51+
}
52+
],
53+
"category": "vendor",
54+
"name": "Isduba Development Community"
55+
}
56+
]
57+
},
58+
"vulnerabilities": [
59+
{
60+
"cve": "CVE-2025-20333",
61+
"notes": [
62+
{
63+
"category": "summary",
64+
"text": "Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software VPN Web Server Remote Code Execution Vulnerability"
65+
}
66+
],
67+
"product_status": {
68+
"known_not_affected": [
69+
"isduba-all-versions"
70+
]
71+
},
72+
"threats": [
73+
{
74+
"category": "impact",
75+
"details": "Vulnerable component not present",
76+
"product_ids": [
77+
"isduba-all-versions"
78+
]
79+
}
80+
]
81+
},
82+
{
83+
"cve": "CVE-2025-20362",
84+
"notes": [
85+
{
86+
"category": "summary",
87+
"text": "Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software VPN Web Server Unauthorized Access Vulnerability"
88+
}
89+
],
90+
"product_status": {
91+
"known_not_affected": [
92+
"isduba-all-versions"
93+
]
94+
},
95+
"threats": [
96+
{
97+
"category": "impact",
98+
"details": "Vulnerable component not present",
99+
"product_ids": [
100+
"isduba-all-versions"
101+
]
102+
}
103+
]
104+
},
105+
{
106+
"cve": "CVE-2025-20363",
107+
"notes": [
108+
{
109+
"category": "summary",
110+
"text": "Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, IOS Software, IOS XE Software, and IOS XR Software Web Services Remote Code Execution Vulnerability"
111+
}
112+
],
113+
"product_status": {
114+
"known_not_affected": [
115+
"isduba-all-versions"
116+
]
117+
},
118+
"threats": [
119+
{
120+
"category": "impact",
121+
"details": "Vulnerable component not present",
122+
"product_ids": [
123+
"isduba-all-versions"
124+
]
125+
}
126+
]
127+
}
128+
]
129+
}
Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
-----BEGIN PGP SIGNATURE-----
2+
3+
iQGzBAABCgAdFiEEol/g8XWJa/pjbxoFHeZFsZJoNd0FAmj7eKEACgkQHeZFsZJo
4+
Nd22zwv9GRCeZOyfTCMdWBmuyp7vG/ZSGNwzqED5ZirOP2+F6TkojgJf2p3jJnrL
5+
NiTa19l49YSnDECpaRITto5fvRj8IcfMdDpD/g8LEwO52ZyvYEixk9EKLsbZ9/0P
6+
MJMR9KAk8FmUSs8Xmlq4Xx0u/af3wJWOf5DYcLfs5GKKi2ykxnK72ZUyp76rB+3t
7+
Dfyz1AljhCYYVz0aL7wmHV6CmKQW2HGjz26TG6udW0Prfi3NEMAxuCWjBBarGC2u
8+
4RYrieejsh69l1RCJfkX8VSa5vLU1XYAE5Ii/dCWqMyMi+xEPIDXHEogiRe6+A1L
9+
wCsPkS1RZ4jAtRspzRBrM1YwlOUNJcA+33W2sMBPdNEam+8MZtlb2mezG8kFwcLQ
10+
FwsnUAGE9E8bbg8mORPS24nIMjd1u662pd0XW7AEGH9fD7POcKutxr5IpYc46c4+
11+
fMGtkELrIhqFV1n28wGWzOJykQwG3TrtVLq5+QYgGu1jKpFUzbD7T5a0iKpHY8ep
12+
BJZ7i60h
13+
=Op54
14+
-----END PGP SIGNATURE-----

0 commit comments

Comments
 (0)