LogicSRC standards surface
++ One file a security tool serves about what it found in the open. A directory reads the + reporter instead of a vendor feed, and the reporter decides what it discloses. +
+
+ Every security tool finds things, and every one keeps what it found behind its own login.
+ A scanner that runs on a thousand public repositories knows which rules fire and where,
+ and says nothing, because saying it would mean a feed, a schema, an API key and a sales
+ call. The threat feeds that exist are products with terms that forbid redistribution.
+ OpenThreat is the small file a tool can serve in an afternoon at{" "}
+ /.well-known/openthreat.json, with a rule for what may go in
+ it.
+
+ Status: 0.1. The first reporter is{" "} + threatcrush.com/discovery, built from the + scans its GitHub App ran on public repositories; the first directory is{" "} + nichedb.dev/c/threats. +
+
+ Only reporter.name and a threat's{" "}
+ title are required. Everything at{" "}
+ /.well-known/ is TLP:CLEAR by definition.
+
{DESCRIPTOR}
+
+ rule is the same string a SARIF ruleId carries;{" "}
+ subject is what the threat is about and is public by
+ definition; status is open, fixed, mitigated, blocked or
+ withdrawn, and a withdrawn threat stays in the file a while so directories retract it.
+ The second threat above is a secret: no location, no message, by rule.
+
| kind | +what it is | +
|---|---|
+ {kind}
+ |
+ {what} | +
Every other rule degrades. These two are the reason the file can exist at all.
+| + {what} + | +{why} | +
+ A subject that was scanned did not ask to be listed. Announcing is on by default, because
+ a finding in a public repository is public already, and opting out is one switch in the
+ tool's own settings. A subject that opts out leaves the file on the next build, and
+ is served once more as withdrawn so directories retract it.
+
| + {what} + | +{why} | +