Next in thread → Next in month →

Re: [cti] More Github Repos

From
Jordan, Bret <>
Date
2016-09-02T15:49:53+00:00
ID
Thread
Re: [cti] More Github Repos
Well said, and I agree. 

Thanks,

Bret

Bret Jordan CISSP
Director of Security Architecture and Standards | Office of the CTO

Blue Coat Systems

PGP Fingerprint: 63B4 FC53 680A 6B7D 1447  F2C0 74F8 ACAE 7415 0050

"Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg." 

On Sep 2, 2016, at 08:24, Allan Thomson <> wrote:

I would also say that presumably these new repos are not going to include the previous STIX 1/TAXII versions so technically they only will include 2.x and future revs. Not 1.x. If they are named without version I would expect all versions including 1.x.

 

I have a slight preference for the number in the repos because it helps distinguish from the previous version that is very different as Bret says.

 

Regarding major vs minor changes. I think the heart of the issue is not the number per se but what defines compatibility/interoperability. For example, introducing a new optional TLO may not break any implementation if those implementations don’t need to support that TLO. Whereas if the use case requires use of that TLO then they would obviously want to support that TLO and make sure they support the mandatory aspects including agreed behavior.

 

I would rather we focus on defining what is required for compatibility and interoperability and less about the number of the spec.

 

allan

 

From: "" <> on behalf of "Jordan, Bret" <>Date: Friday, September 2, 2016 at 7:18 AMTo: "Wunder, John" <>Cc: Jason Keirstead <>, Patrick Maroney <>, "" <>Subject: Re: [cti] More Github Repos

 

I like the distinction it gives.  Keep in mind that the reason we are using these repos (the official specification ones) is not for the source control, but for the wiki and issue tracking.  Branching and Tagging and all of the other Git stuff is not what we are looking to use these repos for.  

 

Bret Sent from my Commodore 64

On Sep 2, 2016, at 6:29 AM, Wunder, John A. <> wrote:

Our thinking was just that if we ever have another major version release of (for example) STIX, it would be due to very fundamental changes and we’d want a clean break. And of course to distinguish from the “legacy” DHS/MITRE repositories.

 

I’m fine either way.

 

From: <> on behalf of Jason Keirstead <>Date: Friday, September 2, 2016 at 8:11 AMTo: Patrick Maroney <>Cc: Bret Jordan <>, "" <>Subject: Re: [cti] More Github Repos

 

I would say I agree with Patrick... I am not sure why we should put version numbers on the repo names. Versioning is part of Github. STIX 2 "stable" would just be a tag and/or branch...-Jason KeirsteadSTSM, Product Architect, Security Intelligence, IBM Security Systemswww.ibm.com/security | www.securityintelligence.comWithout data, all you are is just another person with an opinion - Unknown <image001.gif>Patrick Maroney ---09/01/2016 08:05:12 PM---I would argue instead for a single Open and Work Product repo for each of the 4 SCs and the use of GFrom: Patrick Maroney <>To: "Jordan, Bret" <>Cc: "" <>Date: 09/01/2016 08:05 PMSubject: Re: [cti] More Github ReposSent by: <>

I would argue instead for a single Open and Work Product repo for each of the 4 SCs and the use of Github Branches for variants. Ultimately Github provides a number of very useful capabilities for managing workflow, variants, releases that will serve us well.Patrick MaroneyPresidentIntegrated Networking Technologies, Inc.Desk: (856)983-0001Cell: (609)841-5104Email: [email protected]_____________________________From: Jordan, Bret <>Sent: Thursday, September 1, 2016 6:58 PMSubject: Re: [cti] More Github ReposTo: Patrick Maroney <>Cc: <>I think major release numbers are okay... Since if we ever do a STIX 3, we will probably want to start fresh at that point.Thanks,BretBret Jordan CISSP Director of Security Architecture and Standards | Office of the CTOBlue Coat SystemsPGP Fingerprint: 63B4 FC53 680A 6B7D 1447 F2C0 74F8 ACAE 7415 0050"Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg."

On Sep 1, 2016, at 14:24, Patrick Maroney <> wrote:Recommendation: Remove the version specific attributes from the requested Chartered Work and and Open Repository Names/Descriptions.Understand that we need to discriminate (for now) between the “Legacy” and “Next Generation” Github Repositories. However, making Version specific instantiations of the multitude of separate Chartered Work and and Open Repository will greatly complicate things long term (i.e., as new major releases occur).Patrick MaroneyOffice: (856)983-0001Cell: (609)841-5104<image001.png>PresidentIntegrated Networking Technologies, Inc.PO Box 569Marlton, NJ 08053From: "" <> on behalf of Bret Jordan <>Date: Thursday, September 1, 2016 at 2:09 PMTo: "" <>Subject: [cti] More Github ReposI move that the TC approve the requesting of OASIS to set up the following OASIS Chartered Work Repository projects, stix2, cybox3, and taxii2 named cti-stix2, cti-cybox3 and cti-taxii2 using the following pieces of information:Purpose Statement: This STIX repository will contain official specification documents along with wikis and issues relating to the official specifications. Initial Maintainers: Bret Jordan, John WunderGitHub Name: cti-stix2Short Description: OASIS Chartered Work Repository: Official repository for STIX 2 workPurpose Statement: This CybOX repository will contain official specification documents along with wikis and issues relating to the official specifications. Initial Maintainers: Ivan Kirillov, Trey DarleyGitHub Name: cti-cybox3Short Description: OASIS Chartered Work Repository: Official repository for CybOX 3 workPurpose Statement: This TAXII repository will contain official specification documents along with wikis and issues relating to the official specifications. Initial Maintainers: Bret Jordan, Mark DavidsonGitHub Name: cti-taxii2Short Description: OASIS Chartered Work Repository: Official repository for TAXII 2 workThanks,BretBret Jordan CISSPDirector of Security Architecture and Standards | Office of the CTOBlue Coat SystemsPGP Fingerprint: 63B4 FC53 680A 6B7D 1447 F2C0 74F8 ACAE 7415 0050"Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg."

Attachment:
signature.asc

Description: Message signed with OpenPGP using GPGMail
Next in thread → Next in month →