Skip to content

Added RDX risk alignment. Add safety. Minor refactor - #1120

Open
stevespringett wants to merge 3 commits into
2.0-devfrom
2.0-dev-safety
Open

stevespringett wants to merge 3 commits into
2.0-devfrom
2.0-dev-safety

Conversation

@stevespringett

Copy link
Copy Markdown
Member

Supersedes #1041. Closes #954.

Signed-off-by: Steve Springett <steve@springett.us>
…gnment). Added test cases.

Signed-off-by: Steve Springett <steve@springett.us>
… and ISO 26262

Threat scenarios carry feasibility only, risks pair them with damage scenarios and reference one way, and naming, statuses, and scales are now unified across the two models.

Signed-off-by: Steve Springett <steve@springett.us>
@stevespringett stevespringett added this to the 2.0 milestone Sep 21, 2026
@stevespringett stevespringett self-assigned this Sep 21, 2026
@stevespringett
stevespringett requested a review from a team as a code owner September 21, 2026 02:37
@stevespringett stevespringett added proposed core enhancement request for comment RFC notice sent A public RFC notice was distributed to the CycloneDX mailing list for consideration labels Sep 21, 2026
@devashridatta-dotcom

Copy link
Copy Markdown

Thanks Steve, this looks like the right CycloneDX-native direction. I see that #1120 supersedes #1041 and closes #954. The mapping to SRAC is clear to me: triggeredBy covers the change trigger, risks.assessments[] covers change impact analysis, safetyIntegrityLevels[] carries the classified safety context, and conclusion/evidence support release decisioning.
I’ll review closely and add a few comments, mainly around preserving SRAC semantics, SPDX alignment notes, canonical safety level tokens, and whether safety integrity should also be allowed on requirements or only on blueprint asset classifications.

@devashridatta-dotcom

Copy link
Copy Markdown

Opened #1122 as the follow-up CycloneDX Safety Perspective proposal for SRAC and safety impact workflows. The intent is to document how safety stakeholders can use the #1120 model consistently across CVE and non-CVE safety triggers, without adding a competing SRAC object.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

proposed core enhancement request for comment RFC notice sent A public RFC notice was distributed to the CycloneDX mailing list for consideration

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants