Source review
CISA KEV, NVD/CVE, CVSS context, coordinated disclosure, vulnerability disclosure policy, and product-security bad-practices sources are tracked as requirements.
KEV, NVD, Disclosure, and Release Blocking
Latticra records vulnerability-management requirements before any production release, update, package, installer, internet-facing service, or security-product claim. It does not scan live feeds, publish advisories, submit CVEs, patch dependencies, generate SBOMs, publish releases, or claim product security.
Current Rule
The baseline requires CISA KEV review, NVD/CVE review, coordinated vulnerability disclosure paths, dependency and component inventory, exception ownership, exception expiration, mitigation records, and public non-claim review before release wording can promote.
CISA KEV, NVD/CVE, CVSS context, coordinated disclosure, vulnerability disclosure policy, and product-security bad-practices sources are tracked as requirements.
Production wording needs release artifact inventory, component inventory, dependency review, SBOM review, and CPE or purl mapping review.
Known exploited vulnerability handling, critical/high exception records, and non-exploitability claims need written evidence.
Publication, supported-version claims, security-product claims, vulnerability-free wording, and advisory publication remain blocked.
Current Snapshot
These fields represent a controlled release boundary. They are not evidence that Latticra is vulnerability-free, supported, production-ready, or a security product.
Release Gate
No production release, installer, package, update lane, internet-facing service, hosted service, security-product claim, or supported-version claim can promote until the required vulnerability-management fields are complete.
Baseline, status record, guard script, source references, release blockers, and public non-claim wording.
Artifact inventory, component inventory, dependency review, SBOM review, CPE or purl mapping, KEV review, NVD/CVE review, mitigation records, exception records, disclosure path, advisory template, supported-version scope, and release non-claim review.
Release artifact publication, production release claims, production installer claims, production update claims, supported-version claims, security-product claims, vulnerability-free claims, KEV exceptions, internet-facing service claims, and advisory publication.
Exception Records
A future exception requires a visible owner, deadline, affected component, exposure context, mitigation or compensating control, and public claim review. Without that record, the release gate remains closed.
Future exceptions must name the vulnerability identifier, affected component, affected version, and exposure context.
Exploitability analysis, mitigation, compensating controls, and non-exploitability evidence must be written down.
Every exception needs an owner, expiration or review deadline, operator-visible status, and public claim review.
A release cannot promote because a vulnerability is described as unlikely, theoretical, out of scope, or non-exploitable without evidence.
Local Commands
These guards validate source records and public-entry alignment. They do not query live feeds, scan dependencies, publish advisories, generate SBOMs, submit CVEs, or release artifacts.
sh scripts/test-vulnerability-management-release-gate-baseline.sh
sh scripts/test-supply-chain-security-baseline.sh
sh scripts/test-cyber-incident-reporting-response-baseline.sh
Source Records