SPECIFICATION
Specification
GAVR is implementable without reading anybody's source. The schema, the numbered rules and a language-neutral conformance corpus are published so a body running its own advisory system can validate records the same way this registry does.
The documents
The specification itself, as plain Markdown. Start with the README, which carries a table of what each document covers and how the two machine-readable artefacts below fit around them.
The record schema
JSON Schema draft-07, matching the CVE Record Format's target so every language's most available validator can read it. Necessary but not sufficient on its own, which is what the companion rules are for.
- Canonical URL
- https://gavr.gadvisory.org/schemas/gavr-record-1.0.json
Companion rules
The constraints a stock validator cannot express, each with a stable id. A rule id is stored data the moment it reaches the wire, so one is never renumbered and never reused.
Conformance corpus
Documents and the verdict a conforming implementation must reach on each. Whether a case is caught by a validator is derived from each rule rather than asserted per case, so the corpus proves the claim instead of restating it.
The registry's signing key
Every countersignature is made with this key. It is published here, separately from the records it signs, because verifying a countersignature against a key taken from the record carrying it proves only internal consistency, which any forger can arrange.
- Key id
- ed25519:Hj1XBQyrgDXt5mb-Tk_rggNC6PvNtGwT-jKHD6JeW7o
- Public key
- zp6omXJrJS5Bq4GO-0At7FryPabicDrIOVtD_jAd7Uc