SPECIFICATION

Specification

GAVR is implementable without reading anybody's source. The schema, the numbered rules and a language-neutral conformance corpus are published so a body running its own advisory system can validate records the same way this registry does.

The documents

The specification itself, as plain Markdown. Start with the README, which carries a table of what each document covers and how the two machine-readable artefacts below fit around them.

The record schema

JSON Schema draft-07, matching the CVE Record Format's target so every language's most available validator can read it. Necessary but not sufficient on its own, which is what the companion rules are for.

Canonical URL
https://gavr.gadvisory.org/schemas/gavr-record-1.0.json

Companion rules

The constraints a stock validator cannot express, each with a stable id. A rule id is stored data the moment it reaches the wire, so one is never renumbered and never reused.

Conformance corpus

Documents and the verdict a conforming implementation must reach on each. Whether a case is caught by a validator is derived from each rule rather than asserted per case, so the corpus proves the claim instead of restating it.

The registry's signing key

Every countersignature is made with this key. It is published here, separately from the records it signs, because verifying a countersignature against a key taken from the record carrying it proves only internal consistency, which any forger can arrange.

Key id
ed25519:Hj1XBQyrgDXt5mb-Tk_rggNC6PvNtGwT-jKHD6JeW7o
Public key
zp6omXJrJS5Bq4GO-0At7FryPabicDrIOVtD_jAd7Uc