Open the case
Open a case and bring in the advisory with a note of where it came from. The same advisory arriving under a CVE and a GHSA name is recognised as one, so it is never worked twice.
Post-market & PSIRT cases
The hardest questions come after release: which of our shipped versions are exposed, who looked, what did we decide, and what did we tell customers? The case workflow answers them from the release records you already keep, and writes down every step your team takes.
Straight status, up front: this is a limited, experimental preview. You can run it in v0.5.0, and its records and commands may still change. It is the surface we most want design partners to shape toward production.
The case, from intake to closure
A case keeps a tamper-evident journal. Every step that matters names the person who took it.
Open a case and bring in the advisory with a note of where it came from. The same advisory arriving under a CVE and a GHSA name is recognised as one, so it is never worked twice.
Check the advisory against every shipped release in your local evidence store. Each match is a candidate, never an “affected” verdict, and it says what the match did not settle. The case also lists every release it could not examine, and why, so zero candidates never looks like a clean bill of health.
Candidates can be split by product variant and channel, and weighed against the fielded population you record. Where that inventory is incomplete, the case says partial or unknown, never zero.
A named person owns the case and records the outcome for each candidate. “Not affected” needs a valid justification or it is downgraded, loudly. While candidates are unreviewed or questions are open, the case stays where it is.
Verify a fix against the release that carries it. An unverified removal blocks closure unless a named person records why. A risk acceptance is time-boxed, surfaced before it expires and never extended automatically.
Draft and approve the messages your team sends, and record them once they are sent through your own channels. Export an advisory as a CSAF document watermarked UNSIGNED DRAFT. The disclosure record shows each stage as recorded or not recorded, and “not recorded” never means “not required”.
Where related products may share the problem, the case can propose them for review. A proposal changes no decision.
What the case workflow never does:
For a single release, a newer advisory snapshot can also be checked without opening a case — see vulnerability review. If you work under the EU Cyber Resilience Act, its optional regime view adds reporting drafts, always unsigned.
Pick an advisory your team handled after a release shipped. As a design partner you run the case workflow on your own records, in your own environment, and tell us where it fits and where it does not.