Repository navigation
Add ATLAS threat taxonomy support - #1054
devashridatta-dotcom wants to merge 1 commit into
Conversation
|
CI note: I compared the 2.0 schema linter reports from this PR run ( This ATLAS taxonomy change does not introduce new 2.0 schema lint findings; the remaining red linter jobs appear to reflect the current |
|
could you rebase on 2.0-dev branch? you fill find the |
Signed-off-by: devashridatta-dotcom <252791751+devashridatta-dotcom@users.noreply.github.com>
b29242b to
be5b543
Compare
|
Rebased onto the latest \2.0-dev\ (base \7a3ab082) and force-updated this PR branch. The ATLAS schema change is now under \schema/2.0/modules/cyclonedx-threat-2.0.schema.json, following the model-to-modules rename, and both ATLAS test fixtures remain included. I verified that all three changed JSON files parse, local file references resolve, and \git diff --check\ is clean. GitHub now reports the PR as mergeable; CI has been retriggered. |
Summary
Adds MITRE ATLAS as a named threat classification taxonomy for CycloneDX 2.0 threat categories.
ATLASto the threat categorytaxonomyenum.categoryvalues to the 16 ATLAS matrix tactics.Context
Refs #976.
This follows the direction from #956 that AI attack techniques belong in the threat layer, with ATLAS as the natural classification taxonomy. The tactic list follows the current public MITRE ATLAS data, where
dist/ATLAS-latest.yamlresolves todist/v6/ATLAS-2026.07.yaml.Source: https://github.com/mitre-atlas/atlas-data/blob/main/dist/v6/ATLAS-2026.07.yaml
Validation
pnpm run test:v2.0:t2-json-schema-semanticpasses.ATLAS+credential-accessacceptedATLAS+linkabilityrejectedMITRE-ATTACK+initial-accessstill acceptedNote:
pnpm run test:v2.0:t1-json-schema-validateandpnpm run test:v2.0:t3-json-schema-functionalstill fail before sample validation with the existing unresolved reference:model/cyclonedx-common-2.0.schema.json#/$defs/extensiblePropertiesThis same failure is present on the current 2.0-dev test path and is not introduced by this change.