-
Notifications
You must be signed in to change notification settings - Fork 90
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
JSON Baseline Profiles Do Not Contain JSON Catalog Links #103
Comments
Thanks for your report, @rgauss. We will look at this in conjunction with usnistgov/oscal-content#59. |
@rgauss I (as part of FedRAMP) discussed this with the NIST OSCAL developers. The pipeline work as surfaced here and usnistgov/oscal-content#59 will require significant modifications that will not be addressed by OSCAL tooling, not just FedRAMP's baseline updates using it. I will review a workaround solution and/or manual effort for the 1.0.0 release potentially, but cannot commit to that at this time. I will update this issue and its tracking tags accordingly. |
@ohsh6o, thanks for looking into it! We can implement temporary workarounds on our end in the meantime. |
@rgauss I am going to attempt to work on a CI/CD fix that is mutually beneficial in the interim, for our FedRAMP's own 1.0.0 release, that will be beneficial to FedRAMP and NIST. Stay tuned and I will appropriately message in this bug report. Thanks again! |
I have been working on this locally on my workstation but it might not be ready for 1.0.0. I published a workaround by publishing all the profile formats in parallel in #103 to address the particular need, but it will continue to write a more programmatic check, and potentially revert this change and not include all formats in the future. :-) |
This will remove a TODO that has been closed according to GSA/fedramp-automation#103.
Describe the bug
The JSON representation of baseline profiles only contain XML rlinks (example) for the catalog back-matter resource.
There should be an rlink to a JSON representation of that catalog with an
application/oscal.catalog+json
media type (example with a currently incorrect extension due to reported issue).Who is the bug affecting?
Anyone using JSON representations of baseline profiles.
What is affected by this bug?
The ability to resolve catalog controls for baseline profiles.
When does this occur?
Always
The text was updated successfully, but these errors were encountered: