Skip to content

feat: implement mapping integrity validator for CWE and MITRE ATLAS - #147

Open
rashim27us wants to merge 1 commit into
GenAI-Security-Project:mainfrom
rashim27us:feature/mapping-integrity-validator
Open

rashim27us wants to merge 1 commit into
GenAI-Security-Project:mainfrom
rashim27us:feature/mapping-integrity-validator

Conversation

@rashim27us

Copy link
Copy Markdown

Summary

This PR adds the first phase of automated cross-framework mapping integrity validation for the 2026 release, starting with CWE 4.20 and MITRE ATLAS 2026.06 as requested in #132.

  • Adds a local and CI validator that checks mapping catalogs against version-pinned primary datasets, including identifier existence, duplicate IDs, title/metadata consistency, source version checks, pinned ATLAS source enforcement, and SHA-256 verification via new source_sha fields.
  • Updates cwe-4.20.json and mitre-atlas-2026.06.json to pin machine-readable source URLs and record the verified source digests, replacing the CWE homepage URL with the version-specific XML archive.
  • Adds offline negative tests, a GitHub Actions workflow, and mapping documentation so future framework validators can follow the same pattern.

Test plan

  • Run python .github/scripts/test_validate_mappings.py
  • Run python .github/scripts/validate_mappings.py --download
  • Confirm both 2026/final/mappings/cwe-4.20.json and 2026/final/mappings/mitre-atlas-2026.06.json pass validation
  • Verify negative cases fail for invalid IDs, duplicate IDs, title mismatches, deprecated ATLAS source paths, version mismatches, and SHA mismatches

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants