Work Product Manifest File This manifest file is an administrative metadata document produced by OASIS Staff as part of the approved Work Product publication process. It provides detailed information about the artifacts which constitute the Work Product in any published release, viz., for each specific level of approval (csd01, csd02, cs01, cos, etc). Users may find the manifest file useful in the following situations, or similar situations, to help answer basic questions: 1) "Can I examine the extent/content/structure of the published Work Product without having to download the distribution package from the OASIS Library and then UNzip the entire canonical release package from the ZIP format?" Yes: scan the manifest file published in any release directory (e.g. in /csd01/, /csprd02/) and inspect the section "ZIP archive contents" 2) "Someone sent me an XML schema file for the level CS01 instance of an OASIS specification: how can I determine whether this schema file is identical to the one published by OASIS?" Compute the MD5 or SHA-1 digest for the file you have, and compare it to the value(s) presented in the manifest file. =============================== Contents of this manifest file =============================== - Essential bibliographic information - ZIP archive listing for contents and storage hierarchy - Digest/hash values (MD5, SHA-1) for files in the release directory * Note that the digest/hash values are not intended to support security per se: they are provided simply for casual checking of a local file's hash value against the published file to detect disk corruption or other non-malicious alteration. * Note that the MD5/SHA-1 digest/hash values for primary ".html" format files in the OASIS Library release directory, as displayed below, are computed for OASIS server function, whereas the same ".html" files included in the ZIP package file, as prepared for local use, vary by a few bytes. The ZIP archive contents listing includes the digest/hash (CRC-32) and byte count for these ".html" files in the ZIP package. ====================================== Essential bibliographic information ====================================== Common Security Advisory Framework Version 2.0 Committee Specification 03 01 August 2022 Copyright (c) OASIS Open 2022. All Rights Reserved. Produced by: OASIS Common Security Advisory Framework (CSAF) TC https://www.oasis-open.org/committees/csaf/ Release URI: https://docs.oasis-open.org/csaf/csaf/v2.0/cs03/csaf-v2.0-cs03.zip Manifest URI: https://docs.oasis-open.org/csaf/csaf/v2.0/cs03/csaf-v2.0-cs03-manifest.txt =========================== ZIP archive contents =========================== Archive: csaf-v2.0-cs03.zip Length Method Size Cmpr Date Time CRC-32 Name -------- ------ ------- ---- ---------- ----- -------- ---- 1852987 Defl:N 920869 50% 08-01-2022 16:00 9b3781be csaf-v2.0-cs03-DIFF.pdf 414594 Defl:N 82164 80% 08-01-2022 16:00 09d79f94 csaf-v2.0-cs03.html 294546 Defl:N 68759 77% 08-01-2022 16:00 eb8c9f27 csaf-v2.0-cs03.md 776210 Defl:N 586081 25% 08-01-2022 16:00 8d7ac190 csaf-v2.0-cs03.pdf 0 Stored 0 0% 08-01-2022 16:00 00000000 schemas/ 7433 Defl:N 1582 79% 08-01-2022 16:00 be29c768 schemas/aggregator_json_schema.json 7365 Defl:N 1526 79% 08-01-2022 16:00 94e7c40a schemas/provider_json_schema.json 57152 Defl:N 10592 82% 08-01-2022 16:00 0e06d8f2 schemas/csaf_json_schema.json -------- ------- --- ------- 3410287 1671573 51% 8 files ======================================================================== MD5 digest/hash values for files in the OASIS Library release directory ======================================================================== 59cfbffb8b5c2bb3a9b2e20a2e556f3e csaf-v2.0-cs03-DIFF.pdf 0b0af435518b42e145ab604821f92ee0 csaf-v2.0-cs03.html 5d7bdb9565810eb2088a0d93aad9e24b csaf-v2.0-cs03.md 1453b27422ce30a583c4892c9a4873db csaf-v2.0-cs03.pdf 00bbc1e78afe06a0385f942bb4943b5e csaf-v2.0-cs03.zip 5487fc51f276b08ed2194ccf5f92957a schemas/aggregator_json_schema.json 0e1bc03d417db16a1ef2b34ac97ea86b schemas/csaf_json_schema.json 5232a582d26630b74699f4f215f9c743 schemas/provider_json_schema.json ========================================================================== SHA-1 digest/hash values for files in the OASIS Library release directory ========================================================================== 4e60cc05da412c4ee006c5838227c267c14a3652 csaf-v2.0-cs03-DIFF.pdf c4e42e991f1877ae47554de1acc5852555b5d7b7 csaf-v2.0-cs03.html f358a69538df358fd6b6ea3c0bf59676687a3f63 csaf-v2.0-cs03.md 30721ec6b9ff1d6ea80f0ca71c1820189a8e811a csaf-v2.0-cs03.pdf 61b64f3f948f3afc1f3193097e805df7681b5309 csaf-v2.0-cs03.zip 96fbe7774676b603bc95fc236df516c45ea5f7c0 schemas/aggregator_json_schema.json 1946b630b68fefb8a28ba9606667a8fdea95783c schemas/csaf_json_schema.json ea11e6971cb18021c83bc7d8162a86b282de3d20 schemas/provider_json_schema.json