[REQUEST] Ensure external_references' urls are RFC3986 Compliant
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 68/100
- Issue type
- Feature
- Clarity
- Clearly specified
- Activity status
- Quiet
- Tech stack
- typescript
- Domain
- backend
Research direction
Start with src/schemas/common/property-schemas/stix-external-references.ts and review the RFC3986 and STIX 2.1 references in the issue. Check the historical examples in attack-stix-data issue 16, then verify that external_references URL values are accepted or rejected according to the requested compliance requirements.
Written by the indexing model from the issue text.
Description
Is your feature request related to a problem? Please describe.
STIX 2.1 requires that the Common Data Type of External Reference (external_references) have their url field be RFC3986 compliant (link to STIX 2.1 reference). Ensuring this in the ATT&CK Data Model would help ensure that URLs stay in compliance with STIX 2.1 requirements.
Describe the solution you'd like
This could be added to the zod schema here: https://github.com/mitre-attack/attack-data-model/blob/main/src/schemas/common/property-schemas/stix-external-references.ts
Describe alternatives you've considered
Alternatively we could not bother with this enhancement since it is STIX 2.1 specific, but if not here, then where!?
Additional context
This has bitten the ATT&CK dataset in the past, e.g. here: https://github.com/mitre-attack/attack-stix-data/issues/16
The referenced issue has some good examples of what was historically included in the STIX bundles before they were manually corrected
- Dominant language
- MDX
- Stars
- 93
- Forks
- 25
- PR merge metrics
- No merged PRs in 30d
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from mitre-attack/attack-data-model
-
Missing subtechnique-of relationships for T1053.001 and T1547.011May be free again @seansica claimed this 245 days ago, and no pull request is open. Open
mitre-attack/attack-data-model#64 · 1 assignee ·
-
enhancement
Difficulty 3/5 1-2 days Newbie friendliness 35/100
-
enhancement
Difficulty 5/5 Over a week Newbie friendliness 20/100
mitre-attack/attack-data-model#52 · 1 comment ·
-
Overhaul ES6 Class ImplementationsPossibly taken @seansica claimed this 434 days ago. Openenhancement
mitre-attack/attack-data-model#37 · 1 assignee ·
-
Add registry descriptions to all schemasMay be free again @seansica claimed this 434 days ago, and no pull request is open. Openbug documentation
mitre-attack/attack-data-model#36 · 1 assignee ·
All issues in mitre-attack/attack-data-model
Similar issues
-
bug needs-triage
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
DataDog/dd-trace-go#5469 ·
Maintainers usually reply within 1 day
-
Team: SCM
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
[Bug]: Reusing BFSDeepCrawlStrategy leaks the previous crawl's max_pages budget into a fresh runOpen
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
unconfirmed bug
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
Rapptz/discord.py#10529 ·
Maintainers usually reply within 1 day
-
[Bug]: MRV2 prepare_inputs signature is incompatible with updated vLLM num_active_loras argumentOpenbug
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
vllm-project/vllm-ascend#17710 ·
Maintainers usually reply within 1 day