# GCVE BCP-05-X-04 - Vulnerability Handling and Advisory Publication State

**URL:** <https://discourse.ossbase.org/t/gcve-bcp-05-x-04-vulnerability-handling-and-advisory-publication-state/1136>\
**Category:** GCVE\
**Tags:** bcp-05\
**Created:** [October 4, 2026, 7:29am UTC](https://discourse.ossbase.org/t/gcve-bcp-05-x-04-vulnerability-handling-and-advisory-publication-state/1136 "2026-10-04T07:29:21Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![adulau](https://discourse.ossbase.org/user_avatar/discourse.ossbase.org/adulau/32/6_2.png) [@adulau](https://discourse.ossbase.org/u/adulau)\
**Post date:** [October 4, 2026, 7:29am UTC](https://discourse.ossbase.org/t/gcve-bcp-05-x-04-vulnerability-handling-and-advisory-publication-state/1136/1 "2026-10-04T07:29:22Z")

</div>

> **GCVE BCP-05-X-04 — Vulnerability Handling and Advisory Publication State**

Its purpose would be to represent the **current snapshot** , while BCP-05-X-03 remains the historical timeline.

Some state ideas:

- `not-public`
- `embargoed`
- `scheduled`
- `published`
- `withdrawn`
- `superseded`

The current challenge is to define embargoed. Means that a publication could be have done already done to a private group. So those state could be combined. We saw also case of publication which were limited to a trusted group and never going fully public.

---

<div class="post-metadata">

**Author:** ![cedric](https://discourse.ossbase.org/user_avatar/discourse.ossbase.org/cedric/32/112_2.png) [@cedric](https://discourse.ossbase.org/u/cedric)\
**Post date:** [October 6, 2026, 9:31am UTC](https://discourse.ossbase.org/t/gcve-bcp-05-x-04-vulnerability-handling-and-advisory-publication-state/1136/2 "2026-10-06T09:31:40Z")

</div>

I think that public is public, no need to say fully public. If there is an embargo, it isn’t public it is restricted. So public is not compatible with embargo. For me these are not the same kind of state. That’s why I detect some incompatibilities (states that are incompatible). It’s an issue and a solution in the same time. We can have the 3 types of states (for example):

1. Visibility

- not-public
- published

1. Publication process

- (draft)
- scheduled
- published
- withdrawn

1. Disclosure restrictions / or lifecycle (maybe redundant with what we have in BCP-005)

- embargoed
- superseded

That’s why the combinations of **any** of these states become awkward. But it works with types.

I added `draft` state for the case when the vulnerability coordinator is currently working on a new advisory. A draft is not necessaru private. I was not fan of this idea of “private draft” because I think that practically some people will use it to write advisory taht are not public (they will stay in draft mode for days). So here we could have a way to say “ **public draft** ” or “ **private draft** ”. I **encourage** “public draft” ! And from the beginning. It’s like with open source code. Public even before it is ready to be shown.  
So this is a public draft (as encouraged by me):

```json
{
  "publication": {
    "state": "draft",
    "visibility": "public"
  }
}

```

I would also make published explicitly mean “publicly published”.

and then we can have a model like:

```json
{
  "publication": {
    "state": "published",
    "published_at": "...",
    "visibility": "public"
  },
  "handling": {
    "embargoed": false
  },
  "superseded_by": null
}

```

but now my issue is:

```json
{
  "publication": {
    "state": "published",
    "published_at": "...",
    "visibility": "public"
  },
  "handling": {
    "embargoed": true
  },
  "superseded_by": null
}

```

this should be forbidden!  
Default value of embargoe should be `false`. And during the embargoe:

```json
{
  "publication": {
    "state": "scheduled",
    "scheduled_at": "...",
    "visibility": "restricted"
  },
  "handling": {
    "embargo": {
      "until": "2026-11-01T12:00:00Z"
    }
  },
  "superseded_by": null
}

```

and then we are transparent on when will be the end of the embargo.

`state = published` **implies** `visibility = public`.  
When we have the state `public` the state can be omitted.

As for `superseded_by`, should we use the same in as in BCP-05. We have `relationships` and `deprecation` record type. So I would just set an id here to keep it simple. And don’t add redundancy in the global record.

---

<div class="post-metadata">

**Author:** ![cedric](https://discourse.ossbase.org/user_avatar/discourse.ossbase.org/cedric/32/112_2.png) [@cedric](https://discourse.ossbase.org/u/cedric)\
**Post date:** [October 6, 2026, 9:56am UTC](https://discourse.ossbase.org/t/gcve-bcp-05-x-04-vulnerability-handling-and-advisory-publication-state/1136/3 "2026-10-06T09:56:49Z")

</div>

> [@cedric](#):
>
> `restricted`

the scope is the GNA owner of the record.  
Another GNA can publish independently the information.
