Open Vulnerability and Assessment Language (OVAL)
Offical Language Release Repository Downloads News — November 5, 2009 Search
link to OVAL home page

Version 5.7 (Planning)

This page provides information on proposed changes to the OVAL Language. All information about the new version is included in this centralized location. Read the Review Process.

New in Version 5.7

Version 5.7 of the Official OVAL Schema is a direct result of feedback from the OVAL Community. This will be a major version change and may require some new development by tools that support earlier versions of the Language. The changes pending to the different schemas are outlined below. "Open" status means the item is under consideration or being worked upon, "Closed" status means that the item has been incorporated and work on it is completed, and "Suspended" status means that the item will not be included in this version but may be included in a future version.

Items addressed in this version include:

StatusItem Description
  • open -- allow the use of filters at the set level instead of just the object reference level
  • open -- make it uniform throughout the schema to put references as attributes
  • open -- introduce a way to leverage content at an external location
  • open -- typo in sedenyremoteInteractivelogonright entity name
  • open -- unix files: need enumeration for type, rethink nillable filename
  • open -- add schematron rules to ensure values match datatypes
  • open -- add a new test for windows rights inheritance settings
  • open -- add a new windows user-level share permissions test
  • open -- support statements that return multiple n-tuples in xml, sql, wmi, and activedirectory tests
  • open -- change the epoch entity of rpminfo_test from string to int
  • open -- date/time entities should use the built-in xml date type
  • open -- add the ability to use xml:lang for comment attributes
  • open -- add an attribute to the entity base type for case sensistivity
  • open -- add a new Apache config file test
  • open -- add attribute supporting order of elements for functions like concat
  • open -- typo in inetlisteningservers_test name
  • closed -- consider allowing a test to reference multiple states
  • open -- add the divide and subtract operations to the arithmetic function
  • closed -- add support for registry keys that contain both the path and the filename
  • open -- align all test, object, state, and item names
  • open -- add a new test for active network connections on windows
  • open -- add additional protocols to the win-def:port_test
  • open -- change several unix-sc item entities to be based on ints rather than strings
  • open -- PIXOS line_test doesn't seem to be setup to work off of a single line
  • open -- change the maxOccurs attribute value in win-sc:sharedresource_item/win-sc:current_uses
  • open -- change the maxOccurs attribute value in win-sc:sharedresource_item/win-sc:max_uses
  • open -- change the win-sc:sharedresource_item/win-sc:shared_type entity type to align with the windows-definitions-schema
  • open -- limit the flag entity of the unix-def:interface_state and unix-sc:interface_item to an enumeration

Timeline for Version 5.7

PLANNING DRAFT RELEASE CANDIDATE OFFICIAL
28 August 2009 TBD TBD TBD

Status Reports on Version 5.7

Status updates are included below. You may also review the Community Forum Archives for discussions about Version 5.7, or enter "Version 5.7" as a keyword search for a list of forum discussions about the new version.

[2009-08-28]

Version 5.7 is currently in the planning stage. If you have any suggestions for changes that should be included, please send them to the OVAL Community.

Page Last Updated: September 02, 2009

Comments and questions on the proposed schemas are welcome on the OVAL Developer’s List.