Skip to content

docs: add evidence package manifest appendix#10

Merged
jinsonvarghese merged 3 commits intoOWASP:mainfrom
Hinotoi-agent:docs/evidence-package-manifest
Apr 19, 2026
Merged

docs: add evidence package manifest appendix#10
jinsonvarghese merged 3 commits intoOWASP:mainfrom
Hinotoi-agent:docs/evidence-package-manifest

Conversation

@Hinotoi-agent
Copy link
Copy Markdown
Contributor

@Hinotoi-agent Hinotoi-agent commented Apr 18, 2026

Summary

  • add a non-normative evidence package manifest appendix with YAML/JSON examples
  • link the appendix from the standard README plus the Auditability and Reporting implementation guides
  • extend the Vendor Evaluation Guide with a concrete evidence-package review prompt

Why

Issue #6 asks for a practical manifest example that ties together evidence integrity, provenance, review state, and downstream handoff without making one format mandatory.

Affected sections

  • standard/appendix/Evidence_Package_Manifest.md
  • standard/README.md
  • standard/5_Auditability/Implementation_Guide.md
  • standard/8_Reporting/Implementation_Guide.md
  • standard/appendix/Vendor_Evaluation_Guide.md

Contributing.md checklist

Notes

  • informative appendix only; no new normative requirements added
  • writing kept vendor-neutral and organization-neutral
  • terminology follows the existing style guide

Closes #6

@jinsonvarghese
Copy link
Copy Markdown
Member

@Hinotoi-agent Good work on this! One change needed before merge:

  1. A row needs to be added for the new appendix in standard/Getting_Started.md under the Document Map table

Also heads up; this PR and #9 both modify standard/README.md and Vendor_Evaluation_Guide.md, so whichever merges second will need a rebase.

@Hinotoi-agent
Copy link
Copy Markdown
Contributor Author

Thanks — I addressed the requested change by adding a Document Map row for the new appendix in standard/Getting_Started.md.

I also removed the cross-cutting standard/README.md and Vendor_Evaluation_Guide.md edits from this branch to reduce merge conflicts with the other appendix PRs.

Updated on commit 85e0b6d.

@jinsonvarghese jinsonvarghese merged commit 7644022 into OWASP:main Apr 19, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Proposal: add an evidence package manifest schema for findings and audit artifacts

2 participants