Document:
Alignment between SARIF and OMG TOIF

Document Number: omg sysa-18-02-01
Draft (A preliminary unapproved sketch, outline, or version.)

Details

Submitted By Dr. Nikolai Mansourov on 2018-02-28 9:56 pm UTC

Publication Type

None at this time.

Group / Folder

OASIS Static Analysis Results Interchange Format (SARIF) TC / Documents

Modified by

Not modified.

Copy

This document is not a copy.

Technical Contact

None at this time.

Download Count

574

Download Agreement

None at this time.

Description

This document describes the alignment between OASIS SARIF and the OMG Tools Output Integration Framework (TOIF), gives a detailed object-by-object comparison and suggests a roadmap for the interoperability between the two specifications. The proposed roadmap includes further alignment of the core concepts, a generic adaptor from SARIF to TOIF, a standard converter from TOIF to SARIF, coordinated efforts towards common weakness measures in the context of SCA tools, using SARIF to capture existing tool-specific measures, using TOIF as the platform for developing common ranking tools, and using TOIF as a platform for common risk assessment tools.