Skip to content

Supplier Contacted

Supplier Contacted (ssvc:SCON:1.0.0)

Has the reporter made a good-faith effort to contact the supplier of the vulnerable component using a quality contact method?

Value Definition
No (N) The supplier has not been contacted.
Yes (Y) The supplier has been contacted.
Supplier Contacted (ssvc:SCON:1.0.0) JSON Example
{
  "name": "Supplier Contacted",
  "description": "Has the reporter made a good-faith effort to contact the supplier of the vulnerable component using a quality contact method?",
  "namespace": "ssvc",
  "version": "1.0.0",
  "schemaVersion": "1-0-1",
  "key": "SCON",
  "values": [
    {
      "key": "N",
      "name": "No",
      "description": "The supplier has not been contacted."
    },
    {
      "key": "Y",
      "name": "Yes",
      "description": "The supplier has been contacted."
    }
  ]
}

Quality Contact Method

A quality contact method is a publicly posted known good email address, public portal on vendor website, etc.