Releases: ocsf/aws
Releases · ocsf/aws
v1.1.0
Immutable
release. Only release title and notes can be modified.
[v1.1.0] - May 22nd, 2026
Added
-
Event Classes
- Added
Remediation Target Findingevent class to the Findings category. Identifies resources that, when remediated, resolve or reduce severity of grouped findings. - Added
Network Scan Findingevent class to the Findings category.
- Added
-
Objects
- Added
remediation_outcome,contributing_finding, andremediation_stepobjects for remediation impact tracking. Extendedremediationwithis_immediateandpost_remediation_steps. - Added
adjusted_metricobject for CVSS environmental metric modifications. Extendedcvsswithadjusted_score,adjusted_vector_string, andadjusted_metric_list. Extendedvulnerabilitywithvendor_score. - Added
port_scan_resultobject for per-port scan probe outcomes. - Added
network_scan_infoobject for scan job metadata. - Added
content_policy_filterandguardrail_evaluation_resultobjects for AI guardrail content filter results.
- Added
-
Dictionary Attributes
- Added
adjusted_scoreas afloat_t,adjusted_vector_stringas astring_t, andadjusted_metric_listas an array ofadjusted_metricobjects. - Added
cvss_metricandupdate_reasonasstring_t, andvendor_scoreas afloat_t. - Added
target_traitas atraitobject,remediation_outcomeas aremediation_outcomeobject, andcontributing_findingsas an array ofcontributing_findingobjects. - Added
resolved_findings_count,severity_reduction_findings_count,severity_unchanged_findings_countasinteger_t. - Added
updated_severityas astring_t,updated_severity_idas aninteger_tenum, andupdated_traitsas an array oftraitobjects. - Added
is_immediateas aboolean_tandpost_remediation_stepsas an array ofremediation_stepobjects. - Added
likelihood_idas aninteger_tenum andlikelihoodas astring_t. Aligns with NIST SP 800-30 Rev. 1 qualitative likelihood scale. - Added
network_scan_infoas anetwork_scan_infoobject,port_infoas aport_infoobject, andport_scan_result_listas an array ofport_scan_resultobjects. - Added
scan_durationas atimespanobject andscanner_endpointas anetwork_endpointobject. - Added
tcp_banneras astring_t. - Added
content_policy_filtersas an array ofcontent_policy_filterobjects. - Added
guardrail_evaluation_resultas aguardrail_evaluation_resultobject.
- Added
Improved
-
Event Classes
- Added
likelihoodandlikelihood_idtoDetection Finding(class 2004). - Added
guardrail_evaluation_resulttoDetection Finding(class 2004).
- Added
-
Objects
- Added
labelsto thenodeobject for grouping nodes into named subgraphs. - Added
labelsandprivilege_attack_info_listto theedgeobject. - Added
orgto theat_leastconstraint in theuserobject. - Added
tcp_banner,tls, andhttp_responseto theport_scan_resultobject.
- Added