Open remediation standards for regulated consumption
A provisional FINOS OSERA evaluation draft for producing, publishing, and consuming open patches with provenance, release evidence, vulnerability feeds, and recipient-focused test guidance. This branch proposes an initial OSERA-SP-0.1.0 standards pack for open discussion.
Candidate standards pack
OSERA-SP-0.1.0 proposes the first versioned set of remediation standards for issue #12. The pack includes conventions that current implementers can plausibly follow on day one and defers immature areas such as certification and estate-wide automated application.
Why this exists
OSERA patch work has moved from a small set of experiments into a larger patch library spanning older Java ecosystems, build tooling variations, and end-of-life software lines. The emerging practice now needs a stable, open, bank-consumable format.
What it standardizes
The draft focuses on fork management, source-change provenance, release compatibility, VEX/SBOM feeds, and the recipient evidence enterprises need to assess what changed and what surface area to test.
Standards catalog
Numbered requirements and examples, modeled on the SDLC Controls Framework catalog style and adapted for patch production and consumption.
Standard lifecycle status and standards-pack membership are tracked separately. Ratifying a pack records the exact standard versions included in that pack; it does not rewrite every future draft into the pack. The same structured metadata is published in the generated standards catalog.
Recipient evidence is part of the standard
Patch delivery should not stop at a patched coordinate. Providers should publish a concise, machine-readable explanation of what changed, why it changed, and what application surface area recipients should consider testing.