Repository navigation
STIX export: omit null properties and empty lists - #7
Merged
Merged
Conversation
added 4 commits
October 8, 2026 12:22
The exporter emits null x_nrdax_family/surface/bound_failure for a pending technique and [] for x_nrdax_chains when there are no instances. STIX 2.1 forbids both, and the OASIS validator rejects them. The fixture drops the three nulls, matching the backend fix (nrdax-api #38).
A pending technique now omits x_nrdax_family/surface/bound_failure (and x_nrdax_producer_family when absent); one with no instances omits x_nrdax_chains. validate_bundle rejects a null property or an empty list at any depth. Matches the backend (nrdax-api #38); the reader already used .get(), so absence reads as the null it replaces.
The fixture is the backend's golden stix.json again (post nrdax-api #38). The backend has led every bundle with a CC-BY-4.0 marking-definition referenced by each attack-pattern's object_marking_refs; this exporter never did, so its 'byte-identical to the backend' claim had silently stopped being true.
…end does A statement marking-definition (deterministic UUIDv5 id, fixed created) leads every bundle and each attack-pattern references it via object_marking_refs. The export is byte-identical to the backend's golden again.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Same defect, same fix as the API side (NullRabbitLabs/nrdax-api#38):
attack_pattern()emittedx_nrdax_family/x_nrdax_surface/x_nrdax_bound_failureasnullfor a pending technique andx_nrdax_chainsas[]for one with no instances. STIX 2.1 forbids both, so any bundle exported through this package fails the OASIS stix2-validator. The shipped test fixture carried the defect too.Change
x_nrdax_producer_familywhen it is absent;x_nrdax_classification: "pending"still says why the axes are missing.validate_bundlenow rejects a null property or an empty list at any depth.Verified
NRDAX.from_api()) through the patched exporter and ran stix2-validator 3.3.1: 0 invalid objects.Compatibility: the STIX reader (
sources/stix.py) already reads these properties with.get(), so an omitted property reads as theNoneit replaces.License marking (second fix, 4945bb4 red, 1099987 green). The fixture is again the backend's golden
stix.json(post-#38). The backend leads every bundle with a CC-BY-4.0marking-definitionthat each attack-pattern references throughobject_marking_refs; this exporter never did, so the "byte-identical to the backend" test was passing against a stale fixture. It now emits the same marking with the same deterministic id, and the export is byte-identical to the backend's golden again.Verified again. The full live registry exported through this branch is 524 objects (523 techniques plus the marking), with 0 invalid under stix2-validator.
Still not modelled. The Python
Techniquehas no scope or AADAPT crosswalk, so this exporter cannot emitx_nrdax_out_of_scopeormitre-aadaptreferences the way the backend does. That is a model gap, not this bug. No release is cut here.