Measuring CVE Performance Vuln4Cast 2024, Ben Edwards
https://bjedwards.observablehq.cloud/measuring-cna-performance/

CWE Diversity

Some CNAs specialize, others dabble in everything

Shannon Diversity

A measure of variance across a categorical distribution

For CNA j who has published i={1,...,k} CWEs

Scales with more CWEs

Some CNAs have only published one type of CWE

Some have a huge diversity of CWEs

No clear pattern by type