Skip to content

Conversation

@pohanhuangtw
Copy link

@pohanhuangtw pohanhuangtw commented May 20, 2024

Summary

  1. Add Critical CVE Severity to support CVSS v3 scores 9.0-10.0

How to verify

update from the previous version, say previous version have 5 High, but in CVSS 3.0 is 4 High 1 Critical
And current threshold for high is 5.

  1. if user didn't update the pipeline script => it should hold the previous result, which is fail
  2. if user update the pipeline scripts and remain the high is 5, no setting for others => it should pass.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants