-
-
Notifications
You must be signed in to change notification settings - Fork 261
Closed
Description
Code to collect and store SSVC decision trees in VulnerableCode.
We have some elements of the scoring system already in place, in particular for vulnrichhment, the goal is to systematically store the data as trees to support context-aware decision down the road in DejaCode.
We need further design.
References:
- https://github.com/CERTCC/SSVC
- https://github.com/theparanoids/PrioritizedRiskRemediation
- POST: it is hard to rate the severity of vulnerabiliies www.aboutcode.org#21
- cravex2-reachability: Enhance the vulnerability-ranking system for trees dejacode#366
- Consider SSVC for vulnerabilities prioritization #1457
- fedcode-next: Code, UI and models to curate severity scoring #1719
Return the ssvc vector and the decision value class SSVCScoringSystem(ScoringSystem):
Metadata
Metadata
Assignees
Labels
No labels
Type
Projects
Status
Validated