Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Assistance Required: Issue with Vulnerability Count Using Cybeats API #40

Open
Deekshitha-40024389 opened this issue Dec 12, 2024 · 0 comments

Comments

@Deekshitha-40024389
Copy link

Hi Team,

We have the below requirements to meet using Cybeats API, and we would appreciate your support.
We attempted to approach the requirements using Cybeats API doc cybeats.api.
The requirement is still not met.

Requirement:
       API to get the vulnerability count of individual application (Ex: hsdp-iam-auth), assume there are total count of 3 vulnerabilities found, and developer creates VEX for one component (Ex: spring-boot-actuator-autoconfigure is is VEX'd) then total count must reduce to 2.

Approach:
      We couldn't find any direct API to get the count of vulnerability, so we preferred getting software component catalog description api (https://cybeats.readme.io/reference/get-by-software), by which we are able to filter the total count of vulnerabilities of application (Ex:hsdp-iam-auth) as below.

We VEX'd one of the components and expected total vulnerability count to reduce by 1 (i.e. Total Vulnerabilities: 10, where Critical: 0), but the count remained same (i.e. 11)

Please prioritize this and provide your assistance, your response is highly appreciated.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant