You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Right now, we report the number of CVEs found even if our triage then says we want to ignore them. This probably isn't what we want. We should instead report
the number of CVEs found minus any that are ignored or mitigated
a count of CVEs that are ignored or mitigated (so these are known and can be re-evaluated if needed)
The text was updated successfully, but these errors were encountered:
There are also instances where the reported numbers don't seem to be adding up. I tried this when disabling a data source which seems to introduce a few issues.
There are 29 CVEs identified by cve_scanner but the summary only shows 27 CVEs - this is becuase there are CVEs with UNKNOWN severity which are not included in the summary.
It states that there are 7 files but there are 8 files shown. This is becuase a product was being added if there ARE CVEs but if all the CVEs are from a disabled data source, the products was still being included.
Right now, we report the number of CVEs found even if our triage then says we want to ignore them. This probably isn't what we want. We should instead report
The text was updated successfully, but these errors were encountered: