Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Report on the CVSS Score and vector information from NPM Audit API responses #5552

Closed
aikebah opened this issue Mar 10, 2023 · 0 comments · Fixed by #5546
Closed

Report on the CVSS Score and vector information from NPM Audit API responses #5552

aikebah opened this issue Mar 10, 2023 · 0 comments · Fixed by #5546
Assignees
Milestone

Comments

@aikebah
Copy link
Collaborator

aikebah commented Mar 10, 2023

Is your feature request related to a problem? Please describe.
Currently NPM Audit results are using a textual severity description, but for at least a significant part of the NPM Audit responses CVSS information is also included.

Describe the solution you'd like
When available DependencyCheck should use the CVSS scores and vector information when reporting the severity of the NPM Audit API findings. When CVSS scores are not present ODC fall back to using the textual severity from the NPM Audit API response.

Describe alternatives you've considered
Keeping the severities as is, resulting in loss of information compared to the NPM Audit API response.

@aikebah aikebah self-assigned this Mar 10, 2023
@aikebah aikebah linked a pull request Mar 10, 2023 that will close this issue
aikebah added a commit that referenced this issue Mar 16, 2023
@aikebah aikebah added this to the 8.2.0 milestone Mar 16, 2023
@github-actions github-actions bot locked as resolved and limited conversation to collaborators Dec 21, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant