EPSS Scores in the GitHub Advisory Database 🚀 #141713
Unanswered
ghostinhershell
asked this question in
Code Security
Replies: 1 comment
-
Looks like the REST API includes the EPSS in the response to the GET /advisories/{ghsa_id} endpoint. Is there a plan to include these in the Dependabot alerts as well, GET /repos/{owner}/{repo}/dependabot/alerts/{alert_number}? |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
The GitHub Advisory Database now features the Exploit Prediction Scoring System (EPSS) from the global Forum of Incident Response and Security Teams (FIRST), helping you better assess vulnerability risks.
EPSS scores predict the likelihood of a vulnerability being exploited, with scores ranging from 0 to 1 (0 to 100%). Higher scores mean higher risk. We also show the EPSS score percentile, indicating how a vulnerability compares to others.
For example, a 90.534% EPSS score at the 95th percentile means:
Learn more in the FIRST’s EPSS User Guide.
This feature will be available in GitHub Enterprise Server version 3.16 and later.
Beta Was this translation helpful? Give feedback.
All reactions