devguard icon indicating copy to clipboard operation
devguard copied to clipboard

Improve Risk Assessment for First-Party Vulnerabilities

Open refoo0 opened this issue 10 months ago • 0 comments

First-party vulnerabilities do not have a raw risk assessment, resulting in a default value of 0. This leads to the automatic assignment of low-severity labels, which may not accurately reflect the actual risk. We should consider skipping severity labels for first-party vulnerabilities unless a proper risk assessment is available.

refoo0 avatar Feb 26 '25 12:02 refoo0