claircore
claircore copied to clipboard
debian: change severity mapping
trafficstars
Really seems like the severity mapping should be:
| Debian Severity | Claircore Severity |
|---|---|
| unimportant | Negligible |
| low | Low |
| medium | Medium |
| high | High |
| * | Unknown |
instead of
| Debian Severity | Claircore Severity |
|---|---|
| unimportant | Low |
| low | Medium |
| medium | High |
| high | Critical |
| * | Unknown |
Originally posted by @hdonnay in https://github.com/quay/claircore/pull/1067#discussion_r1334607884
@RTann, do you recall what the thinking was on the current mapping?
https://github.com/quay/claircore/discussions/828 context here
Yeah #828 covers the reasoning. I aligned Debian's definitions with Red Hat's and that's how the severity mapping was done. I think it makes sense, as users who may want to filter by critical vulns will never see Critical Debian's vulns if we never use it