Recalculating a vulnerability's Severity and CVSS score based on injected temporal/environmental metrics #9926
Unanswered
quentinkhoo
asked this question in
Q&A
Replies: 1 comment
-
|
Hi @quentinkhoo ! You can write a module that patches the results https://trivy.dev/docs/latest/guide/advanced/modules/ |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Question
Hi all! Apologise if I'm starting this discussion wrongly.
Anyway I was wondering, like passing in a rego policy to the
--ignore-policyargument as described here, is there a way in Trivy to perhaps on atrivy image --scanners vulnat runtime to pass in a configuration file of some sort to achieve an idea like:Modified Availability (MA)isnone.Network.TLDR --> can i pass in to trivy some sort of file to get trivy to recalculate CVSS results based on certain metrics?
Target
Container Image
Scanner
Vulnerability
Output Format
JSON
Mode
Standalone
Operating System
MacOS Tahoe
Version
Beta Was this translation helpful? Give feedback.
All reactions