Skip to content

Conversation

@ahouseholder
Copy link
Contributor

@ahouseholder ahouseholder commented Sep 12, 2025

This PR adds a few explanatory callouts in the EPSS how to articles. One of them mentions that SSVC users could use EPSS to sort within an SSVC outcome category. It's not something we're going to recommend, but it is an available option for folks if they really feel strongly about "sorting" over and above "categorization".

Note

I also intend to start a discussion thread to capture some thoughts on how to approach the "but we need numbers so we can sort" folks. (Not hostile to it, I just think there are a few alternative pathways to consider before concluding that sorting is necessary. Interested to get community feedback on that. Maybe it turns into future guidance in the site.

Copilot Summary

This pull request adds helpful Q&A sections to the documentation for using EPSS with SSVC, making the guides more user-friendly and addressing common questions about combining exploitation data and prioritizing vulnerabilities.

Documentation improvements:

  • Added a "What's in this How-To?" question box to epss_percentiles.md and epss_probability.md to clarify the content and goals of each guide. [1] [2]
  • Added a question box to epss_percentiles.md explaining how to sort vulnerabilities within a given SSVC outcome category using raw EPSS probability scores as a secondary sorting key.

@ahouseholder ahouseholder self-assigned this Sep 12, 2025
@ahouseholder ahouseholder added the content/semantic Changes to the semantic content of the SSVC documentation label Sep 12, 2025
@ahouseholder ahouseholder added this to the 2025-09 milestone Sep 12, 2025
Copy link
Contributor

@sei-vsarvepalli sei-vsarvepalli left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All looks good. Only thing I can think of is to add this is applicable in both cases for any numeric score that is used to represent a decision point.

@ahouseholder
Copy link
Contributor Author

All looks good. Only thing I can think of is to add this is applicable in both cases for any numeric score that is used to represent a decision point.

Yeah, I started writing more about that and realized I have a short essay about "things to consider when you perceive the need to sort". I'm drafting that and will post it into a discussion post soon.

@ahouseholder ahouseholder merged commit fd232a0 into main Sep 12, 2025
5 checks passed
@ahouseholder ahouseholder deleted the update-epss-howto branch September 12, 2025 18:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

content/semantic Changes to the semantic content of the SSVC documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants