Skip to content

METABUG: Potential concrete data quality improvements for 5.2.0 #298

@andrewpollock

Description

@andrewpollock

I thought I'd capture an umbrella issue for discussing a package of improvements for 5.2.0

A possible use-case based approach:

Use case 1: "Does this vulnerability apply to me?" "How do I make it not apply to me?"

Use case 2: "How do I prioritize the vulnerabilities that apply to me?"

  • I have CVSS, EPSS etc scores to stack rank the vulnerabilities identifiable from use case 1, so that I can determine the next steps for responding to them

Use case 3: "How can I perform aggregate, historical analytics on the vulnerabilities that apply/did apply to me?"

  • I can broadly bucket vulnerabilities to answer questions like "How many memory safety vulnerabilities impacted me last year?"

Some other general input validation issues worth noting here:

Related validation work happening elsewhere:

Metadata

Metadata

Assignees

No one assigned

    Labels

    invalidThis doesn't seem right

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions