Is there an existing issue for this?
Feature description
Currently we only check CVSS scores. Not all CVEs get these, and we base filtering on the maximum of all provided scores. It would be good to be able to also consider EPSS exploitability scores, and even potentially support an actual expression (cel?) evaluation of the scores to accept/ignore a given images exploits.
What would the ideal solution look like to you?
No response
Anything else?
No response
Is there an existing issue for this?
Feature description
Currently we only check CVSS scores. Not all CVEs get these, and we base filtering on the maximum of all provided scores. It would be good to be able to also consider EPSS exploitability scores, and even potentially support an actual expression (cel?) evaluation of the scores to accept/ignore a given images exploits.
What would the ideal solution look like to you?
No response
Anything else?
No response