|
|
|
|
|
by eyakubovich
1205 days ago
|
|
Great feedback. 1) We want to be cautious about changing a score that someone else assigned (CVSS) but we'd like to add our insight to inform of its impact. 2) Absolutely and we'd like to bundle it with active blocking. After reviewing the CVE, we'll let the user either accept (e.g. mute) it or block that specific package from being used (e.g. for dormant ones). 3) We think our service is most useful to slightly larger orgs with dedicated security functions and bigger supply chains. We want to help slow down the fire-hose of vulnerability reports coming from the security to devs. |
|
Would be interested to hear more strategy here -- in my experience, the only way to actually lift this dev burden is to make upgrading dependencies something that's expected, routine, and near-automatic.