Skip to main content

Add a short description here!

Project description

rst.. These are examples of badges you might want to add to your README:

please update the URLs accordingly

Built Status ReadTheDocs Coveralls PyPI-Server Conda-Forge Monthly Downloads Twitter
Project generated with PyScaffold OpenSSF Badges

cvss_rescore

Rescore cvss3 and 3.1 results from any json file based on custom rules.

The Problem

Cvss scoring consists of three components: Base, Temporal, and Environmental.

When working with third-party dependency (SCA) vulnerabilities, nearly every tool reports it’s scores only using the base score. This is understandable, as the reporters of the vulnerabilities would only know about the vulnerabilities themselves. They would have no idea how the vulnerable package is actually used in your project. Do you have mitigating controls in place? Is it only a test project? Is it only in a protected CI/CD pipeline? All of these factors and more can impact the environmental score, which can lower the actual score of a vulnerability significantly.

How We Use This

Output-Agnostic

We use the cvss-rescore packate as a post-processor after our SCA scan has been run. Because the cvss-rescore package can take any json format output, it is tool-agnostic. We have tested it successfully using Dependabot and JFrog Xray, but there’s no reason any other tool can’t be used so long as the output is json.

Rules-Based

Because we leverage the Python rule-engine package as a dependency, users can create a rules_actions.json file in their root directory. Users can create as many rules as they need, modifying one or more cvss vector metrics per rule.

Requirements
  • Python 3.6 or higher

  • A working knowledge of CVSS calcuation. You can reference the calculator at

Documentation

You can get the current documentation at https://cvss-rescore.readthedocs.io/en/latest/

Dependencies
Note

This project has been set up using PyScaffold 4.3.1. For details and usage information on PyScaffold see https://pyscaffold.org/.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

cvss_rescore-0.0.2.tar.gz (28.3 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

cvss_rescore-0.0.2-py3-none-any.whl (6.0 kB view details)

Uploaded Python 3

File details

Details for the file cvss_rescore-0.0.2.tar.gz.

File metadata

  • Download URL: cvss_rescore-0.0.2.tar.gz
  • Upload date:
  • Size: 28.3 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/4.0.2 CPython/3.9.5

File hashes

Hashes for cvss_rescore-0.0.2.tar.gz
Algorithm Hash digest
SHA256 f193bb2d48e49854e0743697b417aeb8d44b3724e8e7becb7d707a961a48daf3
MD5 a18c8caf44947bff6fe073b44832a4d2
BLAKE2b-256 4b31589b1351d8129597690ed20a71c615e4b09d372635c3ca75dfa6c6ccb467

See more details on using hashes here.

File details

Details for the file cvss_rescore-0.0.2-py3-none-any.whl.

File metadata

  • Download URL: cvss_rescore-0.0.2-py3-none-any.whl
  • Upload date:
  • Size: 6.0 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/4.0.2 CPython/3.9.5

File hashes

Hashes for cvss_rescore-0.0.2-py3-none-any.whl
Algorithm Hash digest
SHA256 842073574c24beb8003599a555bc6a4d5ae0bff84686ef3c6998b77ae3a7ecf8
MD5 35ccc60190a6ab4ff7253facf6b3dcf9
BLAKE2b-256 ea30374d9aa655de911baa8f6dc19c8a537c5da274fcd369a695367d42c10c22

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page