Replies: 3 comments
-
Some incomplete ideas capturing notes from conversation on 2021-02-24:
|
Beta Was this translation helpful? Give feedback.
-
Converting to discussion. Note also that #78 referenced above has also been converted to discussion #227 |
Beta Was this translation helpful? Give feedback.
-
One thing that might be plausible is for deployer stakeholders, who are at least some times prioritizing patches (which patch multiple CVE IDs) rather than individual vuls, that the analyst might scope what is chainable to or from each other as all the vuls that are addressed in the patch being considered. That helps keep the problem from exploding, but still might be practically useful. |
Beta Was this translation helpful? Give feedback.
-
@cgyarbrough :
This would be a good topic to address when we address #78 (after v2 is set)
Beta Was this translation helpful? Give feedback.
All reactions