Replies: 3 comments 2 replies
-
What does a "fix" mean specifically? A vendor patch? A code release? Where is it obtained? I may be in support of this but I think the field needs to be more clearly defined and understand how it would be used. Telling someone there is a fix without explaining what it is, just opens questions... |
Beta Was this translation helpful? Give feedback.
-
So if remediation already covers this case then why is this field needed? Just check if a remediation exists or not? |
Beta Was this translation helpful? Give feedback.
-
What I mean is the modeling of the field should be to create a remediation object (which may be mostly all empty, but that's a whole other thing) Adding another field that just says "remediation exists" when we already have an object for that doesn't make sense |
Beta Was this translation helpful? Give feedback.
-
Currently
vulnerability
object does not have a field in place to account for information indicating if a fix for the vulnerability is available or not. Such information is provided by log sources such AWS Inspector.I propose we add a boolean field named
fix_available
in this object.8 votes ·
Beta Was this translation helpful? Give feedback.
All reactions