Skip to content

Commit e32cd40

Browse files
authored
Add 'Severity changes' heading to security findings page (#2687)
* Add 'Severity changes' heading to security findings page * Add explicit id to 'Severity changes' heading for direct linking --------- Co-authored-by: mark-rln <mark-rln@users.noreply.github.com>
1 parent 04eed54 commit e32cd40

1 file changed

Lines changed: 2 additions & 0 deletions

File tree

docs/organizations/managing-security-and-risk.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -103,6 +103,8 @@ For findings on transitive dependencies, the finding also displays the **depende
103103

104104
![Security and risk management finding dependency chain](images/security-risk-management-finding-dependency-chain.png)
105105

106+
### Severity changes {: id="severity-changes"}
107+
106108
The same Common Vulnerability and Exposure can be classified with different severities in different sources, like cve.org or NVD, and Trivy uses these and other sources to update their database. As such, there may be situations where the severity attributed to a Finding by Trivy is not in line with a specific source. Subsequent analysis can then close a Finding and re-open it with a different severity, if a Trivy database update occurs.
107109

108110
## Sharing a filtered view of findings {: id="sharing-filtered-view"}

0 commit comments

Comments
 (0)