Change the scoring method to be based on vendor (first priority) and NVD (second). #310
Labels
kind/deprecation
Categorizes issue or PR as related to a feature/enhancement marked for deprecation.
Currently Trivy uses the NVD score.
There are cases where vendor (e.g. Redhat) says that vulnerability is medium, while NVD says it is critical.
We should prefer Vendor's verdict as our primary source of truth.
The text was updated successfully, but these errors were encountered: