Skip to content

Filter software by severity (CVSS v3) and known exploit (CISA) #19099

@nonpunctual

Description

@nonpunctual

Goal

User story
As a security engineer in the Software > Software Titles/Versions tables,
I want to filter software by vulnerability severity (CVSS v3) and known exploit (CISA)
so that I can decide which software to prioritize patching.

Context

Changes

Product

  • UI changes: Figma
  • REST API changes: API design PR is here.
  • Outdated documentation changes: Update REST API docs
  • Changes to paid features or tiers: New filters are available in Fleet Premium

Engineering

  • Database schema migrations: TODO
  • Load testing: TODO

ℹ️  Please read this issue carefully and understand it. Pay special attention to UI wireframes, especially "dev notes".

QA

Risk assessment

  • Requires load testing: TODO
  • Risk level: Low / High TODO
  • Risk description: TODO

Manual testing steps

  1. Step 1
  2. Step 2
  3. Step 3

Testing notes

Confirmation

  1. Engineer (@____): Added comment to user story confirming successful completion of QA.
  2. QA (@____): Added comment to user story confirming successful completion of QA.

Metadata

Metadata

Labels

#g-endpoint-opsEndpoint ops product group:productProduct Design department (shows up on 🦢 Drafting board)P2Urgent: Supported workflow not functioning as intended, newly drafted feature with urgent Fleet needcustomer-faltonacustomer-firenzecustomer-flaviacustomer-honoriacustomer-rialtostoryA user story defining an entire feature~csaIssue was created by or deemed important by the Customer Solutions Architect.~vulnerability-management

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions