Skip to content

fix: Use unscored severity only in absence of any CVSS baseScore and add CVSSv4 score evaluation#448

Merged
jeremylong merged 1 commit intodependency-check:mainfrom
aikebah:fix/unscoredFailureScoring
Mar 16, 2025
Merged

fix: Use unscored severity only in absence of any CVSS baseScore and add CVSSv4 score evaluation#448
jeremylong merged 1 commit intodependency-check:mainfrom
aikebah:fix/unscoredFailureScoring

Conversation

@aikebah
Copy link
Copy Markdown
Collaborator

@aikebah aikebah commented Mar 15, 2025

Counterpart for gradle-plugin of dependency-check/DependencyCheck#7530

Fixes dependency-check/DependencyCheck#7528 in the gradle plugin and adds the still missing CVSSv4 score to the failure threshold evaluations

…add CVSSv4 score evaluation

Counterpart for gradle-plugin of
dependency-check/DependencyCheck#7530

Fixes dependency-check/DependencyCheck#7528 in the gradle plugin
and adds the still missing CVSSv4 score to the threshold evaluations
Copy link
Copy Markdown
Contributor

@jeremylong jeremylong left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@jeremylong jeremylong merged commit 59c64ce into dependency-check:main Mar 16, 2025
2 checks passed
@aikebah aikebah deleted the fix/unscoredFailureScoring branch March 29, 2025 13:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Build fails at CVSS 9.8 even when failOnCVSS is set to 10.0 for cve-2021-23369

2 participants