Skip to content

cravex2-reachability: Collect available SSVC in VulnerableCode/cravex2-reachability #1963

Description

@pombredanne

Code to collect and store SSVC decision trees in VulnerableCode.

We have some elements of the scoring system already in place, in particular for vulnrichhment, the goal is to systematically store the data as trees to support context-aware decision down the road in DejaCode.

We need further design.

References:

Activity

  1. moved this from Needs prep to In prep in 00-AboutCodePlanneron Aug 6, 2025
  2. TG1999 commented on Aug 8, 2025

    @TG1999
    Contributor

    The design is overall like this:

    class SSVC:
       vector
       options
       advisory
       decision
    

    In dejacode, we get a package, and it's vulnerable to a known advisory ID, we can send the SSVC's options and decision to the user, and give the reference to SSVC calculator to show how we came up to the decision.

  3. moved this from In prep to Todo ready in 00-AboutCodePlanneron Aug 12, 2025
  4. moved this from Todo ready to In progress in 00-AboutCodePlanneron Oct 3, 2025
  5. TG1999 commented on Dec 9, 2025

    @TG1999
    Contributor

    Here is a design refinement:

    Problem:

    How shall we store and relate SSVC scores and trees to advisories

    Explanation:

    We have a vulnrichment importer that today imports SSVC as scores in severity and do not store decision and tree with it, only stores the vector.

    What we thought initially was to store SSVC in a separate table and relate it to advisories that share the alias/advisory ID, but the issue is that those SSVC does not come from those advisories with which we are trying to relate those SSVCs, so it would be wrong to show those SSVCs. So what shall we do?

    Probable Solutions:

    • Store SSVC in the separate table with the original CVE that's coming from the importer, and do not relate it to any advisory

    • In UI show some tooltip stating that the SSVC does not come from the advisory source it's coming from this URL and it's just a computed relation. In API document that and also show the original SSVC source data URL

  6. TG1999 commented on Dec 15, 2025

    @TG1999
    Contributor

    Support for SSVC in VulnerableCode is completed.

    The main tracking PR is:

    The SSVCs are stored in this model:

    Image
    • We return the SSVC as vector and tree data in the API:
    Image
  7. moved this from Done to Validated in 00-AboutCodePlanneron Dec 30, 2025
  8. changed the title [-]cravex2-reachability: Collect available SSVC in VulnerableCode[/-] [+]cravex2-reachability: Create code to collect and store SSVC decision trees in VulnerableCode[/+] on Sep 23, 2026
  9. changed the title [-]cravex2-reachability: Create code to collect and store SSVC decision trees in VulnerableCode[/-] [+]cravex2-reachability: Collect available SSVC in VulnerableCode/cravex2-reachability[/+] on Sep 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions