Skip to content

Comments

fix: Add support to parse CVSSV4 findings for the Trivy parser#14379

Open
coheigea wants to merge 1 commit intoDefectDojo:devfrom
coheigea:coheigea/trivy-support-cvssv4
Open

fix: Add support to parse CVSSV4 findings for the Trivy parser#14379
coheigea wants to merge 1 commit intoDefectDojo:devfrom
coheigea:coheigea/trivy-support-cvssv4

Conversation

@coheigea
Copy link
Contributor

Description

The Trivy parser currently only parses CVSSV3 scores, but this is problematic as ghas is using CVSSv4 scores for recent findings and DefectDojo doesn't report the score in this case.

Test results

Added a unit test with a CVSSv4 finding

@coheigea coheigea force-pushed the coheigea/trivy-support-cvssv4 branch from 7bc19fc to bdac8f7 Compare February 24, 2026 11:16
@valentijnscholten valentijnscholten added this to the 2.56.0 milestone Feb 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants