dependency-check / azuredevops

Dependency Check Azure DevOps Extension
Apache License 2.0
44 stars 26 forks source link

separate warning threshold or CVSS score output #139

Open cyberblast opened 7 months ago

cyberblast commented 7 months ago

Hi, I would like to suggest adding a separate warning threshold. I know there's warnOnCVSSViolation parameter, but unfortunately it's implemented as boolean only.

The idea is to be able to have different task result based on CVSS score.

e.g. 0-4 => ok 4-6 => warning 6-10 => fail

Alternatively, would it be possible to declare CVSS score as output variable? This way we could easily evaluate the score and break the pipe in a sebsequent task ourself...