fleetdm / fleet

Open-source platform for IT, security, and infrastructure teams. (Linux, macOS, Chrome, Windows, cloud, data center)
https://fleetdm.com
Other
3.16k stars 433 forks source link

Add ability to dismiss/mark (ignore) a detected vulnerability #3152

Closed noahtalerman closed 1 month ago

noahtalerman commented 3 years ago

UPDATE: Closed as a duplicate of #22761


This issue's remaining effort can be completed in ≤1 sprint. It will be valuable even if nothing else ships.

It is planned and ready to implement. It is on the proper kanban board.

Goal

User story
As a vulnerability management engineer,
I want to exclude specific vulns
so that I can cater vuln reporting for leadership.

Changes

Product

Engineering

ℹ️  Please read this issue carefully and understand it. Pay special attention to UI wireframes, especially "dev notes".

Context

QA

Risk assessment

Manual testing steps

  1. Step 1
  2. Step 2
  3. Step 3

Testing notes

Confirmation

  1. [ ] Engineer (@____): Added comment to user story confirming succesful completion of QA.
  2. [ ] QA (@____): Added comment to user story confirming succesful completion of QA.
lucasmrod commented 2 years ago

Community discussion: https://osquery.slack.com/archives/C01DXJL16D8/p1647772823147719

noahtalerman commented 1 year ago

Noah: Is this about dismissing false positives (incorrect vulns) or about dismissing correct vulns they don't care about?

Kathy: The latter

Noah: Does the customer use the vuln dashboard or Fleet product for vulns?

Noah: How does this stack up against the customer's other request in terms of priority? #14500

Noah: WONT.

noahtalerman commented 1 year ago

@Patagonia121 this wasn't prioritized. Please bring it back to FF if you think we should reconsider.

noahtalerman commented 1 year ago

Noah and Mike: Start w/ an air guitar for this one. Let’s do it next sprint

noahtalerman commented 1 year ago

Feature fest: Related to vuln dashboard in Fleet. Let's weight this against other vuln features for air guitars.

noahtalerman commented 1 year ago

Hey @zayhanlon and @Patagonia121 heads up, we pulled this into the upcoming design sprint as an air guitar.

Patagonia121 commented 1 year ago

Customer-stazzema also asked us today for the ability to tag CVEs or applications in the UI - they want to tag the following things:

  1. false positive apps
  2. false positive CVE
  3. add to exception with an explanation

If they take Acrobat uninstaller, chrome helper, teams helper, umbrella menu app - those apps were incorrectly identified as being vulnerable

rachaelshaw commented 1 year ago

@zayhanlon this didn't make it into the current sprint, bringing back to Feature Fest.

noahtalerman commented 12 months ago

@noahtalerman check recordings w/ the customer.

noahtalerman commented 11 months ago

Hey @zayhanlon, heads up, this didn't make the 3 week drafting timeline so we're removing it from the drafting board. Bringing back to feature fest.

noahtalerman commented 8 months ago

@Patagonia121 heads up, we didn't get to this air guitar in the current sprint.

Please feel free to bring this back to feature fest.

nonpunctual commented 4 months ago
Screenshot 2024-07-08 at 10 52 41 AM
JoStableford commented 2 months ago

Related to a Slack conversation

pintomi1989 commented 1 month ago

Hey @noahtalerman,

Here is the Gong clip for customer-stazzema: https://us-65885.app.gong.io/call?id=906807851651077667&highlights=%5B%7B%22type%22%3A%22SHARE%22%2C%22from%22%3A314%2C%22to%22%3A350%7D%5D

fleet-release commented 1 month ago

Marked vulnerabilities fade, In the cloud city's soft light, A clearer vision made.