fleetdm / fleet

Open-source platform for IT, security, and infrastructure teams. (Linux, macOS, Chrome, Windows, cloud, data center)
https://fleetdm.com
Other
2.92k stars 406 forks source link

Add ability to dismiss/mark (ignore) a detected vulnerability #3152

Open noahtalerman opened 2 years ago

noahtalerman commented 2 years ago

This issue's remaining effort can be completed in ≤1 sprint. It will be valuable even if nothing else ships.

It is planned and ready to implement. It is on the proper kanban board.

Goal

User story
As a vulnerability management engineer,
I want to exclude specific vulns
so that I can cater vuln reporting for leadership.

Changes

Product

Engineering

ℹ️  Please read this issue carefully and understand it. Pay special attention to UI wireframes, especially "dev notes".

Context

QA

Risk assessment

Manual testing steps

  1. Step 1
  2. Step 2
  3. Step 3

Testing notes

Confirmation

  1. [ ] Engineer (@____): Added comment to user story confirming succesful completion of QA.
  2. [ ] QA (@____): Added comment to user story confirming succesful completion of QA.
lucasmrod commented 2 years ago

Community discussion: https://osquery.slack.com/archives/C01DXJL16D8/p1647772823147719

noahtalerman commented 11 months ago

Noah: Is this about dismissing false positives (incorrect vulns) or about dismissing correct vulns they don't care about?

Kathy: The latter

Noah: Does the customer use the vuln dashboard or Fleet product for vulns?

Noah: How does this stack up against the customer's other request in terms of priority? #14500

Noah: WONT.

noahtalerman commented 11 months ago

@Patagonia121 this wasn't prioritized. Please bring it back to FF if you think we should reconsider.

noahtalerman commented 10 months ago

Noah and Mike: Start w/ an air guitar for this one. Let’s do it next sprint

noahtalerman commented 10 months ago

Feature fest: Related to vuln dashboard in Fleet. Let's weight this against other vuln features for air guitars.

noahtalerman commented 10 months ago

Hey @zayhanlon and @Patagonia121 heads up, we pulled this into the upcoming design sprint as an air guitar.

Patagonia121 commented 9 months ago

Customer-stazzema also asked us today for the ability to tag CVEs or applications in the UI - they want to tag the following things:

  1. false positive apps
  2. false positive CVE
  3. add to exception with an explanation

If they take Acrobat uninstaller, chrome helper, teams helper, umbrella menu app - those apps were incorrectly identified as being vulnerable

rachaelshaw commented 9 months ago

@zayhanlon this didn't make it into the current sprint, bringing back to Feature Fest.

noahtalerman commented 9 months ago

@noahtalerman check recordings w/ the customer.

noahtalerman commented 8 months ago

Hey @zayhanlon, heads up, this didn't make the 3 week drafting timeline so we're removing it from the drafting board. Bringing back to feature fest.

noahtalerman commented 6 months ago

@Patagonia121 heads up, we didn't get to this air guitar in the current sprint.

Please feel free to bring this back to feature fest.

nonpunctual commented 2 months ago
Screenshot 2024-07-08 at 10 52 41 AM