in-toto / attestation

in-toto Attestation Framework
Other
233 stars 59 forks source link

Conflict in Vulnerabilities predicate definition #342

Open sherzberg-1 opened 6 months ago

sherzberg-1 commented 6 months ago

scanner.result.[*].vulnerability.severity, required object

says that the severity value should be an object, but then the description says

The severity contains a list to describe the severity of a vulnerability using one or more quantitative scoring method.

And the example has

"severity": [