ossf / secure-sw-dev-fundamentals

Secure Software Development Fundamentals courses (from the OpenSSF Best Practices WG)
Creative Commons Attribution 4.0 International
176 stars 47 forks source link

Including EPSS in addition to CVSS? #161

Open nmav opened 1 month ago

nmav commented 1 month ago

As mentioned in the training material CVSS has some issues, and in practice it results to a large list of vulnerabilities that need to be addressed even though if it doesn't overlap with the vulnerabilities list that are being exploited or are exploitable. There is the EPSS model from first.org that focuses on that problem. That is on making the list of vulnerabilities to be addressed smaller - i.e., more actionable. What are your thoughts in including this information in addition to CVSS?