CVSS Score using CSV Output Format
- Dominant language
- CodeQL
- Stars
- 10.1k
- Forks
- 2.1k
- Avg merge
- 2d 15h
- Merged PRs (30d)
- 141
Description
Is there a way to have the CVSS score be included in the information that's output when the "database analyze" command is run? I know there SARIF format includes the CVSS score under the "security-severity" attribute, but the CSV output is more useful for my current purposes, and the CVSS score is valuable information that I would like to have included in that format.
If anyone could help me out, I'd appreciate it a lot.
Contributor guide
Research direction
Start by locating the implementation and tests for the `database analyze` command's CSV output, then compare how SARIF exposes the `security-severity` attribute. The work is complete when the CSV output includes the CVSS score in a documented, tested column.
Written by the indexing model from the issue text.
Assessment
- Domain
- cli, security
- Issue type
- Feature
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100