github / github/codeql

CVSS Score using CSV Output Format

Open
#13,650 2 comments 0 reactions 0 assignees View on GitHub
question
Dominant language
CodeQL
Stars
10.1k
Forks
2.1k
Avg merge
2d 15h
Merged PRs (30d)
141

Description

Is there a way to have the CVSS score be included in the information that's output when the "database analyze" command is run? I know there SARIF format includes the CVSS score under the "security-severity" attribute, but the CSV output is more useful for my current purposes, and the CVSS score is valuable information that I would like to have included in that format.

If anyone could help me out, I'd appreciate it a lot.

Contributor guide

Open the contributing guide

Research direction

Start by locating the implementation and tests for the `database analyze` command's CSV output, then compare how SARIF exposes the `security-severity` attribute. The work is complete when the CSV output includes the CVSS score in a documented, tested column.

Written by the indexing model from the issue text.

Assessment

Domain
cli, security
Issue type
Feature
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.