Tune CVE triage deadlines
- Dominant language
- Java
- Stars
- 8
- Forks
- 13
- Avg merge
- 1h 19m
- Merged PRs (30d)
- 1
Description
### Description
**Problem:** Private Triage Overdue goes red at 1, and the deadlines are tight — 2 business days for severity/important. That's a short window for triage, especially across time zones or during holidays. Combined with the red-at-1 threshold, a single issue arriving on a Thursday afternoon can show the team as red by Tuesday morning.
**Proposal:** Follow the same approach we used for bugs: start with more generous deadlines and gradually tighten them as the triage process matures.
### Value Proposition
Deadlines that match the team's current capacity keep the dashboard useful as a health indicator rather than something that's always red.
### Goals
- Start with longer CVE triage deadlines and reduce gradually over time
- Account for cross-timezone collaboration and holidays
### Discussion
_No response_
### Motivation
_No response_
### Details
_No response_
Contributor guide
No contributing guide indexed for this repository
Research direction
No files, tests, or entry points are named. First locate the configuration and dashboard logic that sets CVE triage deadlines and the red-at-1 threshold, then review how bug deadlines are defined. Done means implementing a gradual deadline policy that accounts for business days, time zones, and holidays, with coverage for the stated Thursday-to-Tuesday case.
Written by the indexing model from the issue text.
Assessment
- Domain
- security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100