Use the latest CVSS version in SCA rules
If your organization has activated the Unified Policy feature, which replaces agent rules, all agent-based scans use Common Vulnerability Scoring System (CVSS) version 3 to evaluate your vulnerabilities.
You can use CVSS version 3 in your agent-based scanning rules to evaluate your vulnerabilities against the latest version of the standard.
Before you begin:
You must have the Security Lead, Workspace Administrator, or Workspace Editor role to edit the CVSS version for a workspace rule. You must have the Security Lead role to edit the CVSS version for an organization rule.
To complete this task:
-
In the Veracode Platform, select Scans & Analysis > Software Composition Analysis.
-
Click the Agent-Based Scan tab.
-
Select a workspace.
-
Click the Custom Rules tab.
-
Click Edit.
-
Choose a rule control you want to modify or click Add control to create a new control.
-
For Level, choose if you want violations of this control to result in an error or a warning.
noteErrors result in a build failure. Warnings result in log entries to the continuous integration systems, but they do not cause a build failure.
-
Expand the control row to display all condition options.
-
From the Severity dropdown menu, select the CVSS score you want to use for this control.
-
If you want to generate issues based on the CVSS severity, select the Create Issue checkbox.
-
Click Save.