Skip to content

Add tutorial for rating findings in context - #274

Open
fahedouch wants to merge 2 commits into
DependencyTrack:mainfrom
fahedouch:tutorial-owasp-rating-from-vex
Open

fahedouch wants to merge 2 commits into
DependencyTrack:mainfrom
fahedouch:tutorial-owasp-rating-from-vex

Conversation

@fahedouch

@fahedouch fahedouch commented Sep 23, 2026

Copy link
Copy Markdown

Shows how an OWASP risk rating travels from a VEX to the finding it lands on: same component, two projects, two ratings. Every VEX example in the docs today carries an analysis decision, so nothing shows a ratings entry standing on its own.

Ran it end to end against a 5.1.1 quickstart stack before pushing. Also lists vens under community integrations, which is where the tutorial's "What's next" sends readers looking for tools that write these documents.

@fahedouch
fahedouch force-pushed the tutorial-owasp-rating-from-vex branch 2 times, most recently from b0a497b to 8197f73 Compare September 23, 2026 10:29
@fahedouch fahedouch changed the title Add tutorial for scoring findings in context Add tutorial for rating findings in context Sep 23, 2026
Signed-off-by: Fahed Dorgaa <fahed.dorgaa@gmail.com>
@fahedouch
fahedouch force-pushed the tutorial-owasp-rating-from-vex branch from 8197f73 to 87c3b1b Compare September 23, 2026 10:32
@fahedouch
fahedouch marked this pull request as ready for review September 23, 2026 10:43
Signed-off-by: Fahed Dorgaa <fahed.dorgaa@gmail.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant