Skip to content

Severity Differences #1

@CanardMandarin

Description

@CanardMandarin

How should we handle severity differences between audit firms?

For example Ackee Blockchain (in the marinade audit) reported the usage of Anchor as a high severity vulnerability.
This kind of vulnerability could potentially bump the Dependencies class higher in the classification.

In the future, it may become necessary to standardize the severity of vulnerabilities.
How should we do that?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions