Skip to content

Add CVE compensating control verification gates#1630

Open
malb200710-dev wants to merge 1 commit into
UnitOneAI:mainfrom
malb200710-dev:codex/cve-compensating-control-1629
Open

Add CVE compensating control verification gates#1630
malb200710-dev wants to merge 1 commit into
UnitOneAI:mainfrom
malb200710-dev:codex/cve-compensating-control-1629

Conversation

@malb200710-dev
Copy link
Copy Markdown

Summary

  • Adds a compensating-control verification step to CVE triage before SLA de-escalation.
  • Requires exploit-path mapping, runtime scope, effectiveness evidence, bypass review, owner/expiry, and explicit SLA impact.
  • Adds output fields and prompt-injection safety guidance to avoid lowering remediation urgency from unverified mitigation claims.
  • Links implementation to review issue [REVIEW] cve-triage: require compensating-control exploit-path evidence #1629.

Validation

  • Confirmed markdown code fences are balanced.
  • Confirmed the edited file remains ASCII.
  • Checked the new version, Step 7, exploit-path fields, de-escalation rule, and output fields are present.

Bounty request: Improver Moderate ($100) if accepted. I can provide payment details if accepted.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant