Repository navigation
Add explainable multicloud vulnerability scoring - #1
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2fb37b8cf2
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| if any(word in normalized for word in ("known", "wide", "confirmed")): | ||
| return "known_exploited" |
There was a problem hiding this comment.
Match negative exploitability values before "known"
For GCP findings whose CVE reports NO_KNOWN_EXPLOITATION, or normalized findings that explicitly use unknown, this substring check matches known and classifies them as known_exploited. score_finding consequently adds 20 risk points and can materially inflate both finding and environment scores; recognize negative/unknown tokens before positive aliases or use exact enum matching.
Useful? React with 👍 / 👎.
| category=str( | ||
| metadata.get("displayName") or properties.get("displayName", "unknown") | ||
| ), |
There was a problem hiding this comment.
Omit the raw Azure assessment title from reports
When an Azure assessment supplies metadata.displayName, this copies the provider's raw human-readable title into Finding.category, which build_report writes verbatim. Reports produced with --output therefore retain raw titles—including potentially sensitive custom assessment text—despite the documented privacy guarantee that original titles are omitted; derive a non-sensitive category or omit/pseudonymize this value.
Useful? React with 👍 / 👎.
Objetivo
Transformar o repositório em um MVP demonstrável de auditoria de vulnerabilidades multicloud, alinhado ao perfil de Auditoria de TI, Cyber GRC e Cloud.
Entregas
Limites declarados
O projeto não solicita credenciais, não acessa contas cloud, não executa remediações e não afirma conformidade. O score é próprio e não substitui os scores oficiais dos provedores ou uma avaliação humana.
Validação local