Remove hardcoded "Medium" confidence for Container Scanning vulnerabilities

Problem to solve

We're currently setting the confidence on all container scanning vulnerabilities to Medium. We're not sure of the origin of this decision and it may give users an inaccurate idea of the severity's confidence.

Intended users

Persona: Security Analyst

Proposal

Let's answer 2 questions:

  1. Can we dynamically create more accurate confidence for each vulnerability?
  2. If not, should we instead set the confidence to Unknown?

What is the type of buyer?

GitLab Ultimate

Edited Aug 28, 2019 by Olivier Gonzalez
Assignee Loading
Time tracking Loading