Add severity override audit events

Overview

To keep security teams and administrators informed, and ensure they have visibility into the behavior of our vulnerability severity, create a new audit event. This event should be triggered when overriding vulnerability (or security finding) severity.

Requirements

  • The audit event should be a project-level audit.
  • Audit event message should include:
    • "Vulnerability severity was changed from X to Y"
  • Audit event should include the vulnerability URL as its target.
Edited by Gal Katz