
5/13/2026 · Grant Hickman
What this post added
Introduced vulnerability management policies that allow for automated severity overrides based on defined rules (CVE ID, CWE ID, file path, directory). Supports 'Set Severity', 'Increase Severity', and 'Decrease Severity' operations. Provides use cases for downgrading low-risk CVEs in internal services, upgrading injection vulnerabilities in production code, normalizing severity across scanners, aligning severity with exploitation intelligence, and applying org-wide risk models at the group level. Details on policy creation, validation, and quick reference for parameters are included.