
3/12/2025 · Fernando Diaz
What this post added
This post introduces the integration of CVSS, KEV, and EPSS frameworks into GitLab's vulnerability management capabilities. It details how these frameworks can be combined to effectively prioritize security risks across dependency and container image vulnerabilities. The post explains each framework's purpose and how to leverage them within GitLab's UI, including adding security scanners to pipelines, viewing vulnerability insights, and changing vulnerability statuses. It also highlights the use of GitLab Duo's AI capabilities for vulnerability explanation and auto-resolution.