Skip to content

Improve patch exception revalidation gates#1438

Open
danyili2632 wants to merge 1 commit into
UnitOneAI:mainfrom
danyili2632:improve/patch-deferred-revalidation-gates
Open

Improve patch exception revalidation gates#1438
danyili2632 wants to merge 1 commit into
UnitOneAI:mainfrom
danyili2632:improve/patch-deferred-revalidation-gates

Conversation

@danyili2632

Copy link
Copy Markdown

Summary

  • adds trigger-based revalidation gates for deferred vulnerability exceptions
  • covers vendor patch/advisory availability, CISA KEV, EPSS movement, public/active exploitation, exposure/criticality changes, scanner evidence changes, and compensating control drift
  • adds required report output fields for last/next revalidation, triggers checked, SSVC/SLA change, control retest, and resulting action
  • adds a common pitfall warning against waiting for fixed review dates after conditions change

Validation

  • git diff --check
  • rg -n "Deferred Vulnerability Revalidation|Vendor patch|CISA KEV|EPSS|public exploit|Asset exposure|Compensating control retest|Last revalidation|Next revalidation|fixed review date" skills/vuln-management/patch-prioritization/SKILL.md
  • verified Markdown fence count remains even: 12

Closes #1401

Bounty target: Improver Moderate if accepted.
Preferred payout: Base USDC 0x6CBF4b5cb88b8C2B7af776Bc2B073163B5d3C08A

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[REVIEW] patch-prioritization: add deferred vulnerability revalidation gates

1 participant