devops folders consolidate
This commit is contained in:
@@ -81,6 +81,26 @@ Expect all logs at `Information`. Ensure OTEL exporters include the scope `Stell
|
||||
|
||||
## 5. Conflict Classification Matrix
|
||||
|
||||
### 5.1 Linkset Conflicts (v2 Correlation)
|
||||
|
||||
Linkset conflicts now carry typed severities that affect confidence scoring:
|
||||
|
||||
| Severity | Penalty | Conflicts | Triage Priority |
|
||||
|----------|---------|-----------|-----------------|
|
||||
| **Hard** | -0.30 to -0.40 | `distinct-cves`, `disjoint-version-ranges` | High - investigate immediately |
|
||||
| **Soft** | -0.05 to -0.10 | `affected-range-divergence`, `severity-mismatch`, `alias-inconsistency` | Medium - review in batch |
|
||||
| **Info** | 0.00 | `metadata-gap`, `reference-clash` (disjoint only) | Low - informational |
|
||||
|
||||
| Conflict Reason | Severity | Likely Cause | Immediate Action |
|
||||
|-----------------|----------|--------------|------------------|
|
||||
| `distinct-cves` | Hard | Two different CVE-* IDs in same linkset cluster | Investigate alias mappings; likely compound advisory or incorrect aliasing |
|
||||
| `disjoint-version-ranges` | Hard | Same package, no version overlap between sources | Check if distro backport; verify connector range parsing |
|
||||
| `affected-range-divergence` | Soft | Ranges overlap but differ | Often benign (distro vs upstream versioning); monitor trends |
|
||||
| `severity-mismatch` | Soft | CVSS scores differ by > 1.0 | Normal for cross-source; freshest source typically wins |
|
||||
| `alias-inconsistency` | Soft | Disconnected alias graph (no shared CVE) | Review alias extraction; may indicate unrelated advisories grouped |
|
||||
|
||||
### 5.2 Merge Conflicts (Legacy)
|
||||
|
||||
| Signal | Likely Cause | Immediate Action |
|
||||
|--------|--------------|------------------|
|
||||
| `reason="mismatch"` with `type="severity"` | Upstream feeds disagree on CVSS vector/severity. | Verify which feed is freshest; if correctness is known, adjust connector mapping or precedence override. |
|
||||
|
||||
Reference in New Issue
Block a user