Files
git.stella-ops.org/docs/modules/scanner/fixtures/adapters/mapping-cvss4-to-cvss3.csv
StellaOps Bot e1262eb916 Add receipt input JSON and SHA256 hash for CVSS policy scoring tests
- Introduced a new JSON fixture `receipt-input.json` containing base, environmental, and threat metrics for CVSS scoring.
- Added corresponding SHA256 hash file `receipt-input.sha256` to ensure integrity of the JSON fixture.
2025-12-04 07:30:42 +02:00

866 B

1source_fieldtarget_fieldrulenotes
2AVAVNetwork->N, Adjacent->A, Local->L, Physical->PPreserve mapping; CVSS 4 AT handled separately
3ACACLow->L, High->H
4PRPRNone->N, Low->L, High->H
5UIUINone->N, Passive->P, Active->ACVSS3 has R (Required) approximate with A
6VCCHigh->H, Low->L, None->NImpact mapping: VC→Confidentiality
7VIIHigh->H, Low->L, None->N
8VAAHigh->H, Low->L, None->N
9SCSHigh->C, Low->C, None->UScoped impact collapses to Scope Changed/Unchanged; default Changed when SC>None
10SISHigh->C, Low->C, None->USame as SC
11SASHigh->C, Low->C, None->USame as SC
12ATN/AdropAttack requirements not represented in CVSS3
13ThreatTemporalmap to E: NotDefinedThreat metrics not supported; set Temporal NotDefined