Vulnerability Triage

Parse, normalize, group, and prioritize security findings from GitLab vulnerability reports (JSON), and produce evidence-backed dispositions (fix vs. justified false positive). Triggers on phrases like: vulnerability report, gl-dependency-scanning-report.json, gl-sast-report.json, GitLab security report, CVE, CVSS, EPSS, KEV, triage findings, group vulnerabilities, deduplicate findings, false positive, is this exploitable, reachability, severity, prioritize remediation. Use whenever a GitLab (or GitLab-schema) security report is being analyzed, even if the user just pastes a JSON report or asks 'which of these do we actually need to fix?'

aws-samples 999208f 5 files · 28.5 KB Updated

File contents

aws-samples/sample-ramp-aidlc-mod-starter-packs/tree/main/vulnerability-remediation-pipeline/skills/vulnerability-triage commit 999208f363

Frequently asked questions

npx skillmds@latest add aws-samples/vulnerability-triage