a year ago
Look at the improvement in this ARM policy!
We are pleased to announce the enhancement of the agent when executing the policy: "DevSecOps: Minimum CVSS 3.1 score of vulnerable spots for the agent to break the build in Strict Mode" where passing the CLI value as an argument in --breaking will take into account the minimum severity value for breaking the build.
Thanks to this improvement, you can be sure that any value you stipulate will not be higher than the policy; it will be equal to or lower than it, so the agent breaks the build according to the metrics specified in your organization or group, avoiding vulnerabilities with a higher CVSS score from passing the check.