What is the overall severity distribution, including human code?
Based on the churn I have fixing security vulnerabilities reported by Snyk and Trivy, I have a feeling that issues have a tendency to be labeled mostly as HIGH or CRITICAL when they are assigned a CVE, for better or worse.
TrinaryWorksToo · 27m ago
How do we know this isn't Survivorship Bias? Perhaps there aren't any low-severity bugs because they're all high severity?
weare138 · 1h ago
This is an ongoing longitudinal study with inherent reporting biases and coverage limitations.
Based on the churn I have fixing security vulnerabilities reported by Snyk and Trivy, I have a feeling that issues have a tendency to be labeled mostly as HIGH or CRITICAL when they are assigned a CVE, for better or worse.
Well at least they're honest...