dependency-track icon indicating copy to clipboard operation
dependency-track copied to clipboard

Option to trigger notifications based on severity of the CVE

Open tapmch opened this issue 1 year ago • 4 comments

Current Behavior

I can configure an alert notification for newly detected vulnerabilities.

Proposed Behavior

Currently, it is possible to configure a notification when a new vulnerability is detected. I would like to be able to trigger an alert notification only when the severity level is critical or high.

Checklist

tapmch avatar May 28 '24 16:05 tapmch

This feature would be incredibly helpful in reducing the number of notifications sent to our security champions. Currently, some teams in our organization manage numerous microservices, and they receive notifications about new vulnerabilities for every severity level. This results in a flood of emails, which can lead to important messages being ignored due to the sheer volume.

By filtering notifications based on severity, we could limit the emails to only high and critical vulnerabilities. This would significantly reduce the number of emails, ensuring that only the most important notifications are sent, making it easier for our security champions to stay focused on critical issues.

farsheedify avatar Oct 27 '24 13:10 farsheedify

We also need this feature. Actually our usecase would be to separate only Critical vulnerabilities and give them e.g. Warning level.

If you have a vision, how it should be configured - I could take this task.

Right now I see it as new setup page (Notifications -> Severity Mapping) which will have such a grid:

Severity Notification level
Critical ERROR
High WARNING
Medium INFORMATIONAL
Low INFORMATIONAL
Unassigned INFORMATIONAL

I'm not sure if it's OK to tag @nscuro , sorry if it's not. But I'm ready to help with this one.

Thanks!

Hunroll avatar Mar 28 '25 12:03 Hunroll

PR's posted @nscuro

emyhrberg avatar Apr 25 '25 12:04 emyhrberg

Im currently facing the same issue, and i was wondering if there is still someone working on getting this released?

jamie-teqplay avatar Nov 25 '25 10:11 jamie-teqplay