LogoLogo
  • Welcome
  • Getting Started
    • Getting Started with a Free Codefortify Account
    • Setting Up Gitleaks for Secret Detection
    • Setting Up a Project
    • Configuring Custom Severity Scores in Codefortify
    • Enable the GitHub Dependency Graph for SBOM Insights
    • Generating an SBOM
    • Reviewing and Resolving a Vulnerability
    • Activating a New Scanner
    • Setting Up Two Factor Authentication
    • Adding a New User to Your Team
    • Authenticate to Your GitHub Account
    • Upgrading Your Plan
Powered by GitBook
On this page
Edit on GitHub
  1. Getting Started

Configuring Custom Severity Scores in Codefortify

This guide will help you configure custom severity scores and prioritize vulnerabilities within your projects, enabling your team to focus on the most critical issues for effective security management

PreviousSetting Up a ProjectNextEnable the GitHub Dependency Graph for SBOM Insights

Last updated 6 months ago

To help you prioritize vulnerabilities based on your project's unique needs, Codefortify allows you to set custom severity scores and adjust vulnerability categories. Follow these steps to configure your settings:

Steps to Set Custom Severity Scores

  1. Navigate to the Projects Tab Begin by selecting the Projects tab in the main navigation.

  1. Open a Specific Project Select the project for which you want to configure custom severity scores.

  2. Access Project Settings Click the Settings button to open the configuration options.

  1. Set Custom Severity Scores In the Custom Severity Scores section, specify your preferred score values for each severity level.

    • Recommended Starting Scores:

      • Low: 50

      • Medium: 100

      • High: 200

      • Critical: 300

  1. Adjust Vulnerability Categories In the Vulnerability Categories section, you can set focus areas for:

    • Category

    • Language

    • Technology

    Use the range selector to increase or decrease the importance of each category based on your project needs.

  1. Save Changes Once you’ve set your custom scores and categories, click Save Changes to apply.

What to Expect

Once you save your custom scores and category settings All new and existing vulnerabilities will be evaluated and updated with scores based on your configured rules, helping your team visually prioritize the most critical issues.

To view the specific metadata used in scoring each vulnerability, navigate to the specific vulnerability within your project. This metadata provides detailed insights into how each vulnerability aligns with your custom severity scores and categories.

This customized scoring will help you and your team visually prioritize the vulnerabilities that matter most, ensuring that resources are focused on the most critical issues.