Skip to content

Commit 4194ce5

Browse files
authored
Merge pull request #94221 from agantony/ROX29347-rhacs-docs-main
[RHACS] [Docs] ROX-29347: Adding docs to report CVE and RHSA data
2 parents 155e224 + a17e481 commit 4194ce5

6 files changed

+131
-4
lines changed

modules/scan-inactive-images.adoc

Lines changed: 30 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -15,6 +15,36 @@ You can also configure {product-title-short} to scan inactive (not deployed) ima
1515

1616
. In the {product-title-short} portal, click *Vulnerability Management* -> *Results*.
1717
. Click *More Views* -> *Inactive images*.
18+
. Optional: Choose the appropriate method to view the component and advisory data associated with a CVE:
19+
** To view the component and advisory data associated with a CVE from the list of CVEs, complete the following steps:
20+
... Click the *<number> CVEs* tab.
21+
... In the list of CVEs, click a CVE to do any of the following tasks:
22+
**** To view the component and advisory data associated with an image:
23+
..... Click the *<number> Images* tab.
24+
..... Expand the image.
25+
+
26+
You can find the component data in the *Component* column, and
27+
you can find the advisory data in the *Advisory* column.
28+
**** To view the component and advisory data associated with a deployment:
29+
..... Click the *<number> Deployments* tab.
30+
..... Expand the deployment.
31+
+
32+
You can find the component data in the *Component* column, and
33+
you can find the advisory data in the *Advisory* column.
34+
** To view the component and advisory data associated with a CVE from the list of images, complete the following steps:
35+
... Click the *<number> Images* tab.
36+
... In the list of images, click an image.
37+
... To view the component and advisory data associated with a CVE, expand the CVE.
38+
+
39+
You can find the component data in the *Component* column, and
40+
you can find the advisory data in the *Advisory* column.
41+
** To view the component and advisory data associated with a CVE from the list of deployments, complete the following steps:
42+
... Click the *<number> Deployments* tab.
43+
... In the list of deployments, click a deployment.
44+
... To view the component and advisory data associated with a CVE, expand the CVE.
45+
+
46+
You can find the component data in the *Component* column, and
47+
you can find the advisory data in the *Advisory* column.
1848
. Click *Manage watched images*.
1949
. In the *Image name* field, enter the fully-qualified image name that begins with the registry and ends with the image tag, for example, `docker.io/library/nginx:latest`.
2050
. Click *Add image to watch list*.

modules/understanding-vulnerability-scores.adoc

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -22,6 +22,4 @@ CVSS v3 scores are only available if you are using the StackRox Scanner version
2222
For example, `6.5`.
2323
2424
You can use the API to get the CVSS scores.
25-
If CVSS v3 information is available for a vulnerability, the response might include both CVSS v3 and CVSS v2 information.
26-
27-
For a Red{nbsp}Hat Security Advisory (RHSA), the CVSS score is set to the highest CVSS score among all the related CVEs. One RHSA can contain multiple CVEs, and Red{nbsp}Hat sometimes assigns a different score based on how a vulnerability affects other Red{nbsp}Hat products.
25+
If CVSS v3 information is available for a vulnerability, the response might include both CVSS v3 and CVSS v2 information.

modules/vulnerability-management-more-views-all-vuln-images.adoc

Lines changed: 30 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -23,6 +23,36 @@ You can view a list of vulnerabilities for user workloads, platform vulnerabilit
2323
* *<number> CVEs*: Displays vulnerabilities organized by CVE
2424
* *<number> Images*: Displays images that contain discovered vulnerabilities.
2525
* *<number> Deployments*: Displays deployments that contain discovered vulnerabilities.
26+
. Optional: Choose the appropriate method to view the component and advisory data associated with a CVE:
27+
** To view the component and advisory data associated with a CVE from the list of CVEs, complete the following steps:
28+
... Click the *<number> CVEs* tab.
29+
... In the list of CVEs, click a CVE to do any of the following tasks:
30+
**** To view the component and advisory data associated with an image:
31+
..... Click the *<number> Images* tab.
32+
..... Expand the image.
33+
+
34+
You can find the component data in the *Component* column, and
35+
you can find the advisory data in the *Advisory* column.
36+
**** To view the component and advisory data associated with a deployment:
37+
..... Click the *<number> Deployments* tab.
38+
..... Expand the deployment.
39+
+
40+
You can find the component data in the *Component* column, and
41+
you can find the advisory data in the *Advisory* column.
42+
** To view the component and advisory data associated with a CVE from the list of images, complete the following steps:
43+
... Click the *<number> Images* tab.
44+
... In the list of images, click an image.
45+
... To view the component and advisory data associated with a CVE, expand the CVE.
46+
+
47+
You can find the component data in the *Component* column, and
48+
you can find the advisory data in the *Advisory* column.
49+
** To view the component and advisory data associated with a CVE from the list of deployments, complete the following steps:
50+
... Click the *<number> Deployments* tab.
51+
... In the list of deployments, click a deployment.
52+
... To view the component and advisory data associated with a CVE, expand the CVE.
53+
+
54+
You can find the component data in the *Component* column, and
55+
you can find the advisory data in the *Advisory* column.
2656
. Optional: Choose the appropriate method to re-organize the information in the *User Workloads* tab:
2757
** To sort the table in ascending or descending order, select a column heading.
2858
** To filter the table, use the filter bar.

modules/vulnerability-management20-creating-report.adoc

Lines changed: 10 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -29,7 +29,16 @@ The following values are associated with image types:
2929
*** *Deployed images*
3030
*** *Watched images*
3131
** *CVEs discovered since*: Select the time period for which you want to include the CVEs in the report configuration.
32-
** Optional: Select the *Include NVD CVSS* checkbox, if you want to include the NVD CVSS column in the report configuration.
32+
** Optional: Choose the appropriate column that you want to include in the vulnerability report:
33+
+
34+
[NOTE]
35+
====
36+
You can select one or more columns to include in the report configuration.
37+
====
38+
+
39+
*** Select the *Include NVD CVSS* checkbox, if you want to include the NVD CVSS column in the report configuration.
40+
*** Select the *Include EPSS probability* checkbox, if you want to include the EPSS probability column in the report configuration.
41+
*** Select the *Include advisory name and link* checkbox, if you want to include the advisory name and link column in the report configuration.
3342
** *Configure collection included*: To configure at least one collection, do any of the following tasks:
3443
*** Select an existing collection that you want to include.
3544
+

modules/vulnerability-management20-view-platform-cve.adoc

Lines changed: 30 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -99,6 +99,36 @@ a|
9999
* *<number> CVEs*: Displays vulnerabilities organized by CVE
100100
* *<number> Images*: Displays images that contain discovered vulnerabilities.
101101
* *<number> Deployments*: Displays deployments that contain discovered vulnerabilities.
102+
. Optional: Choose the appropriate method to view the component and advisory data associated with a CVE:
103+
** To view the component and advisory data associated with a CVE from the list of CVEs, complete the following steps:
104+
... Click the *<number> CVEs* tab.
105+
... In the list of CVEs, click a CVE to do any of the following tasks:
106+
**** To view the component and advisory data associated with an image:
107+
..... Click the *<number> Images* tab.
108+
..... Expand the image.
109+
+
110+
You can find the component data in the *Component* column, and
111+
you can find the advisory data in the *Advisory* column.
112+
**** To view the component and advisory data associated with a deployment:
113+
..... Click the *<number> Deployments* tab.
114+
..... Expand the deployment.
115+
+
116+
You can find the component data in the *Component* column, and
117+
you can find the advisory data in the *Advisory* column.
118+
** To view the component and advisory data associated with a CVE from the list of images, complete the following steps:
119+
... Click the *<number> Images* tab.
120+
... In the list of images, click an image.
121+
... To view the component and advisory data associated with a CVE, expand the CVE.
122+
+
123+
You can find the component data in the *Component* column, and
124+
you can find the advisory data in the *Advisory* column.
125+
** To view the component and advisory data associated with a CVE from the list of deployments, complete the following steps:
126+
... Click the *<number> Deployments* tab.
127+
... In the list of deployments, click a deployment.
128+
... To view the component and advisory data associated with a CVE, expand the CVE.
129+
+
130+
You can find the component data in the *Component* column, and
131+
you can find the advisory data in the *Advisory* column.
102132
. Optional: Choose the appropriate method to re-organize the information in the *User Workloads* tab:
103133
** To sort the table in ascending or descending order, select a column heading.
104134
** To select the categories that you want to display in the table, perform the following steps:

modules/vulnerability-management20-view-workload-cve.adoc

Lines changed: 30 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -101,6 +101,36 @@ a|
101101
* *<number> CVEs*: Displays vulnerabilities organized by CVE
102102
* *<number> Images*: Displays images that contain discovered vulnerabilities.
103103
* *<number> Deployments*: Displays deployments that contain discovered vulnerabilities.
104+
. Optional: Choose the appropriate method to view the component and advisory data associated with a CVE:
105+
** To view the component and advisory data associated with a CVE from the list of CVEs, complete the following steps:
106+
... Click the *<number> CVEs* tab.
107+
... In the list of CVEs, click a CVE to do any of the following tasks:
108+
**** To view the component and advisory data associated with an image:
109+
..... Click the *<number> Images* tab.
110+
..... Expand the image.
111+
+
112+
You can find the component data in the *Component* column, and
113+
you can find the advisory data in the *Advisory* column.
114+
**** To view the component and advisory data associated with a deployment:
115+
..... Click the *<number> Deployments* tab.
116+
..... Expand the deployment.
117+
+
118+
You can find the component data in the *Component* column, and
119+
you can find the advisory data in the *Advisory* column.
120+
** To view the component and advisory data associated with a CVE from the list of images, complete the following steps:
121+
... Click the *<number> Images* tab.
122+
... In the list of images, click an image.
123+
... To view the component and advisory data associated with a CVE, expand the CVE.
124+
+
125+
You can find the component data in the *Component* column, and
126+
you can find the advisory data in the *Advisory* column.
127+
** To view the component and advisory data associated with a CVE from the list of deployments, complete the following steps:
128+
... Click the *<number> Deployments* tab.
129+
... In the list of deployments, click a deployment.
130+
... To view the component and advisory data associated with a CVE, expand the CVE.
131+
+
132+
You can find the component data in the *Component* column, and
133+
you can find the advisory data in the *Advisory* column.
104134
. Optional: Choose the appropriate method to re-organize the information in the *User Workloads* tab:
105135
** To sort the table in ascending or descending order, select a column heading.
106136
** To select the categories that you want to display in the table, perform the following steps:

0 commit comments

Comments
 (0)