Hi. I Can't see a way of making a feature request, so will open an issue.
We currently partition our cluster up into namespaces, using Kubernetes RBAC to limit what a user can do in a namespace. We also grant each user a StackRox login, limiting what namespaces they can view in StackRox.
It would be great if StackRox could support vulnerability deferral by namespace. Currently, when someone has the VulnerabilityManagementRequests resource, they can defer CVEs. However this defers the CVE for all namespaces. Our issue is that it might be sensible to defer a CVE for users of one namespace (since their code is not affected by the CVE), but not another namespace (since their code is affected).
Is this possible?
Hi. I Can't see a way of making a feature request, so will open an issue.
We currently partition our cluster up into namespaces, using Kubernetes RBAC to limit what a user can do in a namespace. We also grant each user a StackRox login, limiting what namespaces they can view in StackRox.
It would be great if StackRox could support vulnerability deferral by namespace. Currently, when someone has the VulnerabilityManagementRequests resource, they can defer CVEs. However this defers the CVE for all namespaces. Our issue is that it might be sensible to defer a CVE for users of one namespace (since their code is not affected by the CVE), but not another namespace (since their code is affected).
Is this possible?