Skip to content

Make Vulnerability Deferral per namespace #13011

Description

@cjreyn

Hi. I Can't see a way of making a feature request, so will open an issue.

We currently partition our cluster up into namespaces, using Kubernetes RBAC to limit what a user can do in a namespace. We also grant each user a StackRox login, limiting what namespaces they can view in StackRox.

It would be great if StackRox could support vulnerability deferral by namespace. Currently, when someone has the VulnerabilityManagementRequests resource, they can defer CVEs. However this defers the CVE for all namespaces. Our issue is that it might be sensible to defer a CVE for users of one namespace (since their code is not affected by the CVE), but not another namespace (since their code is affected).

Is this possible?

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions