Open
Description
I think we should add a short description of what each severity entails to make things clearer to the client. For example, ConsenSys uses this:
Minor
issues are subjective in nature. They are typically suggestions around best practices or readability. Code maintainers should use their own judgment as to whether to address such issues.
Medium
issues are objective in nature but are not security vulnerabilities. These should be addressed unless there is a clear reason not to.
Major
issues are security vulnerabilities that may not be directly exploitable or may require certain conditions in order to be exploited. All major issues should be addressed.
Critical
issues are directly exploitable security vulnerabilities that need to be fixed.
Metadata
Metadata
Assignees
Labels
No labels