Release
Release 1 — Living CVE intelligence
Goal
Make intelligence changes understandable and actionable from scan, watchlist, dashboard, policy, and notification workflows.
Scope
- Add a finding timeline showing the original result and subsequent source-attributed changes.
- Show original scan verdict and current posture separately.
- Add policy rules for CVE state, KEV, EPSS, fix availability, and intelligence freshness.
- Recalculate watchlist posture after verified intelligence changes.
- Add deduplicated notifications for newly exploited, newly fixed, increased, reduced, rejected, and stale-intelligence events.
Acceptance criteria
- Historical pipeline verdicts never change after completion.
- Current posture updates are visible without rescanning the image.
- Each material change produces at most one notification per configured rule.
- A policy requiring fresh intelligence returns an operational error when the feed is stale.
- Timeline entries link to the contributing source and show before/after values.
Release
Release 1 — Living CVE intelligence
Goal
Make intelligence changes understandable and actionable from scan, watchlist, dashboard, policy, and notification workflows.
Scope
Acceptance criteria