pub struct VulnerabilityMetrics {
pub components_with_vulns: usize,
pub total_vulnerabilities: usize,
pub with_cvss: usize,
pub with_cwe: usize,
pub with_remediation: usize,
pub with_vex_status: usize,
}Expand description
Vulnerability information quality metrics
Fields§
§components_with_vulns: usizeComponents with vulnerability information
total_vulnerabilities: usizeTotal vulnerabilities reported
with_cvss: usizeVulnerabilities with CVSS scores
with_cwe: usizeVulnerabilities with CWE information
with_remediation: usizeVulnerabilities with remediation info
with_vex_status: usizeComponents with VEX status
Implementations§
Source§impl VulnerabilityMetrics
impl VulnerabilityMetrics
Sourcepub fn from_sbom(sbom: &NormalizedSbom) -> Self
pub fn from_sbom(sbom: &NormalizedSbom) -> Self
Calculate vulnerability metrics from an SBOM
Sourcepub fn documentation_score(&self) -> Option<f32>
pub fn documentation_score(&self) -> Option<f32>
Calculate vulnerability documentation quality score (0-100)
Returns None when no vulnerability data exists, signaling that this
category should be excluded from the weighted score (N/A-aware).
This prevents inflating the overall score when vulnerability assessment
was not performed.
Disclosing vulnerabilities at all earns a 40-point baseline; the remaining 60 points reward per-vulnerability documentation quality (CVSS 24, CWE 18, remediation 18). Without the baseline, a bare disclosure scored 0 — LOWER than saying nothing (N/A redistributes the category weight), which punished transparency: an author was better off stripping vulnerability data than disclosing it undocumented.
Trait Implementations§
Source§impl Clone for VulnerabilityMetrics
impl Clone for VulnerabilityMetrics
Source§fn clone(&self) -> VulnerabilityMetrics
fn clone(&self) -> VulnerabilityMetrics
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreSource§impl Debug for VulnerabilityMetrics
impl Debug for VulnerabilityMetrics
Source§impl<'de> Deserialize<'de> for VulnerabilityMetrics
impl<'de> Deserialize<'de> for VulnerabilityMetrics
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
Auto Trait Implementations§
impl Freeze for VulnerabilityMetrics
impl RefUnwindSafe for VulnerabilityMetrics
impl Send for VulnerabilityMetrics
impl Sync for VulnerabilityMetrics
impl Unpin for VulnerabilityMetrics
impl UnsafeUnpin for VulnerabilityMetrics
impl UnwindSafe for VulnerabilityMetrics
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> DeserializeOwned for Twhere
T: for<'de> Deserialize<'de>,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
Source§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more