Trivy output plugin that enriches vulnerability scan results with EPSS exploit prediction scores, CISA KEV catalog data, and a composite risk score for vulnerability prioritization.
Note
Work in progress
See the product requirements document.
The documentation can be found in the docs/ subdirectory.
The source code of trivy-plugin-vuln-prio is released under the Apache License, Version 2.0. See the bundled LICENSE file for details.