Severity in a vacuum.
CVSS scores the technical impact of a single CVE in isolation. A CVSS 9.8
in a library you don't ship is noise. A CVSS 6.1 in axios, used
by half of npm, is an emergency. The score can't tell the difference.
- No notion of dependency graph or blast radius
- No notion of exploitation activity in the wild
- No notion of maintainer account compromise
- Zero coverage of malicious packages without a CVE