ROX-30738: Add prop for ransomware to KnownExploitLabel #16641
+16
−3
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
Follow up question from David Caravello at sprint demos about plans for Known To Be Used in Ransomware Campaigns from CISA KEV.
Lean toward the future, although selection and implementation of visual presentation does not imply that ransomware has been added to MVP scope.
See pictures of alternative visual presentations below. We will adjust with guidance from stakeholders.
User-facing documentation
Testing and quality
Automated testing
How I validated my change
npm run tsc
in ui/apps/platform folder.npm run lint:fast-dev
in ui/apps/platform folder.npm run start
in ui/apps/platform folder with staging demo as central.Manual testing
Temporarily edit code to display possibilities.
Visit /main/vulnerabilities/all-images
No known exploit (no change from demo)

Has known exploit but not known to be used in ransomware campaigns (no change from demo)

Has known exploit and known to be used in ransomware campaigns
Most specific label (with parallel wording for ransomware)

Both labels (with parallel wording for ransomware)

Both labels (with different wording for ransomware that is similar to CISA KEV catalog)

https://www.cisa.gov/known-exploited-vulnerabilities-catalog