---
name: "cve-stack-relevance"
description: "Decide whether a CVE or advisory matters to the actual stack and show the data behind that judgement."
triggers: ["does this CVE affect us", "CVE relevance", "advisory impact", "are we vulnerable", "stack exposure"]
version: "1"
---
# CVE stack relevance
Use this for one advisory or a small related set.
## Test the chain
Answer each question with evidence:
1. Is the named package and ecosystem the one in this stack?
2. Does the installed version fall in the verified affected range?
3. Does the shipped service include and load it?
4. Is the vulnerable feature or configuration present?
5. Can an attacker meet the access and privilege conditions?
6. What data, control, or availability could be lost?
7. Is a fixed version or verified mitigation available?
## Give a result
Label the result **confirmed**, **likely**, **not affected**, or **unknown**.
Cite the advisory source and the repository, image, configuration, or runtime
evidence used for each step. Explain any conflict between vendor, maintainer,
and database records.
## Next action
Name the smallest check or change that resolves the uncertainty or risk. Do not
use absence from a scanner as proof of safety. Do not claim a fix until the
fixed version is present in the built artifact and the relevant tests or checks
pass.