Repository navigation
docs: distinguish Severity, Priority Score, and Risk Score (DOCT-2728) - #1753
Merged
Merged
Conversation
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
mihaisau-snyk
approved these changes
Sep 8, 2026
Contributor
There was a problem hiding this comment.
AI review
No style or structural issues found.
Verified: all 6 changed files pass link validation · terminology aligns across Severity, Priority Score, and Risk Score · score ranges (0–1,000 ranks vs CVSS/CCSS bands) and product coverage are consistent across glossary entries and prioritization pages · no invalid contractions or banned modals.
Sent by Cursor Automation: PR review for User Docs
…ing on Priority Score - Severity factor said "CVSS framework v3.1"; severity-levels.md states Snyk adopted CVSS v4.0 as its primary framework in 2024. Now scoped to v4.0 where a v4.0 vector exists, v3.1 for older vulnerabilities. - "See Calculation of Priority Score" linked the page to its own anchor via a full filename. Now a plain anchor link. - Removed "An example follows of Priority Scores displayed in a Project view." No example follows it. - Split the semicolon sentence and fixed the singular/plural disagreement in "There are no settings related to the Priority Score; they are read-only". Refs DOCT-2728
…ty levels The "Severity levels and Priority Score" section named only Priority Score, so the page most readers land on first sent them to two of the three concepts they are trying to tell apart. Now covers Risk Score, and states the distinction customers keep asking about: a severity level is a band with a defined score range, while both scores are ranks from 0 to 1,000 with no defined bands. Refs DOCT-2728
…he hub page - "Priority Score and Risk Score rank the severity of an issue" repeated the score-equals-severity conflation. As the hub page this is the first framing many readers get. Severity is now stated as a separate label that feeds the scores. - Repaired "This helps you asse are calculated as part of the priority score." The sentence was truncated mid-word. Refs DOCT-2728
… the mapping question This page carried the specific sentence customers keep acting on: "Both scores provide a number between 1 and 1000, where 1 means low severity and 1000 means high severity." Both halves were wrong. The range is 0 to 1,000 (as stated on priority-score.md, risk-score.md, the glossary, and breakdown-of-code-analysis.md), and a score is a rank rather than a severity band. Changes: - Corrected the range and replaced the severity equivalence with an explicit rank-not-band statement, including why a Critical issue can rank below a High issue. - Added a "Can I map scores to priority levels?" section. Nine support cases ask for a score-to-level mapping; support has been answering that none exists. The 700 Fix PR default is named as an automation setting rather than a band, with a caveat that scores move when their factors move. - Snyk coverage row omitted Snyk IaC while the body text on the same page includes it twice. Added. - Renamed the second "Coverage" row to "Where it appears": the table had two rows named Coverage meaning different things. - Risk Score Integrations read "NA"; now "Not supported". - Style per snyk-docs-writing-rules: removed a contraction and first-person plural, corrected "analyses" to US spelling, sentence-cased list labels, fixed the "Fixed in available" filter-name typo, and repaired an ungrammatical closing sentence. Refs DOCT-2728
…ity Score replacement claim - The Exploit maturity table sits under "Objective likelihood risk factors" but every row described an effect on the Impact subscore. The page's own Likelihood subscore list names exploit maturity as a likelihood factor. Corrected all four rows to Likelihood. - "Risk Score replaces the Priority Score directly" was unscoped, though the same page states two paragraphs later that the swap covers only Snyk Open Source and Snyk Container and only after a retest. Now scoped, and states that Snyk Code and Snyk IaC continue to use the Priority Score. - Removed a duplicated business-criticality default statement and the inconsistent capitalization of the attribute name. - Style per snyk-docs-writing-rules: replaced the "should expect" modal and "since" used for "because". Not addressed here, pending an Engineering ruling: the Provider urgency factor is documented twice with conflicting values for Medium, and both tables describe Impact effects while one sits under Likelihood. The Likelihood subscore summary list also names Scope, while the drill-down documents Attack complexity instead. Refs DOCT-2728
…lly distinguishable The three entries a reader consults to tell these terms apart never referenced each other, so landing on any one of them did not distinguish it from the other two. Risk Score was a single sentence with no release status, no product coverage, and no link. Each entry now states what the term is, its scale, how it differs from the other two, what it covers, and where to read more: - Priority Score: names the rank-not-band distinction explicitly, and its product coverage including the Snyk Code and Snyk IaC carve-out. - Risk Score: capitalized to match the feature name, plus Early Access status, product coverage, the license-issue exclusion, Snyk Preview enablement, and the post-retest replacement behavior. - Severity: names Critical, High, Medium, Low, and the fact that each level maps to a defined score range, with the CVSS and CCSS sources distinguished, the Snyk Code absence of Critical, and the license-policy path for license issues. Refs DOCT-2728
VeronicaSnyk
force-pushed
the
docs/doct-2728-score-terminology-corrections
branch
from
September 10, 2026 11:37
12504ef to
ec68fce
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Addresses DOCT-2728. Follow-up to #1735, which fixed the glossary links; this fixes what they lead to.
The reader problem
Support cases keep asking the same question: what is the difference between Priority Score, Severity, and Risk Score, and what score range maps to which priority level? Two cases name the documentation as the root cause in the support engineer's own words:
500PU000004QcqbYAC(HUMAN MANAGED) — "The customer's confusion stems from a lack of clear categorization or mapping of Snyk Priority Scores to specific priority levels... The documentation doesn't explicitly define score ranges for different priority levels."500PU00000gmcXcYAI(Export Development Canada, still open) — "The customer lacks clear documentation or understanding regarding Snyk Code's vulnerability scoring mechanisms and the distinction between its various scoring metrics."Correction to the ticket's evidence: DOCT-2728 claims nine cases and lists ten IDs. On verification, two do not exist (
500PU00000XMRcyYAH, and the Flipkart-attributed500PU00000OBwgGYAT, which appears to be a mangled500PU00000OBwn7YAD/Securian), one needs manual Salesforce confirmation (500PU00000Xc6r0YAB), and two are about other problems (Paylocity500PU00000sZgriYACis aneffective_severity_levelmethodology question; ADP500PU00000pGCnwYAGis mostly exploit-field mapping). The defensible count is six on-topic cases, and two of those are not in the ticket:500PU00001AF0RFYA1(CGS International) and500PU000007AanlYAC(Trio Advisory). The ticket should be amended.The answer the docs never gave
The distinction is short, and it was assemblable from four pages but stated on none:
This is also why the confusion is reasonable rather than careless: Snyk publishes a score-to-level table for severity and shows a 0–1,000 number in the same UI column. Assuming the second also has a table is a fair inference.
Changes
The sentence that was generating tickets
priority-score-vs-risk-score.mdread:Wrong on both counts, and the outlier:
priority-score.md,risk-score.md,breakdown-of-code-analysis.md,enable-automatic-fix-prs.md, and the glossary all say 0–1,000. Replaced with the range plus an explicit rank-not-band statement, including why a Critical issue can rank below a High issue.Also on that page:
NA→Not supported.snyk-docs-writing-rules: contraction and first-person plural removed,analyses→analyzes, sentence-cased list labels,Fixed in availablefilter-name typo, one ungrammatical sentence.Glossary — the three entries
None of the three referenced the others, so landing on any one did not distinguish it.
Risk scorewas a single sentence with no release status, no coverage, and no link at all. Each entry now states what it is, its scale, how it differs from the other two, its coverage, and where to read more.Risk score→Risk Scoreto match the feature name (anchor unchanged).Per the reference-page template in
snyk-docs-writing-rules, the "how these relate" content (ask #4 on the ticket) lives on the comparison page, with all three glossary entries pointing to it, rather than as a conceptual section wedged into an A–Z list.Severity levels
The
Severity levels and Priority Scoresection named only Priority Score — so the page most readers land on first sent them to two of the three concepts. Now covers Risk Score and states the band-versus-rank distinction.Corrections found while editing (not in the ticket)
priority-score.mdwas stale on CVSS. It said the severity factor is "calculated using CVSS framework v3.1";severity-levels.mdstates Snyk adopted v4.0 as its primary framework in 2024. Now scoped: v4.0 where a v4.0 vector exists, v3.1 for older vulnerabilities.risk-score.mdExploit maturity table sits under Objective likelihood risk factors but all four rows described an effect on the Impact subscore. Corrected to Likelihood.risk-score.md"Risk Score replaces the Priority Score directly" was unscoped, though the same page says two paragraphs later that the swap is Open Source and Container only, and only after retest. Now scoped.prioritize-issues-for-fixing/README.mdrepeated the conflation — "rank the severity of an issue" — on the hub page, which is the first framing many readers get. Fixed.Deliberately not in this PR
Each needs an owner's answer before docs can state it. Raised as open questions on the ticket:
risk-score.mdwith conflicting values forMedium, both tables describe Impact effects while one sits under Likelihood, and the two callouts contradict each otherpriority-score.mdlists seven factorsseverity-levels.mdclaims? Not in the factor listrisk-score.mdsays "not available in the CLI", but reachability-in-CLI material says the CLI returns a Risk Score, and IDE Closed Beta shipped 2026‑01‑19Also left alone: the Low = 0.0–3.9 band in both the CVSS and CCSS tables. CVSS defines 0.0 as None, and Snyk's own
opa-rules/scoring/severity.pymaps 0.0 tonone— but the same 0.0 figure ships in fourapp-uireport templates, so changing docs alone would create a new inconsistency. Needs a docs + app-ui change.nav_contextacross this cluster is inconsistent (agnosticon two pages,classicon two) — same defect class #1735 routed to the consistency ticket, so added there rather than here.Verification
main, and each pushed blob SHA was checked against a locally computedgit hash-object— all six match, so no unintended change slipped in.#severity-levels-and-cvss,#calculation-of-priority-score) exist on their target pages.One claim worth a reviewer's eye: Priority Score applying to Snyk IaC.
priority-score-vs-risk-score.mdstates it twice, but an SME notes the IaC issue card shows a severity level rather than a score, with the score visible in Reports and the API. Stated as coverage here; flag if that is wrong.Note
Low Risk
Documentation-only edits to prioritization terminology and factual corrections; no application or API behavior changes.
Overview
Clarifies a recurring support confusion: severity is a labeled band (Critical–Low with published CVSS/CCSS ranges); Priority Score and Risk Score are 0–1,000 ranks that order issues but do not map to those bands.
Glossary — Rewrites Priority Score, Risk Score (heading casing), and Severity so each cross-links the others, states coverage (including when Risk Score replaces Priority Score), and points to the comparison page.
Hub and severity page —
prioritize-issues-for-fixing/README.mdstops conflating scores with “ranking severity,” fixes a broken reachability sentence, andseverity-levels.mdnow ties both scores to severity in one section with the band-vs-rank distinction.Priority Score vs Risk Score — Replaces incorrect “1–1000 = low/high severity” wording with 0–1,000 urgency ranks; adds “Can I map scores to priority levels?” (no mapping; default 700 fix-PR threshold as automation, not a band); comparison table adds Snyk IaC, renames duplicate Coverage to Where it appears, and minor style/filter fixes.
Reference fixes —
priority-score.mdupdates severity factor text to CVSS v4.0 / v3.1;risk-score.mdscopes Priority Score replacement to Open Source/Container, and corrects exploit-maturity table effects from Impact to Likelihood subscores.Reviewed by Cursor Bugbot for commit ec68fce. Bugbot is set up for automated code reviews on this repo. Configure here.