Safety & Security · Data artifact
Vulnerability Gate Policy
Data artifactSafety & SecuritySafety, Security & Governancearc:VulnerabilityGatePolicy
A policy stating which vulnerability severities, with or without available fixes, fail a build, and how explicitly acknowledged CVE exceptions are handled.
Responsibility. Defines when scanned vulnerabilities block deployment.
Also known as: CVE severity threshold, Vulnerability exception process
Relationships
configures structural
Design guidance
- SHOULD fail builds on critical or high-severity vulnerabilities with available fixes; unpatched high-severity issues MAY deploy with manual approval and compensating controls.
- SHOULD require security teams to explicitly acknowledge CVE exceptions when no remediation exists and exploitation does not apply.
Classification
- Quality attributes
- Security (ISO/IEC 25010 | NIST AI RMF: secure and resilient)Maintainability (ISO/IEC 25010)
- Risks mitigated
- Blocking all deployments on unpatched dependency CVEs
Sources
- Ch4.2: T. Nguyen, "Deployment and Scaling," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 4.2. ISBN: 9798244538229.