This post discusses how to implement severity override policies in GitLab for vulnerability management. It highlights the limitations of the Common Vulnerability Scoring System (CVSS) in accurately reflecting risk based on an environment and offers five practical policies to adjust vulnerability severity effectively. The strategies include downgrading severities for internal services, upgrading critical vulnerabilities in production, normalizing severity across different scanning tools, aligning severity with exploitation intelligence, and applying organization-wide risk models. The article provides actionable configurations and use cases for each policy to enhance security posture and reduce manual triage efforts.