Findings inbox

The organization and repository inboxes, their views and filters, and what a finding page shows.

Every finding lands in an inbox, where you read it, work on it and close it out. This page shows where the inboxes are, how to narrow them, and what a finding's page holds.

Organization and repository inboxes

Findings in the sidebar is your organization's inbox. It lists the findings of every repository in the workspace, each read at its default branch head.

Each repository workspace (/repos/<owner>/<repo>) has a Findings list of its own. It holds that repository's findings at the branch, pull request or commit you pick; see Positions.

A finding has a key such as F-42. Each row shows the finding's severity, status, key, title, repository, focus, assignee and age.

Views, filters and groups

The tabs above the list are views. Each shows its count.

ViewShows
OpenFindings that are Open or Investigating. The inbox opens on this view.
MineOpen findings assigned to you
UnassignedOpen findings with no assignee
Last 7 daysOpen findings first seen in the last seven days. On a narrow screen the tab reads New.
AllEvery finding except dismissed ones
DismissedOnly dismissed findings. They appear in no other view.

Filter narrows the view by Status, Severity, Focus, Repository, Assignee or Source (Agent or Human). A finding from a run that carried several focuses matches the Focus filter for each of them. A view does not offer a filter it already applies: Status appears only under All and Dismissed, and Mine and Unassigned leave out Assignee. With filters on, the button shows their number, as in Filter (2).

Group by is the icon beside Filter; its tooltip names the current grouping, such as Group by Severity. It bands the rows by Status, Severity, Focus, Repository, Assignee or Age. Age bands are This week, This month, This quarter and Older. The menu offers only groupings that split the current rows into more than one band. Grouping by Status gives three bands: Open, Fixed and Closed, where Closed holds findings that are Won't fix, Duplicate or False positive.

Your browser remembers your filters and grouping. The inbox has no search box.

You can change a finding's status, severity and assignee from the list; see Triage findings. The download icon beside Group by exports the list; see Export the inbox.

The finding page

Click a row to open the finding. The page reads from top to bottom:

  • The title and description.
  • The code. A card for each file the finding points to, with its repository, path and commit. If V12 cannot read a file, its card shows just the lines the finding cites and counts the lines it cannot show. A location with no lines to show is listed under Evidence instead.
  • PoC and Fix, when the run produced them: the proof-of-concept test and the patch, as cards like the code above, each led by V12's note on what it shows or changes. The PoC's test starts folded under that note; Show n lines opens it in place. The fix card shows each change with a few lines around it; Show unchanged lines opens the rest of the file in place. A PoC or fix that did not complete says so on its card.
  • Activity: the finding's history and its comments. Write in Leave a comment, and type @ to reference a line, a commit, a run or a finding. Reply answers a comment in its thread.

In a wide window, a rail on the right holds the rest:

  • Copy link copies the finding's address. More actions dismisses or restores the finding.
  • Properties shows the status, severity and assignee. Click one to change it; see Triage findings.
  • Origin lists the repositories, focuses and runs (Run #12) the finding came from, and a commit for each repository. Click a repository or a run to open it.
  • Related lists findings linked to this one as duplicates. It appears only when there are some.

In a narrower window the rail is hidden. The status, severity and assignee then appear as buttons under the title, with chips for the repositories and runs.

On this page