Triage findings

Severity, the six statuses and where each applies, dismissing and restoring, and undo.

Triage sets how serious a finding is, where it stands and who is assigned to it. Every member of an organization can triage, Admins and Members alike. So can guests of a shared repository inbox.

You can triage from two places:

  • The finding page. Click the status, severity or assignee under Properties, in the rail on the right. The rail shows only in a wide window; if it is hidden, hide the sidebar to make room, or triage from the inbox.
  • The inbox. Click a row's severity mark, status mark or assignee avatar. Right-click a row for Status, Assign and Severity. To change several findings at once, tick their checkboxes and use the bar at the bottom: Assign, Investigating, Fixed or Won't fix.

Severity

A finding's severity is one of Critical, High, Medium, Low or Informational. Severity belongs to the finding, so one change applies everywhere.

Status

A finding has one of six statuses. Some are recorded per commit, others apply to the whole finding.

StatusApplies to
OpenA commit
InvestigatingThe whole finding
FixedA commit
Won't fixThe whole finding
DuplicateThe whole finding
False positiveA commit

Because Open, Fixed and False positive are recorded per commit, a finding can be fixed on one branch and open on another. When you set one of them from Findings, V12 records it at each repository's default branch head. From a repository workspace, it records it at the branch, pull request or commit you are viewing.

The inbox combines all of this into one status. The first rule that matches wins:

  1. Duplicate, if the finding is linked as a duplicate of another.
  2. Won't fix, if someone decided not to fix it. A decision to accept the risk also shows as Won't fix.
  3. Investigating, if someone is investigating it.
  4. False positive, if it is marked false positive in every repository.
  5. Fixed, if the problem is gone from every repository.
  6. Otherwise, Open.

A finding marked Won't fix offers only Open in its status menu. Reopen it before you choose another status.

Duplicate means the finding repeats another one, which is listed under Related on its page. You cannot set it yourself: choosing Duplicate only shows the message "Choose the primary finding under Related". Open the other finding from Related to work on it there; a guest of a shared inbox sees it listed without a link.

Assign

The assignee menu lists your organization's members by email. Choose No one to unassign.

Dismiss and restore

Dismissing takes a finding out of the inbox without changing its status. On the finding page, open More actions (the … button above Properties) and choose Dismiss from inbox. The finding then appears only in the Dismissed view. More actions is in the rail on the right, which shows only in a wide window.

To bring it back, open it from Dismissed and choose More actions → Restore to inbox.

Undo

After you change a status, severity or assignee, a confirmation appears at the bottom of the screen with an Undo button. On the finding page it reads "Finding updated."; in the inbox it describes the change, such as "Set F-12 to high." Click Undo within about eight seconds, while the confirmation is showing.

Dismissing and restoring offer no Undo. To reverse one, use the other action.

On this page