Skip to main content

Statuses

These are the current workflow statuses for vulnerabilities.
StatusMeaning
openNew vulnerability, not yet reviewed
confirmedVerified as a real issue
needs_reviewRequires human attention
in_progressBeing worked on
in_reviewFix submitted, under review
resolvedFinal state. Resolution required
closedFinal state. Resolution required

Status notes

  • When you move a vulnerability to resolved or closed, a resolution is required
  • Available transitions depend on the current status
  • Reopening a final status is tracked as a regression and shown in the vulnerability detail view

Resolutions

Resolutions describe the outcome when a vulnerability is marked resolved or closed.
ResolutionMeaning
fixedIssue was fixed
wont_fixAccepted risk, will not fix
false_positiveNot a real issue
duplicateSame as another vulnerability
cannot_reproduceUnable to verify
doneCompleted
rejectedSystem-only, set when analysis determines it is not a vulnerability