Skip to main content

Triaging Container Security Results

Important

The following permissions enable users to triage results:

  • update-result-state-not-exploitable (can change to this state only)

  • update-result-state-propose-not-exploitable (can change to this state only)

  • update-result-states (can change all states except not-exploitable; can’t change the severity)

  • update-result-severity (can change only severities)

For additional details about triage permissions, see here.

Triaging a Vulnerability

To change the result predicate:

  1. Hover over a vulnerability and click on the Edit button.

  2. In the dialog that opens, you can click on the Severity, State or risk Score and select the value that you would like to assign.

    Image_1693.png
  3. You can add a note explaining the reasoning for the change. You can select different vulnerabilities within the same package and triage each of them.

Image_919.png

Bulk Action Triaging Results

You can triage multiple vulnerabilities with a single bulk action.

  1. In the Vulnerabilities tab, select the checkbox next to each vulnerability that you would like to include in the bulk action triage. Then, click on Edit Properties.

    Image_969.png

    All of the selected vulnerabilities are shown and you can click on each one to see the relevant details.

  2. Make changes to the Severity, State, and/or risk Score. The changes are applied to all of the selected vulnerabilities.

    Image_970.png