Findings
What a LaunchSafe finding is: severity, proof status, evidence, and the statuses a finding moves through, from open to verified fixed.
What a finding is
A finding is one issue in one project. The same issue seen by several scans is one finding with several occurrences, so your triage decisions carry over. A finding has a severity (critical, high, medium or low), a source (code, dependency, secret, Supabase settings), a location, a plain description of what is wrong and how to fix it, and evidence.
Proof status
Not every finding is proven. Each one says how far it got:
| Proof status | Meaning |
|---|---|
| Needs review | Reported but not reproduced. Treat it as a suspicion until someone checks it |
| Reproduced | The scan reproduced it and recorded that it did |
| Verified | A retest confirmed the issue is there |
Evidence is masked: secrets, tokens and personal data in it are hidden. A committed secret is shown by its type, file and line, never its value.
Statuses
| Status | How it is set |
|---|---|
| Open | The starting status |
| To fix | By a person |
| Accepted risk | By a person, with a note and an end date: 90 days unless you choose, at most a year. The finding reopens when the date passes |
| False positive | By a person, with a reason |
| Fixed | By a retest that covered the finding and found it fixed |
| Verified fixed | By a retest of the branch it was found on, or where its fix merged |
Fixed and verified fixed are never set by hand. Only a retest closes a finding. A scan that merely stops seeing a finding closes nothing: it starts a free retest instead, and the finding stays open unless the retest finds it fixed.
A finding found again after it was closed reopens, and the history says why. A rescan never changes a decision you made.
Fixing
A fix pull request needs your approval and opens as a draft by default. See fix pull requests and retests.
Duplicates and work tools
You can merge duplicate findings in the same project. Linked findings can have an issue in Jira or Linear. See Jira and Linear.
Scan Types
What LaunchSafe scans today: free public repository grades and Supabase settings checks today, and code scans of GitHub repositories when they open. Live-app testing is not open yet.
Fix Pull Requests and Retests
How LaunchSafe turns a finding into a fix pull request you approve, and how a retest decides whether it is fixed.