Findings

What a LaunchSafe finding is: severity, proof status, evidence, and the statuses a finding moves through, from open to verified fixed.

Edit on GitHub

What a finding is

A finding is one issue in one project. The same issue seen by several scans is one finding with several occurrences, so your triage decisions carry over. A finding has a severity (critical, high, medium or low), a source (code, dependency, secret, Supabase settings), a location, a plain description of what is wrong and how to fix it, and evidence.

Proof status

Not every finding is proven. Each one says how far it got:

Proof statusMeaning
Needs reviewReported but not reproduced. Treat it as a suspicion until someone checks it
ReproducedThe scan reproduced it and recorded that it did
VerifiedA retest confirmed the issue is there

Evidence is masked: secrets, tokens and personal data in it are hidden. A committed secret is shown by its type, file and line, never its value.

Statuses

StatusHow it is set
OpenThe starting status
To fixBy a person
Accepted riskBy a person, with a note and an end date: 90 days unless you choose, at most a year. The finding reopens when the date passes
False positiveBy a person, with a reason
FixedBy a retest that covered the finding and found it fixed
Verified fixedBy a retest of the branch it was found on, or where its fix merged

Fixed and verified fixed are never set by hand. Only a retest closes a finding. A scan that merely stops seeing a finding closes nothing: it starts a free retest instead, and the finding stays open unless the retest finds it fixed.

A finding found again after it was closed reopens, and the history says why. A rescan never changes a decision you made.

Fixing

A fix pull request needs your approval and opens as a draft by default. See fix pull requests and retests.

Duplicates and work tools

You can merge duplicate findings in the same project. Linked findings can have an issue in Jira or Linear. See Jira and Linear.

On this page