Understanding Results

How to read a LaunchSafe finding: severity, proof status, evidence, the fix, and what happens to it afterwards.

Edit on GitHub

Where results are

  • Findings lists every finding in the organization. You can narrow it to a project or a scan.
  • A project's page shows its own findings.
  • A scan's page shows what the scan covered.

One finding is one issue, however many scans see it. A later scan that sees the same issue adds to the same finding.

Reading a finding

Each finding shows:

  • Severity: critical, high, medium or low.
  • Source: code, dependency, secret, or Supabase settings.
  • Where: the file and lines, the package, or the Supabase object.
  • Proof status: how it was proven. See findings.
  • What is wrong, what could happen, and how to fix it.
  • Evidence, masked so secrets and personal data are not shown.
  • History: every status change, who made it and when.

A CVSS score is shown only when the finding carries one.

What to do with it

  1. Triage. Mark it To fix, Accepted risk (with a note and an end date) or False positive (with a reason).
  2. Fix it. Request a fix pull request, or copy a fix prompt for your own coding assistant, or fix it yourself.
  3. Retest. A retest decides whether it is fixed.
  4. Report. Issue a signed report when someone needs proof.

Reports

Reports are issued on request: Reports → New report. They are not created after every scan.

On this page