Understanding Results
How to read a LaunchSafe finding: severity, proof status, evidence, the fix, and what happens to it afterwards.
Where results are
- Findings lists every finding in the organization. You can narrow it to a project or a scan.
- A project's page shows its own findings.
- A scan's page shows what the scan covered.
One finding is one issue, however many scans see it. A later scan that sees the same issue adds to the same finding.
Reading a finding
Each finding shows:
- Severity: critical, high, medium or low.
- Source: code, dependency, secret, or Supabase settings.
- Where: the file and lines, the package, or the Supabase object.
- Proof status: how it was proven. See findings.
- What is wrong, what could happen, and how to fix it.
- Evidence, masked so secrets and personal data are not shown.
- History: every status change, who made it and when.
A CVSS score is shown only when the finding carries one.
What to do with it
- Triage. Mark it To fix, Accepted risk (with a note and an end date) or False positive (with a reason).
- Fix it. Request a fix pull request, or copy a fix prompt for your own coding assistant, or fix it yourself.
- Retest. A retest decides whether it is fixed.
- Report. Issue a signed report when someone needs proof.
Reports
Reports are issued on request: Reports → New report. They are not created after every scan.
Run Your First Scan
Start a LaunchSafe code scan of a GitHub repository: choose a depth, see the price first, and follow it to the end.
Scan Types
What LaunchSafe scans today: free public repository grades and Supabase settings checks today, and code scans of GitHub repositories when they open. Live-app testing is not open yet.