Findings

Retesting

Re-check a finding, and what a scan does to the findings before it.

A finding is a claim about a moment. Retesting is how you find out whether it still holds, and a finding follows the result on its own.

One finding across every scan

A finding is one issue on one asset. When a later scan meets the same issue it updates that finding instead of filing another, so Last seen is the last scan that reproduced it and its history stays in one place.

Every scan retests the asset

A scan re-checks the asset's known findings, and records one of three results for each:

  • Reproduced — the proof still works.
  • Not reproduced — the scan reached the endpoint, replayed the proof, and it no longer works.
  • Not retested — the scan could not check it, for example because a login expired or the endpoint was out of scope for that run.

The scan's Diff tab groups its findings by that result: new, resolved, persistent, and not retested.

What changes a status

  • Not reproduced moves an open or in-progress finding to Resolved, with the failed replay kept as evidence.
  • Reproduced on a resolved finding reopens it as a regression, so a fix that was reverted does not stay hidden.
  • Not retested changes nothing. A scan that could not check a finding never counts as proof that it was fixed.
  • False positive and Risk accepted are your decisions and are never changed by a scan.

Every change appears in the finding's Activity, with the scan that caused it.

Linked tickets

When a retest resolves a finding, its linked tickets are closed as well: the GitHub or GitLab issue is closed, the Jira issue moves to a done status, the Linear issue to a completed state, the Datadog work item is closed, and the ServiceNow incident is resolved. If a tracker refuses, for example because its workflow has no path to done, the finding's activity says so and the ticket stays open for you to close.

Retest one finding

Re-test on a finding replays that one finding, using the configuration of the scan that last saw it. It does not rescan the whole asset, so it is the quick way to confirm a fix after you ship it; the other findings on the asset are recorded as not retested and keep their status.

On this page