Skip to content

Commit 1737de0

Browse files
committed
feature: Document ignore security findings feature [TAROT-2883]
1 parent 307fcd7 commit 1737de0

File tree

5 files changed

+35
-0
lines changed

5 files changed

+35
-0
lines changed

docs/organizations/audit-logs-for-organizations.md

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -80,3 +80,10 @@ The sections below list the events that Codacy logs for your organization at use
8080
| Update quality settings for repository | Update quality settings for repository |`repositories.settings.quality.repository.update`|
8181
| Update quality settings for pull requests | Update quality settings for pull requests |`repositories.settings.quality.pullrequests.update`|
8282
| Update file state | Ignore or Unignore file |`repositories.file.update`|
83+
84+
### Security and Risk Management
85+
86+
|Event|Description|Action|
87+
|-----|-----------|------|
88+
|Ignore security finding|Security finding was ignored|`srm.finding.ignore`|
89+
|Unignore security finding|Security finding was unignored|`srm.finding.unignore`|
439 KB
Loading
651 KB
Loading
433 KB
Loading

docs/organizations/managing-security-and-risk.md

Lines changed: 28 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -106,6 +106,34 @@ To share the current view of the overview or findings page, click the **Copy URL
106106

107107
!!! Important " [**Segments**](../segments) filter won't be considered when sharing the filtered view"
108108

109+
## Ignoring findings {: id="ignoring-findings"}
110+
111+
!!! info "This feature is available only to organization admins and organization managers"
112+
113+
In the findings details page, it is possible to ignore it using the context menu. When ignoring an issue you can optionally specify a reason for doing so.
114+
115+
![Security and risk management finding ignore](images/security-risk-management-finding-ignore.png)
116+
117+
From an organization standpoint, ignoring a finding means that you accept the risk it poses and you're not planning on adressing the issue.
118+
119+
From Codacy's standpoint, ignoring a finding means it will be removed from the metrics featured in the [overview page](#dashboard) page. Note that the [Open Findings history](#open-findings-history) chart will only be changed at the start of next week.
120+
121+
!!! info [Jira](./integrations/jira-integration.md) findings can't be ignored in Codacy. You should closed the issue directly in Jira.
122+
123+
!!! warn Ignoring findings detected on [Git repositories](#how-codacy-manages-findings-detected-on-git-repositories--idopening-and-closing-codacy-items) will also [ignore the issue at the repository level](../repositories/issues.md#ignoring-and-managing-issues).
124+
125+
You can still see **Ignored** findings in the [findings list](#findings--iditem-list), by filtering for the **Ignored** status in the **Status** dropdown. Check the **Status** column to know the status of a finding.
126+
127+
![Security and risk management finding unignore list](images/security-risk-management-finding-unignore-list.png)
128+
129+
An Ignored finding can be **unignored** directly from the [findings list](#findings--iditem-list) or by going to the same menu where the ignore action was performed, in the findings details page. Unignoring a finding reverts the effect of ignoring it.
130+
131+
![Security and risk management finding unignore](images/security-risk-management-finding-unignore.png)
132+
133+
!!! warn Unignoring findings detected on [Git repositories](#how-codacy-manages-findings-detected-on-git-repositories--idopening-and-closing-codacy-items) will also [unignore the issue at the repository level](../repositories/issues.md#ignoring-and-managing-issues).
134+
135+
!!! info Ignoring and unignoring findings are [auditable actions](../organizations/audit-logs-for-organizations.md#security-and-risk-management).
136+
109137
## Exporting findings {: id="exporting-the-security-item-list"}
110138

111139
!!! info "This feature is available only to organization admins and organization managers"

0 commit comments

Comments
 (0)