Triaging issues

All issues are classified as new by default. You can see an issue classification by viewing the issue status.

About this task

Use issue triage to help you:

Reduce noise so that you can focus on the real issues.
While you are reviewing issues, you can classify those issues that do not need to be fixed as noise or passed. Noise issues include those issues that might be false positives. Passed issues require manual verification or review. After you classify issues as noise or passed, you can then focus on other issues, such as open, reopened and in progress. Issues that are open or reopened have a negative impact on your overall summaries.
Track progress toward remediation.
You can track progress by evaluating each new issue and classifying it as fixed, in progress, noise, or passed. Assigning issues a status helps you better manage the volume of issue data. You can identify and track what issues to fix first and what does not need to be fixed at all.
Show positive results.
Classifying issues also helps you show positive results or progress in your organization's scores to give your key stakeholders a more realistic picture of your site's performance.

Procedure

  1. In an application tab, click to the Issues view. Sort the Status column to arrange the issues by the weight of critical classification (open, in progress, reopened, noise, passed, fixed, new).
  2. Click the row for a specific issue, to open the Issue details panel. This panel contains valuable information about the issue, such as advisories and fix recommendations. Use this information to help you determine whether the issue is really an issue for your organization.
  3. To change an issue status from a new state:
    1. Verify that an issue is really an issue according to your corporate standards before you change its status or assign it to be fixed. Click the Location link to open the page in a new browser. By checking the live page of the issue, you can see the full context of the issue as your website users might experience it.
    2. If the issue needs further attention but you are not assigning it yet to be fixed, classify it as open.
    3. If the issue needs further attention, classify it as in progress. Then you can assign it to a team member to fix.
    4. If the issue does not need further attention, classify it as fixed, noise, or passed.
    5. When the issues are fixed, run the appropriate scans again in your third-party scanner. Import the issues again and repeat the process until all of the issues are triaged.