Skip to main content

Overview

The Vulnerabilities page provides an organization-wide view of open security findings. Use it to review findings across projects, investigate details, export results, and apply triage decisions without opening each scan separately.
The Vulnerabilities Workbench is available to organizations where it has been enabled by Corgea. Contact your Corgea representative to request access. Users also need permission to view at least one finding type.
Vulnerabilities Workbench with summary cards, finding-type tabs, Team and Tags filters, and grouped findings
The summary cards show Open findings (with estimated Hours Saved), Critical & High, and Past SLA. Findings are separated into these tabs:
  • Secrets
  • SAST
  • Logic & Auth
  • SCA Packages
  • Containers
  • IaC
Each tab is available only when you have permission to view that finding type. The badge on a tab shows its unfiltered open-finding count.

Find and review findings

Select a tab, then expand its groups and projects to reach individual findings. Grouping is tailored to each finding type—for example, SCA findings begin with packages, container findings with images, and IaC findings with rules. Use Previous and Next to browse grouped results. Group, CVE, and project lists show the current row range without a total or numbered page links. Use the status controls to switch between Open, Fixed, False Positive, and the additional statuses available for that finding type. You can also search and filter by severity, project, and Tags. Selecting multiple tags shows findings from projects that have any selected tag. Tag matching is case-sensitive and must match the stored project tag exactly. The Secrets tab adds a validity filter, while SCA Packages adds a reachability filter. Use the Team filter on any tab to show findings from projects owned by the selected team that you have permission to view. Combined with a project filter, it shows only projects that match both filters. The team filter also applies when expanding groups, exporting filtered results, and selecting all findings matching the current filters.
Vulnerabilities Workbench with the Team filter open, listing teams you can use to limit findings
Select a finding to open the details drawer. From the drawer, you can review its evidence, assign it, change its disposition, or open the full finding page. A comment is required when changing a disposition, and it has to explain the decision rather than repeat it—see Triage Justifications. When suppressing a supported finding as accepted risk, you can also choose when the suppression expires. SAST findings carried forward from a previous scan during an incremental scan retain their triage status, justification, assignee, due date, and accepted-risk expiry date. Carrying a finding forward does not reset or remove its due date or expiry date. SCA and container findings open in the details pane within the workbench, where you can review details and history, plus reachability when available. Use Open Full View to open the full finding page. The browser URL preserves the selected finding, so reopening it restores the details when that finding is present in the current results. If your company requires triage approval for False positive or Accepted risk, changing to that disposition creates a request and leaves the finding unchanged. A different authorized reviewer can approve or reject it from the approvals queue or the finding details. Requesters can withdraw their own pending requests.

Export findings

Click Export to download a CSV containing the findings that match the active tab, status, search, and filters. The export includes the latest occurrence of each finding and is limited to 25,000 rows. To export only particular findings, select them and click Export selection in the action bar.

Triage findings in bulk

Select individual findings or an expanded group. You can also choose Select all findings matching the current filters after making an initial selection. The bulk action bar lets you:
  • Assign findings to a team member
  • Reopen findings
  • Suppress findings as accepted risk
  • Mark findings as false positives
  • Export the selection
Bulk status changes require a comment, and the same justification requirement applies: a comment that only repeats the decision is sent back and no status is changed. The action bar summarizes the number of selected findings, projects, and teams, and reports any findings that were skipped. A bulk selection can contain up to 1,000 findings.
Assignment and disposition controls appear only when you have permission to change that finding type. Export remains available with view permission.