For Recommend level findings, developers can submit exception requests if they determine the finding should not be considered an issue to deter development.
Before you begin
Generally, exceptions require approval from a system administrator. However, certain settings configured by a system administrator may determine if the exception is automatically approved or rejected. If the exception is
approved, the finding is excluded from technical debt.
Note: The record under the
Scanned Record field of the finding,
sn_se_finding, record should be extending
sys_metadata table in order for the Scan Engine Exceptions
UI action button to be available. For more information on configuring exception properties, refer to
Configure exception reason properties.
Role required: sn_se.scan_engine_admin, sn_impact_common.Impact Developer, or sn_impact_common.Impact App Admin
Procedure
-
When a Recommend level finding is detected, select View finding details in the summary banner to open the Findings panel.
-
In the Findings panel, select the Recommend tab to view Recommend level findings.
-
On the finding card, select Create exception.
-
Enter the reason in the Exception Reason field for why an exception should be made for this finding.
-
Select Request Approval to submit the exception for review by a system administrator.
If approval requests are enabled, the exception state is set to Requested. If not, the state is Not Yet Requested.
-
Select OK to save the exception request.
The finding card updates to show a gray background with an
Exception requested label. The
Create exception button is replaced with a link to view the exception reason
that was entered.
Note: If the requester name or email notification does not display correctly in the exception record after submission, ensure your user account is properly synchronized between development and production
environments. The Scan Engine exception workflow requires consistent user identification across instances.