When real-time enforcement, enforce_real_time_validation is set to true, Recommend level findings require an approved exception reason before the form can be saved.
Avant de commencer
Role required: sn_se.scan_engine_admin, sn_se.scan_engine_read_user, sn_se.internal_rest_integration
Procédure
-
Select whether to Enforce rejected exception reason validations.
When enabled, and if an exception reason is rejected, the object linked to that reason becomes read-only. Users cannot make additional changes until either:
- The Recommend level message is resolved.
- A new exception reason is submitted.
This ensures strict compliance with validation rules and prevents inconsistent or unauthorized updates while an exception is unresolved.
-
Select whether to Enable approvals in production.
If enable_exception_reason_approvals_in_production is set to false, exceptions can only be approved in the instances in which they are raised.
-
Approval groups will approve or reject exception requests and receive notifications.
- Use the
Enable approvals in production setting to control whether exceptions can be approved in production instances or only in development environments.
- Approval group(s) displays the group or groups that will approve or reject exception reasons and also receive notifications when new approvals are requested.
Remarque : This setting is only applicable to Production instances.
-
Select whether to Exclude approved exception reasons from technical debt.
When enabled, findings with approved exception reasons will be excluded from technical debt metrics.
Remarque : This does not remove the finding from the system.
-
Upon new finding found,
er_finding_number_validation , determines how exception reasons are handled when the same issue is detected again in a subsequent scan.
Options are: Auto Accept Existing Reason and Re-approve Existing Reason.
-
Upon line number change,
exception_reason_validation
Determines how approved exception reasons are handled when the finding's line number changes in the code.
- Options are Auto Accept Existing Reason (default) and Re-approve Existing Reason.
Choose whether to automatically accept the existing reason.