About audit issue history

You can view the changes in the attributes of an issue as you upload new scans for an audit. The issue history provides a list of all the changes made to an attribute value and the date and time the changes were made.

The issue history includes all the attributes that Application Security extracts from uploaded scans. Issue history only includes attributes that you can use for searching or filtering in the AUDIT page.

To enable audit issue history, see Enabling audit issue history.

The Issue History tab provides information for the following issue attributes:

Issue attributes

analyzer

issueInstanceId

remediation_effort

accuracykingdomrule
audiencelikelihoodseverity
categorylinesink
classmanualsource
codesnippet

mapped_category

sourcefile
confidence

min_virtual_call_confidence

sourceline

engine_priority

package

source_context

file

primary_context

taint
impactprobabilityurl

  • When you enable audit issue history, Application Security saves the list of attributes whose values have changed along with their old values and new values for any new uploaded FPR.

  • Uploading scans that are older than the newest uploaded scan in an application version does not generate new changes for the issue history.

  • Deleting FPRs from an application version results in the deletion of the issue history entries that were created by the upload of that FPR.

  • Copying an application version does not include the existing issue history.

See Also

Auditing Scan Results