Reference G: Scanner to issue category mapping
Use this mapping to relate a configuration setting to the results the setting produces.
IaC
Configurations
Produces IaC misconfiguration detections in Terraform, CloudFormation, Kubernetes, and Helm templates.
SCA
Vulnerabilities, license miscompliance and package operational risk
One scanner produces three issue categories. CVE vulnerability detections appear under Vulnerabilities; package operational risk and license miscompliance
Secrets
Secrets
Detects credentials in the working tree, and in commit history when Git History Scan is enabled.
Note: A repository with the SCA scanner disabled produces no Vulnerabilities issues and no Package Integrity issues. Confirm the enabled scanner set before interpreting an empty category as a clean result.
Last updated
Was this helpful?
