Reference H: Pull request comment feedback
Cortex Cloud posts pull request scan results as comments. This gives authors feedback at the point of introduction without Cortex Cloud access.
SCA vulnerabilities
The affected package and version, plus vulnerability IDs, fixed version, CVSS, EPSS, and CISA KEV status. Direct and transitive dependencies are reported separately
Secrets
The detected credential finding, presented for removal and rotation
IaC misconfigurations
The misconfigured resource and matched detection
License miscompliance
The package and license obligation that triggered the detection
Malicious packages
The package name and version, Malware ID with advisory link, and required removal action
The comment records remediation progress across commits. It records fixes and regressions for previously reported vulnerabilities.
Note: Pull request comments require VCS pull request write access. GitHub requires
pull_requests: Write. Azure DevOps requires pull request thread access.
Last updated
Was this helpful?
