For the complete documentation index, see llms.txt. This page is also available as Markdown.

Reference H: Pull request comment feedback

Cortex Cloud posts pull request scan results as comments. This gives authors feedback at the point of introduction without Cortex Cloud access.

Detection type
Comment content

SCA vulnerabilities

The affected package and version, plus vulnerability IDs, fixed version, CVSS, EPSS, and CISA KEV status. Direct and transitive dependencies are reported separately

Secrets

The detected credential finding, presented for removal and rotation

IaC misconfigurations

The misconfigured resource and matched detection

License miscompliance

The package and license obligation that triggered the detection

Malicious packages

The package name and version, Malware ID with advisory link, and required removal action

The comment records remediation progress across commits. It records fixes and regressions for previously reported vulnerabilities.

Note: Pull request comments require VCS pull request write access. GitHub requires pull_requests: Write. Azure DevOps requires pull request thread access.

Last updated

Was this helpful?