Issue table attributes reference
This reference lists the column attributes available across the Cortex Cloud Application Security code scan issue tables. Six issue types belong to the code scan family and share a common attribute core: IaC Drifts, IaC Misconfigurations, Licenses, Malicious Packages, Secrets, and Vulnerabilities.
Every code scan issue table attributes are common to all six issue types. The remaining attributes are type-specific and are listed in Table 3.
NOTE: This reference covers the six code scan issue types only. The CI/CD Risks table is not a code scan family table.
To show or hide any attribute in an issue table, select the column picker in the table header.
Table 1: Common attributes exposed by default
The following attributes are exposed by default in all six code scan issue tables. These attributes identify the issue, rank the issue, and locate the issue in the codebase.
Severity
The severity level assigned to the issue: Critical, High, Medium, Low, Informational, or Unknown. A matched unified policy may override the severity. The pre-override value is retained in the hidden Original Severity attribute
The severity source differs by type. Vulnerabilities derives severity from the CVSS score of the CVE. Licenses derives severity from the license category. IaC Misconfigurations and Secrets derive severity from the detection rule that matched. IaC Drifts derives severity from the security policy the deployed resource violates. Malicious Packages raises every finding at Critical severity
Name
The descriptive name of the issue. The Name attribute is the primary identifier for the issue in every code scan table
Each type names the finding and the affected object. Vulnerabilities uses a form such as CVE-2021-44228 detected in log4j-core. Secrets names the credential type and the containing file. Malicious Packages names the package and the confirmed-malicious version
File Path
The path to the file where the issue was detected, including the affected line range, such as /app/package.json (15-15)
Licenses, Malicious Packages, and Vulnerabilities report the dependency manifest file. IaC Drifts and IaC Misconfigurations report the template file. Secrets reports the source or configuration file that contains the credential
Branch
The repository branch where the issue was detected, such as main
IaC Drifts reports the branch that holds the declared-state baseline rather than the branch where the deviation occurred
Created
The timestamp when the issue was first detected
None
Table 2: Common attributes hidden by default
The following attributes are common to all six code scan issue tables and are hidden by default. Expose these attributes when you need identity references for API operations, remediation guidance, ownership context, or triage state.
Identity and source
Asset ID
The internal identifier of the scanned asset
Licenses, Malicious Packages, and Vulnerabilities report the SCA asset. IaC Drifts and IaC Misconfigurations report the IaC resource asset
Issue ID
The internal issue identifier used for API operations and cross-referencing
None
Finding ID
The unique identifier of the underlying finding
None
Rule ID
The detection rule identifier that produced the finding
Licenses reports rules BC_LIC_1 through BC_LIC_5. Secrets rules belong to the SECRETS framework or the GIT framework
Rule ID Link
A link to the detection rule documentation
None
Detection and provenance
Detection Method
The scanner that detected the issue
Vulnerabilities reports CAS_CVE_SCANNER. Licenses reports CAS_LICENSE_SCANNER, which runs as part of the SCA scanning pipeline. Malicious package detection also runs as part of SCA scanning
Alert Source
The originating scanner source
None
Data Source
The VCS provider where the repository is hosted
IaC Drifts reports the VCS provider that supplies the declared state
Git User
The Git author associated with the commit that introduced the finding
IaC Drifts reports the author of the commit that declared the intended state
Provider Link
A direct link to the affected file in the VCS provider
Licenses, Malicious Packages, IaC Drifts, and IaC Misconfigurations link to the manifest or template file
Code Lines
The line range within the file where the finding is declared
Licenses, Malicious Packages, and Vulnerabilities report the manifest line range. IaC types report the template line range. Secrets reports where the credential appears
Classification
Original Severity
The severity assigned before any policy override
The pre-override source matches the Severity source for each type. Malicious Packages is always Critical
Domain
The security domain classification, such as POSTURE
None
Finding Category
The category classification of the finding, such as Application Security
None
Subcategory
The subcategory classification of the finding
None
Tags
User-defined or system-generated tags applied to the issue
None
Description and remediation
Alert Description
A detailed description of the finding, including the impact and the recommended remediation
Malicious Packages states the attack class — typosquatting, backdoor, hijacked version, or credential theft. Licenses describes the obligations the license imposes on use, modification, and distribution
Manual Fix Suggestion
The recommended manual remediation steps
Vulnerabilities states the fixed package version. Secrets covers rotation at the issuing provider and replacement with a secrets manager reference. IaC Drifts states both reconciliation directions. Malicious Packages states removal steps; automatic remediation is not supported for this issue type
Triage and ownership
Assignee
The user assigned to remediate the issue
IaC Drifts assigns reconciliation. Malicious Packages assigns package removal. Licenses assigns review or remediation
Assignee Name
The display name of the assigned user
None
Resolution Status
The current resolution state: New, In Progress, or Resolved
None
Resolution Comment
The comment provided when the resolution status was changed
IaC Drifts records the reconciliation direction. Licenses records the legal determination. Malicious Packages records whether credentials were rotated
Last Updated
The timestamp of the most recent update to the issue
None
Table 3: Type-specific attributes
The following attributes are not common to all six code scan issue types. Attributes shared by more than one type are listed once under a shared grouping, with the owning types identified. The remaining attributes are exclusive to a single type and are listed under that type.
Shared by more than one type
Prioritization Labels
IaC Drifts, IaC Misconfigurations, Malicious Packages, Secrets, Vulnerabilities
Exposed
The prioritization signals applied to the issue. Not available in the Licenses table
Domain Provider
IaC Drifts, IaC Misconfigurations, Secrets, Vulnerabilities
Hidden
The cloud provider domain associated with the issue. Not available in the Licenses or Malicious Packages tables
Package
Licenses, Malicious Packages, Vulnerabilities
Exposed
The dependency package the issue was detected on
Root Package
Licenses, Malicious Packages, Vulnerabilities
Hidden
The top-level dependency that transitively introduces the affected package
Dependency Path
Licenses, Malicious Packages, Vulnerabilities
Hidden
The full dependency chain from the root package to the affected package
Package Manager
Licenses, Malicious Packages
Hidden
The package manager that resolves the dependency. Not available in the Vulnerabilities table
Dependency Type
Licenses, Malicious Packages
Hidden
Whether the dependency is direct or transitive. Not available in the Vulnerabilities table
Resource
IaC Drifts, IaC Misconfigurations
Exposed
The infrastructure resource the issue was detected on
YOR Trace ID
IaC Drifts, IaC Misconfigurations
Hidden
The YOR trace identifier that links the IaC resource to the deployed resource
Internet Exposed
IaC Drifts, IaC Misconfigurations
Hidden
Whether the affected resource is reachable from the internet
Vulnerabilities only
CVE ID
Hidden
The Common Vulnerabilities and Exposures identifier, such as CVE-2021-44228
CVSS Score
Hidden
The Common Vulnerability Scoring System score (0.0–10.0) assigned to the CVE
wfgsdbgsEPSS Score
Hidden
The Exploit Prediction Scoring System probability (0.0–1.0) indicating the likelihood of exploitation in the wild within the next 30 days
KEV Status
Hidden
Whether the CVE is listed in the CISA Known Exploited Vulnerabilities catalog
Reachability
Hidden
Whether the vulnerable function in the package is reachable from the application code: Reachable, Not Reachable, or No Data
Fix Version
Hidden
The minimum package version that resolves the vulnerability
License Type
Hidden
The open-source license of the vulnerable package, such as MIT, Apache-2.0, or GPL-3.0
IaC Misconfigurations only
Code Snippet
Hidden
The excerpt of the resource block that contains the misconfiguration
Is Deployed
Hidden
Whether the misconfigured resource is deployed to a runtime environment
Is Fixable
Hidden
Whether an automatic fix is available for the misconfiguration
Affected Assets Count
Hidden
The number of assets affected by the misconfiguration
IaC Framework
Hidden
The infrastructure-as-code framework the template is written in
Resource Type
Hidden
The resource type the misconfiguration was detected on
Compliance Standards
Hidden
The compliance standards the misconfiguration violates
Secrets only
Secret Type
Exposed
The credential type that was detected
Validation
Hidden
Whether the detected credential was confirmed valid against the issuing provider
Repository Visibility
Hidden
Whether the repository containing the credential is public or private
Number of Occurrences
Hidden
The number of times the credential appears
Detected in Git History
Hidden
Whether the credential appears in the Git commit history in addition to the current revision
Commit
Hidden
The commit that introduced the credential
Secret Hash
Hidden
The hash of the detected credential value
IaC Drifts only
Declared Value
Hidden
The value declared in the infrastructure-as-code template
Runtime Value
Hidden
The value observed on the deployed resource
Cloud Account
Hidden
The cloud account that hosts the drifted resource
Application Criticality
Hidden
The business criticality of the application associated with the drifted resource
Privileged Capabilities
Hidden
The privileged capabilities the drifted resource holds
Malicious Packages only
Advisory ID
Hidden
The identifier of the advisory that confirms the package as malicious
Advisory Link
Hidden
A link to the advisory that confirms the package as malicious
Malicious Package Type
Hidden
The attack class of the malicious package
Intelligence Updated
Hidden
The timestamp when the threat intelligence for the package was last updated
Licenses only
License
Exposed
The open-source license attached to the package
License Category
Hidden
The risk category the license is classified into
SPDX Identifier
Hidden
The SPDX short identifier of the license
OSI Approved
Hidden
Whether the license is approved by the Open Source Initiative
Attribute coverage summary
IaC Misconfigurations
7
33
40
12
Vulnerabilities
7
33
40
12
IaC Drifts
7
31
38
10
Malicious Packages
7
31
38
10
Licenses
7
30
37
9
Secrets
7
30
37
9
Last updated
Was this helpful?
