For the complete documentation index, see llms.txt. This page is also available as Markdown.

Investigate issues with C2C

Vulnerabilities and IaC Misconfiguration issues include a Code to Cloud tab in the issue side panel. The tab traces the specific defect from the code file to the impacted runtime resource, helping the investigator verify whether a vulnerability is actively deployed before prioritizing remediation.

When to investigate issues: Because the trace originates from the specific issue rather than from the asset as a whole, issue investigation is the surface to use when the question is is this specific vulnerability live in production, as distinct from is this asset fully traced (the Code-to-Cloud tab) or how many assets like this one are untraced (the Coverage dashboard).

For information on CVE Vulnerabilities, refer to Software Composition Analysis (SCA) vulnerability issues.

For information on IaC misconfiguration issues, refer to Infrastructure as Code (IaC) misconfiguration scanner.

Last updated

Was this helpful?