Features and capabilities

Scoped policy, risk acceptance, and download decisions

Turn organization-, project-, or repository-scoped rules into traceable PASS, WARN, or BLOCK decisions.

Content statusVerified in sourceDocumentation versionLatest

Policy scope

Severity rules are applied through priority and scope resolution; results and later reevaluations remain in history.

Risk acceptance

Exceptions are recorded with scope, reason, reference, and expiry; task and audit history remain durable.

Decision outcomes

Policy evaluation can produce PASS, WARN, BLOCK, or NOT_EVALUATED when required context is absent. Whether consumed during scanning, proxy resolution, or CI/CD, the result must remain traceable to policy revision, scope, and evaluation identity.

  • Organization, project, and repository scope plus rule priority selecting the expected policy
  • Separate testing of severity threshold boundaries for PASS, WARN, and BLOCK results
  • Policy changes producing reevaluation without deleting historical results
  • Firewall or CLI results reconciling with the durable policy-evaluation record

Risk-acceptance lifecycle

Risk acceptance is not an unbounded bypass. Target finding or scope, rationale, reference, expiry, and creating actor are recorded, and creation starts reevaluation. After expiry or revocation, applicable policy must apply again while history remains preserved.

Analysis boundary

Within verified scope, decision inputs are OSV vulnerability data and severity or policy rules. Do not interpret results as malware, license, namespace-confusion, or quarantine decisions. The organization must separately define approval, duration, and review policy for WARN and risk acceptance.