Reading your results

What your grade, score and severities mean, what new and resolved findings are, and where to see changes over time.

What it is

Every scan gives each repository a security score from 0 to 100 and a grade from A to F, and lists its findings: the problems it found.

Who gets it

Every plan sees grades, scores and finding counts. Cloud and Cloud Plus also see each finding's details, the Findings page list and filters.

How to use it

Your score and grade

The score starts at 100 and goes down for each open finding:

Severity Points off
Critical 25
High 15
Medium 5
Low 0
Grade Score
A 90 and above
B 80 to 89
C 70 to 79
D 60 to 69
F below 60

The Overview shows one score across your repositories. App URLs are graded on their own and don't change it. See App URLs.

Severities

  • Critical: an attacker can likely use this now, for example a leaked secret key or a database anyone can read. Fix today.
  • High: a serious weakness. Fix before your next release.
  • Medium: worth fixing; less likely to be used on its own.
  • Low: good practice; doesn't lower your score.

New, open, resolved

  • New: first seen in the latest scan. Marked NEW.
  • Open: still present.
  • Resolved: no longer found. SafeWeave marks it resolved after the next scan.
  • Reopened: came back after being resolved.
  • False positive: you dismissed it. See Fixing issues.

On a repository page, switch between Open, Resolved, Reopened and False positives.

The Findings page

Click Findings in the sidebar to see every open finding across your repositories, worst first.

  • Search by title, rule, file, CWE or repository.
  • Click Critical, High, Medium or Low to filter by severity.
  • Choose a repository in All repositories.
  • Click a row to open the finding.

The Findings page with search and severity filters

  • History lists every scan, newest first, grouped by day. Click View scan → to open one, and Load older scans to see more.
  • Trends shows how findings and scans changed over 7d, 14d, 30d or 90d, for all repositories or one.

The Trends page

What you'll see

The Overview sums it up: Security score, Open findings, Scans in the last 7 days, and what's connected. Fix first lists the critical and high findings to start with.

Limits

  • On Free, the Findings page and repository pages show counts per severity. Click Start 14-day free trial to see the list.

If something goes wrong

  • "No open findings" right after connecting: the repository hasn't been scanned yet. Click Scan now on Repositories.
  • "Not enough scan history yet" on a repository's trend chart: trends appear after a few scans.
  • "Could not load findings.": reload the page.