Skip to main content
Each finding has one category. Each category has a risk type. The web app shows the category name. The ID is the value that Vidoc stores.

Risk types

Vidoc does not write pull request (PR) comments for compliance findings. These findings show in the web app. For the other rules about which findings go to the PR, refer to How Vidoc works.

Attack categories

Compliance categories

¹ Sensitive data logging. The web app shows the ID of this category.

Other categories

Vidoc does not do software composition analysis (SCA). It does not compare the versions of your third-party libraries with vulnerability databases.