Using exports to globally review findings

Security for Bitbucket exports can be used to globally review findings, using the following steps.

  1. Generate an export that contains the findings that you want to review.

  2. Locate the “Match text” column, and copy it to another spreadsheet:

Screenshot 2023-07-31 at 1.30.44 PM-20230731-183106.png
The “Match text” column in an export
image-20230731-183203.png
The “Match text” column in a new spreadsheet

If the “Include full finding text in exported reports” setting is disabled, then the “Match text” column won’t be present.

  1. Edit the spreadsheet. Delete any rows which are legitimate scan findings, leaving only things you want to mark as false positives, revoked credentials, etc.

  2. Export the spreadsheet as a CSV.

  3. Upload it on the settings page using the “Add reviewed” button under the “Globally Review Findings” heading.

image-20231116-234011.png