Sometimes, Security for Jira will find false positives, credentials which have already been revoked, etc. If this happens, you can review the scan finding. This marks the finding, as well as any other findings which exactly match it, as reviewed in current and future scans.
In the Soteri Dashboard, reviewed false positives are not counted towards the total scan finding count when determining if a space is secure.
Reviewing a finding from the Security Analysis
To review a finding, click the finding’s menu button, then select Mark reviewed. This will open a confirmation dialog.
Marking a finding as reviewed saves the exact string captured by the rule (in this case, AKIAIO5FODNN7EXAMPLE). That exact string will be marked as reviewed for all existing and future scans, even if the original finding is deleted.
A reviewed false positive can be scoped in three different ways:
-
Just the content it appears in (work item description, comment, or attachment).
-
To the entire space.
-
Globally, to the entire Jira instance.
-
This scope is only shown to Jira administrators and those granted explicit app access.
-
Some findings cannot be reviewed at space level or higher (because they do not capture the entire secret). These can can be reviewed at content level only.
A reason category and additional notes can also be supplied. To make sure the reviewer is always required to supply a reason when reviewing, enable the Require a reason when reviewing false positives toggle in settings.
Once reviewed, you can click Reviewed to change the review scope and/or reason, or remove the review.
Reviewed false positives are stored independently of any findings. In other words, after clicking Mark reviewed on a finding, that reviewal persists and marks all future matching results as reviewed, even if the original finding is deleted.
Reviewed details may be seen by hovering over the Reviewed status.
Exporting reviewed false positives
Information about reviewed false positives, such as who marked them reviewed and when, may be exported from the Security Analysis by clicking Export Space and then Reviewed False Positives.
You can export reviewed space and content scoped false positives in all your spaces from the Soteri Dashboard.
Reviewing findings globally in bulk
Jira administrators and users granted explicit app access can add reviewed false positives which apply across all spaces in your Jira instance using a bulk CSV upload workflow.
Findings which match any of the global false positives show up as “Globally Reviewed” on the Security Analysis page.
Bulk adding new global false positives
Navigate to the settings page. Then, click on the “Add Reviewed” button under “Globally review false positives”:
Clicking on this button will open a modal which allows you to download a template for adding global false positives, and select an existing file to upload.
Uploaded files should be CSVs that have a column titled Match text (like exports). Every row will be interpreted as a case-sensitive globally reviewed text to add.
You can also optionally add Reason category and Reason notes columns to the upload to note reasons and notes about the review. If the Require a reason when reviewing false positives toggle is enabled, the Reason category and Reason notes columns will be required.
Note that some spreadsheet software—notably Microsoft Excel—rounds numbers and/or displays them in scientific notation by default. We recommend LibreOffice, Apple Numbers, or Google Sheets instead to edit uploads.
Bulk deleting globally reviewed false positives
Navigate to the settings page. Then, click on the “Remove Reviewed” button under “Globally review false positives”:
Clicking on this button will open a modal which allows you to download a template for removing globally reviewed false positives, and select an existing file to upload.
Uploaded files should be CSVs with a column titled Match text. Every row will be interpreted as a case-sensitive globally reviewed text to remove.
Exporting globally reviewed false positives
Navigate to the settings page. Then, click on the “Export” button under “Globally review false positives”:
Exports are in CSV format and include:
-
The exact text that is considered reviewed
-
Who reviewed it
-
When it was reviewed
-
If present, a review reason category
-
If present, review notes