For issues detected in the course of static application security testing, there is triage, i.e, AI-generated tips with risk and criticality assessment, false positive probability analysis, and possible fixes.
On the Home tab, navigate to Repositories and select a repository.
Navigate to one of these sections on the repository page under Security:
Secret scanning: List of detected secrets.
Code scanning: List of SAST issues.
In the top-right corner, click Triage with AI.
In the window that opens, in the Minimum severity field, select the minimum alert severity level for the AI to initiate triage: Critical, High, Medium, or Low. Only alerts with this severity or higher will be triaged.
Click Triage alerts.
Once prioritization is complete, an additional icon displaying the AI-estimated severity rating will appear next to each triaged alert in the list.