Skip to content

Match equivalent findings across Standard and Deep scans #669

Description

@soyeon-oai

Standard and Deep scans of the same repository revision can assign different identity.anchor values to the same vulnerability. Consequently, scans compare may report the previous finding as unknown and the equivalent new finding as newly introduced.

Reproduction: run both scan modes against the same synthetic vulnerable repository, then compare their results.

Expected: equivalent findings with matching vulnerability families and source locations remain identifiable across scan modes.

Activity

  1. su-jin1425 commented on Aug 28, 2026

    @su-jin1425

    Hi, I’d like to work on this issue. I’ll investigate how identity.anchor is generated across Standard and Deep scans, identify why equivalent findings receive different anchors, and add a fix with regression tests. I’ll share my plan ASAP. Please confirm before I start investigating and implementing a fix.

  2. added a commit that references this issue on Sep 8, 2026
    18bacf8
  3. IvanCaceres commented on Sep 9, 2026

    @IvanCaceres

    I've opened a PR to fix this issue #832

  4. added
    area:findingsFinding schemas, identity, deduplication, severity, and comparison decisions.
    bugSomething isn't working
    on Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:findingsFinding schemas, identity, deduplication, severity, and comparison decisions.bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions