Set a repository's risk profile
Documentation Index
Fetch the complete documentation index at: https://docs.sourcery.ai/llms.txt
Use this file to discover all available pages before exploring further.
A finding on a public, customer-facing service is more urgent than the same finding on an internal tool. Set a repository’s risk profile to tell Sourcery which kind of repository it is. Sourcery weights severities to match.
The two dimensions
Section titled “The two dimensions”A risk profile has two dimensions:
| Dimension | Choices |
|---|---|
| Network exposure | Public network, internal only |
| Data sensitivity | Critical, high, standard, low, none |
The more exposed the network and the more sensitive the data, the more Sourcery raises the severity of findings in that repository. Sourcery treats a repository with no profile as standard data sensitivity and makes no network-exposure adjustment.
Set the profile
Section titled “Set the profile”-
Open the repositories page
Go to Repositories and find the repository.
-
Choose its exposure and sensitivity
Set the network exposure and data sensitivity that describe how this repository is deployed and what data it handles.
-
Save
Save the profile. It applies on the repository’s next scan.
When it takes effect
Section titled “When it takes effect”A risk profile feeds severity scoring, which happens at scan time. Setting a profile does not re-score what is already on screen. On the next scan, Sourcery re-scores the repository’s findings with the new profile. If you’d rather not wait for the schedule, queue a scan to pick it up sooner.