Skip to content

Set a repository's risk profile

Documentation Index

Fetch the complete documentation index at: https://docs.sourcery.ai/llms.txt

Use this file to discover all available pages before exploring further.

A finding on a public, customer-facing service is more urgent than the same finding on an internal tool. Set a repository’s risk profile to tell Sourcery which kind of repository it is. Sourcery weights severities to match.

A risk profile has two dimensions:

DimensionChoices
Network exposurePublic network, internal only
Data sensitivityCritical, high, standard, low, none

The more exposed the network and the more sensitive the data, the more Sourcery raises the severity of findings in that repository. Sourcery treats a repository with no profile as standard data sensitivity and makes no network-exposure adjustment.

  1. Open the repositories page

    Go to Repositories and find the repository.

  2. Choose its exposure and sensitivity

    Set the network exposure and data sensitivity that describe how this repository is deployed and what data it handles.

  3. Save

    Save the profile. It applies on the repository’s next scan.

A risk profile feeds severity scoring, which happens at scan time. Setting a profile does not re-score what is already on screen. On the next scan, Sourcery re-scores the repository’s findings with the new profile. If you’d rather not wait for the schedule, queue a scan to pick it up sooner.